Election Security & PSYOP: Mission Domain Intelligence Guide
The claim that the count was rigged was already trending three weeks before polls opened. The infrastructure held perfectly. The narrative had been pre-positioned anyway.
The claim that the count was rigged was already trending three weeks before polls opened. The infrastructure held perfectly. The narrative had been pre-positioned anyway.
What Election Security & PSYOP covers as a mission domain
Election security and psychological operations analysis covers the protection of electoral processes and the detection of influence campaigns aimed at voters, officials and confidence in results. The technical side includes voter registration database integrity, election management system and vendor supply chain security, results reporting and transmission, and the physical security of polling places, ballots and staff. The human side covers targeted psychological operations: pre-emptive delegitimisation narratives, voter suppression messaging, intimidation and doxxing of election officials, and manipulation aimed at depressing or redirecting turnout in specific communities.
Sub-areas include electoral infrastructure defence, official and poll-worker protection, voter-facing information integrity, and post-election dispute monitoring. Actor types include foreign state services pursuing strategic destabilisation, domestic political operators running paid amplification, financially motivated actors monetising outrage, and hacktivists attacking results-display systems for visible effect. Election management bodies themselves are part of the picture, since capacity, transparency and communication quality determine how much traction any manipulation gains.
Why it matters
Elections concentrate attack surface and consequence into a fixed calendar with no ability to postpone. A results-reporting outage lasting an hour can be more damaging to confidence than a real compromise, because perception is the actual target. Officials face sustained personal threat that drives experienced staff out of the profession, degrading capability for years. Observers, regulators and platforms all need indicators early enough to correct rather than merely document.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Voter registration extracts appearing for sale or free download on criminal forums ahead of a scheduled poll.
- Typosquatted or lookalike domains registered against election management body names, especially those configured for credential collection.
- Delegitimisation narratives seeded weeks before voting, asserting fraud in a process that has not yet occurred.
- Coordinated messaging giving incorrect polling dates, locations, identification requirements or eligibility rules to specific communities.
- Doxxing and threat campaigns against named election officials and poll workers, typically following a viral accusation about one location.
- Denial of service or availability incidents targeting results-display and unofficial tally sites rather than the counting systems themselves.
- Synthetic audio or video of a candidate or official released inside the period when correction cannot realistically catch up.
- Late procedural changes, observer accreditation refusals or unexplained polling station relocations in specific districts.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- CISA election security resources — Guidance, advisories and risk management material for election infrastructure owners and operators in the United States.
- EI-ISAC and MS-ISAC — Sector threat sharing, indicator feeds and incident support specifically for election officials and jurisdictions.
- OSCE ODIHR election observation reports — Detailed methodological assessments of electoral process, administration and legal framework by country.
- International IDEA and IFES — Comparative electoral systems data, electoral integrity resources and risk management frameworks.
- EU Election Observation Mission reports — Independent observation findings and recommendations covering administration, media environment and dispute resolution.
- Certificate Transparency logs and WHOIS records — Detection of lookalike domain registration and phishing infrastructure targeting electoral bodies.
- Platform transparency and threat reports — Meta, Google TAG and similar disclosures of coordinated inauthentic behaviour and influence operations by campaign.
- National electoral commission publications — Official results feeds, procedural rules, observer accreditation policy and complaint adjudication records.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Map the electoral attack surface — Inventory registration systems, vendors, tabulation, transmission, results display and physical sites, including the third parties each depends on.
- Set the pre-election baseline — Establish normal levels of political conversation, domain registration and official mention volume so a manipulation surge is measurable.
- Monitor infrastructure indicators — Watch for credential exposure, lookalike domains, leaked voter data and vendor compromise, feeding findings straight to the affected jurisdiction.
- Track narrative pre-positioning — Identify delegitimisation and suppression themes early, recording seeding order across platforms and the accounts introducing them.
- Protect the human layer — Monitor for doxxing and threat activity against officials and poll workers, and route it to protective services quickly.
- Run a live operations picture — On polling day, correlate reported incidents, outage reports and viral claims so real problems are separated from manufactured ones.
