The use of ballot counting systems, also known as vote tabulation technology, to replace manual ballot counting during democratic elections is gaining wider adoption. These technologies can help improve the efficiency of the ballot tabulation process, as well as reduce human-related errors during the ballot counting process.
This publication provides guidance on the cyber security considerations and system requirements for deploying vote tabulators during democratic elections. It highlights the key risks, threats and safeguards that elections management authorities should assess when considering ballot counting systems.
Table of contents
- Scope
- Electronic voting
- Ballot counting and tabulation
- Threat analysis
- Security control considerations
- Physical and hardware security
- Lifecycle security
- Continuous risk assessment
- Protect your data
- Network isolation safeguards
- Secure access controls
- Validate and authenticate devices
- Patches and system updates
- Secure application development
- Audit log monitoring
- Business continuity
- Educate users
- Security control effectiveness
- Conclusion
Adopting digital technologies to improve the efficient delivery of the electoral process is an increasingly attractive proposition for modern democratic elections. Elections administrators are embracing the use of modern digital methods to improve or replace traditional and manual voting processes. Manual counting can be subject to human errors from fatigue, eyestrain, or distractions, which can lead to ballots being misjudged and misallocated. In very tight electoral races, those errors can have serious consequences. Using electronic vote counting technologies to support aspects of the elections process can help prevent human-related computational errors, expand voter accessibility options, and improve election transparency. These technologies can also allow for the timely reporting of elections results.
Although federal elections in Canada do not use vote tabulators or ballot counting systems, these systems have been used in provincial and municipal government elections. Vote tabulators are electronic devices used to automate the counting of marked paper ballots. Some specific models may support the storage of digital ballot records, integration with assistive devices or vote capturing capabilities, and other additional functionalities. However, despite their potential benefits, the associated risks must be carefully considered.
Replacing traditional processes with vote tabulators can have many advantages; however, this can introduce new vulnerabilities and threats into the democratic process, allowing threat actors opportunities to inflict harm. These threats may come from sophisticated nation-state actors or unprincipled stakeholders interested in disrupting the peaceful conduct of the democratic process. Before deploying vote tabulators, elections authorities should conduct a detailed risk assessment to evaluate the potential risks and associated security threats. The Cyber Centre’s Cyber threats to democratic process: 2025 update assesses that the likelihood for state-sponsored cyber actors to target Canadian elections is almost certain. It is important to understand specific risks and threats that may be associated with electronic vote tabulation deployments.
In this publication, we discuss important cyber security considerations for elections administrators when deciding whether to use vote tabulators, the recommended secure architecture model for deploying these devices, as well as the security controls required to safeguard the integrity of the system. Note that it is difficult to establish suitably secure network connectivity for any election’s infrastructure.
Scope
This guidance applies to vote-tabulation systems that process paper ballots only, not systems that handle electronic ballots. While some recommendations may also apply to electronic ballot systems, they may not fully address the distinct threats those systems face.
Electronic voting
Electronic voting system architectures are complex and can involve many disparate systems. An electronic voting system architecture describes the information systems components involved in electronic voting and how these components interact with each other. These systems may include:
- public websites
- party registration systems
- voter registrations systems
- ballot creation and printing systems
- election management systems
- online voting systems
- ballot counting or vote tabulation systems
- results publishing systems
These systems often run distinct software and firmware technologies, can be interconnected, and may communicate across diverse network protocols. Figure 1 depicts a generic modern electronic voting systems architecture, based on the Center for Internet Security’s (CIS) Handbook for Elections Infrastructure Security.

Figure 1: Generic elections systems architecture presents a visual representation of a generic electronic voting system architecture. The image provides additional details on how ballots go from creation and printing to having the results counted and tabulated to the results being published.
