International Foundation for Electoral Systems
Exploit
Drawing on the specific vulnerabilities identified during steps two and three, the HEAT team will guide
responsible EMB officials through a tailored election simulation tabletop exercise (TTX) to test EMB
responses to specific forms of exploitation. A TTX is a training simulation that mirrors real-world
conditions, uses an accelerated timeline to increase pressure, gives everyone a role with corresponding
responsibilities, and enables participants to absorb information, make decisions, and execute plans. It is
similar to the “red-teaming” process used by the U.S. Department of Defense to “challenge emerging
operational concepts in order to discover weaknesses before real adversaries do.”104 The HEAT team will
draw on the vulnerabilities identified in step three of the HEAT process and test participant responses as
these vulnerabilities emerge or are exploited in a simulated environment. This step has two purposes –
testing existing capacity and responses of EMB officials and serving as a more impactful learning exercise
for officials who will be responsible for making necessary changes to reduce EMB cybersecurity
exposure. Lower-level commissions require substantial training related to the election process, in
general, and cybersecurity is no exception. The TTX can help reveal and emphasize for EMB officials the
exact training needs required for different staff in the EMB, for example around cyber hygiene and
spear-phishing.
Adapt
The final step of the HEAT process is a collaborative de-briefing exercise and strategy session with the
relevant EMB officials. This session will aim to identify and prioritize actions to address vulnerabilities
that were not satisfactorily mitigated in the exploitation phase, with the ultimate goal of minimizing
levels of exposure across the five dimensions. The session will consider who has responsibility to fix or
correct vulnerabilities, short and long-term cost considerations, time considerations, and transparency
and communication.
In terms of technology exposure, some of the essential tools that EMBs might consider using to avoid
system crashes are carefully designing systems, testing, set-up, configuration, piloting, audits and
contingency planning. EMBs should have back-up plans for new systems, including the possibility to
revert to old systems in the event of a crisis. For example, if seat allocation is relatively complex, the
EMB that bears responsibility may decide not to rely exclusively on software being used for the first
time, even if that software has been tested.105 EMBs should have advanced network-monitoring
capabilities to determine with some level of certainty the nature of events that occur in its systems.
Having a strategy in place would allow EMBs to react quickly, apply contingency plans, or restore from
backups.
104
Defense Science Board Task Force, The Role and Status of DoD Red Teaming Activities, United States
Department of Defense, 2003, https://fas.org/irp/agency/dod/dsb/redteam.pdf.
105
In Denmark during the 2009 European Parliament elections, Statistics Denmark used seat allocation software
but also informally had MS Excel spreadsheets as a backup to check that their calculations were correct.
32