Defending democracy
Page 4 of 6
Guidance for organisations coordinating elections

Why is this guidance necessary?
Elections are a crucial part of the UK democratic process, and organisations with a role coordinating them may face threats from criminals and nation-state actors who wish to disrupt the electoral process.
This makes it essential to put in place the right cyber security measures, as any disruption to the electoral process could undermine confidence in the integrity of an election.
Who is it for?
This guidance is for organisations involved in administering UK elections, including:
-
local authorities in England and Wales
-
valuation joint boards in Scotland
-
the Electoral Office of Northern Ireland
It is primarily for IT teams managing the networks of these organisations and will help you take care of the cyber security of your Electoral Management System (EMS) data and systems, including your wider IT systems.
Protecting your electoral systems and data
EMS software has a crucial role in the logistical elements of the electoral process, such as voter registration, ballot preparation and election administration. This makes it a particularly important security consideration when it comes to ensuring the integrity of the electoral process.
You should work with your EMS supplier to gain assurance on how they are managing the risks in the service they are providing.
Risk management in cyber security helps ensure that the technology, systems and information in your organisation are protected in the most appropriate way. Risk assessment can be complicated and time-consuming, as there are many variables to consider.
It's important to gain confidence that the package of mitigation measures you put in place have effectively managed the risks you have identified, and that you consider how you will maintain that confidence as your systems are used in future.
The risks to your electoral systems will vary, depending on the scale and complexity of your infrastructure, and that of your suppliers. This includes your EMS supplier, and also any infrastructure hosting your EMS that your managed service provider runs on your behalf.
Whatever your set-up, it's important to regularly review and understand the risks you are managing. The NCSC has a risk management framework to help you with this and facilitate your work with electoral services colleagues to understand and assess the business impact of cyber risks to the EMS and supporting IT infrastructure.
Managing your organisation’s cyber security risk isn’t just a cyber security issue. It’s essential for seniors in your organisation, including the management board, to buy into it too so they can make informed cyber decisions aligned to wider organisational risks. You will also need their support for cyber security to receive the investment it needs against competing business demands.
The NCSC’s Board Toolkit helps boards ensure that cyber resilience and risk management are embedded throughout organisations.
You should have confidence that your EMS supplier has the right cyber security measures in place. The NCSC has guidance on questions to ask a supplier to make sure their security practices meet your requirements.
There are now cloud-hosted EMS options that are provided as software as a service (SaaS). The NCSC’s cloud security principles can help you choose a provider that meets your security needs.
All EMS data, including the electoral roll itself, must be protected from unauthorised access, modification or deletion. The NCSC has guidance on protecting bulk personal data, which covers understanding what data you have, who has access, and how you are protecting it. As part of this, you may want to specifically consider:
- Hosting infrastructure. The NCSC guidance on device security and secure system administration are useful references, regardless of where you host your infrastructure. If you are hosting your data in the cloud, you should review the NCSC cloud security guidance which helps you enhance your cloud security. The ‘lift and shift' advice, which explains the practice of replicating an existing local system, machine-for-machine, but in the cloud, may be particularly relevant in this context.
- Access control. Control access to your systems and data through clear identity and access management policies. Your aim here is to restrict the opportunities for an attacker to compromise these accounts. Regularly review the level of access individuals have, and make sure it’s appropriate for their roles.
- Data encryption. Use current standardised cryptographic algorithms to protect your data both at rest and in transit. Old algorithms, or those not accepted as standards, offer less protection and could create a false sense of security. The section on data security in the NCSC’s 10 Steps to Cyber Security is a useful resource here.
It’s essential to regularly back up your EMS data so that you can recover quickly. This particularly applies to critical data, such as the electoral roll.
There are different ways to back up data but you should make sure you include an offline backup in your arrangement. Keeping backups off your live network in a physically secure location – if on premises – or in a separate cloud instance – if cloud hosted – will help mitigate the risk.
If you back up your EMS data in the cloud, you should use the NCSC principles for ransomware resistant cloud backups and cloud security principles to gain assurance on the arrangements you have in place.
It’s common for untested backups to be found to be unrestorable, so it’s important to regularly test backup procedures to make sure they work.
Protecting your systems
The resilience of your EMS depends on the network that is used to host and access it. In the lead-up to an election, you should review, and if necessary uplift, the availability and support requirements for the infrastructure, software and services supporting the election process.
Infrastructure should be well maintained, using supported software and hardware with the latest security updates installed. The NCSC 10 Steps to Cyber Security is designed to provide a sensible approach to enhancing your organisational resilience.
Devices used to support the electoral process at polling stations should be corporately managed. We recommend using the NCSC device security guidance to help mitigate any risk.
As you prepare for elections, you should also consider the wider security of your supply chain. Incidents across different sectors have shown that the supply chain is an opportunity for attackers to target one organisation to gain access to the network of another, disrupt its services, and steal its data.
As organisations are increasingly connected with each other to provide digital services, it’s important to gain assurance on the cyber security of your suppliers. The NCSC has supply chain security principles to support this.
Protecting your people
Individuals with a role in delivering an election, such as local government employees – including those in temporary roles to support an election – may be of interest to attackers who could use social engineering and spear-phishing to gain access to information, or to compromise their accounts.
The NCSC phishing guidance for organisations provides information to help you defend your organisation from phishing, and underlines the importance of a multi-layered approach.
The National Protective Security Authority (NPSA) has general guidance on social engineering which raises awareness of the types approach and helps educate staff to be alert to the threat it poses.
The majority of individuals with a role in delivering an election have integrity and show discretion, but a small minority may seek to exploit their accesses for unauthorised purposes. This could be to access electoral information for financial gain, ideology, personal grievance, or for recognition.
To mitigate this, you should put in place an identity and access management policy that covers:
- who should have access to which systems, data and functionality
- why they require access, and
- under what circumstances
Make sure you consider all users including employees, contractors, volunteers, students and visitors.
For more information, the NCSC has guidance on reducing the risk of data exfiltration by insiders and the NPSA offers advice about managing insider risk.
Organisations should plan, exercise and validate incident response plans to safeguard elections. Swift reporting and resolution of cyber incidents are crucial to maintain election integrity.
- Build confidence. Be ready to respond to cyber incidents. Document and test your incident response plans. These plans should align with your business continuity and disaster recovery strategies. The NCSC Incident Management guidance can help with this.
- Test readiness. Use the NCSC’s Exercise in a Box to assess your response to various cyber incidents. Identify areas for improvement in your response plan.
- Incident reporting. Report incidents, suspicious or unusual activity to the NCSC. Be aware of the NCSC Cyber Incident Response (CIR) scheme which provides a list of assured commercial incident response organisations if an attack happens.
Through its Active Cyber Defence (ACD) programme, the NCSC has a number of tools and services for eligible public sector organisations to enhance organisational resilience, which are free at the point of use:
- Early Warning helps organisations investigate potential threats on your network by notifying you of malicious activity detected in various information feeds
- Web Check and Mail Check help strengthen website and email security
- Check Your Email Security helps assess your email domain security for DMARC policy implementation
Further resources
The NCSC has resources to support organisations raise awareness of cyber security through training and exercising – Exercise in a Box and Top Tips for staff may be useful here.
Returning Officers and staff with a role in the electoral process should familiarise themselves with the NCSC guidance for high-risk individuals. This provides information on how to secure and manage personal devices and accounts.