CSIS Election Cybersecurity Scorecard: The Outlook for 2018, 2020 and Beyond
Photo: CSIS
Available Downloads
Securing Election Systems Against Cyber Attacks: Risks and Solutions for 2018, 2020 and Beyond
The 2016 election was a wake-up call for the United States that our largely digitized election systems are vulnerable. The Russian government targeted US campaigns, candidates, and election systems in a series of coordinated cyber attacks and influence operations intended to undermine confidence in American democracy.
In the last two years, federal, state and local election officials have made significant efforts to secure our election infrastructure and defend our democracy. Basic cybersecurity best practices have been implemented across most of our 50 states, and more than $800 million has been allocated by federal and state officials to harden election systems against cyber threats. We are better prepared in 2018 to deal with the threat of foreign election interference, but there is much more to be done to ensure the integrity and resilience of our elections against cyber threats for 2020 and beyond.
The 2018 midterm elections involve thousands and local, state and federal contests for everything from local selectman seats to 468 seats in the U.S. Congress. Cyber attacks could target systems run by any of thousands of campaigns and political party organizations, voter registration and election managment systems administered by the 10,000 jurisdictions that oversee U.S. elections, voting machines or vote tallying systems, or election night reporting by official election websites or traditional and social media.
Understanding the risks to our election systems requires understanding the threats to these systems posed by foreign nation states, the vulnerability of our electoral system to different types of disruption and manipulation, and the measures we have in place to secure each of these systems.
Our primary cyber adversary, Russia, continues to target campaigns and candidates with cyber attacks in 2018, building off their successful tactics in the 2016 election to manipulate political discourse in the U.S. through influence operations. We have yet to see a foreign adversary attempt to disrupt our core election infrastructures – voter registration databases, election management systems, voting machines or vote counting systems – despite the fact that attacking these systems could directly disrupt or manipulate the results of an election.
Over the last two years, a great deal of effort and investment has gone into securing core election infrastructures against cyber threats, and implementation of basic cybersecurity practices has improved. More remains to be done, but campaigns and election night reporting systems have received comparatively little attention. While these systems cannot be used to directly disrupt or manipulate elections, attacks on these systems pose a serious threat to public confidence in American democracy.
The greatest overall risk in 2018 is to campaigns and candidates, where cybersecurity practices remain inconsistent but our adversaries have focused their attacks. However, to ensure that Russia does not escalate its attacks to disrupt election systems, we must continue to invest in the security of those systems, and communicate clearly to the Russians that interfering with the conduct or results of U.S. elections will have serious consequences.
Over 99% of votes in the United States are cast or counted by computers, and many of these systems are vulnerable to cyber threats. Computerized voting, while potentially vulnerable to cyber threats, has some significant advantages over all paper ballots. Computerized voting can reduce miscounted or discarded votes due to voter error, enable voters with disabilities to vote, help voters in rural areas to access the polls, and speed up the delivery of election results.
But we have underinvested in securing digital election systems. Across the country, state and local officials have limited staffs and budgets for security, and many of the most competitive races in 2018 are being held in some of the most vulnerable areas.
We surveyed our extensive network of cybersecurity experts to find out what cyber threats they worry most about in 2018. More than 80% of our experts identified Russia as the number one cyber threat to U.S. elections, reflecting the strong evidence of ongoing Russian cyber attacks against the 2018 election over the last few months.
While a third of our experts worry about Russian attacks on voter registration and voting systems, the primary risk remains cyber-enabled influence operations and espionage targeting campaigns and candidates. Dozens of attacks have already been reported on campaigns and party organizations across the country, disrupting websites and stealing documents and communications.
While headlines often focus on vulnerabilities that remain in election systems, much has already been done to strengthen our cyber defenses for the 2018 midterms. We identified 40 states that have invested more than $75 million of federal and state funds to secure election systems since 2016. This includes 26 states that have conducted security assessments and implemented cybersecurity upgrades, 20 states that have invested in enhanced cybersecurity training for election officials, 15 states that have upgraded or replaced voting equipment, and nine states that are expanding post-election audits.
The federal government has also taken measures to support election security efforts. The Department of Homeland Security (DHS) has designated election systems as critical infrastructure, created a dedicated election thread under the Multi-State Information Sharing and Analysis Center (MS-ISAC), and recruited more than 1,300 local jurisdictions and all 50 states to participate in information sharing through the newly established Elections Infrastructure ISAC (EI-ISAC). 41 states and 68 counties have also installed DHS’s Albert intrusion detection sensors to protect their election systems, and in August, DHS held a three-day tabletop exercise with 44 states to practice coordinated responses to a range of simulated cyber attacks on election day. Meanwhile, the FBI has established programs to provide cybersecurity training and support to campaigns and election officials.
Much more is being done to prepare for the 2020 general election. Over $800 million, including $380 million of federal money under the Help America Vote Act (HAVA), has been earmarked for election cybersecurity across the 50 states. More than $300 million of this funding has already been allocated to projects that will be completed ahead of the 2020 elections.
The critical importance of a voter verifiable paper audit trail (VVPAT) has been embraced by election officials across the country. 46 of our 50 states have committed to establishing a VVPAT for all voters. In 2020, 38 states will use all paper ballots or voting machines with a VVPAT, two more will have a paper trail for all but their accessible voting machines for disabled voters, and six more will be in the process of implementing VVPAT for all voters.
Progress is being made, but there is also much more to be done. All votes in the United States should have a VVPAT, and all 50 states should conduct risk-limiting post-election audits to ensure that any attempt to manipulate voting systems is detected and mitigated. No system is perfect (including paper ballots, which have been manipulated many times over the course of modern history), but a paper audit trail and risk-limiting audits are an important first step in establishing resiliency against cyber threats.
We must also increase funding for election security. Following the 2000 presidential election, in 2002 Congress allocated more than $3 billion to the states to modernize election systems, the equivalent of $4.2 billion in today’s dollars. Today, the threat to our elections is much greater, but only $380 million has been allocated by Congress to support state election security efforts. We must invest in strong cybersecurity for our election systems today, and ensure that adequate funding is available in the future to maintain and upgrade election systems as technology and threats evolve.
We also need to look beyond the risks to core election infrastructures and redouble our efforts to secure campaigns, party organizations, and election night reporting systems against cyber threats. While cyber attacks on these systems cannot be used to directly manipulate the results of votes, they pose a significant threat to public confidence in our leaders and in our elections.
Finally, campaigns and election officials should leverage all available partnership opportunities to improve their security. In addition to state resources and support from DHS and the FBI, private companies including Microsoft, Cloudflare, Akamai, and Symantec, among others, have offered pro-bono cybersecurity services to election systems and campaigns.
Conclusion
If Russia, or any other foreign adversary, attempts to interfere with the 2018 midterm elections, they will find this country better secured, better prepared, and ready to take action to defend our sovereignty. But federal, state and local officials must continue to work after November to strengthen the security of election systems for 2020 and beyond. We will be ready for Russia’s 2016 tactics in 2020, but our adversaries continue to innovate, and it will take sustained effort and investment to maintain the security and resilience of American democracy against cyber threats.
This Project is made possible by support from Raytheon Company.