The components outlined in the image represent the entirety of a generic elections system architecture, including:
- voter registration systems
- party and candidate registration and verification
- campaign finance management
- election management systems
- ballot creation and printing
- electronic poll books
- ballot capturing devices
- ballot counting and tabulation
- ballot scanners
- ballot counting and tabulators
- results transmission and publishing
This guidance is focused on the ballot counting and ballot tabulation components of this architecture. Our recommendations address core cyber security and operational issues that require attention to safely operate and deploy these systems. First, we provide a generic description for ballot counting and tabulation systems.
Ballot counting and tabulation
Ballot counting and tabulation is the process of counting and aggregating used and unused ballots in an election. The process involves gathering valid and invalid (spoiled) ballots, counting unused ballots, and aggregating valid ballots for each candidate in the election. Ballot counting and tabulation can be completed manually (namely by hand-counting) or by using electronic systems such as vote tabulators. Both methods can introduce errors in the process for various reasons. For example, if elections workers are tired or distracted, counting ballots by hand may lead to computational errors. Similarly, software flaws or compromises of electronic vote tabulators may lead to votes being inaccurately categorized. In general, it is important for elections administrators to continually assess counting methods and implement mechanisms to determine or validate that their counting processes are operating within accepted error rates.
The ballot counting method used is often determined by legal provisions. For example, the Canada Elections Act requires ballots cast during federal elections to be hand-counted, while some provinces, territories and municipalities have changed local laws to allow the use of electronic vote tabulators in their local elections.
At a high level, a typical ballot counting and tabulation process includes the following activities:
- validating each ballot
- sorting and counting valid or invalid (spoiled) cast ballots
- aggregating valid cast ballots for each candidate
- generating a tabulated summary from tallied ballots
Note that the transmission of election outcomes is considered a separate process, as this may require additional system components for transmitting and sharing that information. Results aggregation may also require additional collation at a central facility before official results are released.
The following are some methods that may be used to tabulate ballots during elections.
Manual counting and tabulation
In this method, elections officials manually sort, validate, and count casted paper ballots. All activities are done by hand, including generating election results tables. As noted by Elections Canada in the Returning Officer’s Manual, in Canadian federal elections, ballots are counted manually at polling stations, and preliminary results are then transmitted (often by telephone) to Elections Canada .
For elections where a different tabulation method is primarily used (e.g. provincial or municipal elections), manual ballot counting and tabulation are commonly used as a fallback measure. Manual ballot counting and tabulation are also used to perform election audits. Manually counting and tabulating ballots can be tedious and time-consuming, especially for polling stations with higher voter density. While manual counting processes may provide a greater degree of trust due to their inherent simplicity and easier security auditability, they may allow for human subjectivity and errors.
Electronic counting and tabulation
This method involves using electronic vote tabulators to sort, validate, and count election ballots. This method can be used to count both paper and digital ballots. Paper ballots are fed into and analyzed by the device while digital ballots are captured and processed. Electronic vote tabulators may have built-in printing capabilities or may support connectivity with external printers. Note that any external or peripheral devices connected to a vote tabulator must adhere to the same security control standards as the vote tabulator system. We recommend maintaining independence between the counting system and the ballot creation system so that a threat or attack against one does not impact the other.
Types of vote tabulators
There are different types of vote tabulators, often defined by their function, capabilities, and use cases.
Unit vote tabulators
These are digital scan machines that read and record ballots at a polling station. They are designed for light use only. They may or may not contain additional programmable capabilities which can assist with ballot validation, sorting, calculations, and local results processing.
Central tabulators
These are devices used to process ballots at a central location. They are typically industrial-sized and designed to process large amounts of ballots. They can also be used to rapidly perform large-scale recounts or to process mail-in ballots.
Optical scan tabulators
These are optical scan readers commonly used to help process marked paper ballots. These scanners rely on optical character recognition (OCR) or optical mark recognition (OMR) technology to read ballots. The scanner generates a digital representation of the original ballot which can then be used for additional processing. Optical scan systems are often used to process mail-in ballots.
