The following is a list of works completed by the ESE Lab, applying risk and decision analysis to election security, poll worker training, and voter trust, with related work in cybersecurity, and insider risk.


Elections Security

SECURING U.S. ELECTIONS: THREATS, VULNERABILITIES, MITIGATIONS, AND OPPORTUNITIES FOR TECHNOLOGY

Amarachi Silverline Offor, Vincent Schiavone, Natalie M. Scala, Josh Dehlinger, Noah Hibbler, Navya Gautam

Proceedings of the American Society for Engineering Management 2025 International Annual Conference

This research provides one of the most comprehensive overviews to date of threats and vulnerabilities in U.S. election systems and explores how emerging technologies could strengthen security and public trust. Building upon the foundational 2009 Election Assistance Commission (EAC) attack tree, the study catalogs and classifies cyber, physical, and insider risks across modern voting equipment such as ballot marking devices (BMDs) and precinct count optical scanners (PCOS). The team also evaluates distributed ledger technologies (DLT) — including blockchain-based systems — as a potential tool to enhance transparency, auditability, and real-time verification of vote counts. By identifying both persistent weaknesses and promising innovations, the paper outlines a research roadmap for integrating secure, verifiable technologies that can counter disinformation, accelerate accurate counting, and reinforce confidence in U.S. elections.

IMPROVING THE ANNE ARUNDEL COUNTY VOTING EXPERIENCE

Technical Report, 2026

We conducted a voter experience survey of registered voters in Anne Arundel County. The survey, distributed to all registered voters with an email address, invited participants to reflect on their voting experiences in the county. Analyses focused on four key areas: the Maryland Midterm Election, polling place experiences, mail-in and absentee voting, and confidence in election security. While responses were largely positive, results indicated opportunities to strengthen voter information and outreach for specific demographic groups. These findings provide valuable insight to enhance the accessibility, effectiveness, and security of the voting processes in Maryland.

IMPROVING ELECTION SYSTEM SECURITY THROUGH SOFTWARE FAILURE MODES EFFECTS ANALYSIS

Vanessa Gregorio, Hao Nguyen, Skylar Gayhart, Josh Dehlinger, Natalie M. Scala

Proceedings of the American Society for Engineering Management 2025 International Annual Conference

This study strengthens the security of U.S. election technology by adapting a proven reliability-engineering method—Software Failure Modes and Effects Analysis (SFMEA)—to modern voting systems. The team analyzed precinct count optical scanners (PCOS), which tabulate most in-person ballots nationwide, to uncover weaknesses across cyber, physical, and insider threat dimensions. By combining SFMEA’s bottom-up view of software failures with attack tree modeling’s top-down mapping of threats, the research identified 60 new vulnerabilities and created a more comprehensive, data-driven threat framework. The result is a bi-directional risk model that helps election officials, engineers, and policymakers better prioritize mitigations and demonstrate that voting equipment has been rigorously analyzed for today’s evolving adversaries. The approach can also be applied to other critical infrastructure systems that rely on complex human-technology interactions.

CYBERSECURITY AND INSIDER RISK: ANALYZING SECURITY BEHAVIORS AND PROPOSING MITIGATIONS

Hao Nguyen, Breanna Patino, Natalie M. Scala, Josh Dehlinger

Proceedings of the American Society for Engineering Management 2023 International Annual Conference

This research aims to understand individual responses to personal cybersecurity practices and propose effective measures for mitigating cybersecurity risks. Data were collected via survey built from the Security Behavior Intentions Scale (SeBIS) and the Human Aspects of Information Security Questionnaire (HAIS-Q) inventories. We find inconsistency and uncertainty in insider behaviors, particularly within device securement, password generation, and social media use. Additionally, there are strong connections between behavioral intentions and demographic factors. Furthermore, we also compare our results with a known sample of SeBIS data collected on United States poll workers, to examine any considerable differences. The goal of the comparison is to examine potential robustness in security behaviors across sectors and demographic groups.

Enhancing Election Integrity Through Data-driven Poll Worker Training

Hao Nguyen, Navya Gautam, Shreenidhi Ayinala, Natalie M. Scala, Josh Dehlinger

SIAM News, October 2024

Election equipment is critical infrastructure in the U.S., and the highly seasonal (and often volunteer) poll workers have access to all of the necessary apparatuses to effectively oversee election processes at polling places. The use of analytics—such as foundational artificial intelligence (AI) and data mining—can address poll workers’ specific needs and help to maintain the security and integrity of voting protocols. By understanding the unique backgrounds of different poll worker groups via cluster analysis, election administrators can develop targeted training programs and implement proactive measures that mitigate insider risks, optimize resources, and enhance the effectiveness of efforts to safeguard election integrity.

Influence Of Election Misinformation On Voter Perceptions: Lessons For The 2024 United States Elections And Beyond

Jada Riley, Vanessa Gregorio, Navya Gautam, Marie Kouassi, Natalie M. Scala, Josh Dehlinger

Technical Report, October 2024

This research statistically examines how political mis/dis-information that spread via social media and news outlets during the 2020 U.S. General Election influenced perceptions of election security and integrity specific to in-person and mail-based voting, including influences to voting behavior.  We also convene a Delphi panel of election security and misinformation experts to develop mitigations and countermeasures to combat belief in mis/dis-information and disenfranchisement in voting.  This analysis extends the literature beyond just dissemination of mis/dis-information to provide novel, fundamental insight into how belief in political mis/dis-information impacts perceptions that influence voting behaviors.  This research is also the first to provide a systemic analysis of countermeasures, extending the literature beyond just basic recommendations to targeted, evaluated actions.

An Information-Theoretic Analysis of Security Behavior Intentions Amongst United States Poll Workers

Natalie M. Scala, Jayant Rajgopal, Yeabsira Mezgebe, Josh Dehlinger

Risk Analysis, 45(6), p. 1558-1574, 2025

Elections equipment in the United States constitutes critical national infrastructure, and its operation relies on poll workers, who are trusted insiders.  However, those insiders may pose risks if they make mistakes with detrimental consequences or act with malice.  We analyze a large Security Behavior Intentions Scale (SeBIS) data set of poll workers and potential poll workers. We develop a novel model to examine potential weaknesses in security behaviors and identify poll worker security practices to improve to ensure the integrity of our elections.  We also recommend action items and security countermeasures for states and localities.

Securing democracy: threat mitigations for the Mail voting process

Vanessa Gregorio, Natalie M. Scala, Josh Dehlinger

ISE Magazine, p. 29-33, August 2024

The 2020 U.S. General Election saw record voter participation with 46% of all voters indicating that they voted by absentee or via a mail-in ballot. Evenso, public discourse continued to question the security and integrity of continuing to allow mail-based voting as a modality to vote in future elections. This article identifies threat countermeasures to general election processes to assess their suitability to mail voting to better understand how to: (1) protect this critical democratic process; (2) enhance the threat and mitigation training of the poll workers that administer this election process; and, (3) educate the public on the ways to reduce threats to the mail voting process to ensure its continued security and integrity. Link to magazine issue

The Spread of Voting Misinformation: (Un)intentionally Disenfranchising Voters in the United States 

Vanessa Gregorio, Josh Dehlinger, Natalie M. Scala

SSRN Preprint, July 2024

This paper examines the intersection of voting misinformation and the disenfranchisement of voters in the United States, highlighting how false narratives surrounding election security have led to restrictive policies that undermine democratic participation. We trace the historical progression of voting rights, showing how shifts in misinformation have been used to justify both explicit and implicit restrictions on the voting process, particularly affecting marginalized communities. Despite claims of protecting election integrity, modern voting laws disproportionately hinder access for historically underrepresented groups, contributing to a cycle of disenfranchisement driven by misinformation. Recognized in December 2024 on SSRN's Top Downloads list for Election Law & Voting Rights.

