people voting

DHS official: Look beyond November on voting-system security

With the 2016 elections just seven weeks away, state and local governments continue to work with the Department of Homeland Security to scan for vulnerabilities in voting and voter registration systems. DHS's Andy Ozment, however, contends that the real emphasis should be elsewhere.

"That’s a conversation that we’re having with state and local governments," said Ozment, DHS's assistant secretary of cybersecurity and communications, at a Sept. 20 event. "It’s an important conversation, but it’s not the conversation that should be the focus of our time right now."

Politically motivated cyberattacks on Democratic Party organizations, thought to be the work of Russian organizations, have raised concerns that the November elections could be hacked. And many election systems have been found to be far from secure. DHS Secretary Jeh Johnson said in August that the administration might classify election systems as critical infrastructure worthy of federal protection.

Ozment, who took part in a Washington, D.C., panel discussion hosted by the nonprofit organization Center Forward, said there was no timeline for a final decision on the critical infrastructure designation. He also voiced confidence in the system’s overall resiliency as Election Day approaches and urged a longer term view.

"We have an incredibly distributed election system," Ozment said. "We have thousands of state and local governments who are responsible for voting in their jurisdiction.  That makes it a robust system." He added that few actual voting systems were connected to the internet, while acknowledging that voter registration systems and databases might have more online exposure.

"We should absolutely be focused on cybersecurity for that system," he said, but it's more important "to take the focus that we’ve got and -- particularly as we upgrade these systems over the next four years -- make sure that we build cybersecurity in from the get-go."

In the meantime, Ozment said, DHS is "making sure state and local governments are aware of all the resources we have to offer to help them."  Those resources, he said, range from best practices guidance to "vulnerability scans across state government networks. We’ll do this for free; we’ll give them a report about every vulnerability we see."

Some of those services are available through the Multi-State Information Sharing and Analysis Center -- an independent organization set up to help state, local, tribal and territorial governments on cybersecurity matters without directly engaging DHS. Others, Ozment said, are being provided by various DHS components, though he stressed that none of them were mandatory.  

While there have been some calls (and concerns) for cybersecurity responsibilities to be more centralized, Ozment said DHS aims to be more like a firefighter for cyber -- scrambling to help when an incident occurs, while working to educate and empower others to prevent problems in the first place.

"Every aspect of government has to be dealing with cybersecurity," he said.  "There’s no way to say this one agency in charge."

About the Author

Troy K. Schneider is the Editor-in-Chief of both FCW and GCN, two of the oldest and most influential publications in public-sector IT. Both publications (originally known as Federal Computer Week and Government Computer News, respectively) are owned by GovExec. Mr. Schneider also serves GovExec's General Manager for Government Technology Brands.

Mr. Schneider previously served as New America Foundation’s Director of Media & Technology, and before that was Managing Director for Electronic Publishing at the Atlantic Media Company, where he oversaw the online operations of The Atlantic Monthly, National Journal, The Hotline and The Almanac of American Politics, among other publications. The founding editor of, Mr. Schneider also helped launch the political site in the mid-1990s, and worked on the earliest online efforts of the Los Angeles Times and Newsday. He began his career in print journalism, and has written for a wide range of publications, including The New York Times,, Slate, Politico, Governing, and many of the other titles listed above.

Mr. Schneider is a graduate of Indiana University, where his emphases were journalism, business and religious studies.


  • Records management: Look beyond the NARA mandates

    Pandemic tests electronic records management

    Between the rush enable more virtual collaboration, stalled digitization of archived records and managing records that reside in datasets, records management executives are sorting through new challenges.

  • boy learning at home (Travelpixs/

    Tucson’s community wireless bridges the digital divide

    The city built cell sites at government-owned facilities such as fire departments and libraries that were already connected to Tucson’s existing fiber backbone.

Stay Connected