Threat analysis
The Cyber Centre periodically releases an assessment of Cyber threats to Canada’s democratic process (TDP). In its most update, the Cyber Centre assesses that democratic processes across the globe remain a target of interest for cyber threat actors and that the likelihood for state-sponsored cyber actors to target Canadian elections is almost certain. Vote tabulation systems may certainly introduce new vulnerabilities within the electoral process and may become a target for motivated, state-sponsored threat actors. Election agencies should conduct detailed threat and risk assessments to ensure that they understand the risks associated with using these systems and that vote tabulator systems are protected against such threats.
Threat actors often seek to undermine public confidence in the legitimacy of the democratic process. According to the 2025 TDP report, state-sponsored actors may attempt to weaken trust by altering content on devices used during the elections process. Threat actors can infiltrate and compromise the supply chains used to procure vote tabulator devices. They can also launch disruptive attacks against these devices to render them inoperative, thereby impacting the smooth conduct of elections. Malicious actors can use targeted misinformation or disinformation campaigns to spread inaccuracies about the operation of vote tabulator devices, thereby undermining voter trust and confidence.
State-sponsored threat actors have conducted numerous attacks against electoral systems and processes in recent years. For example, Ukraine, Estonia, Ecuador, and even the UK, have been targeted. Some of the attack vectors have included deploying disruptive malware on servers used to tabulate votes and planting fake results with the intention of releasing them publicly.
Based on the prevailing threat environment, it is very likely that cybercriminals and state-sponsored actors will target ballot counting and tabulation processes to achieve their overall objectives. The following are ways threat actors could launch attacks and target ballot counting and tabulation systems:
- taking over vote tabulation systems for the purpose of altering the results
- infiltrating device or systems-component manufacturers to compromise the supply chain for ballot counting and tabulation devices
- compromising elections record databases, resulting in unauthorized disclosure of confidential electronic voter records and undermining confidence in the democratic process
- disrupting vote tabulation system functions through exhaustion and destruction attacks such as distributed denial of service (DDoS) and ransomware attacks
- impersonating elections authorities to spread misinformation or falsehoods about the integrity of the process or devices to sow mistrust and erode confidence in the democratic process
- compromise privileged credentials to gain access to back-end systems to alter tabulation records or trigger further disruptive attacks
Security control considerations
In this section, we highlight important security controls you should consider when acquiring, deploying, and operating vote tabulation systems. These recommendations are aligned with the Cyber Centre’s Cyber security and privacy risk management: A lifecycle approach (ITSP.10.033). Election administrators should consider foundational system design and security principles to safeguard hardware, firmware, software components, and related processes.
Physical and hardware security
Physical layer protections in vote tabulator systems are critical in ensuring that other security controls can be trusted, and that the entire system operates as intended. Vote tabulators must be designed, manufactured, operated, and decommissioned in accordance with secure by design principles to better protect them against threats, such as supply chain compromise during any stage of its lifecycle.
Design systems to withstand physical and environmental hazards
Vote tabulators should be designed for operational resilience . The devices, storage media, and other system components should be able to withstand physical and environmental hazards, such as physical shocks, high humidity, and temperature fluctuations, to protect against data loss. These devices should also have an emergency power supply; an intelligent back-up power system will also allow for graceful power-down processes. It is important to protect devices and their electronic data from power surges and outages. We also recommend having electromagnetic shielding and tamper-evident seals as feature considerations.
Manufactured for purpose
Vote tabulators should be manufactured for a single purpose to ensure security functions are operating within defined security boundaries. Single purpose systems avoid the complexity associated with multi-use designs, while also ensuring system functions are strictly defined and security restrictions can be adequately enforced. General-purpose or multi-use systems extend the attack surface, providing additional opportunities for the adversary to compromise. We recommend that vote tabulators should be purpose-built and dedicated, single-use systems.
