Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the State Government & Elections topic

No spam. Unsubscribe anytime.

Committee hears election-security bill: .gov domains, network isolation and breach reporting for vendors

2136494 · January 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Senate Bill 5014 would expand election-security requirements to include voter-assistance platforms and county network configurations, require vendor breach reporting, and recommend a phased implementation timeline.

Senate Bill 5014, introduced to the Senate Government, Tribal Affairs and Elections Committee on Jan. 21, would expand statutory security requirements for election systems beyond voting machines to include equipment and platforms used to provide voter assistance, tighten vendor breach-reporting requirements and require county auditors to implement a series of cybersecurity best practices.

Danielle Creech, committee staff, summarized the bill as performing three broad functions: extending Secretary of State approval beyond voting systems to any equipment or platforms used for voter assistance; requiring disclosure of security breaches by manufacturers, distributors, or contracted organizations that support the voter registration database to the Secretary of State and the attorney general; and directing county auditors to adopt cybersecurity measures such as using the dot-gov top-level domain, logically and physically partitioning election infrastructure from other county IT systems, isolating ballot-counting equipment from other networks, purchasing voting systems with security documentation, and restricting data transfers to single-use, pre-erased media provided by the Secretary of State.

State Senator Matt Behnke, prime sponsor, described the proposal as a way to modernize protections and give election administrators tools to detect and respond to intrusions, highlighting intrusion-detection systems, monitoring, and incident response as necessary to preserve public trust in elections.

Kevin McMahon, Assistant Secretary of State, testified for Secretary of State Steve Hobbs and urged the committee to adopt the bill’s measures while noting practical implementation needs. Kylie Zabel, director of the Information Security and Response Division at the Office of the Secretary of State, said the .gov domain strengthens public trust because it signals a verified government presence and that transition costs are covered by existing grants the office administers. Zabel said the office has provided up to $80,000 per county per fiscal year for election-security improvements and recommended a compliance deadline of July 1, 2027, to give counties time to implement changes.

Committee members raised concerns about smaller counties’ capacity and budgets. Senator Wilson asked for details on the $80,000 fund and whether counties lacking resources would have a path to comply; McMahon and Zabel said the Secretary of State’s office intends to support implementation within existing resources and pledged follow-up with members on county-specific needs. Zabel and McMahon also clarified that current tabulation machines are already segmented from other networks but that the bill’s broader technical requirements cover additional systems and vendor practices.

No committee vote was taken following the hearing. Committee staff indicated a fiscal note was ordered but not yet available at the time of the hearing.