Significant concerns have been raised about the security of the 2020 United States election. Hundreds of millions of dollars in Federal funding has been made available to state and local governments to improve the security of election systems and remediate vulnerabilities within critical organizations. Congressional hearings have highlighted risks to electronic voting systems and the vendors who manufacture them. Government task forces have been created to address the challenge.
Are these efforts having an impact?
After Congressional testimony was received in January 2020 from Voting System Vendors and experts, Bitsight began tracking the security performance of a number of Voting Systems Vendors who together represent a large percentage of the U.S. election infrastructure market. Voting System Vendors are companies that produce electronic voting machines, equipment, software, and services for use in U.S. elections. Bitsight continuously collects over 200 billion security events on a daily basis from around the global internet leverage in an automated, non-intrusive fashion, and leverages this data to track security performance of organizations around the world.
Since January 2020, Bitsight has observed steady improvement in security hygiene among critical Voting Systems Vendors, suggesting that these organizations have made changes to their security programs that have resulted in improvements.
Back in January 2020, the median Bitsight security rating of Voting System Vendors was 695. (The Bitsight rating scale is from 250-900, with lower scores correlated to breach probability). Bitsight observed a number of critical security issues. For example:
- A Voting System Vendor was observed with multiple instances of network administration and monitoring interfaces exposed to the Internet. As a best practice, such interfaces should be protected behind a firewall to prevent them from being discovered as a potential attack surface. If compromised, network infrastructure devices can enable attackers to rapidly expand access to an organization by enabling them to monitor internal network traffic for sensitive information and attack other internal network services.
- A Voting System Vendor was observed running software vulnerable to a critical severity vulnerability (CVE-2019-11581). This extremely high severity vulnerability means that an attacker can likely gain remote access to the host operating this software with minimal effort.
- A Voting System Vendor was observed running remote access software that is no longer supported by the platform on which it operates. Such software may not receive updates to critical security issues, leaving it potentially vulnerable to exploitation. This represents evidence that the Vendor does not operate an effective software patching program.
- A Voting System Vendor was observed operating an open DNS resolver, meaning one that will respond to requests for which it is not configured to resolve authoritatively. In addition to making this DNS resolver vulnerable to an array of attacks and compromises, it is a misconfiguration that may reflect a poor understanding of networking principles on behalf of the staff responsible for managing and securing the Vendor’s network infrastructure.
Since we first made these observations in January, Bitsight has observed improvements in the Voting System Vendors’ security posture. From January 1, 2020 until August 28, 2020, Bitsight has observed that Voting System Vendors median Bitsight security ratings have improved from an average rating of 695 to an average rating of 745, a 50 point improvement over the timeframe. Because Bitsight ratings are the only security rating independently correlated with breach, this measurable improvement means that the group significantly reduced their breach probability during the critical run-up period to the election.