Operate systems with strict physical access controls
When deploying and operating vote tabulators, you should implement strict physical access controls. Only authorized individuals on approved access lists should have physical access to the devices before, during, and after elections. The locations where these devices are stored, deployed, or transported throughout their lifecycle should be monitored, and mechanisms should be in place to detect and deter unauthorized access. When choosing where to deploy vote tabulators, you should consider how you will secure them from unauthorized observation and access. Device screens should be set up to prevent on-screen information from being read or observed from a distance. Electoral management bodies (EMBs) should maintain access records for each device throughout its lifecycle, from acquisition to decommissioning.
Monitor systems and maintain strong chain of custody records
Maintaining chain of custody records plays a significant role in ensuring the physical and logical integrity of the vote tabulators. Elections administrators should implement rigorous chain of custody practices to prevent tampering and other malicious device alterations. The following are some ways of protecting vote tabulators and the data contained therein.
- Record all vote tabulator devices movement and access throughout their lifecycles
- Use tamper-evident seals
- Transport vote tabulators in secure containers to and from polling centres
- Document and verify chain of custody when transporting vote tabulators
- Protect and authenticate all physical access to vote tabulation equipment
- Review security monitoring controls before, during, and after elections to validate their effectiveness
- Decommission devices when chain of custody records cannot be securely validated
Device decommissioning procedures must ensure devices are cryptographically sanitized before disposal or destruction. Use only approved sanitization methods appropriate for the device media and use-case. Some sanitization methods are not effective or suitable on some media types. For example, solid-state drives (SSD) require at least a double overwrite pass and a secure erasure (SE) to achieve the sanitization objectives. For more information on Cyber Centre recommended guidance, refer to IT media sanitization (ITSP.40.006).
Lifecycle security
Democratic processes may be vulnerable to planned, persistent threats because of system lifecycle risks. In the context of information technology (IT) security risk management, “lifecycle” refers to the design/development, acquisition, integration/installation, operation, monitoring, maintenance, and disposal of IT assets which, for the purposes of this guidance, include electronic vote tabulators. Examples of lifecycle risks to electronic vote tabulators include procuring them through unsecure supply chains or having them designed or developed by unverified or untrusted manufacturers. Therefore, you should keep security in mind at every stage of a vote tabulator’s lifecycle and address and mitigate potential risks that could allow threat actors to compromise the integrity of an election.
Acquire devices through trusted supply chains
Vote tabulation systems typically contain millions of individual micro-components, as well as component sub-systems such as an image scanner unit, a paper ballot verification unit, device firmware or software, power systems, data storage units, and others. Threat actors can infiltrate supply chains to compromise the security of these devices and systems. The complexity of modern system lifecycles makes it difficult for commercially available systems to guarantee protection against supply chain embedded compromises. As a result, organizations should assume such compromises may exist on their device. We recommend adopting strategies to assess and mitigate supply chain-related risks by following the Cyber Centre’s approach to assessing cyber supply chain risks.
Elections officials should source vote tabulators and system components through trusted supply chains and physically inspect the devices before and after acquiring them, as well as before, during and after elections. Vote tabulators should have tamper-evident seals, tape, or security labelling to aid the detection of unauthorized physical access or unauthorized changes to hardware or physical system components.
Elections administrators should establish secure procurement procedures to limit the potential for threat actors to infiltrate supply chains. The following are some actions that could ensure the security of the vote tabulator infrastructure supply chain:
- Establish a supply chain risk management (SCRM) program to assess risks associated with procurement processes
- Assess and vet all technology suppliers to ensure underlying processes and relationships are secure
- Periodically assess suppliers and their cyber security practices
- Ensure that only trusted and vetted supplier personnel have access to sensitive electoral and system data throughout the system development lifecycle
- Collaborate with technology vendors to ensure verification processes are in place
- Ensure that the components of vote tabulators are genuine and have not been compromised through third-party relationships
- Specifically, work with vote tabulator manufacturers to implement tools to validate the integrity of hardware, firmware, and software running on tabulation devices
- Election agencies can also request information on detailed Hardware Bill of Materials (HBOM) or Software Bill of Materials (SBOM) to adequately track vulnerability risks associated with hardware and software components
For more information on supply chain cyber security, read Supply chain threats and commercial espionage and Supply chain security for small and medium-sized organizations (ITSAP.00.070).
