Looking back at the ballot – securing the general election

On 4 July 2024, tens of millions of people cast their votes for thousands of candidates across 650 constituencies in the UK general election. Within just 36 hours of the polls opening, the votes had been counted, a new prime minister appointed and a new government was already taking shape.
Delivering an election with less than seven weeks’ notice showed hugely impressive agility by the UK Electoral Commission, local authorities and others. And doing so securely at a time of heightened geopolitical tensions, enhanced cyber threats and unprecedented technological change is an even greater feat.
The Electoral Commission’s initial assessment, when the polls closed, is that people were able to cast their ballot securely. I’m proud of the role the NCSC played in delivering this, working alongside policing, the civil service, the crown service, central and local government, the NPSA and private sector organisations.
Safe and secure elections should never be taken for granted and I am always mindful of the sacrifices people in this country have made to gain the right to vote. Democracy has a long and ancient history, and we have a solemn responsibility to those who came before us to protect our freedoms.
While voting in the UK is undertaken with pencil and paper – thereby reducing the attack surface for cyber actors looking to do us harm – securing digital infrastructure and upholding the integrity of the information space remains a significant task.
One month on, and with international allies going to the polls later this year, we are taking this opportunity to share some of the NCSC’s takeaways from our election security experience. Sharing these reflections is vital for building collective cyber resilience.
Practising what we preach
While we didn’t know exactly when the election would be called, we understood building resilience for such an event couldn’t be achieved overnight, or even in a matter of weeks.
Over many months, we worked with partners across the public and private sectors to ensure we were well placed to transition easily to an operational footing when the time came, with all our efforts driven by the assessments, insights and intelligence we can access by being part of GCHQ.
Preparation is the key to any successful risk management strategy, and we advise organisations to maintain this mindset to help prevent cyber incidents.
We exercised potential scenarios, such as responding to concurrent incidents, to test our readiness; we advised key stakeholders on how to bolster their defences, and we provided dedicated support and services to individuals at higher risk of targeting by nation-state actors.
You can see some of the results in our Defending Democracy collection of guidance – a suite of resources published with the general election in mind but which now provides enduring advice to individuals and organisations involved in politics and facilitating our electoral processes.
I also encourage individuals seeking advice on staying safe to read the wider collection of guidance available, including on protective security. The government, police and Electoral Commission have made it clear that candidates faced unacceptable intimidation during the election campaign. Such threats, whether physical or digital, must not be tolerated.
Whole of society approach
Cyber security is a team sport and in liberal democracies, we all have a stake in safeguarding our democratic values and institutions from online threats.
Protecting elections cannot be the responsibility of a single organisation. In the UK, collaboration was central to our approach from the start. Within UK government, the Joint Election Security and Preparedness Unit, established by the Defending Democracy Taskforce, led on the coordination of key partners to analyse common issues.
Meanwhile, the NCSC engaged with many stakeholders across the UK economy and society to ensure they had the necessary tools to keep the election safe. This included engagement with key service providers, political parties, election officials, candidates and teams that were not technically focused.
Cyber risk is like any other risk; it needs to be managed effectively by senior leaders who must understand their responsibilities, regardless of their formal training.
Waiting for a clearer picture
Advances in technology offer significant advantages for our democracies, including enhanced engagement. However, they also present challenges, notably with information integrity.
These challenges should not be underestimated, and the risks presented by AI-generated content are growing. The government surged resources into handling this issue for the election but our public lexicon for this subject must evolve.
Too often, the instinct to call foul and blame deep fakes and ‘hack and leak’ arises. However, as we have learned from previous national security incidents, we must take care with the language we use until the picture is clearer.
Our discourse about information integrity should avoid jumping to conclusions and take a measured tone until the authorities with the necessary details and intelligence have made an assessment.
Making premature claims about misinformation or disinformation risks accusations of irresponsibility and can further muddy the waters.
Meanwhile, the government will continue empowering citizens with the knowledge and media literacy skills we all need to critically consume content online, so misinformation and disinformation can be more easily identified both during and outside of election periods.
Confidence and integrity
As the UK’s technical authority for cyber security, the NCSC remains committed to raising awareness of cyber threats and keeping the UK safe online.
But as public servants it is incumbent on us to remember that democracy needs to be accessible. We must avoid over-securitising elections, making them feel like overly technical exercises that might distract from the simple act of voting.
As the reality of the threats we face becomes more complex, this will get harder and so a balance needs to be struck between openness and the technical assurance provided by experts.
To succeed, we need engagement from all stakeholders—tech companies, civil society leaders, and the public. And we need to keep working together internationally, throughout our respective election cycles, to share insights and reflections for our collective benefit.
I have every confidence that through a concerted effort, participation, and maintaining integrity, we can uphold the core values of our democracy.