Protecting Maryland’s Mail Voting Processes through Poll Worker Training

Vanessa Gregorio, Josh Dehlinger, Natalie M. Scala

Baltimore Business Review: A Maryland Journal, p. 26-30, 2024

The COVID-19 pandemic necessitated the broadening of vote-by-mail opportunities to allow for safe and accessible access to cast a ballot. Maryland residents can also now choose to permanently vote by mail, receiving a ballot for each election.  The nearly 1 million poll workers needed nationwide to administer a General Election are oftentimes the first line of defense in maintaining the integrity and security of elections. This paper further contributes to improving the security and integrity of election infrastructure through cyber, physical, and insider threat training for poll workers explicitly for the vote-by-mail processes. Specifically, this paper details the design, validation, and dissemination of a vote-by-mail threat training module.

Understanding the Impact of Poll Worker Cybersecurity Behaviors on U.S. Election Integrity

Abigail Kassel, Isabella Bloomquist, Natalie M. Scala, Josh Dehlinger

Proceedings of the IISE Annual Conference & Expo 2024

Poll workers play a crucial role in safeguarding election security and integrity. We examine the benefits of training poll workers to mitigate potential cyber, physical, and insider threats that may emerge during U.S. elections through an analysis of the relationship between poll worker training performance and their individual cybersecurity practices, using the Security Behaviors and Intentions Scale (SeBIS). The results indicate that a poll worker’s personal security behaviors related to Device Securement, Password Generation, and Proactive Awareness have a positive relationship with poll workers' knowledge of the threats related to election equipment and processes. These findings have implications for election security policies, emphasizing needs for election officials and managers to prioritize in poll worker training initiatives to enhance election security.

Voting Perceptions and impact of misinformation

Jada Riley, Vanessa Gregorio, Natalie M. Scala, Josh Dehlinger

17th NATO Operations Research and Analysis Conference, 2023 (Presentation only)

This research examines how political misinformation that spread via social media and news outlets during the 2020 U.S. General Election may have influenced perceptions of threats regarding in-person and mail-based voting. We develop a survey to assess spread and acceptance of misinformation, contributing to the literature on how belief in political misinformation influences voting behavior. We also convene a Delphi panel of election security and misinformation experts to develop mitigations and countermeasures to combat belief in misinformation and disenfranchisement in voting. This analysis extends the literature beyond just spread to provide fundamental insight into how belief in political misinformation impacts perceptions that influence voting behaviors, ultimately supporting health of democracy and enabling voters to cast their ballots safely, securely, and confidently.

Preparing Poll Workers to Secure U.S. Elections

Natalie M. Scala, Josh Dehlinger, Lorraine Black

Proceedings of the American Society for Engineering Management 2023 International Annual Conference

With their pivotal role as the first line of defense on Election Day, poll workers bear the responsibility of identifying and thwarting any potential threats that may arise. However, despite their crucial role, poll workers receive minimal, if any, specific training on security threats prior to elections. To address this gap, this research investigates poll worker threat awareness through developing, piloting, and evaluating online threat training modules for poll workers. Through statistical analysis, we show the training modules are effective in increasing poll workers' understanding of cyber, physical, and insider threats and how to mitigate them.

Evaluating Mail-Based Security for Electoral Processes Using Attack Trees

Natalie M. Scala, Paul L. Goethals, Josh Dehlinger, Yeabsira Mezgebe, Betelhem Jilcha, Isabella Bloomquist

Risk Analysis, 42(10), p. 2327-2343, 2022

The objective of this research is to provide greater insight into potential threats to mail-based voting processes. Upon identifying an attack tree provided by the Elections Assistance Commission as an initial structure for evaluation, new threats are postulated, and an updated tree is proposed that accounts for more recent activities related to adaptive adversaries and COVID-19. Then, using an established assessment framework, the relative likelihood of each mail-based voting process attack scenario is identified. The results facilitate providing election officials and policy makers with greater knowledge of how mail-based voting system vulnerabilities develop as well as specific security measures that may be most beneficial. Additional info: Voting Methods by State During 2020 Elections; HotSoS Presentation, Author Accepted Manuscript

Securing Organizations from Within: Opportunities and Challenges of Trusted Insiders

Natalie M. Scala, Josh Dehlinger, Yeabsira Mezgebe

Baltimore Business Review: A Maryland Journal, p. 16-20, 2022

This paper discusses awareness of insider risk in organizations, identifying actions that can be taken to address and mitigate threat.  We also discuss the industry trend of shifting from reactive to proactive insider risk management, as well as the role AI and machine learning have had in identifying and managing risk.  Specifically, the Security Behaviors Intentions Scale (SeBIS) has been used to build AI models for insider risk, and we provide a high-level overview of one such model for elections poll workers, who are trusted insiders responsible for managing and executing an election, by having access to critical infrastructure and ballots. 