Continuous risk assessment
Electoral management authorities should conduct a comprehensive risk analysis of the use of vote tabulators and understand the potential impact on the security of the entire electoral process. Assessing the risks of using vote tabulators should not be done in isolation.
Ascertain the risks associated with using vote tabulation systems
EMBs should consider technology in elections from a risk-management approach. While vote tabulators may offer opportunities for improving elections operations, it is important to understand the associated risks, which then may be mitigated, accepted, or avoided. Transferring the risk is not acceptable, as a compromise of a democratic process can have substantial reputational impacts. EMBs should also avoid using vote tabulators if they are unprepared or unwilling to accept the associated risks. For more information on evaluating and managing risk, please consult our guidance Cyber security and privacy risk management: A lifecycle approach and Security risk assessment for online voting systems supporting democratic processes (ITSM.10.103)
Protect your data
Electronic vote tabulators process, create, and store ballot data. Data is a critical asset for any business process, and especially for democratic processes that rely on digital systems. Therefore, you should have security mechanisms in place to protect the confidentiality, integrity, and availability of all forms of data, whether it is stored on the tabulation device or is in transit for processing.
Establish a holistic data security strategy
A holistic election data security strategy should be established to govern and secure electoral data throughout its lifecycle. This strategy should include data policies, acceptable handling procedures, and guidelines for managing data on vote tabulators. Data security policies may include recommendations on storage media types, secure data processing mechanisms, cryptographic standards, storage data formats, and data encryption. You may also consider performing a data security assessment to identify all data flows, paths, inputs, and outputs to and from the vote tabulator. However, there is no fully secure way to connect vote tabulators to electronic networks. Your data security strategy should address how to secure vote tabulator data throughout its lifecycle, from creation to destruction. For example, it should address how you plan to secure physical and digital ballots, restrict and manage access, enforce data encryption, and ensure compliance with legal requirements wherever your data may reside.
Appropriately classify data
Data classification represents a crucial component upon which many other security activities rely, especially when identifying appropriate security control mechanisms to protect the data. Data on vote tabulators typically exists at different classification levels and the choice of safeguards or security controls should take this into account. The vote tabulation system should be designed based on the highest classification of data or system components. For example, vote tabulators may be required to process cryptographic keys and data validation certificates may be used to encrypt and validate the integrity of election data.
Cryptographic keys represent highly sensitive data and may necessitate higher data classification. The vote tabulation system must be designed to implement security controls at the highest level determined. For more information on data classification assessments, read our publication Cyber security and privacy risk management: Security and privacy controls and assurance activities catalogue (ITSP.10.033).
Classifying data properly, together with implementing matching secure handling controls, can reduce the risk of a data compromise. Elections authorities should put processes in place to ensure that assets are only accessible to users on a ‘need to know’ basis and that electoral systems are only accessed using devices with the appropriate security authorization. Furthermore, only authorized devices should be used for processing and disseminating of elections-related data.
Protect data with cryptographic controls
Vote tabulator data should be protected with cryptographic mechanisms whether it is at rest or in transit (including on portable devices). Ballot data and vote counts should be secured against unauthorized disclosure and integrity attacks prior before and after they are officially released through authorized channels. Encryption can help protect data from unauthorized disclosure and modification. You should identify where the data resides at various points and then ensure you apply appropriate security controls to mitigate the risk of unauthorized use or disclosure. We recommend using only approved cryptographic algorithms and protocols. For more information on recommended cryptographic algorithms, read Guidance on cryptographic algorithms for Unclassified, Protected A, and Protected B information (ITSP.40.111). Maintaining a secure cryptographic key management system is important. Ensure you securely manage when, how, and where your encryption keys are created, stored, and destroyed. Implement a secure backup procedure for encryption keys to enable data recovery.
