Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
e)
Case Law
Several recent cases in national courts have provided various precedents on cybersecurity in elections
centered on the following issues: implementation and transparency of technology in Kenya; electronic
voting machines (EVMs) in India, Germany, and Finland; e-voting in Estonia and Austria; and
cybersecurity in the Philippines, all of which are discussed below. Together, the cases highlight the
importance of a verifiable paper trail for the voting and counting process, transparent tabulation and
certification of results, clear procedures and instructions for using technology, equality among voters,
and the importance of having cybersecurity policies and practices in place.
Implementation and Transparency of Election Technology
In its judgment annulling the August 2017 Kenyan presidential elections, the Supreme Court ruled that
the Independent Electoral and Boundaries Commission (IEBC) had failed to adhere to legal requirements
for “free and open elections.” The election results were finalized and announced based on information
from tabulated results forms (34B) that came from centralized tallying centers, instead of waiting until
the IEBC received all original results forms (34A) from individual polling stations. The court focused on
the IEBC’s failure to provide full access to its servers and server logs and its failure to provide a plausible
explanation for results released based on incomplete information. The court stated it “had no choice”
but to accept the petitioners’ claim that either the servers were infiltrated and the data compromised,
or the IEBC itself had intentionally or unintentionally compromised the data.66 Multiple errors in
implementing technology were referenced in the decision, including interruptions on data mobile
coverage without an adequate backup plan and discrepancies between results published on the website
and official results released when compared to the breakdowns of results transmitted from polling
stations to the National Tallying Center.
Use of Electronic Voting Machines (EVMs)
Courts in India, Germany and Finland have all ruled on EVMs, focusing on the use of VVPATs to
authenticate results, voting technology that is understandable to the average voter, and clear
instructions for EVMs, respectively.
In its judgment of October 8, 2013, the Supreme Court of India directed the government to fund the
gradual phase-in of VVPATs, agreeing with the petitioner that a paper trail is a vital security measure for
e-voting. Although the Indian Election Commission (IEC) was able to print records from their EVMs with
a decoder device, the court ruled that VVPATs were also necessary. The IEC claimed that it had tested
VVPATs in field trials and had not yet adopted them on the basis of those trials. The court noted that
“[f]rom the materials placed by both the sides, we are satisfied that the ‘paper trail’ is an indispensable
66
See section 279 of Odinga and Musyoka v. IEBC et al. (Supreme Court of Kenya 2017): “The IEBC in particular
failed to allow access to two critical areas of their servers: its logs which would have proved or disproved the
petitioners’ claim of hacking into the system and altering the presidential election results and its servers with
Forms 34A and 34B electronically transmitted from polling stations and CTCs.”
15