- Report post-election — Document what happened, what was claimed, and what was substantiated, then feed the gap analysis into the next cycle's preparation.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Election Intelligence — Electoral Processes, Integrity, and Threats
- Disinformation Intelligence — Detecting and Analyzing Information Manipulation
- Social Media Intelligence — Intelligence from Social Platforms and Networks
- Government Intelligence — Government Structures, Policy, and Officials
- Cyber Intelligence — Adversary Activity in Networks and Systems
- News Intelligence — Media Reporting as an Intelligence Source
Worked in these data points
- Social Profile — A social media profile or online account page tied to a persona or identity.
- Keyword / Narrative — A search term, topic, hashtag, or narrative tracked across media and platforms.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- URL — Uniform Resource Locator pointing to a web resource.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Username / Handle — Screen name or handle used across online platforms and services.
Adjacent mission domains
- Disinformation / IO
- Nation State
- Corruption & Governance
- Extremism & Radicalization
- Transnational Repression
Inside the platform: where Election Security & PSYOP lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
gdelt.php— Election Security & PSYOP dashboarddomain.php?d=election— Mission domain hubtheater.php?d=election— Threat theater viewurl-profile.php— Domain Name profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Election Security & PSYOP:
- Disinformation / Influence Op Response — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Phishing Investigation & Takedown — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Sync Intel Domains
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Map the electoral attack surface is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Monitor infrastructure indicators turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report post-election feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Election Security & PSYOP
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence involvement in electoral security is normally limited and carefully bounded: support to civil authorities for logistics and physical security where requested and lawful, protection of military voting arrangements, and assessment of foreign influence activity targeting national decision making. Analysts may support situational awareness for public order contingency planning without becoming involved in the political content of campaigns. Products feed civil-military coordination and force protection. The constraints are the most important part of the brief: armed forces must not collect on domestic political speech, must not be positioned as arbiters of electoral legitimacy, and any technical findings belong with civil election authorities and the national cyber authority.
🕵 National intelligence
National intelligence requirements cover foreign state interference: targeting of electoral infrastructure and vendors, influence operations aimed at voters and officials, and hack-and-leak activity timed to the electoral calendar. The analytic and legal boundary is strict, since collection on domestic political activity is prohibited or tightly constrained in most democracies. Fusion combines infrastructure telemetry, platform reporting and foreign intelligence, with careful segregation of domestic content. Because election officials need actionable warning quickly, an unclassified tearline is essential. Judgments should address the integrity of process rather than the merits of any political claim.
👮 Law enforcement
Law enforcement handles threats and harassment against election officials and poll workers, intrusion into election systems, voter intimidation, and fraud offences. Evidential work requires early preservation of threatening communications with full headers and platform records, lawful process for subscriber and content data, and careful handling of any material touching political expression, which is constitutionally protected in most jurisdictions. Investigators should coordinate with election authorities so protective measures are implemented alongside the investigation. Charging typically rests on threat, harassment, computer misuse and election-specific offences, and prosecution decisions are politically scrutinised, so documentation must be immaculate.
🔍 Private investigation and corporate security
Private sector involvement centres on vendors, platforms and civil society organisations supporting electoral processes rather than on campaigns themselves. Legitimate work includes supply chain security assessment for election technology vendors, protective intelligence for organisations and officials receiving threats, and infrastructure monitoring under contract to an election authority. Private actors must not monitor voters, must not profile individuals by political affiliation, and must not conduct any activity that could be characterised as interference. Findings on infrastructure weaknesses go to the election authority and the national cyber authority under coordinated disclosure.
📰 Journalism and OSINT media
Election reporting carries an unusual verification burden because false claims about process are themselves the attack. Verification means going to the election authority and published procedures rather than to viral claims, understanding how results transmission and canvassing actually work in that jurisdiction, and distinguishing an administrative error from evidence of manipulation. Reporting on influence operations should focus on behaviour and infrastructure rather than on the truth value of contested political claims. Protect sources among officials, who face harassment and dismissal. Give authorities a right of reply and avoid amplifying unverified fraud narratives while investigating them.
🌍 NGO, humanitarian and human rights
Civil society organisations conduct observation, voter education, official protection and information integrity work. Practice follows established observation methodology with declared methods and transparent findings, since credibility is the entire asset. Do-no-harm requires care that documentation of irregularities is precise, since imprecise claims fuel delegitimisation narratives regardless of intent. Protection work with officials facing doxxing and threats should be victim centred and coordinated with law enforcement where the person consents. Duty of care extends to observers and local staff, who face intimidation, accreditation denial and in some contexts violence.