Consider data privacy protections
In Canada, election data is subject to privacy laws, including the Privacy Act. These laws mandate that a minimum set of security controls, such as data encryption and access management controls, be implemented to protect information about the voting public and ballots. We recommend you implement appropriate data privacy protections for ballots and voters’ information. The Canada Elections Act requires Elections Canada to share voting data, including elections results, with political parties and provincial governments. Vote tabulators must be evaluated to ascertain compliance and alignment with ballot secrecy and privacy laws. Data residency considerations should also be evaluated, as election laws may require data (in-transit or at rest) to reside within specific geographical boundaries.
Network isolation safeguards
Due to the threat environment and the associated risks posed by state-sponsored threat activity, we recommend that you do not connect vote tabulators to any network at any time. Prior to elections, vote tabulators should be configured without any network connectivity, including Bluetooth and Wi-Fi, and should never be connected to the Internet at any point of their lifecycle. Data should be transferred to and from vote tabulators using non-network procedures, such as trusted portable storage devices or paper-based procedures.
Strict network isolation (airgaps) is the most effective means of mitigating pre-existing compromises that may have been introduced through lifecycle attacks. Network isolation greatly increases the amount of effort required to gain remote command and control of a compromised system and forces an adversary to activate or control the compromised vote tabulator or related system through an alternative data channel, such as acoustic, or through procedural means, such using a compromised systems administrator. Certain serious attacks, like “logic bombs” that autonomously activate based on pre-set conditions, could remain on the system even without network connectivity, but the scope and sophistication of the possible attacks is much smaller without network command and control.
Establish strict network defences
Although deploying vote tabulators on a network is not recommended, elections administrators may still choose to deploy these systems on a network. In such cases, the network infrastructure supporting vote tabulators should be protected against interception, unauthorized data disclosure, modification, and denial of service attacks. You should implement measures to protect against ransomware attacks that may target the tabulation systems. You should track vulnerabilities and fully patch all devices before deploying them for elections. The following are some actions that you can take to implement a defence-in-depth or layered defensive approach to protecting your networks from threat actors.
- Use firewalls or network zoning protections to restrict network access to sensitive assets on the network
- Consider deploying network threat detection/protection systems to mitigate network-based attacks
- Update network devices regularly to minimize exposure to vulnerabilities
- Harden network devices by disabling unnecessary services, ports, protocols and applications
- Avoid connecting vote tabulators to public or untrusted networks
- Disable Internet connectivity on vote tabulators or interconnected systems
- Implement protection against threats associated with third-party (vendors or partners) network connectivity
Secure access controls
When designing and building an electronic tabulation system, it is essential to properly manage user and administrative privileges, isolate sensitive functions, and incorporate security engineering principles. User access rights should be restricted to only those required to perform assigned tasks. System functions should implement the principle of least privilege, which only gives users the set of privileges that is essential for them to perform authorized tasks. The following are some recommended actions you can take to implement secure access controls within vote tabulation systems.
- Verify that all personnel with administrative access to the system at any point in the lifecycle meet the necessary personnel security requirements
- For example, some electoral systems may require that administrative access be given only to Canadian citizens with a valid security clearance
- Maintain formal security vetting for all personnel with administrative access throughout the lifecycle
- Require personnel security screening and background checks for personnel requiring privileged or administrative access to the election and voting infrastructure; software developers, hardware assembly technicians, program managers, and election administrators responsible for administering federal elections will require a security clearance to support the voting infrastructure
- Ensure administrative accounts are used exclusively to perform administrative tasks and that these privileges are regularly audited
- Employ two-person control for all interactions with vote tabulators during their lifecycle, except for the moment when individual voters cast ballots
- Do not share access credentials; ensure that each user has unique credentials to access vote tabulation systems
- Enforce the use of passphrases or strong passwords on voting systems
- Use strong authentication protocols and never store passwords in plain text
- Protect authentication parameters with modern hashing algorithms to provide resilience against cryptographic attacks
- Require multi-factor authentication (MFA) mechanisms for administrative access to vote tabulation systems
For more information on account and access management, read Best practices for passphrases and passwords (ITSAP.30.032), Secure your accounts and devices with multi-factor authentication (ITSAP.30.030), and Top 10 IT security actions: No. 3 Managing and controlling administrative privileges (ITSM.10.094).
