SecurityScorecard report analyzing US political party cyber defenses finds DNC has made improvements following 2016 hacks but still lags behind RNC
Personal data leaks, poor protection of logins, and other gaps still leave major parties vulnerable. — In a study of US and European …
Context & Ripple Effects
The benchmark lands three years after Russian government hackers spent roughly a year inside the DNC network and stole opposition research, the breach that forced both parties to treat cybersecurity as a standing operational function rather than an IT line item.
Since then the DNC has run a visible rebuild — phishing drills, Silicon Valley hires, cloud email, encrypted chat — even as reporting showed down-ballot Democratic campaigns still struggling with basic email security. SecurityScorecard's study of US and European parties now puts numbers on that arc: real improvement at the DNC, but not enough to match the RNC.
First-order effects
- The DNC enters the 2020 cycle with a documented defensive gap against its direct rival, handing the RNC a talking point and raising the stakes on closing login-protection and data-handling weaknesses before attackers probe them.
- SecurityScorecard gains a new constituency: political organizations now have a public scorecard they must respond to, the same way companies do.
Second-order effects
- Both parties face pressure to extend committee-level fixes down to state parties and campaigns, where prior reporting shows the weakest link sits — a vendor and training market for political security stands to grow around that gap.
- Third-party security ratings become ammunition in partisan messaging, pushing each party to treat its score as a competitive metric alongside fundraising and polling.
Third-order effects
- If scored comparisons become routine across US and European parties, cyber posture turns into a standardized, externally audited dimension of democratic competition — with election-technology vendors already under expert criticism for unremediated vulnerabilities likely to be pulled into the same accountability frame.
The trend: Political organizations are being pulled into the same third-party security-rating regime as corporations, making measurable cyber defense a public competitive metric between parties.