An expert says Georgia's voter registration site looks poorly secured, but the secretary of state, a candidate for governor, appears to deflect blame to rivals
IN DECEMBER 2016, Georgia secretary of state Brian Kemp accused the Department of Homeland Security of attempting to hack his office's systems …
Context & Ripple Effects
Brian Kemp has been casting his office as a cyber target since [[a:933864|his December 2016 accusation that the Department of Homeland Security tried to hack Georgia's registration systems]] — a charge that framed federal-state friction rather than his own shop's defenses. Two years on, reporting found that voting infrastructure nationwide remained largely unchanged despite officials' warnings, and now an independent expert assesses Georgia's own registration site as poorly secured.
The timing is political: Kemp is a candidate for governor, and rather than own the finding he appears to redirect suspicion toward political rivals. That inversion — the official responsible for the system treating scrutiny of it as an attack — is what makes this more than a routine vulnerability report.
First-order effects
- Georgia voters' registration data sits behind a portal that a security expert judges weakly defended, while the secretary of state's office — the accountable party — spends its response assigning blame instead of remediating.
- Kemp's gubernatorial campaign converts a technical audit into a partisan dispute, raising the cost for any rival or researcher to press the issue before Election Day.
Second-order effects
- Federal partners like DHS face a credibility trap: after being cast as the attacker in 2016, offers of assistance to Georgia read as intrusion, chilling exactly the cooperation the post-2016 warnings said was needed.
- Vendors and officials who dominate election technology were already faulted for failing to acknowledge vulnerabilities; a sitting official publicly deflecting scrutiny reinforces the incentive structure that lets known flaws persist, as later findings like the 2024 flaw in Georgia's registration cancellation portal would show.
Third-order effects
- When the official who runs election infrastructure is also a candidate on its ballot, independent security review becomes politically adversarial by default — a structural conflict that pushes real auditing toward outsiders, lawsuits, and press rather than internal remediation.
- If the pattern holds — findings issued, defenses unchanged, blame reassigned — election security reform shifts from a technical program to a governance problem: who audits the auditors when the auditor has a stake in the outcome.
The trend: US election infrastructure is accumulating repeated, documented security findings faster than officials remedy them, with the people accountable for the systems increasingly treating scrutiny itself as the threat.