Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies I. Introduction In June 2017, 100 election experts from across the United States penned an open letter to Congress noting that many jurisdictions were “inadequately prepared to deal with rising cybersecurity risks.”1 This concern is echoed globally, as increasing reliance on complex technology-based systems in electoral processes has left troves of sensitive information potentially vulnerable to adversaries.2 Experiences in several recent elections around the world highlight threats to cybersecurity, as well as how the implementation of certain electronic data management technologies can impact post-election disputes.3 However, many election management bodies (EMBs) lack the capacity, resources, or appropriate framework to test whether their data management systems are secure from these vulnerabilities, and to put measures in place well in advance of elections to protect data integrity. Cybersecurity4 should be considered and implemented at the inception phase of building or upgrading any technology-based election system, as a key component of digitizing specific elements of election administration. At the same time, international good practices around cybersecurity and open data require EMBs to act transparently and to ensure election results are verifiable and can ultimately be accepted by the electorate. Therefore, it is important to protect both cybersecurity and transparency in the electoral context – a challenge that is particularly unique to EMBs.5 Beyond striking this balance, election administrators must focus on cybersecurity as an ongoing and ever-changing concern. As soon as cybersecurity good practices are developed, they may become outdated, because technology moves forward very quickly, as does the technical expertise of those who seek to find and exploit its vulnerabilities. While it is important to learn from experience, rapid technological innovation means that EMBs should endeavor to secure the next election, not focus on vulnerabilities in the last election. This means identifying potential future vulnerabilities, not only addressing issues that have been identified or exposed in the past. 1 “Election Integrity Open Letter to Congress,” National Election Defense Coalition, https://www.electiondefense.org/election-integrity-expert-letter/. 2 Reuters, “Two 11-year-olds altered election results in hacker convention’s replica of U.S. voting system,” CBC, August 14, 2018, https://www.cbc.ca/news/technology/def-con-hacking-convention-voter-village-1.4784803. 3 For example, electronic transmission of results at the polling station level or maintenance of national biometric voter registration databases, but also penetration of less high-profile databases such as personnel records for ad hoc staff, that could undermine the public’s confidence in the EMB and its capacity to secure more sensitive databases. 4 A note on definitions: In this paper, IFES uses the terms “cybersecurity,” “data security” and “data protection” interchangeably, in line with ISO standards and academic literature. See, for example, Basie Von Solms, Rossouw von Solms, "Cyber security and information security – what goes where?", Information & Computer Security, https://doi.org/10.1108/ICS-04-2017-0025, which offers a definition that: "Cyber Security [is] part of Information Security, which specifically focuses on protecting the Confidentiality, Integrity and Availability (CIA) of digital information assets against any threats, which may arise from such assets being compromised via (using) the Internet.” 5 For example, other agencies such as defense, or institutions such as banks or insurance agencies, can focus primarily on cybersecurity without the same transparency concerns. 3

Select target paragraph3