Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
I. Introduction
In June 2017, 100 election experts from across the United States penned an open letter to Congress
noting that many jurisdictions were “inadequately prepared to deal with rising cybersecurity risks.”1 This
concern is echoed globally, as increasing reliance on complex technology-based systems in electoral
processes has left troves of sensitive information potentially vulnerable to adversaries.2 Experiences in
several recent elections around the world highlight threats to cybersecurity, as well as how the
implementation of certain electronic data management technologies can impact post-election disputes.3
However, many election management bodies (EMBs) lack the capacity, resources, or appropriate
framework to test whether their data management systems are secure from these vulnerabilities, and to
put measures in place well in advance of elections to protect data integrity.
Cybersecurity4 should be considered and implemented at the inception phase of building or upgrading
any technology-based election system, as a key component of digitizing specific elements of election
administration. At the same time, international good practices around cybersecurity and open data
require EMBs to act transparently and to ensure election results are verifiable and can ultimately be
accepted by the electorate. Therefore, it is important to protect both cybersecurity and transparency in
the electoral context – a challenge that is particularly unique to EMBs.5
Beyond striking this balance, election administrators must focus on cybersecurity as an ongoing and
ever-changing concern. As soon as cybersecurity good practices are developed, they may become
outdated, because technology moves forward very quickly, as does the technical expertise of those who
seek to find and exploit its vulnerabilities. While it is important to learn from experience, rapid
technological innovation means that EMBs should endeavor to secure the next election, not focus on
vulnerabilities in the last election. This means identifying potential future vulnerabilities, not only
addressing issues that have been identified or exposed in the past.
1
“Election Integrity Open Letter to Congress,” National Election Defense Coalition,
https://www.electiondefense.org/election-integrity-expert-letter/.
2
Reuters, “Two 11-year-olds altered election results in hacker convention’s replica of U.S. voting system,” CBC,
August 14, 2018, https://www.cbc.ca/news/technology/def-con-hacking-convention-voter-village-1.4784803.
3
For example, electronic transmission of results at the polling station level or maintenance of national biometric
voter registration databases, but also penetration of less high-profile databases such as personnel records for ad
hoc staff, that could undermine the public’s confidence in the EMB and its capacity to secure more sensitive
databases.
4
A note on definitions: In this paper, IFES uses the terms “cybersecurity,” “data security” and “data protection”
interchangeably, in line with ISO standards and academic literature. See, for example, Basie Von Solms, Rossouw
von Solms, "Cyber security and information security – what goes where?", Information & Computer Security,
https://doi.org/10.1108/ICS-04-2017-0025, which offers a definition that: "Cyber Security [is] part of Information
Security, which specifically focuses on protecting the Confidentiality, Integrity and Availability (CIA) of digital
information assets against any threats, which may arise from such assets being compromised via (using) the
Internet.”
5
For example, other agencies such as defense, or institutions such as banks or insurance agencies, can focus
primarily on cybersecurity without the same transparency concerns.
3