🎓 University and research
Election security research spans infrastructure security, information integrity, administrative resilience and public trust, and the standard hazards are inferring manipulation from anomaly and studying platform data with unrepresentative samples. Distinguish clearly between administrative irregularity, which is common and mostly benign, and evidence of manipulation, which requires a demonstrated mechanism. Ethics approval is required for research involving voters, officials or platform data on individuals. Publish coding rules and sampling frames, cite the specific jurisdiction and election cycle since procedures vary enormously, and coordinate disclosure of any technical vulnerability with the election authority before publication.
Playbook: working Election Security & PSYOP end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Map the electoral system as it actually works
Document the specific processes in the jurisdiction: registration systems and who maintains them, ballot design and printing, polling place operations, tabulation, results transmission, canvassing, audit and certification, and the vendors involved at each step. Most fraud narratives depend on public unfamiliarity with these mechanics, so accurate description is itself a defence. A good output is a process map with the responsible authority and vendor at each stage. Stop when every step from registration to certification has a named owner.
Phase 2 — Inventory the attack surface
Enumerate the technical estate: registration databases, election management systems, ballot marking and tabulation equipment, results reporting websites, official communications channels and the vendors and contractors with access. Include the human surface: officials, temporary poll workers and their onboarding. Election estates are typically distributed across many small jurisdictions with uneven capacity. A good output is an inventory with ownership, connectivity and support arrangements documented. Stop when every internet-facing asset associated with the process is identified and owned.
Phase 3 — Baseline the information environment
Establish the normal pattern of political conversation, the main communities and outlets, and the pre-existing narratives about electoral integrity in the jurisdiction, well before the campaign. Delegitimisation narratives are usually pre-positioned months ahead and reactivated at the count, so a baseline built during the campaign is already contaminated. A good output is a baseline description of communities, outlets and existing integrity narratives with dates. Stop when you could recognise an imported or newly seeded narrative against the local pattern.
Phase 4 — Monitor infrastructure exposure defensively
Track the security posture of election-related domains and services using passive methods: certificate issuance for lookalike domains, domain registrations imitating official sites, publicly visible service exposure and known vulnerable software in vendor products. Passive observation only, with anything active requiring written authorisation from the authority. A good output is an exposure watch with lookalike domains identified for takedown. Stop before any scanning or testing of election systems without explicit authority.
Phase 5 — Detect narrative pre-positioning
Watch for integrity narratives being seeded ahead of the vote: claims that a specific process is corrupt, pre-emptive assertions that only fraud could produce a particular outcome, and targeted messaging aimed at specific communities. Record the earliest observed instance with archival capture, since provenance of a claim is often the whole story once it goes mainstream. A good output is a narrative register with first-observed dates and propagation paths. Stop at behaviour and provenance rather than adjudicating political claims.
Phase 6 — Protect officials and poll workers
Track threats, doxxing and harassment directed at election officials, working with the individuals concerned and with law enforcement where they consent. Preserve threatening material properly with headers and platform identifiers. Practical protective measures, from personal data removal to physical security at facilities, matter more than analysis here. A good output is a protective intelligence picture linked to actual protective measures taken. Stop collecting on the harassers beyond what supports a lawful referral.
Phase 7 — Prepare for incident and rumour response
Agree in advance who speaks, how quickly, and through which channels when an incident or a viral claim occurs, and pre-build factual explanations of the processes most likely to be misrepresented. Speed matters more than completeness on election day, but accuracy matters more than either. A good output is a rehearsed response plan with pre-cleared explanatory material. Stop when the plan has been exercised with the officials who will actually execute it.
Phase 8 — Monitor election day operations
During voting, monitor for coordinated disruption: results site availability, unusual traffic, reports of equipment failure clustering geographically, disinformation about polling hours or eligibility targeted at specific communities, and intimidation at polling places. Distinguish routine operational problems, which occur in every election, from patterns indicating coordination. A good output is a running situational picture with verified incidents separated from unverified reports. Stop amplifying unverified claims even while investigating them.
