Democratic campaigns are still struggling with basic email security after two years of constant news reports about the dangers of political hacking
Someone — the government or Silicon Valley — needs to step in to help. — Maciej Ceglowski is a security trainer and the founder of Tech Solidarity, a San Francisco nonprofit.
Context & Ripple Effects
Maciej Ceglowski's argument lands in the middle of an arc the coverage has been tracking since 2016: the DNC rebuilt its own defenses with phishing drills, cloud email, encrypted chat, and hires from Silicon Valley, yet the security posture stops at the committee door. Down-ballot campaigns run their own email, and Ceglowski's point is that two years of headlines have not closed that gap.
The structural constraint is now explicit: election laws prohibit companies from offering candidates services at a discount, which blocks exactly the Silicon Valley assistance Ceglowski is calling for. A later SecurityScorecard analysis confirmed the asymmetry — the DNC improved after 2016 but still lagged the RNC — so the problem is party-wide, not just one committee's.
First-order effects
- Campaign staff handling donor lists and opposition research remain exposed to routine phishing even as the DNC hardens its own perimeter, leaving the weakest inbox in each campaign as the entry point.
- Silicon Valley companies willing to help are legally constrained from doing so at below-market rates, so free-tier email and ad-hoc volunteer advice remain the de facto standard for most campaigns.
Second-order effects
- Vendors and platforms serving political clients face growing pressure to either build campaign-grade security into standard products or lobby for the election-law fix that would let them discount it.
- Party committees get pulled further into a service-provider role — extending the DNC's internal program outward — because no market mechanism currently delivers security to individual campaigns.
Third-order effects
- If the pattern holds through 2020, US political cybersecurity stratifies into well-defended national committees sitting atop a long tail of under-defended campaigns and local offices — the same email-borne weakness later seen when malware hit a rural Texas county's email system and sent fake messages to voters.
- Sustained private-sector inability to help under current law pushes the responsibility toward government action, making election-security assistance a recurring legislative item rather than a corporate goodwill question.
The trend: American political cybersecurity is consolidating at the party-committee level while individual campaigns and local election offices remain the unpatched edge of the same attack surface.