International Foundation for Electoral Systems Exploit Drawing on the specific vulnerabilities identified during steps two and three, the HEAT team will guide responsible EMB officials through a tailored election simulation tabletop exercise (TTX) to test EMB responses to specific forms of exploitation. A TTX is a training simulation that mirrors real-world conditions, uses an accelerated timeline to increase pressure, gives everyone a role with corresponding responsibilities, and enables participants to absorb information, make decisions, and execute plans. It is similar to the “red-teaming” process used by the U.S. Department of Defense to “challenge emerging operational concepts in order to discover weaknesses before real adversaries do.”104 The HEAT team will draw on the vulnerabilities identified in step three of the HEAT process and test participant responses as these vulnerabilities emerge or are exploited in a simulated environment. This step has two purposes – testing existing capacity and responses of EMB officials and serving as a more impactful learning exercise for officials who will be responsible for making necessary changes to reduce EMB cybersecurity exposure. Lower-level commissions require substantial training related to the election process, in general, and cybersecurity is no exception. The TTX can help reveal and emphasize for EMB officials the exact training needs required for different staff in the EMB, for example around cyber hygiene and spear-phishing. Adapt The final step of the HEAT process is a collaborative de-briefing exercise and strategy session with the relevant EMB officials. This session will aim to identify and prioritize actions to address vulnerabilities that were not satisfactorily mitigated in the exploitation phase, with the ultimate goal of minimizing levels of exposure across the five dimensions. The session will consider who has responsibility to fix or correct vulnerabilities, short and long-term cost considerations, time considerations, and transparency and communication. In terms of technology exposure, some of the essential tools that EMBs might consider using to avoid system crashes are carefully designing systems, testing, set-up, configuration, piloting, audits and contingency planning. EMBs should have back-up plans for new systems, including the possibility to revert to old systems in the event of a crisis. For example, if seat allocation is relatively complex, the EMB that bears responsibility may decide not to rely exclusively on software being used for the first time, even if that software has been tested.105 EMBs should have advanced network-monitoring capabilities to determine with some level of certainty the nature of events that occur in its systems. Having a strategy in place would allow EMBs to react quickly, apply contingency plans, or restore from backups. 104 Defense Science Board Task Force, The Role and Status of DoD Red Teaming Activities, United States Department of Defense, 2003, https://fas.org/irp/agency/dod/dsb/redteam.pdf. 105 In Denmark during the 2009 European Parliament elections, Statistics Denmark used seat allocation software but also informally had MS Excel spreadsheets as a backup to check that their calculations were correct. 32

Select target paragraph3