Phase 9 — Support post-election dispute monitoring
After polls close, the risk shifts to the count, canvass, certification and litigation phases. Monitor delegitimisation narratives reactivating, threats to certification officials, and claims tied to normal procedural steps such as late-counted ballots. Document precisely, since imprecision here fuels the narratives you are tracking. A good output is a phase-by-phase record of claims, their factual basis and their propagation. Stop when the certification process concludes or the litigation record supersedes the analysis.
Phase 10 — Run a structured after-action review
After certification, review what worked: which exposures were closed before the vote, which warnings reached officials in time, which narratives were anticipated and which arrived unseen, and how quickly incidents were correctly characterised. Feed findings into the next cycle's baseline, since electoral security work is cyclical and institutional memory decays with staff turnover. A good output is a written review with specific changes assigned to owners. Stop when the review produces changes rather than observations.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| CISA election security resources | Open | Guidance, advisories, risk assessment materials and services for election infrastructure owners and operators in the United States. | The reference protective guidance and advisory stream for election infrastructure defence, including services offered to election offices. |
| Center for Internet Security and EI-ISAC | Registration | Sector information sharing for election infrastructure with indicators, advisories and member support services. | Peer sharing of live threat activity affecting election offices and vendors, with sector-specific context. |
| OSCE Office for Democratic Institutions and Human Rights | Open | Election observation methodology, mission reports and recommendations covering process integrity across participating states. | The methodological standard for observation and a documented baseline of prior findings by country. |
| International IDEA | Open | Comparative databases on electoral systems, management bodies, political finance and voter turnout across countries. | Establishes how a jurisdiction's system actually works before assessing claims about it. |
| International Foundation for Electoral Systems | Open | Technical assistance materials, research and country resources on electoral administration and cybersecurity for election bodies. | Practical reference on election administration processes, technology and the security capacity building offered to election bodies. |
| EU election observation mission reports | Open | Detailed observation findings and recommendations on electoral processes in observed countries, with methodology annexes. | Documented prior findings and institutional weaknesses to build a jurisdiction baseline from. |
| Certificate Transparency logs via crt.sh | Open | Public logs of issued TLS certificates searchable by domain, revealing newly created lookalike and impersonating domains. | Early detection of domains impersonating election authorities, often visible before any content is published. |
| Platform transparency and threat reports | Open | Periodic disclosures by major platforms on coordinated inauthentic behaviour takedowns, with actor attribution and datasets. | Documents influence operations targeting electoral processes and provides indicators for further research. |
| National electoral commission publications | Open | Official procedures, results, audit reports and administrative guidance published by the election management body. | The authoritative statement of process against which any fraud claim must be assessed. |
| MITRE ATT&CK | Open | Structured catalogue of adversary tactics and techniques with mitigations and detection guidance. | Common framework for mapping observed intrusion activity against election infrastructure to defensive controls. |
| National Vulnerability Database | Open | Catalogue of publicly disclosed vulnerabilities with severity scoring and affected product identifiers. | Relevance assessment for vulnerabilities in election vendor products, supporting infrastructure and the software they depend on. |
| EUvsDisinfo | Open | Searchable database of documented pro-Kremlin disinformation cases with narrative categorisation and source records. | Reference for recurring narratives targeting electoral legitimacy, their historical deployment and the outlets that carried them. |
| ENISA guidance on securing elections | Open | European analysis and recommendations on the cybersecurity of electoral processes, technology and the bodies that administer them. | European framing of election infrastructure security expectations and the recommended controls authorities are measured against. |
| Academic election integrity research archives | Open | Peer-reviewed research on electoral integrity measurement, administration performance and public trust across jurisdictions. | Methodological grounding and comparative benchmarks for assessing integrity claims rather than adjudicating them politically. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Election Security & PSYOP. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Certificate transparency search — Detects newly issued certificates for lookalike election domains. High volume and noisy, so filtering rules matter more than the search itself.
- Passive DNS services — Pivots between impersonating domains and shared hosting infrastructure. Shared hosting produces frequent false relationships that need verification.
- Archival capture tools such as Hunchly and web archives — Preserves claims and pages with timestamps before deletion. Provenance of first appearance is often the decisive evidence in narrative work.
- Social network analysis tooling — Maps propagation of narratives and account clusters. Platform data access limitations increasingly constrain what can be observed at all.
- MISP or OpenCTI — Shares indicators with election authorities and sector partners. Only useful where recipients have the capacity to act on indicators.
- Personal data removal services and privacy tooling — Reduces doxxing exposure for officials and poll workers. Effective at the margin, and no substitute for physical protective measures.
- Tabletop exercise frameworks — Rehearses incident and rumour response with the officials who will execute it. Value depends entirely on realistic injects and honest debriefs.
- Structured narrative registers — Records claims with first-observed dates and propagation paths. Discipline in dating first appearance is what makes the register useful later.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Sync Intel Domains — Refreshes the reference and country-level intelligence datasets from their authorities.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- The narrative usually arrives before the attack, and often instead of it. Pre-positioned delegitimisation claims are seeded months ahead and reactivated at the count, so baseline the information environment long before the campaign begins.
- Accurate description of process is a defence. Most fraud narratives exploit unfamiliarity with normal procedures such as late-counted ballots and canvassing, so pre-built factual explanations are protective infrastructure.
- Distinguish administrative irregularity from manipulation ruthlessly. Every election contains errors, and treating error as evidence of manipulation does the attacker's work for them regardless of intent.
- Analyse behaviour and infrastructure, not political content. The moment your work adjudicates contested political claims rather than coordination and provenance, its credibility and often its legality collapse.
- Archive first appearance obsessively. Once a claim goes mainstream, the question that matters is where it originated and how it moved, and that record cannot be reconstructed after deletion.
- Protective measures beat analysis for officials under threat. Personal data removal, facility security and law enforcement referral change outcomes; an elegant threat assessment on its own does not.
- The post-election period is the higher-risk phase in most contested elections. Plan monitoring and protective capacity through certification and litigation, not through election day alone.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Election Security & PSYOP is producing anything, and they are worth baselining before you change process or tooling.
- Number of lookalike or impersonating domains identified and referred for takedown before they were used against voters.
- Time from an infrastructure exposure being identified to remediation by the responsible election authority or vendor.
- Proportion of pre-positioned narratives that had been identified and factually pre-briefed before they went mainstream.
- Time from a viral integrity claim appearing to an accurate public response from the election authority.
- Number of officials receiving threats who were connected to protective measures and, where they consented, to law enforcement.
- Share of monitored incidents correctly characterised as routine operational problems rather than escalated as manipulation.
- Completion of after-action reviews with specific changes assigned to named owners and carried into the following electoral cycle.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Most reported election day problems are ordinary administrative and equipment failures, and treating them as attacks does the adversary's work.
- Measuring influence operation reach is not measuring effect; exposure metrics say nothing reliable about vote change.
- Analysis of electoral integrity is inherently political, and perceived partisanship destroys the credibility the work depends on.
- Amplifying a false claim in order to debunk it frequently extends its reach beyond its original audience.
- Attribution of influence campaigns is slow and often inconclusive, while decision windows around an election are measured in hours.
- Focusing on the vote itself misses the more common target, which is the reporting, certification and dispute period afterwards.
Legal and ethical considerations
Election work sits inside electoral law, which varies enormously and often restricts publication near polling day, including blackout periods and exit poll rules. Voter registration data is personal data and is protected even where portions are public. Foreign nationals and organisations face specific prohibitions on electoral participation and funding in many jurisdictions. Avoid any activity that could be construed as testing live electoral systems, coordinate technical findings through the election authority, and disclose your own funding and methodology.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Election Security & PSYOP, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 7 data points, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Is the main threat to elections technical or informational?
Informational, in most observed cases, though the two are linked. Direct manipulation of votes at scale is difficult in distributed systems with paper records and audits, and it is heavily monitored. Undermining confidence is far cheaper and does not require touching a single system: a pre-positioned narrative that the count is rigged achieves political effect whether or not the infrastructure was ever touched. Even minor technical incidents, such as a results display website outage, become fuel for that narrative. Defence therefore requires both hardening and a rehearsed capability to explain normal processes quickly and accurately.
How do I assess a claim that an election was rigged?
