Election Security: Protecting Democratic Infrastructure from Cyber Threats
Published by the 0g0 research team
No category of critical infrastructure carries greater symbolic and operational weight than election infrastructure. The integrity of elections is the foundation of democratic legitimacy. Successful attacks on voting systems — or credible perceptions of such attacks — undermine not just individual elections but public confidence in democratic institutions.
Foreign adversaries understand this. Russia's Internet Research Agency's interference in the 2016 US election, China's documented targeting of congressional campaigns, and Iran's attempts to influence the 2020 election have all demonstrated that election infrastructure and the political processes surrounding elections are active targets for nation-state cyber operations.
This guide addresses the cybersecurity challenges specific to election infrastructure, the regulatory and organisational landscape that governs election security, and what effective protection looks like for the state and local officials responsible for running America's elections.
The Election Infrastructure Attack Surface
Election infrastructure is more complex and distributed than most people realise. It encompasses:
Voter registration systems: Databases containing voter information that are used to verify eligibility at polling places. Most states now have online voter registration and electronic poll books — creating both efficiency benefits and attack surfaces that did not exist when paper registration was universal.
Election management systems: Software used to program voting equipment, define ballot definitions, and aggregate results. These systems are typically operated by county election offices and connect, at various points, to both the internet (for software updates and result transmission) and voting equipment.
Voting equipment: The devices voters use to cast ballots, including optical scan systems, direct-recording electronic (DRE) machines, and ballot-marking devices. The security of these devices is frequently debated, and the security research community has documented significant vulnerabilities in various equipment models.
Electronic poll books: Tablets or laptops used at polling places to verify voter registrations. These devices are often connected to networks, creating a potential vector for real-time manipulation.
Reporting and results transmission: The systems used to aggregate and transmit unofficial results on election night, from precinct level through county level to state certification.
Campaign and party infrastructure: The computer systems, email accounts, and communications infrastructure of campaigns and political parties, targeted to obtain strategic intelligence and to leak damaging information.
The Russia 2016 Playbook and Its Successors
The 2016 Russian interference operation, documented comprehensively in the Mueller Report and the Senate Intelligence Committee report, established a model that subsequent foreign interference operations have followed and refined:
Scanning and reconnaissance: Systematic scanning of election infrastructure including state voter registration systems and election management systems to identify vulnerabilities. All 50 states were targeted for reconnaissance; successful intrusion was confirmed in a smaller number.
Spear-phishing: Targeted phishing emails against election officials, campaign staff, and party infrastructure. The compromise of John Podesta's email account and the DCCC and DNC networks originated with spear-phishing emails.
Influence operations: Large-scale social media disinformation operations designed to amplify social division, suppress turnout among target demographics, and undermine confidence in electoral processes. The Internet Research Agency created and managed hundreds of social media accounts and pages reaching tens of millions of Americans.
Infrastructure targeting: Attempted intrusions into actual election infrastructure, including voter registration systems in multiple states and election management vendor systems.
Election Security Improvements Since 2016
The intervening years have seen significant investment in election security:
$380 million in federal grants to states through HAVA (Help America Vote Act) funds has supported voter registration system upgrades, security assessments, paper ballot adoption, and post-election audits.
CISA's election security programme provides vulnerability assessments, network monitoring, and intelligence sharing to state and local election offices. Participation is voluntary but widely adopted.
Most states have significantly expanded their election security programmes, with dedicated resources for cybersecurity that many lacked in 2016.
The Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), operated by the Center for Internet Security, provides threat intelligence sharing and security resources specifically for election officials.
Persistent Vulnerabilities
Despite significant progress, election infrastructure retains meaningful vulnerabilities:
Fragmentation: America's election system is administered by approximately 10,000 jurisdictions — state, county, and municipal election offices with widely varying resources, technical capabilities, and security sophistication. The small county with a part-time IT person and a 2015 laptop running voter registration software is a persistent weak point.
Vendor concentration: A small number of vendors supply the majority of election management systems and voting equipment used across the country. Security vulnerabilities in a single vendor's platform potentially affect elections across many states.
Human factors: Spear-phishing against election officials remains highly effective. Many election offices lack basic security awareness training, and the personal email accounts of election officials — outside their official IT security perimeter — remain targeted for credential theft.
Third-party connections: Election management systems connect to various external services — software updates, results reporting platforms, vendor support connections — that create attack surfaces that are often not fully secured.
What Good Election Security Looks Like
Effective election security combines technical controls with operational security practices:
Paper audit trails: The fundamental safeguard for election integrity is the ability to verify electronic results against physical paper records. Optical scan systems with voter-verified paper audit trails (VVPATs) enable post-election audits that can detect manipulation of electronic tabulation.
Risk-limiting audits (RLAs): Statistical auditing approaches that efficiently verify election outcomes with high confidence by sampling ballots. Multiple states have adopted RLAs as a standard post-election practice.
Network segmentation: Election management systems should not be connected to the internet for routine operations. Software updates and result transmission should occur through controlled, monitored processes rather than persistent internet connections.
Multi-factor authentication: All access to election systems — particularly remote access — should require strong multi-factor authentication.
Incident response planning: Every election office should have a specific incident response plan for cyber incidents occurring before or during an election, including manual backup procedures that enable operations to continue if electronic systems are compromised.
The Disinformation Dimension
Technical security of election infrastructure addresses only part of the election security challenge. The disinformation operations that amplify uncertainty about election integrity — even in the absence of actual manipulation — are an equally significant threat that operates outside the technical security domain.
Rapid, accurate communications from authoritative election officials are the most effective counter to disinformation. Election officials who can quickly and clearly explain election processes, demonstrate audit procedures, and provide transparent access to results are better positioned to counter false narratives than those who operate opaquely.
0g0 Aegis provides election security assessments and advisory services to state and local election offices and political organisations. Our election security team has direct experience with the unique regulatory, political, and operational environment of election administration, and we provide practical security improvements that work within the resource constraints that most election offices face.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing