Resource Library: Parallel Election Risks & Practical Mitigations

The Canvas breach serves as a warning for election officials. Below, the Exchange draws parallels between the risks presented by the Canvas breach and election administration and offers simple strategies for reducing those risks.

Communicate Clearly and Transparently

Risk: Login defacements and messaging manipulation created confusion. 

Parallel Election Examples:

  • Fake voting instructions  
  • Compromised election websites  
  • Fabricated “official” communications  

Mitigation Strategy Suggestions:

  • Have a trusted communication framework with established and verified channels
    • Official website domains  
    • Certified social media accounts  
  • Publicly educate voters on where to find trusted information
  • Pre-draft messaging for:
    • System downtime  
    • Cyber incidents  
    • Misinformation events  
  • Monitor for domain spoofing and website defacement 
  • Use content integrity monitoring and DNS security controls (DNSSEC)

Ensure System Redundancy and Backup

Risk: Canvas attackers struck during finals week when disruption would be most impactful. 

Parallel Election Examples:

  • Early voting
  • Election Day
  • Election night reporting

Mitigation Strategy Suggestions:

  • Develop offline contingency procedures
    • Paper pollbooks
    • Manual voter lookup processes
  • Ensure operability without internet-dependent systems
  • Have a “High-Alert Period” security posture
    • Increase monitoring during:
      • 60 days before an election
      • Election week through certification
    • Freeze non-essential system changes during critical periods
  • Avoid tying all processes to a single provider or platform
  • Maintain independent communication channels (e.g., SMS, radio, backup email systems)
  • Regularly test:
    • System backups
    • Data restoration procedures  
  • Validate that backups are unchangeable and offline
  • Enforce:
    • Multi-factor authentication (MFA) across all systems
    • Conditional access (location, device)
  • Eliminate shared accounts
  • Limit admin privileges: Only grant administrative rights to a system or resource when they are specifically needed, and only for a short, set amount of time. Then remove those rights automatically.
  • Monitor and log all privileged activity

Minimize Data Availability

Risk: Exposed data (names, emails, messages) enables targeted phishing and impersonation campaigns. 

Parallel Election Examples:

  • Poll worker contact lists
  • Internal contact lists
  • Public voter information datasets  

Mitigation Strategy Suggestions:

  • Audit and reduce stored communications and historical user data
  • Apply retention limits (e.g., auto-delete old messages/logs)
  • Limit access to internal communications:
    • Use role-based access controls (RBAC)
    • Implement segmentation between admin, election office, and poll worker access
  • Deploy anti-phishing controls
    • Email filtering with advanced threat detection
    • Domain monitoring (lookalike domains, spoofing)
  • Require Domain-based Message Authentication, Reporting, and Conformance (DMARC);  DomainKeys Identified Mail (DKIM); and Sender Policy Framework (SPF) enforcement across election domains

Manage Vendor Risk to Improve Resilience

Risk: The Canvas breach showed how a single vendor failure can cascade across thousands of customers simultaneously. 

Parallel Election Examples:

  • Statewide voter registration systems 
  • Election night reporting platforms
  • Electronic pollbooks 
  • Poll worker management systems  

Mitigation Strategy Suggestions:

  • Strengthen vendor contracts and requirements
    • Require contractual obligations for:
      • Breach notification within defined timeframes (e.g., < 24 hours)
      • Disclosure of attack and affected data
    • Mandate independent security attestations (such as SOC 2 Type II, FedRAMP, where applicable)
    • Require software bill of materials (SBOM) visibility for critical systems. A software bill of materials is a detailed, machine-readable inventory of all components, libraries, and dependencies that make up a software product, enabling transparency, security, and supply chain risk management. Revisit our Newsletter: Issue 10 to learn more about SBOM and for additional resources.
  • Continuously monitor vendor risk
    • Implement tools or services to monitor:
      • Vendor credential exposure
      • Dark web mentions
      • Known vulnerabilities impacting vendor software
    • Assign internal ownership for each critical vendor
  • Reduce single points of failure
    • Avoid reliance on a single provider for mission-critical workflows
    • Establish backup vendors or alternate workflows where feasible

Educate Users

Risk: The Canvas breach likely leveraged social engineering and identity compromise, not just technical flaws. 

Parallel Election Examples:

  • Temporary staff and poll workers 
  • Contractors and vendors  
  • Distributed workforce  

Mitigation Strategy Suggestions:

  • Train permanent and temporary workers to recognize phishing and how to verify requests (e.g., “callback” protocols)
  • Provide simple reporting mechanisms for suspicious activity
  • Conduct tabletop exercises with your Election Security Working Group and local, state, and federal partners to simulate:
    • Vendor outage on Election Day 
    • Phishing attack targeting poll workers  

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.