Following revelations about the national security of elections in the UK, the National Cyber Security Centre (NCSC) has released guidance for individuals and organisations to safeguard the democratic process.
The guidance was released just a day after the UK parliament linked the Electoral Commission cyber-attack of 2021 to China state-affiliated hackers.
The 2021 cyber-attack breached the electoral register and internal emails, but the UK government assured the public that the election and people’s registration status were not impacted.
“Democratic events such as elections are attractive targets for adversaries, and organisations and individuals must be prepared for threats, old and new,” the guidance said.
“Defending UK democratic institutions and processes is a priority.”
The NCSC provided specific adice for high-risk individuals, organisations coordinating elections, and political organisations.
High-Risk Individuals
Here, high-risk individuals are defined as those whose work or public status means they have access or influence over sensitive information. This typically includes those working in politics, academia, journalism, and the legal sector.
Individuals will likely be targeted via spear-phishing or another form of social engineering. To combat this, the NCSC recommends what can essentially be boiled down to good cyber hygiene: strong passwords, enabling two-step verification, and installing updates.
High-risk individuals would also benefit from replacing old devices, knowing how to erase data from devices, or using Lockdown Mode for Apple devices or S mode for Windows devices.
Suspicious links and emails should be reported to an IT department, even if the person has already accidently clicked on it.
Recommended reading
- Electoral Commission Failed Cybersecurity Test During Breach
- UK Electoral Register Reveals it Suffered “Complex Cyber-Attack”
- UK Gov to Link China to Electoral Commission Cyber-attack
Organisations Coordinating Elections
Valuation joint boards in Scotland, local authorities in England and Wales, and the Electoral Office in Northern Ireland, should take heed of this advice.
Securing Electoral Management System (EMS) software, including the data it processes, is vital in maintaining the integrity of elections.
Risk assessment, gaining assurance from EMS suppliers, securing and backing up EMS data, are all paramount steps in securing elections.
Organisations should also ensure the security of their entire electoral supply chain, so that no data is lost or at risk at any step of its journey.
The network EMS depends on should also be audited for its safety and security.
Political Organisations
This guidance is aimed at the staff managing the IT networks, systems, and data of political organisations.
These organisations should protect their cloud services by following previously given NCSC guidance, set up multi-factor authentication, and protect websites from denial of service (DoS) attacks.
IT staff should also make a concerted effort to defend against spear-phishing, which requires educating other staff on safe email practices, as well as implement anti-spoofing controls.





