A look at how the Democratic National Committee has beefed up cybersecurity since 2016, hiring staff from Silicon Valley, warning about phishing, and more
Eric Geller / Politico : Tweets: @ericgeller , @kimzetter , @ilvestoomas , @raffi , @ericgeller , and @donie Tweets: Eric Geller / @ericgeller : New from me: An in-depth look at how the DNC has overhauled its cybersecurity operations since 2016. https://www.politico.com/... Under @raffi's leadership, the DNC is sharing more info with more people than ever before. In an interview at DNC HQ, he walked me through the changes. pic.twitter.com/4Nr8wDCH6R Kim Zetter / @kimzetter : The DNC is doing things for cybersecurity education that even many large companies don't do - “cybersecurity training sessions at every meeting of the DNC or the Association of State Democratic Committees, some of which are mandatory” http://www.politico.com/... http://twitter.com/... Toomas Hendrik Ilves / @ilvestoomas : Do read. This is what parties in democracies world-widen need to do in the Digital Era. You http://twitter.com/... @raffi : there is a lot to do - @boblord & i have been super busy trying to get the security posture of the @DNC into the right place. http://twitter.com/... Eric Geller / @ericgeller : How has the DNC's relationship with the FBI improved since 2016? “It would be surprising if a week went by and I didn't hear from one of the three-letter agencies in my inbox,” DNC CTO @raffi told me. My new story: http://www.politico.com/... Donie O'Sullivan / @donie : Inside the race to hack-proof the Democratic Party https://politi.co/2AePb6q
Context & Ripple Effects
Two years after Russian government hackers spent roughly a year inside the DNC network, the committee has turned a breach-response scramble into a standing operation: Silicon Valley hires, phishing warnings, and mandatory training sessions at every DNC and state committee meeting. This Politico deep-dive extends the earlier BuzzFeed look at the phishing drills, cloud email, and encrypted chat that now anchor day-to-day defense.
The stakes sit outside HQ: Democratic campaigns were reported just weeks earlier as still struggling with basic email security, meaning the party's own hardening does not automatically reach the people actually running races.
First-order effects
- DNC staff and state committee members now face recurring — sometimes mandatory — cybersecurity training, while CTO Raffi Krikorian's team shares threat information more widely than before, with a reportedly improved working relationship and frequent contact with the FBI.
Second-order effects
- SecurityScorecard's later analysis found the DNC had improved since 2016 yet still lagged the RNC, turning party-versus-party security posture into a measurable competitive comparison rather than a private matter.
- Because campaign-level defenses trail headquarters, the DNC's guidance-and-warning apparatus becomes the de facto security layer for down-ballot operations that cannot hire their own teams.
Third-order effects
- If the pattern holds, US parties consolidate into ecosystem defenders — hubs that push training, phishing intelligence, and shared tooling outward to state committees and campaigns — with federal agencies like the FBI as routine counterparts rather than emergency responders.
- Security is also becoming inseparable from data infrastructure: the DNC's move to replace its aging Vertica repository with a BigQuery-based Data Warehouse ahead of 2020 shows election operations being rebuilt with both capability and attack surface in mind.
The trend: Political parties are converting one-off breach response into permanent, platform-style cyber defense that radiates from national headquarters down to individual campaigns.