Former IAS Officer Flags Low Cybersecurity Score of Election Commission Websites
The Election Commission of India (ECI), an institution central to the democratic fabric of the country, is facing serious questions about the security of its digital infrastructure. A recent revelation by former Indian Administrative Service (IAS) officer Kannan Gopinathan has highlighted troubling lapses in the cybersecurity of ECI’s voter services portal and related websites, raising fears about the protection of sensitive citizen data and the integrity of electoral processes.
A Failing Security Score
Gopinathan revealed that the ECI’s official voter services platform scored an alarming 15 out of 100 on the Mozilla Observatory security test, a tool that evaluates a website’s compliance with best practices in web security. For context, this score is considered dangerously low, pointing to glaring vulnerabilities.
The Mozilla test typically checks for important safeguards such as:
Secure HTTP headers like Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS).
TLS/SSL configuration to ensure encrypted communication.
Protection against cross-site scripting (XSS) and other common web-based attacks.
A result this poor suggests that even basic security measures may not be in place. It paints a picture of inadequate preparedness against malicious actors who might exploit these weaknesses to steal data, disrupt services, or manipulate records.
Why This Matters
The Election Commission’s digital systems are not just ordinary websites. They are critical platforms where millions of Indian citizens interact to:
Register as new voters.
Update voter information.
Track their voter ID status.
Access electoral rolls.
This makes them a treasure trove of personally identifiable information (PII) — including names, addresses, photographs, and identification numbers. A breach could not only compromise the privacy of citizens but also pave the way for identity theft, targeted misinformation campaigns, or even electoral manipulation.
The former IAS officer pointed out that these vulnerabilities exist despite the ECI’s responsibility to maintain the highest levels of transparency and trust in the democratic process. If the very systems that manage voter rolls are insecure, public confidence in elections could be undermined.
The Context of Concern
The revelations come in the wake of what Gopinathan referred to as a “mass-deletion attempt” on electoral rolls. This backdrop makes the poor cybersecurity score all the more alarming. It suggests that not only are the systems vulnerable, but also that there may be attempts—whether internal errors or external interference—that could exploit these weaknesses.
Internationally, such concerns are not new. For example:
In Australia, the iVote online voting system was found to have severe vulnerabilities, raising doubts about its reliability.
In the United States, questions over election security and foreign interference have dominated public discourse in recent years.
India, the world’s largest democracy, cannot afford to ignore such warnings.
Calls for Accountability
Kannan Gopinathan’s critique goes beyond simply flagging the problem. He has demanded greater accountability and transparency from the Election Commission regarding how its IT systems are developed, audited, and monitored.
Some of the key questions he raised — and which need answers — include:
- When was the last independent security audit conducted?
- Why were best practices like HTTPS redirection and strong encryption overlooked?
- Does the ECI have an incident response plan in case of a breach?
- Are external experts or ethical hackers invited to test the resilience of these systems?
- How are citizens’ data backups managed to prevent tampering or loss?
The absence of clear responses could erode faith in the very institution tasked with safeguarding democracy.
What Needs to Happen
Strengthening the ECI’s digital infrastructure is no longer a matter of convenience — it is a national imperative. Experts suggest several immediate steps:
Mandatory Security Audits: Conducted by independent cybersecurity firms at regular intervals.
Bug Bounty Programs: Encouraging ethical hackers to responsibly disclose flaws.
Adoption of Global Standards: Following international frameworks for secure election technology.
Transparency Reports: Publishing regular updates on security measures, threats detected, and fixes implemented.
Citizen Awareness: Educating voters about data protection and possible risks.
By implementing these reforms, the ECI can not only plug vulnerabilities but also restore trust among citizens.
The Larger Lesson
This controversy underscores a broader reality: in an increasingly digital world, cybersecurity is inseparable from democracy. Elections are no longer safeguarded only by ballot boxes and paper trails — they are also protected by firewalls, encryption, and secure coding practices.
If institutions like the Election Commission fail to meet these standards, they expose not just themselves, but the entire democratic system, to unprecedented risks.
The warning flagged by Kannan Gopinathan is a wake-up call for India. A score of 15/100 on a basic web security test is not a small oversight — it is a glaring signal that vital public systems are vulnerable. For a nation that prides itself on being the world’s largest democracy, ensuring that its election-related infrastructure is digitally secure is non-negotiable.
The Election Commission must treat this not as criticism to be brushed aside, but as an urgent call to fortify the foundations of democratic trust in the digital age.