Events / August 11, 2025

The Sweet Taste of Security: A Cake Approach to Fortifying Elections (Resources for County IT Professionals)

Today, elections are not what they used to be. They are much more. Like other aspects of county government, modern elections rely on an intricate web of technology and interconnected systems to safeguard the democratic process. The threat of a cyberattack is not a distant problem; it’s a persistent problem. If a vulnerability presents itself in one area, it could have cascading effects elsewhere or spoil one or multiple pieces of the process. To protect this system of systems, county officials should embrace a holistic defense-in-depth strategy, much like a delightfully constructed layer cake (Yum!), that is both resilient and instills public trust. Because if you do find yourself facing down a frosting spatula covered in sophisticated threats, the numerous layers can provide reassurance if one or multiple layers are bypassed.

A cake’s carefully chosen layers and ingredients combine to create an intersecting blend of flavors and textures that together make a superior whole. Similarly, a layered cybersecurity approach, where multiple layers are woven together, provides a stronger and more resilient defense against malicious threats. County IT officials have the latitude to craft a recipe that meets their unique needs. Let’s slice into this further.

First Comes The Foundation

Every cake needs a sturdy base to sit on, and it is non-negotiable. This refers to the physical infrastructure required to support operations, including hardware, facilities, surveillance cameras, and even election equipment. It’s any tangible item that supports vital operations. This layer is important because the digital and physical worlds are deeply intertwined. A compromise to one can result in severe consequences to the other. It’s just as important to focus on physical security protocols when crafting a multi-layered cybersecurity defense plan. Knowing what technology you have and where it resides is the first step.

  • Asset Management – Maintain a comprehensive inventory of all assets (servers, routers, laptops, vendor assets, etc.). You can’t protect and maintain assets without knowing what you have and where it is located.
  • Physical Access Control – Secure physical assets with key card access (and confirm that access logging is turned on), and ensure sensitive equipment is not accessible from public-facing locations. 
  • Secure Storage – Protect sensitive documentation in safe locations, such as locked cabinets or online repositories with strict access controls.

Add the Cake

The various layers of a cake represent network security across an organization, where multiple components come together to support various business operations and sections, such as the network perimeter and segments within the network. Without appropriate segmentation and controls, an unwanted guest can take it upon themselves to grab a bite of multiple layers or business units.

  • Firewalls – Implement and properly configure firewalls to segment your network. For example, the public Wi-Fi at the county courthouse should be isolated from the network used by employees to manage records.
  • Patch Management – Create a strict policy for regularly updating systems and software. If you can automate portions of this, even better. Adversaries are often looking for unpatched systems to exploit.
  • System Hardening – Establish benchmarks for things like servers and employee workstations, disable unnecessary software, ports, services, etc, reducing the potential attack surface.

Pick your Filling(s)

Just as the filling of a cake adds richness and protects its structure, the inner layers of security can safeguard core pieces of the network and assets. These fillings, or security technologies, are essential for detecting, containing, and neutralizing threats before they reach the heart of your infrastructure. Selecting and layering these solutions ensures your network remains resilient, even if a malicious actor finds a viable attack path.

  • Intrusion Detection and Prevention Systems (IDS/IPS) – An IDS acts like a smoke detector, alerting you to suspicious activity. At the same time, an IPS serves as a fire suppression system, blocking known threats.
  • Network Access Control (NAC) – Evaluate all access attempts and only allow entry to authorized devices and users. Also consider implementing this laterally as users navigate between different parts of the network, restricting lateral movement in the event of compromised credentials.
  • Endpoint Detection and Response (EDR) – These solutions can provide more advanced threat detection by monitoring for suspicious behavior. An EDR solution can detect and isolate an infected asset before it spreads to other assets.
  • Encryption – Secure assets and information by weaving in encryption throughout all aspects of the process, whether it’s data at rest or data in transit.

Frost the Cake

Frosting isn’t just delicious; it can be a protective outer layer before someone cuts a slice. This helps ensure that employees have access only to the systems and data they need to perform their duties, including temporary employees who may be required to surge in support of high-profile events, such as elections. 

  • Cybersecurity First Culture: Prioritize cybersecurity awareness throughout the organization, with a shared responsibility approach. It involves integrated planning across all aspects of the business, with executive support. It also includes sustained investment in cybersecurity training, as people are often the initial point of vulnerability.
  • Principle of Least Privilege (PoLP): Only grant users permissions required for their specific functions. This should be enforced strictly, which may require routine review and audits of user principles.
  • Multi-factor Authentication (MFA): Mandate MFA for all employees, especially for access to vital systems. This is one of the most effective controls to prevent malicious actors from gaining a foothold.
  • Zero Trust Security: A framework that assumes no user or device, even those from within the organization, can be trusted. Every access request should be authenticated each time through continuous verification.
  • Mutual/Cooperative Agreements: Form partnerships with neighboring counties, regional entities, or state bodies to improve information sharing, identify cost-sharing/cost-reduction opportunities, or share expertise to improve security proactively.

A Recipe for Trust

In conclusion, a layered approach to security can make a recipe for trust and strength. Each layer plays a crucial role in protecting the integrity of our sacred institutions, ensuring that essential county functions and elections are not only secure but also trusted by the public. By understanding the importance of a layered defense across aspects of the organization, supported by a strong partner network, county officials can work together and implement a strategic, layered approach to fortify essential operations against sophisticated cyber adversaries.

Resources for County Officials

Building a cybersecurity program isn’t a one-time effort. It’s a continuous process, but you’re not alone and there are a lot of peers and partners who are ready to support. Here are some resources to consider: