Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
EMBs also typically lack comprehensive cybersecurity strategies. If an EMB does not lay down their
system design in detail, they will not be fully aware of its potential vulnerabilities and the security
assumptions they make. If they do not evaluate potential threats, both internal and external, they will
not be able to prepare themselves for cyberattacks. And if they do not collaborate with external
institutions, such as consulting their country’s CERT organization and data security standards, they may
fail to employ best practices in cybersecurity. After introducing EVMs, the Indian Election Commission
claimed their machines were invulnerable to attacks. When a group of ICT experts published a paper in
2010 arguing that the EVMs were in fact susceptible to cyberattacks, police arrested one of the writers
and researchers, interrogating him over how he had accessed one of the machines (he was released
soon after).100 In 2013, the Supreme Court of India validated the experts and ordered the phasing-in of
VVPATs for the machines. VVPATs are now used in Indian elections as a back-up security measure. EMBs
must be aware of the security flaws in their technologies and plan accordingly.
IV. Holistic Exposure and Adaptation Testing (HEAT) Process
a)
What Is a HEAT Process and What Is It Not?
IFES’ HEAT process (currently in final development and outlined below) is a process for simultaneously
identifying and testing the potential exploitation of vulnerabilities in the use of election data
management technology. HEAT tests the technology itself, as well as the legal and operational
frameworks in which the technology is being deployed. In contrast to a technology certification or basic
testing process, the HEAT process is a holistic way to examine vulnerabilities and ensure they can be
corrected, communicated, or managed. For example, in a traditional certification process, a certain
technology platform may be tested to ensure that data is secure. The process would not, however,
prepare the EMB for a simple website disruption that could severely damage the institution’s credibility
with the public, regardless of whether the data remains free of errors or incursions.
The HEAT process is not intended to provide certification of any systems. Technology certification is a
specific process of evaluating voting hardware and software to ensure they provide all the basic
functionality, accessibility, and security capabilities required. There are various challenges associated
with pure “certification” processes in practice, in which only the hardware or software is considered in
isolation from the wider electoral environment. In 2010, the Philippines COMELEC sought a vendor to
certify their EVMs. It was clear from the outset that any company contracted for certification would
identify several potential security flaws and would make recommendations to absolve themselves if
anything went wrong. The company ultimately chosen, SysTest Labs, noted that the EVMs were
appropriate for their intended use, but only under certain conditions. SysTest Labs recommended
adequate safeguards and procedures, including a “statistically significant random manual audit” and a
disaster recovery plan. They recognized risks to using the machines, and their recommended procedures
were meant to detect potential flaws and to scrap the automation if necessary, even mid-election. In
100
Matt Ford, “Indian Democracy Runs on Briefcase-Sized Voting Machines,” The Atlantic, April 15, 2014,
https://www.theatlantic.com/international/archive/2014/04/indian-democracy-runs-on-briefcase-sized-votingmachines/360554/.
27