Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
between hardware and software, or the wholescale introduction of new hardware and software into an
electoral process. Both can produce vulnerabilities, but systems integration can give rise to unique
challenges, particularly where a new solution is essentially “bolted on” to an existing system or platform.
The level of public trust and confidence in the electoral process and the EMB specifically must also be
taken into account when deciding whether to implement new election technology.40 If public trust in the
electoral process is already low, introduction of a new system may cause public unrest.41 Rather,
technology should be introduced at a stage when all electoral stakeholders enjoy significant trust in the
process, rather than attempting to use technology to mask the problems. In terms of confidencebuilding measures, IFES has previously noted that, while fully open source code for technology platforms
may not be necessary, it is the more preferable option to support transparency and public trust.42 A
growing number of governments are requiring open source technologies, which can aid with re-use,
integration, and standardization, while also making the technology more sustainable and cost-effective.
Open source solutions are also inherently transparent, which can improve credibility with stakeholders
and avoid vendor or implementer lock-in or conflict of interest. Should open source code not be used,
IFES has noted that “experts representing key electoral stakeholders (political actors and civil society)
should be allowed sufficient access to review the source code and should not be restricted in reporting
their analysis of its content by the use of any non-disclosure agreements (NDAs).”43 In cases where open
source technologies are not or cannot be used, NDAs should be pre-negotiated as part of the
procurement process to protect the intellectual property of the technology providers and to ensure that
critical stakeholders, such as political parties, observers, and election commissions, have access to the
code in order to rigorously test the security and functionality of the technology and maintain minimum
levels of public trust.
To build trust, the Council of Europe recommends public debates or consultations that include all voters.
These public outreach activities should lead not only to greater trust in the technology itself but to
greater trust in the implementers of the new technology, which is equally important. International
IDEA’s recommendations include releasing the results of pre-implementation testing, auditing the new
technology regularly, and developing and publicizing clear policies “that cover all aspects of technology
use.”44 Specific tools that provide independent ways to test the system, such as voter verified paper
audit trails (VVPATs) and post-election audits of technology systems, are also a good means to gain
public trust and secure against fraud.45 Public communication around contingency planning is also
40
European Commission, Methodological Guide on Electoral Assistance, 57.
Council of Europe, “Guidelines on the implementation of the provisions of Recommendation CM/Rec (2017) 5 on
standards for e-voting,” CM-Rec(2017)50, June 14, 2017.
42
Ben Goldsmith and Holly Ruthrauff, Implementing and Overseeing Electronic Voting and Counting Technologies,
IFES and NDI, 2013, 175-176.
43
Ben Goldsmith and Holly Ruthrauff, Implementing and Overseeing Electronic Voting and Counting Technologies,
IFES and NDI, 2013, 175-176.
44
Helena Catt, et al., Electoral Management Design, revised ed., International IDEA, (Stockholm, Sweden: 2014)
266-267.
45
European Commission, Methodological Guide on Electoral Assistance, 63.
41
11