Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Election Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative auditors flag insider cybersecurity risks in Utah election systems; recommend hardware limits
Summary
Legislative auditors told the Legislative Audit Committee that hands‑on testing of election equipment identified cybersecurity weaknesses that increase the risk of insider threats and operational disruption, though auditors said they found no evidence that vote tallies had been changed.
Get email alerts on the Election Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative auditors told the Legislative Audit Committee that hands‑on testing of election equipment identified cybersecurity weaknesses that increase the risk of insider threats and operational disruption, though auditors said they found no evidence that vote tallies had been changed.
The auditors, Jesse Martinson and Jake Dinsdale of the Office of the Legislative Auditor General, told the committee they inspected voting hardware and software in multiple counties, scanned network traffic and wireless signals, and reviewed internal configuration settings and physical ports. “Because of the sensitive nature of the concerns, we’re not gonna go into great detail about specifically what we found,” Dinsdale said, adding that the report’s recommendations target vulnerabilities identified in testing.
Why it matters: The auditors emphasized that Utah’s current layered protections — offline voting equipment, software certification and post‑election audits — reduce the likelihood that an attack would change election outcomes without detection. But they said procedural lapses and hardware features retained in some systems increase risk.
Key findings: Auditors reported (1) some voting servers had wireless networking components even when configured not to connect; (2) some user accounts had broader access rights than necessary; (3) election day observations showed paper lists of usernames and passwords kept near election workstations; and (4) a small number of election computers were stored in public or accessible spaces rather than secured vaults. Jake Dinsdale said the presence of wireless components “gives you the capability to connect,” and the auditors recommended the Legislature consider prohibiting wireless hardware in voting equipment.
County response and context: Ricky Hatch, Weber County Clerk/Auditor, speaking for Utah’s 29 county clerks, said clerks welcome the independent review and that many of the protections the auditors cited are already in place. “Voting systems are not connected to the internet,” Hatch said. He described protective measures including hash validation, multi‑factor authentication, security cameras, public logic‑and‑accuracy testing and post‑election audits. Hatch also said counties have begun implementing the audit recommendations, and that the specific unsecured computers the auditors photographed were not part of the ballot scanning/tabulation system.
Committee questions and follow up: Committee members asked whether the vulnerabilities implied a realistic chance of changing vote totals. Auditors and Hatch said post‑election audits and reconciliation processes are designed to surface tampering or discrepancies and would likely raise red flags if a change occurred. Auditors characterized the primary risk as an “insider” threat — someone with credentials and access — rather than a remote external hack.
Outcome and next steps: President Adams moved to refer the performance audit of election cybersecurity to the Government Operations Committee as lead and to the Political Subdivisions Interim Committee as the review committee. The committee approved the referral by voice vote. The auditors recommended statutory change to prohibit wireless components in election equipment; the report also includes operational recommendations (access control, credential practices, physical security and training) that auditors said counties should implement and that the Legislature may wish to consider.
Ending: Auditors said they will follow up on the recommendations and that the Legislative Audit Office and the lieutenant governor’s office will continue oversight and training work with counties.
