A whistle blower has revealed to the BBC that the same month the Electoral Commission was breached by hackers, accessing records for over 40 million voters, it was told by cybersecurity auditors that it was not compliant with the Cyber Essentials Scheme.
The Scheme is a voluntary government-backed system that helps organisations protect themselves against the most common cyber-attacks. Under the scheme, the Electoral Commission has landed an automatic failure, citing outdated software on around 200 staff laptops, and the use of unsupported smartphones as the leading causes.
While the Commission was reprimanded for poor cyber-defences, unknown perpetrators breached voter databases. The hackers accessed the Commissions email correspondence, and potentially databases holding the names and addresses of 40 million registered votes, including those not on public registers.
The Cyber Essentials Scheme, while voluntary, is a good indicator if organisations are up to date in cybersecurity. However, as Ryan McConechy, CTO of Barrier Networks puts it: “The certification is more than another compliance check box to be ticked; It is a solid baseline to make sure that, as an organisation, many obvious pitfalls have been avoided, helping remove the easy wins so attackers give up or move on.”
The Commission first failed to get certified in 2021, around the time when the attacks could have begun. According to a commission spokesperson speaking to the BBC, the commission has still not completed the basic certification.
Recommended
- UK Electoral Register Reveals it Suffered “Complex Cyber-Attack”
- MPs Call for Laws to Prevent Online Interference During Elections
- Facebook Political Ad Overhaul Aims for Greater Transparency
“No organisation that handles the data of the UK population should ever gamble with security, the requirements of Cyber Essentials should be met as a standard practice and achieving certification should be a guarantee,” said McConechy.
However, the spokesperson claims the grounds for failing were not linked to the cyber-attack that breached its email servers.
The Information Commissioner’s Office (ICO) is now investigating the implications of the breach for data privacy and security since the compromised information belonged to both the public domain, and also to voters who opted out of public registers.





