Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies EMBs also typically lack comprehensive cybersecurity strategies. If an EMB does not lay down their system design in detail, they will not be fully aware of its potential vulnerabilities and the security assumptions they make. If they do not evaluate potential threats, both internal and external, they will not be able to prepare themselves for cyberattacks. And if they do not collaborate with external institutions, such as consulting their country’s CERT organization and data security standards, they may fail to employ best practices in cybersecurity. After introducing EVMs, the Indian Election Commission claimed their machines were invulnerable to attacks. When a group of ICT experts published a paper in 2010 arguing that the EVMs were in fact susceptible to cyberattacks, police arrested one of the writers and researchers, interrogating him over how he had accessed one of the machines (he was released soon after).100 In 2013, the Supreme Court of India validated the experts and ordered the phasing-in of VVPATs for the machines. VVPATs are now used in Indian elections as a back-up security measure. EMBs must be aware of the security flaws in their technologies and plan accordingly. IV. Holistic Exposure and Adaptation Testing (HEAT) Process a) What Is a HEAT Process and What Is It Not? IFES’ HEAT process (currently in final development and outlined below) is a process for simultaneously identifying and testing the potential exploitation of vulnerabilities in the use of election data management technology. HEAT tests the technology itself, as well as the legal and operational frameworks in which the technology is being deployed. In contrast to a technology certification or basic testing process, the HEAT process is a holistic way to examine vulnerabilities and ensure they can be corrected, communicated, or managed. For example, in a traditional certification process, a certain technology platform may be tested to ensure that data is secure. The process would not, however, prepare the EMB for a simple website disruption that could severely damage the institution’s credibility with the public, regardless of whether the data remains free of errors or incursions. The HEAT process is not intended to provide certification of any systems. Technology certification is a specific process of evaluating voting hardware and software to ensure they provide all the basic functionality, accessibility, and security capabilities required. There are various challenges associated with pure “certification” processes in practice, in which only the hardware or software is considered in isolation from the wider electoral environment. In 2010, the Philippines COMELEC sought a vendor to certify their EVMs. It was clear from the outset that any company contracted for certification would identify several potential security flaws and would make recommendations to absolve themselves if anything went wrong. The company ultimately chosen, SysTest Labs, noted that the EVMs were appropriate for their intended use, but only under certain conditions. SysTest Labs recommended adequate safeguards and procedures, including a “statistically significant random manual audit” and a disaster recovery plan. They recognized risks to using the machines, and their recommended procedures were meant to detect potential flaws and to scrap the automation if necessary, even mid-election. In 100 Matt Ford, “Indian Democracy Runs on Briefcase-Sized Voting Machines,” The Atlantic, April 15, 2014, https://www.theatlantic.com/international/archive/2014/04/indian-democracy-runs-on-briefcase-sized-votingmachines/360554/. 27

Select target paragraph3