A PROCESS MAP AND RISK ASSESSMENT FOR MAIL-BASED VOTING

Natalie M. Scala, Isabella Bloomquist, Yeabsira Mezgebe, Betelhem Jilcha, Paul L. Goethals, Josh Dehlinger

Proceedings of the 2021 IISE Annual Conference

This paper develops a process model for mail-based voting and also identifies and maps cyber, physical, and insider threats to the process.  We apply a utility-based methodology for assessing threat to evaluate the process model scenarios and nodes.  We illustrate the model using Maryland’s mail-based voting process as a case study and identify nodes or activities of concern due to higher relative risk.  Results provide election officials insight on how voting system vulnerabilities develop and when and where to employ mitigating security measures. Mail Voting Process Node Descriptions

POLLWORKER SECURITY: ASSESSMENT AND DESIGN OF USABILITY AND PERFORMANCE

Josh Dehlinger, Saraubi Harrison, Natalie M. Scala

Proceedings of the 2021 IISE Annual Conference

This paper discusses improving the security of election infrastructure through intentional, targeted, cyber, physical, and insider threat training for poll workers. We detail the engineering design, pedagogy, and deployment of online, election-specific, threat training modules. Results of a System Usability Scale assessment indicate the content and online platform are easy to interact with and use. Further, the developed modules were piloted and then deployed in a mid-Atlantic state; participating counties include over 1,900 poll workers who serve nearly 750,000 voters.

Empowering election judges to secure our elections

Natalie M. Scala, Josh Dehlinger, Lorraine Black, Saraubi Harrison, Katerine Delgado Licona, Aikaterini Ieromonahos

Baltimore Business Review: A Maryland Journal, p. 8-12, 2020

This paper presents training modules for poll workers to identify and respond to potential cyber, physical, and insider threats that may emerge at polling places. We present the design of the modules and discuss the methods for deploying them as training. The modules are used by counties in Maryland during the 2020 Presidential Election cycle. PDF; Additional information: Questions used in pre-post-test

Protecting Maryland’s Voting processes

Megan Price, Natalie M. Scala, Paul L. Goethals

Baltimore Business Review: A Maryland Journal, p. 36-39, 2019

This paper outlines two research projects that specifically address the security of Maryland’s voting processes.  The first is a preliminary risk model for cyber, physical, and insider threats to polling places.  The model evaluates vulnerabilities in the voting process and recommends how the State of Maryland should focus resources to combat threat.  The second project involves creating training modules for poll workers so that they can identify and respond to cyber, physical, and insider threats. 

sources of risk in elections security

Hannah Locraft, Priya Gajendiran, Megan Price, Natalie M. Scala, Paul L. Goethals

Proceedings of the 2019 IISE Annual Conference

This research examines sources of risk in voting systems, identifies potential vulnerabilities in voting processes, and suggests a risk model framework to assess and mitigate vulnerabilities. We examine patterns and trends in a state’s elections security and the characteristics of its voting processes. We also present diagrams of sources of cyber, physical, and insider risk to voting processes and discuss an outline of a Markov model to assess evolving threat. Correlation Matrix Data

other applications

Analysis of security behaviors of supply chain professionals

Hao Nguyen, Natalie M. Scala, Josh Dehlinger

Proceedings of the IISE Annual Conference and Expo 2024

As supply chain professionals can pose an insider risk to supply chain cybersecurity, this research delves into their information security behaviors. The objective is to assess the security practices of supply chain professionals and identify strategies for improvement. Utilizing principles from information theory for analysis, results of this preliminary research reveal significant inconsistency in information security behaviors among supply chain professionals, particularly with the Password Generation, Device Securement, and Proactive Awareness from the Security Behaviors Intentions Scale. Ultimately, this research is part of a larger project that seeks to provide recommendations for training programs aimed at reducing the risk of incidents or breaches stemming from trusted insider professionals within the supply chain. Mutual information matrix