Lock down devices
Elections administrators should ensure that the configuration and security settings shipped with vote tabulators are updated to align with organizational policies. Elections administrators should also consider taking the following actions to lock down vote tabulators:
- Restrict the services enabled on the systems and devices, and prevent users from creating or changing system settings or configurations
- Only enable services that are required for performing intended tasks
- Disconnect external devices, such as printers, fax systems, and computing devices, from voting tabulators when they are not in use
- Restrict access to any existing auxiliary or data ports
- If there is an operational need to enable these ports, it should be evaluated through a risk assessment review process
Validate and authenticate devices
It is important to implement robust authentication mechanisms to ensure that vote tabulation devices remain trusted. Consider mechanisms to continuously validate and authenticate the integrity of vote tabulators through their lifecycle. For example, confirm the validity of trusted public key infrastructure (PKI) digital signatures on software packages. Elections administrators should consider software logic and accuracy testing to validate that the vote tabulators operate as expected. Using device cryptographic certificates can also help with physical device certification.
Patches and system updates
It is essential to undertake regular patch management to protect the vote tabulator against known and unknown threats. You should also implement the following measures:
- Ensure device firmware and software are kept up to date
- Apply device patches and software updates regularly
- Use cryptographic mechanisms to verify firmware and software before applying updates
- Validate that update deployment cycles do not operationally impact scheduled election events
Secure application development
Elections administrators may require software application development or procurement to meet specific legal or bylaw requirements. Security considerations should be evaluated throughout all phases of the development or procurement process. Regardless of the software application acquisition model selected, security requirements should be clearly defined and documented to assess functional and security objectives. Threat modeling or threat assessment techniques can also be used to identify and address potential threats associated with software applications to be deployed on the vote tabulator. Modern software stacks are so complex that lifecycle compromises should be assumed. Elections agencies can reduce their attack surface by identifying and managing risks early during the application design stage and architect to adequately mitigate those risks.
Software application testing
Static and dynamic testing approaches may be used to test the security of system software. Static testing involves source and binary code testing, while dynamic testing involves testing the application in functional use. Your software assurance process should allow you to evaluate applications in a test environment. Adopt functional and penetration testing controls to validate security objectives and address all identified vulnerabilities. Do not assume that an application has been vetted; instead, conduct your assessment in line with your security objectives. Leverage formal testing standards such as those defined by Common Criteria, OWASP Application Security Verification Standard (ASVS), and ISO/IEC 27034-1 Information technology — Security techniques ― Application security.
Audit log monitoring
Enable event and log collection capabilities on the vote tabulator to assist with incident investigations. Activity events should be logged in protected storage, like write-once media, and retention of log data should adhere to legal and privacy regulations. Make sure to coordinate logging activities with incident response and forensic objectives to ensure that the activity logs collected contain the information needed to investigate incidents.
Business continuity
You should establish and test business continuity plans and procedures to ensure your election activities can recover from adverse events. Business planning should identify which data must be backed up and establish testing and recovery procedures for your back-ups. In addition, you should consider which combination of onsite or offsite back-up options best meet your needs. Back-ups require the same security protections as actual devices, including physical security, network isolation, controlled access, and two-person-control.
For more information on business continuity planning, read Developing your business continuity plan (ITSAP.10.005). For more information on back-ups, read Tips for backing up your information (ITSAP.40.002).
