Connecting election experts, advancing security
Planning insights from the Election Security Exchange

Planning Desk, Week E-25: Analysis – From Signal to Decision

As detailed in our previous Planning Desk, detection tells you something happened. Analysis tells you what it is, how bad it is, and who needs to know. This is the step that turns a signal into a decision, and it is where most offices either over-react (a routine error gets broadcast as an attack) or under-react (a real incident gets logged as a glitch and forgotten until it comes back bigger).

The good news: you already have your Incident Response Plan (IRP) from the Planning Desk in issues 11-13. Analysis is the step that determines whether to activate it and at what level.

When a signal arrives, ask these three questions in this order:

  1. What is it? Error, incident, or attack? Each answer requires a different response. An unofficial results shift caused by a data entry error on election night is not a cyber incident, even though it can look like one from the outside. Getting this framing right the first time is critical.
  2. How bad is it? Scope (one precinct, one office, statewide), impact (confidentiality, integrity, or availability), and urgency (does it affect a process running right now). A written severity scale, agreed to in advance, makes this a 10-minute conversation instead of a 90-minute debate.
  3. Who needs to know? Internal leadership, your state election director, MS-ISAC, FBI, CISA, law enforcement, fusion center, legal counsel, and the public? Each contact has its own notification threshold, timeline, or contributions. Set those thresholds before Election Night, not during it.

Tie Severity to Action

Analysis is only useful if it drives a decision. The cleanest way to make that happen is to tie your severity tiers to specific actions in your IRP. For example:

  • Tier 1 (low): Monitor, notify the person responsible for documenting new incident reports. No activation. Reporting is largely informational and helpful.
  • Tier 2 (medium): Activate the IRP core team. Notify your Election Security Working Group. Prepare holding communications. Immediate reporting is necessary.
  • Tier 3 (high): Full IRP activation. Notify external stakeholders as outlined in your IRP. Issue public communications on a defined timeline. Immediate reporting is imperative.

The exact tiers matter less than the fact that they exist, are written down, and are familiar to the people who will use them.

Communications

The pressure to say something publicly will arrive before your analysis is complete. A clear, short holding statement (“We are aware of a reported issue, we are verifying the details, we will update at [time].”) buys you time to get the characterization right. Silence is worse than a holding line, and speculation is worse than silence. Draft the holding language now, so you are not writing it under pressure.

This is also where your analysis and your earlier detection log pay off together. The best public explanation of what happened is usually the honest, documented one. Communicating During an Election Incident offers guidance and additional resources on preparing communications. 

Actions You Can Take

  • Write down the three questions. Post them in the room where the IRP team will sit.
  • Agree on severity tiers and their triggers. Be specific about which scenarios hit which tier and what each tier activates.
  • Name the analyst role. One person owns characterization before escalation. That person does not have to solve the problem, only describe it accurately.
  • Tabletop real scenarios. Use last cycle’s reporting errors, a phishing attempt aimed at staff, and a polling-place power outage. For each, run the three questions and pick a tier.
  • Pre-draft holding communications. A short, honest placeholder for each tier, approved in advance.

Next issue, we move into Phase 3 of the Incident Response Process: containment, eradication, and recovery, where a well-run analysis hands off cleanly for a well-executed response.


The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.