TRUSTED INSIDERS AND THE TEMPTATION TO TALK: PREVENTING UNAUTHORIZED DISCLOSURES

Sara Freedman, James Raymond, Taylor Seaman, Natalie M. Scala

Baltimore Business Review: A Maryland Journal, p. 14-18, 2023

External disclosures of an organization’s protected or proprietary information prior to authorization can cause incalculable damage.  This research explores the causes and motivations behind individuals’ decisions to disclose, which include negative work environments, shortcomings in security training, poor security attitudes and approaches, and lack of reporting. We develop four categories of recommendations to mitigate and prevent such events: modifications to training, shifts in work environment, implementation of leadership training, and development of more accessible reporting mechanisms. Within each of these four categories, corresponding recommendations and implementation strategies are summarized.

Operations Research

Paul L. Goethals, Natalie M. Scala, and Nathaniel D. Bastian

Chapter 7 of Mathematics in Cyber Research, CRC Press, p. 233-266, 2022

This chapter provides an overview of applications of operations research and prescriptive analytics techniques the cyber realm. In particular, the chapter focuses on decision analysis, mathematical optimization, and stochastic process modeling. Case studies in elections security (utility theory), network interdiction (optimization), and malware spread (stochastic process modeling) are included to illustrate the covered topics.

A model for and inventory of cybersecurity values: Metrics and best practices

Natalie M. Scala and Paul L. Goethals

Chapter 14 of the Handbook of Military and Defense Operations Research, CRC Press, p. 305-330, 2020

We propose a cybersecurity value model for security metrics and best practices that is supported by industry-based data and interviews with subject matter experts. We illustrate the value model using the supply chain as a case study, but propose an overall framework that can be customized for any organization or industry. We also contribute an inventory of valued components of a secure cyber system, identified through a survey of cyber professionals. This survey also examined potential differences in values based on an organization’s history of attacks and/or breaches. Results will enable organizations to assess the performance of their respective cyber systems, manage risk, and continuously improve their cybersecurity posture.

Risk and the Five hard problems of cybersecurity

Natalie M. Scala, Allison C. Reilly, Paul L. Goethals, Michel Cukier

Risk Analysis: An International Journal, 39(10), p. 2119-2126, 2019

We consider the Five Hard Problems (5HP) as defined by Science of Security (SoS) initiative at the National Security Agency and encourage the application of risk analysis principles to cybersecurity research. The 5HP are (1) scalability and composability; (2) policy‐governed secure collaboration; (3) security‐metrics–driven evaluation, design, development, and deployment; (4) resilient architectures; and (5) understanding and accounting for human behavior. We show how risk analysis can be applied to each hard problem to enable growth and insight in both cybersecurity and risk research. Recognized as a Top Downloaded Paper amongst work published between January 2018 and December 2019. AAM via Wiley Self-Archiving Policy

Values and Trends in Cybersecurity

Lorraine Black, Natalie M. Scala, Paul L. Goethals, James P. Howard, II

Proceedings of the 2018 Industrial and Systems Engineering Research Conference

We survey information technology professionals as well as small legal firms and solo practitioners to understand what they value in a secure cyber system.  We identify differences in values between the two populations as well as how a previous attack or breach can affect value.  Finally, we provide an inventory of values, as identified by the survey respondents, which can be inputs to a value model.

 

Best Practices in Cybersecurity: Processes and Metrics

Jasmin Farahani, Natalie M. Scala, Paul Goethals, Adam Tagert

Baltimore Business Review: A Maryland Journal, p. 28-32, 2016

This paper draws attention to the nature and severity of cyberattacks, especially breaches that have occurred in the State of Maryland.  We identify a selection of metrics and best practices that can be implemented to increase cybersecurity posture as well as outline an agenda for research.

 

A Review of and Agenda for Cybersecurity Policy Models

Natalie M. Scala, Paul Goethals

Proceedings of the 2016 Industrial and Systems Engineering Research Conference

We review three cybersecurity policy models: the three tenets model, attack graph and attack surface models, and the cybersecurity heuristic model.  We also outline a value based research model for cyber metrics.