Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies e) Case Law Several recent cases in national courts have provided various precedents on cybersecurity in elections centered on the following issues: implementation and transparency of technology in Kenya; electronic voting machines (EVMs) in India, Germany, and Finland; e-voting in Estonia and Austria; and cybersecurity in the Philippines, all of which are discussed below. Together, the cases highlight the importance of a verifiable paper trail for the voting and counting process, transparent tabulation and certification of results, clear procedures and instructions for using technology, equality among voters, and the importance of having cybersecurity policies and practices in place. Implementation and Transparency of Election Technology In its judgment annulling the August 2017 Kenyan presidential elections, the Supreme Court ruled that the Independent Electoral and Boundaries Commission (IEBC) had failed to adhere to legal requirements for “free and open elections.” The election results were finalized and announced based on information from tabulated results forms (34B) that came from centralized tallying centers, instead of waiting until the IEBC received all original results forms (34A) from individual polling stations. The court focused on the IEBC’s failure to provide full access to its servers and server logs and its failure to provide a plausible explanation for results released based on incomplete information. The court stated it “had no choice” but to accept the petitioners’ claim that either the servers were infiltrated and the data compromised, or the IEBC itself had intentionally or unintentionally compromised the data.66 Multiple errors in implementing technology were referenced in the decision, including interruptions on data mobile coverage without an adequate backup plan and discrepancies between results published on the website and official results released when compared to the breakdowns of results transmitted from polling stations to the National Tallying Center. Use of Electronic Voting Machines (EVMs) Courts in India, Germany and Finland have all ruled on EVMs, focusing on the use of VVPATs to authenticate results, voting technology that is understandable to the average voter, and clear instructions for EVMs, respectively. In its judgment of October 8, 2013, the Supreme Court of India directed the government to fund the gradual phase-in of VVPATs, agreeing with the petitioner that a paper trail is a vital security measure for e-voting. Although the Indian Election Commission (IEC) was able to print records from their EVMs with a decoder device, the court ruled that VVPATs were also necessary. The IEC claimed that it had tested VVPATs in field trials and had not yet adopted them on the basis of those trials. The court noted that “[f]rom the materials placed by both the sides, we are satisfied that the ‘paper trail’ is an indispensable 66 See section 279 of Odinga and Musyoka v. IEBC et al. (Supreme Court of Kenya 2017): “The IEBC in particular failed to allow access to two critical areas of their servers: its logs which would have proved or disproved the petitioners’ claim of hacking into the system and altering the presidential election results and its servers with Forms 34A and 34B electronically transmitted from polling stations and CTCs.” 15

Select target paragraph3