Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies will need to have in place in the event a security breach or system failure occurs, or in case the system is challenged in court. This is particularly important with respect to the type of evidence required and admissible with respect to election technology, and to establish a chain of evidence that can be used in future legal challenges. ICT officials need to work closely with legal officials within an EMB to address this vulnerability. As with all aspects of the electoral process, positive public perceptions and public trust are critical to the credibility of elections and the acceptance of results. The HEAT process is designed to help reinforce with political stakeholders and the public the risk-mitigation measures inherently needed for the proper use of election technology and the importance of contingency planning. Ultimately, the HEAT process aims to increase public confidence in the electoral process and help EMBs to exercise and document due diligence measures. However, because the HEAT process focuses on identifying vulnerabilities, it must be carefully managed and communicated to build, rather than erode, public confidence in the EMB and in the technology. Hence, an EMB must ensure it has enough time and resources to address the issues that are found, or these vulnerabilities could be exploited to call into question various aspects of the process, from the validity of the voter register, through to the legitimacy of the election result. b) Outlining the HEAT Process Identify The responsible EMB personnel identifies the election data management technology or technologies that should be HEATtested. Collect The responsible EMB personnel collects and collates all relevant information for the HEAT team and conducts a systemsmapping exercise to visualize linkages and information flow between institutions and individuals. Expose Using the five types of exposure, the HEAT team tests the technology and the human, legal and procedural framework in which it is deployed, identifying and documenting specific vulnerabilities. Exploit Drawing on the specific vulnerabilities identified, the HEAT team guides responsible EMB officials through a tailored election simulation to test EMB responses to specific forms of exploitation. Adapt The EMB and HEAT team will jointly identify and prioritize actions to address vulnerabilities that were not satisfactorily mitigated in the exploitation phase, with the ultimate goal of minimizing levels of exposure across the five dimensions. Identify The HEAT process is designed to be EMB-led and provide a capacity-building element for the EMB, as opposed to an external assessment. As such, the first step of the HEAT process is undertaken by the 29

Select target paragraph3