Start from the mechanism. Ask what specific process is alleged to have been manipulated, who would have had to do what, whether the described mechanism is physically possible given the procedures in that jurisdiction, and whether it would be detectable by the audits and reconciliations that exist. Most claims fail at the mechanism stage because they describe processes that do not work the way the claim assumes. Then check the audit and canvass records, which are usually public. Report the mechanism analysis rather than a verdict on the political claim, and be precise about anything genuinely irregular.
What can be monitored without crossing into surveillance of voters?
Infrastructure, provenance and coordination. Certificate issuance and domain registrations for impersonating sites, publicly visible exposure of election-related services, platform-published takedown datasets, and the behavioural signatures of coordination such as synchronised posting and asset reuse are all legitimate. What is not legitimate is profiling individuals by political affiliation, building databases of voters or their views, or monitoring domestic political speech on behalf of a state security body. The boundary is the unit of analysis: networks, infrastructure and behaviour are in scope, individual voters and their opinions are not.
When should election officials be told about a vulnerability?
Immediately, and before anyone else. Election authorities operate under fixed calendars with no possibility of delay, so remediation windows are short and disclosure timing must respect them. Contact the authority through its published channel, involve the national cyber authority and the sector information sharing body, and agree a remediation and disclosure timeline. Do not test, do not probe further, and do not publish technical detail, since a live vulnerability in election infrastructure is both an attack opportunity and a gift to delegitimisation narratives. Document the disclosure so accountability exists on both sides.
How should threats against election officials be handled?
As a protection problem first and an analytic one second. Preserve the threatening material immediately with full headers, platform identifiers and timestamps, since deletion is common. Then focus on the person: personal data removal, facility and home security review, workplace protocols and, with their consent, referral to law enforcement with the preserved evidence. Officials frequently under-report because they expect nothing to happen, so make reporting easy and visibly acted on. Analysis of the harassment network is useful for pattern and referral purposes, but it should never displace the protective measures.
Does observing an election require a formal mandate?
For formal observation with public findings, yes in practice. Recognised observation operates under invitation and accreditation from the host authority and follows established methodology with declared methods, sampling and reporting standards, because credibility depends entirely on transparent method. Informal or unaccredited observation can create risk for participants and is easily characterised as interference. Independent research and monitoring of the information environment or infrastructure does not require accreditation, but it should be clear about what it is, publish its methodology, and avoid presenting itself as an authoritative verdict on the conduct of the election.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- OSCE Copenhagen Document commitments on democratic elections, which define the standards observation missions assess against.
- OSCE ODIHR election observation handbook methodology, which sets observer conduct, sampling and reporting practice.
- International Covenant on Civil and Political Rights Article 25, which establishes the right to participate in genuine periodic elections.
- Venice Commission Code of Good Practice in Electoral Matters, which sets European standards on electoral law and administration.
- NIST Cybersecurity Framework and election-specific security guidance, which frame infrastructure protection for election bodies.
- Coordinated vulnerability disclosure under ISO 29147 and ISO 30111, adapted to fixed electoral calendars.
- Declaration of Principles for International Election Observation, which governs the conduct and independence of observation missions.
- National data protection law governing political and voter data, which constrains what may lawfully be collected and processed.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Election security resources and advisories — US Cybersecurity and Infrastructure Security Agency. Protective guidance and services for election infrastructure owners
- Election observation reports and methodology — OSCE Office for Democratic Institutions and Human Rights. Observation findings and the methodological standard for election assessment
- Electoral system and management databases — International IDEA. Comparative data on electoral systems, administration and political finance
- Election technical assistance resources — International Foundation for Electoral Systems. Reference material on electoral administration and security capacity
- Elections Infrastructure ISAC — Center for Internet Security. Sector information sharing and advisories for election offices and vendors
- Adversarial Threat Reports — Meta. Disclosures of coordinated inauthentic behaviour takedowns with datasets
- EUvsDisinfo case database — EU East StratCom Task Force. Documented disinformation cases including electoral legitimacy narratives
- Certificate Transparency search — crt.sh. Public certificate logs used to detect impersonating election domains
- Guidance on securing elections — European Union Agency for Cybersecurity. European recommendations on cybersecurity of electoral processes
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: infrastructure exposure monitoring, narrative pre-positioning detection and official threat tracking across the full electoral calendar. Explore the platform, or browse the rest of the library by following any tag above.