Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
exposure, as summarized in the text box). This process encourages a more holistic assessment of what
could go wrong in data and technology management and allows the EMB to identify strategies to reduce
or eliminate different types of exposure in a systematic manner.
Because the HEAT process seeks to provide a holistic approach to cybersecurity in elections, we have
drawn lessons from international principles, election cybersecurity case studies, risk-mitigation
methodologies and technology-related election court judgments. The proposed process is also guided by
international best practices on data management and cybersecurity, as well as transparency, open data
and privacy.
A thorough HEAT process, as described in this paper, has significant time and cost implications.
However, without such a process in place, an EMB may experience an electoral crisis that far exceeds
the time and resources invested in such a risk-mitigation process. It is important to note that a HEAT
process is only suitable for the earlier part of the electoral cycle when there is significant time for the
EMB to implement measures to mitigate identified deficiencies. While the HEAT process itself may be
achievable in a short time period, it is often the case that cyber vulnerabilities cannot be addressed by
“quick fixes,” but require significant lead time to address properly. For example, if certain legal or
procedural vulnerabilities are revealed, several months or more may be required to draft or pass
amendments, or to adjust procedures and then train and publicize new procedures effectively. If a HEAT
process is conducted and reveals vulnerabilities too close to an election to be able to rectify, this could
then have an adverse effect on stakeholder confidence in the electoral process.7 This is particularly true
in environments with pre-existing low trust.
This paper outlines the existing literature on cybersecurity and data protection in elections, including
international standards, good practice guidelines, cybersecurity frameworks, election observer
guidelines, and jurisprudence. This literature is then applied to discuss the various types of exposure
EMBs may face when implementing technology and seeking to protect data and data processing in
elections. This application is important, as while much of the standard-setting is taking place in North
America and Europe, in IFES’ experience many developing democracies outside of these regions are also
considering and using election technologies. Finally, the paper introduces the IFES HEAT process as a
holistic tool for identifying and mitigating different types of cybersecurity exposure in elections.
II. Literature Review
a)
International and Regional Standards for Cybersecurity in Elections
International standards for elections provide the basis for assessing the introduction of technology into
the electoral process. Any introduction of technology must promote core election principles, such as
7
The Venice Commission’s Good Practice in Electoral Matters,
http://www.venice.coe.int/webforms/documents/default.aspx?pdffile=CDL-AD(2002)023rev-e, includes a
provision that the fundamental elements of the election legislation should not be fundamentally amended one
year prior to a forthcoming elections.
5