2020 Election Post-Mortem: What Worked in Election Cybersecurity
With the 2020 U.S. election cycle complete, it is worth examining the efficacy of the cybersecurity preparations made by state and local governments, political campaigns, and civic organizations. While the most significant hurdles of the cycle were outside the digital realm—notably the COVID-19 pandemic—the period validated the necessity of protecting websites that serve as authoritative sources for voting information.
The consensus among security experts is that the election infrastructure held up. A joint statement released on November 12, 2020, by leading election security organizations declared the November 3rd election "the most secure in American history," asserting there was no evidence that any voting system deleted, lost, or changed votes. From our perspective, the absence of any significant publicly reported incidents—described by CISA Director Chris Krebs as "just another Tuesday on the Internet"—points to the benefits of providing free security services to entities across the election space.
Safeguarding the Information Pipeline
Modern elections rely on a complex digital ecosystem that extends far beyond the voting booth. While services do not protect the voting machines themselves, they are critical for the websites and applications that facilitate voter registration, provide polling place locations, and publish results. Since the 2016 election, these government sites have become increasingly frequent targets for cyberattacks.
To address this, Cloudflare maintains two primary initiatives: the Athenian Project and Project Galileo. The Athenian Project, launched in 2017, provides top-tier services to U.S. state and local governments running elections. It currently protects more than 275 election entities across 30 states, with over 100 new government election sites onboarded in the past year alone. Project Galileo, launched in 2014, offers free security services to vulnerable groups, including human rights organizations and journalists. Under this project, Cloudflare protects over 1,400 organizations globally, many of which work to provide accurate voting information, tackle voter suppression, and publish election results.
The support provided to Belmont University illustrates the impact of these programs. When the university was selected to host the final 2020 Presidential Debate, it launched a new website for volunteers, media, and the community. Accepted into Project Galileo, the university received assistance with firewall rules and origin lockdown. This was crucial, as the debate website became the primary source for media registration and event calendars due to the pandemic. During the event, the university saw a 5x increase in traffic and blocked over 80,000 malicious HTTP requests.

Attack Trends: Vulnerability Exploitation vs. DDoS
Analysis of attack data reveals distinct threat profiles for different segments of the election ecosystem. For organizations under Project Galileo that register voters and track ballots, the Cloudflare Web Application Firewall (WAF) blocked more than 10 million attacks in 2020. A majority of these attacks were concentrated in March and June, months that saw a high number of state presidential primaries and voter registration deadlines.
For government sites under the Athenian Project, the pattern was similar. Attack volumes spiked primarily in September, with the WAF blocking roughly 50 million HTTPS requests before election day. Following the election, from November 4 to November 11, the WAF mitigated over 16 million malicious requests as states counted ballots. These were largely unsophisticated attempts to exploit common website vulnerabilities—including file inclusion, SQLi, and cross-site scripting—aimed at gaining access to internal systems rather than taking sites offline in a DDoS attack.

In contrast, political campaigns faced a different threat landscape. Through Cloudflare for Campaigns, launched in January 2020 in partnership with Defending Digital Campaigns, we onboarded 75 federal campaigns and protected more than 450 candidate sites overall. These sites saw an average of 13 million attacks per month, but they were more likely to face DDoS attacks designed to make the site inaccessible, rather than vulnerability exploitation. This difference necessitated a heavier reliance on layer 7 DDoS protection and rate-limiting for campaign sites.

Onboarding and Readiness
In the weeks leading up to election day, engineering teams were on standby to assist state and local governments. Solano County, California, was one such entity that engaged with our team to secure its election resources. The county was onboarded in a few hours, receiving best-practice security configurations tailored for election entities.
The need for these services was felt immediately. Traffic to government election sites increased in November as voters sought polling locations and later checked for periodic ballot count updates. For state and local governments, these protections offered peace of mind. Tim Flanagan, CIO for Solano County, noted that the added security layers "raised confidence in our ability to assure County's residents that our election results were trustworthy."
Key Takeaways and the Path Forward
The 2020 cycle reinforced that election security is not a single point of defense. Security is a layered process, analogous to an onion, where each additional layer protects against a different vector of attack or exposure.
The move to online during COVID-19 highlighted the need for flexibility and attention to digital risks across the election space. Organizations promoting online voter registration were well-suited for this shift, while campaigns had to pivot traditional operations to a digital environment, expanding their threat surface.
Significant progress has been made since 2016. Information sharing across government agencies, private companies, and non-profits has become a cornerstone of preparation. a week before the general election, the Wisconsin Election Commission sent an election security reminder to county and municipal clerks, including resources on mitigating DDoS attacks. Days before November 3rd, engagement with the Cybersecurity and Infrastructure Security Agency allowed for threat intelligence sharing with over 200 general election stakeholders.
Despite the success of the 2020 election, the work is far from over. Future election cycles and the global nature of election security require the ongoing involvement of experienced players. We look forward to continuing to protect the digital infrastructure that supports the electoral process and helps build trust in democratic institutions. As Stacy Mahaney, CIO at the Missouri Secretary of State, aptly summarized, the goal is to make it increasingly difficult for attackers to succeed in making voters question the trust in the democratic process. A dedicated team of engineers and analysts will continue to monitor and support these critical resources.



