On February 1, 2024, at the end of the month-long trial challenging the constitutionality of Georgia’s electronic voting machines, the plaintiffs’ attorney wrapped up his closing argument with a slide summarizing what passes for accountability for system security with Georgia’s election officials:
The slide appeared the next day in national media. It quickly became the go-to meme explaining what is wrong with Georgia’s election system: no one is responsible for detecting, withstanding, and recovering from cyber-attacks. Failure to exercise even nominal controls explains the lingering controversy over who won Georgia’s 16 electoral votes in the 2020 presidential election, but it also suggests a way to restore confidence in Georgia elections before the problems of 2020 metastasize in 2024.

Meme following this year’s Georgia elections suit
Like much of the country, Georgians cannot agree on what happened in 2020. Fortunately, we do not need to agree on the past to remedy the problems and have confidence in this fall’s election.
Here’s what you need to know about Georgia’s election technology: state law mandates two permissible voting methods. One option is to mark paper ballots by hand (HMPB). In the other option, the voter uses a touchscreen computer (called a Ballot Marking Device, or BMD) to record and print voter preferences on a paper ballot. In both cases, the paper ballots are scanned and totaled electronically. Why two methods? Because voters casting absentee or provisional ballots and overseas military service personnel, like 70% of the nation’s voters, hand-mark physical ballots. All other Georgia voters must visit a physical polling location and cast a BMD-marked ballot.
BMDs are computers. Like all computers, they can be misprogrammed, hacked, or misconfigured. The computers in BMDs have a fundamental security flaw, a fact established by researchers over many years and published in peer-reviewed scientific journals. There is no way to prevent undetected discrepancies between what voters see on the screen and the recorded votes. There is no reliable record of voter intent, making it impossible to figure out what happened when there is a controversy.
On the other hand, there are no corresponding cyber vulnerabilities for HMPBs. HMPBs create a trusted audit trail automatically. If hand-marked ballots have been securely preserved in a locked vault, they are a trusted audit trail. Electronic scanning of the HMPB sounds like a vulnerable step, but the existence of a trusted audit trail guarantees that the outcome can be checked to resolve challenges if the scanner/tabulators are inaccurate. This is not true with the paper ballots that the BMDs print. Like the fundamental security flaw of BMDs, the fact that properly preserved HMPBs constitute a trusted audit trail is also established science.
The science that deals with such questions is called cybersecurity. I know this because I am the founder of Georgia Tech’s School of Cybersecurity and Privacy, the top-ranked cybersecurity department in the country. My colleagues and I have warned for many years that there are security weaknesses in computerized voting systems. This is also the view of The National Academy of Sciences, Engineering, and Medicine, the most authoritative voice available to the federal government on science and technology, which concludes: “There is no realistic mechanism to fully secure vote casting and tabulation computer systems from cyber threats.”
Since most Georgians vote on BMDs, confidence in Georgia’s election system depends on how well state election officials understand and apply cybersecurity principles to the 35,000 BMDs and associated equipment scattered around the state’s 159 counties. A simple checklist, applied uniformly and verified by a trusted authority, is standard practice in organizations exposed to cyber threats. As virtually any cybersecurity textbook will tell you, monitoring adherence to security principles is critical. However, in Georgia, no one is responsible for monitoring election cybersecurity.
Assigning responsibility for cybersecurity in Georgia’s elections is not very difficult. An entity already exists with that statutory authority: The State Election Board (SEB). Established by GA Code § 21-2-31 (2022), the SEB has the authority and responsibility to take the two steps that restore accountability to the conduct of elections.
- The SEB has explicit authority to reduce reliance on computers by requiring the use of HMPBs whenever possible, but especially when—as was the case in the 2021 breach in Coffee County—BMD-based voting has been compromised. In cybersecurity terms, this is called shrinking the attack surface. If most ballots are hand-marked, the attack surface of the entire system shrinks.
- The SEB, which has statutory oversight responsibility, can assume actual responsibility by monitoring completeness and compliance with security requirements.
Increasing confidence in elections requires evidence, not blind faith. Simple chants like, “Georgia’s elections are secure and fair, and we are fighting to keep it that way,” are not evidence. Challenging the SEB to assume responsibility for cybersecurity would ensure that confidence-enhancing evidence, not blind faith, is the scientific basis for conducting elections in Georgia. Someone will finally be in charge.
Richard DeMillo is a nationally recognized cyber expert who founded Georgia Tech’s School of Cybersecurity and Privacy.