For live elections, ensure you have contingency procedures and can quickly recover from unplanned events such as vote tabulator failures or theft. You should secure access to and encrypt sensitive data back-ups. You should also back up encryption keys, security certificates and credentials to facilitate recovery when required and disconnect external storage when not in use to minimize the likelihood that back-up data will be corrupted.
Retain paper backups
When designing elections processes that use vote tabulators, it is important that administrators consider resilient solutions to protect against disruption attacks and electronic manipulation. While keeping electronic data back-ups is a critical step in enabling quick recovery from unplanned incidents, paper records or copies of voter ballots and tabulated results should be maintained. If a catastrophic incident impacts the functioning of electoral systems, paper records will ensure the democratic process can proceed.
Plan for incidents and recovery
Security incidents may still occur even if you implement the best cyber security. Elections administrators should be prepared to deal with and recover from cyber security compromises. Have an incident recovery plan in place which outlines roles and responsibilities of all stakeholders. Test your plan regularly to assure its effectiveness. Electoral processes that rely on electronic systems should have manual and off-the-grid back-up measures that can be deployed should electronic systems fail.
For more information on incident response and recovery planning, read Developing your incident response plan (ITSAP.40.003) and Developing your IT recovery plan (ITSAP.40.002).
Educate users
Educating elections staff and volunteers about cyber security risks is critical for maintaining the safe operation of vote tabulators. Frontline elections staff and volunteers should be trained on how their actions could help facilitate or thwart a cyber security attack. Ensure elections staff receive regular training to understand the threat environment. Training and awareness programs should target all users of electoral systems. You should also periodically evaluate the effectiveness of your training programs and ensure the content is aligned with threat assessment feedback and addresses key threat issues.
For more information on tailored cyber security training, read Top 10 IT security actions: No. 6 Provide tailored cyber security training (ITSM.10.093).
Personnel security
An effective security screening process for your staff and volunteers is crucial. Implement a personnel and volunteer screening process to ascertain and validate the integrity of people recruited to work as poll staff or elections officials. Conduct security background checks before employees and volunteers are hired. Ensure the screening process continuously assesses the suitability of employees or volunteers even as they change roles or positions.
To limit the possibility of foreign legal compulsion, only Canadian citizens with the appropriate security clearance should be granted administrative access to the vote tabulation system during any phase of its system lifecycle.
Security control effectiveness
Assessing and testing the effectiveness of security controls deployed on vote tabulators is an important step in ensuring systems are functioning as expected and will be resilient against real-world attacks. Elections administrators can leverage controlled testing strategies such as procedural or physical penetration testing and threat modelling techniques. In addition, the following are some other measures that can help ensure that security controls remain effective:
- Automating assessment measures to continuously validate that operational, technical, and management control measures are functioning as expected
- Identifying relevant security, operational and performance metrics that should be evaluated
- Assessing the cyber resiliency capabilities of the system to withstand disruptive events such as a logic bomb
Conclusion
Vote tabulation devices provide electronic capabilities that can enable and enhance the democratic process and increase efficiency. However, potential threats to vote tabulators, such as disruptions or altered data, can negatively impact trust in the democratic process. The applications and deployment architecture of these systems must therefore be carefully considered. To lessen the impact of potential attacks when deploying and using vote tabulators, elections management bodies should adopt a rigorous focus on security, including appropriate control protections.
Elections administrators must adopt a data-centric strategy which implements security controls across the data path to secure voting systems. They should ensure that vote tabulators used during democratic elections are validated and that appropriate security protections are in place. Elections administrators should further ensure that the integrity of software, firmware, and hardware deployed in tabulation devices is validated, and should continuously protect these devices and systems throughout their entire lifecycle.
Effective date
This publication takes effect on August 6, 2026.
This is an UNCLASSIFIED publication that has been issued under the authority of the Head of the Canadian Centre for Cyber Security (Cyber Centre). For more information, contact the Cyber Centre:
- by email: contact@cyber.gc.ca
- by phone: 613-949-7048or 1-833-CYBER-88