Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies Election Commission (IEC) contracted an international vendor to centralize and digitize the voter register into a single national database that promised biometric de-duplication through fingerprint matching. The 2011 presidential election was held on the basis of the new centralized register. However, given the specific contractual arrangements and proprietary technology in place with the vendor, the IEC remains unable to independently perform data queries, updates, or de-duplication. In advance of the 2016 presidential election, the IEC paid the vendor nearly half the cost of the entire election for its assistance in undertaking The Gambia’s first and only voter registration update since 2011.90 At a cost of 7.9 Euro per registered voter (comparatively extremely costly), the IEC recorded 89,649 new entries, and made no deletions or address changes.91 It remains unclear whether any de-duplication, the predominant reason to implement biometric technology, was ever performed.92 This also undermines attempts by the EMB to ensure data security on its servers and safeguard the database from leaving its premises. Relying on an external vendor can also result in political exposure, opening up the process to accusations of foreign interference. The Democratic Republic of Congo (DRC) is currently facing controversy over its procurement of EVMs from a South Korean company, Miru Systems. South Korea’s National Election Commission has come out against the decision, saying the machines are ill-suited for the Congolese electoral environment. Opposition in the DRC have objected to the machines too, calling them “cheating machines,” a clear case of the use of a foreign vendor lowering trust and providing a pretext for contesting election results. 93 Following the August 2017 presidential election in Kenya, members of Parliament affiliated with the opposition accused the technology vendor, based in France, of providing kickbacks to the EMB and ruling party, while “willfully allowing” unauthorized access to its systems and therefore abetting rigging.94 At the same time, concerns may be raised around privacy of citizen data, including biometric information – especially in countries that are collecting voter data and do not have data protection laws in place, or where data is kept on servers outside the country, raising the risk that such data could be exploited. There are a number of countries in which the central election authority is a de facto extension of the government, regardless of the EMB’s formal status as an independent commission. In countries where political parties appoint election commission members, the ruling party may have a dominant position. This can lead to data security breaches, such as breaches of voter registration data stored in the central election office. If an IT staffer receives an order from a politicized EMB commissioner to copy the entire voter register onto a USB flash drive, he or she may do it without questioning, fearing repercussion. Such actions may go unrecorded and ultimately unsanctioned. The HEAT process outlined below would 90 The vendor provided new hardware (server and 70 laptops) and the assistance of two external experts. For additional information, please see: UNDP and IFES, Getting to the CORE, A Global Survey on the Cost of Registration and Elections, 2005, http://aceproject.org/ero-en/misc/undp-ifes-getting-to-the-core-a-global-surveyon/view. 92 IFES Electoral Integrity Assessment, The Gambia, 2017. 93 “South Korea election panel attacks DR Congo voting system,” The Sun Daily, April 10, 2018, http://www.thesundaily.my/news/2018/04/10/s-korea-election-panel-attacks-dr-congo-voting-system. 94 Patrick Lang’at and Silas Apollo, “Nasa: We don’t want Al Ghurair and Morpho in poll,” Daily Nation, September 18, 2017, https://www.nation.co.ke/news/politics/Nasa-MPs-raise-bribery-claim-in-Kiems-kits-tender/10644101748-ev0kq3z/index.html. 91 23

Select target paragraph3