Accountability is shared across election security teams, IT staff, campaign officials, and voters, because each group influences the attack surface in a different way. Security teams must harden systems and monitoring. IT teams must maintain access controls and patching. Campaign staff and voters must follow safe cyber behavior. Election protection only works when all parties treat it as an operational responsibility.
Shared accountability starts with shared attack surface
Election cyber risk is not owned by one role because the exposure is distributed across systems, people, and decisions. Security teams reduce technical risk by hardening infrastructure and monitoring for abuse, while IT staff own access control, patching, and account hygiene. Campaign staff and voters influence risk through the behaviors that determine whether phishing, weak authentication, or unsafe sharing succeeds.
The practical point is that accountability follows control over the relevant layer. A team cannot be accountable for risks it cannot influence, but it can be accountable for the controls it is expected to operate well. For election environments, that means responsibility is shared, but it is not vague: each group has a specific part of the prevention chain.
Why operational responsibility is different for each group
Security teams are accountable for the systems they defend, including alerting, logging, segmentation, and anomaly detection. IT teams are accountable for the access and maintenance layer, where patching, identity hygiene, device security, and configuration decisions reduce the chance that a routine weakness becomes a compromise. Those obligations map directly to common control failures such as stale accounts, unpatched systems, and weak administrative access.
Campaign officials and staff are accountable for the human processes around election work: verifying requests, protecting credentials, avoiding impersonation, and using approved communication channels. Voters are accountable for their own digital hygiene as well, because personal device compromise, credential reuse, and social-engineering susceptibility can be used to target voter information, campaign communications, or election-related services.
That division matters because election security is often broken at the seams between teams. A technically sound control can still fail if someone bypasses it in practice, and a cautious user can still be exposed if systems are not patched or monitored. CISA cyber threat advisories are useful here because they show how real-world campaigns often blend phishing, credential theft, and exploitation of known weaknesses.
What accountability means in practice
Accountability does not mean every group must do the same thing. It means each group must own the part of the process that only it can control, and the handoffs between groups must be explicit. Election security teams should define the baseline and verify that it is actually enforced, IT should maintain the technical guardrails, and campaign staff and voters should be given clear, repeatable behaviors that reduce exposure.
When accountability is well defined, you can answer three questions quickly: who must prevent the issue, who detects it first, and who can respond fastest. If those answers are unclear, election cyber risk becomes everyone’s concern in theory and no one’s responsibility in practice. For a useful control benchmark, NIST SP 800-53 Rev 5 Security and Privacy Controls provides a structured way to separate access control, authentication, monitoring, and system integrity duties.
That same logic explains why election protection has to be operational, not just policy-driven. The issue is not whether a team has a security statement; it is whether it can demonstrate secure configuration, timely patching, controlled access, and user behavior that does not undermine those safeguards. Where election operations depend on third-party platforms or shared services, CISA Known Exploited Vulnerabilities Catalog is a practical reminder that patch discipline is part of accountability, not an optional maintenance task.
What fails when accountability is treated as someone else’s job
The most common failure mode is role confusion. Security assumes IT has locked down access, IT assumes users will follow guidance, and campaign staff assume the technology layer will absorb unsafe behavior. That creates gaps where phishing, credential theft, exposed systems, or misconfiguration can move from a minor incident to an election-impacting event.
Another failure mode is incomplete ownership of the last mile. Voters and campaign staff are often given advice without clear consequences or easy-to-follow procedures, so the burden shifts to memory and judgment under pressure. In parallel, technical teams may focus on perimeter controls while overlooking the account, device, and communication paths that attackers actually use. When compromise is the concern, MITRE ATT&CK Enterprise is a useful reference for understanding how credential access, privilege escalation, and lateral movement turn weak accountability into operational exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Election cyber risk needs defined ownership across roles and functions. |
| Recommendation — Define and assign risk ownership across security, IT, campaign, and voter-facing controls. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Shared accountability depends on maintaining controlled, reviewable accounts. |
| IA-2 — Identification and Authentication (Organizational Users) | Staff and officials must authenticate securely to reduce misuse and compromise. | |
| Recommendation — Review and govern accounts that support election systems and operations. Enforce strong authentication for organizational users supporting election operations. | ||
| CIS Controls v8 | CIS-5 — Account Management | Accountability here hinges on controlling identities, access, and privileged use. |
| CIS-7 — Continuous Vulnerability Management | Election cyber risk is reduced by timely patching and vulnerability remediation. | |
| Recommendation — Maintain account inventory, review access, and remove unnecessary privileges. Track and remediate vulnerabilities on election-facing systems without delay. | ||
Practitioner Guidance
What to verify: Confirm that each stakeholder group has a named control owner, a defined escalation path, and a short list of actions they are expected to perform under routine and suspicious conditions. If those responsibilities are only documented at a high level, the program will be hard to audit and easy to bypass.
Decision rule: If a control failure can be prevented only by user behavior, treat it as a training and process problem as well as a security problem. If a control failure can be prevented by system settings, make the technical owner responsible for enforcing it by default rather than relying on reminders.
What good looks like: Security teams can show monitoring coverage, IT can show patch and access-control evidence, campaign staff can show safe-verification procedures, and voters receive simple, consistent guidance that matches the actual threat model. The goal is not equal effort from everyone, but reliable ownership at every layer that matters.
Practitioner takeaway: Election cyber risk drops when accountability is assigned to the party that can actually change the outcome, and when handoffs between technical, operational, and human responsibilities are explicit.
Related resources from NHI Mgmt Group
- Who should be accountable for aviation cyber risk across IT and operations?
- Who is accountable for reducing cyber risk in critical infrastructure environments?
- Who is accountable for reducing React2Shell risk across application, runtime, and network layers?
- Who is accountable for reducing deepfake fraud risk across verification and content systems?