Cybersecurity Advocates Press Portugal to Audit and Disclose the Defences Around Its Election Systems
With municipal elections due this autumn, the group Cidadãos pela Cibersegurança wants the Government and Parliament to audit — and publicly report on — the security of Portugal's vote-counting and results systems, and is pressing the EU to act on platform X.
With municipal elections due this autumn, a Portuguese civic group is pressing the state to prove — publicly — that the computer systems behind the country's ballots can withstand a cyberattack. The initiative Cidadãos pela Cibersegurança (Citizens for Cybersecurity) has sent a set of recommendations to the Government, to the Assembleia da República (Assembly of the Republic) and to the European Commission, arguing that too much about the security of Portugal's electoral infrastructure is simply unknown to the public.
The group's central complaint is opacity. Because it has no access to the audit reports covering vote-counting and results-transmission systems, it says it cannot confirm whether those systems are resilient against interference. "It is precisely that opacity that we believe should be corrected, through transparency mechanisms" that allow public scrutiny without exposing operational secrets, the organisation said.
What it is asking for
To the Government, Cidadãos pela Cibersegurança wants regular security tests and independent audits of the electoral systems — especially those that tally votes and transmit results — followed by transparency reports that explain, in plain terms, how well that infrastructure is protected.
To Parliament, it proposes public hearings bringing together the Comissão Nacional de Eleições (National Electoral Commission), the Gabinete Nacional de Segurança (National Security Office) and the Centro Nacional de Cibersegurança (National Cybersecurity Centre), so that lawmakers and citizens can learn which audits have actually been carried out and how often. It also urges that any future move toward electronic voting be preceded by a public technical assessment of the risks, including guarantees of ballot anonymity.
A European dimension
The recommendations reach beyond Lisbon. The group is calling on the European Commission to coordinate periodic evaluations of member states' electoral systems against hybrid threats under the NIS2 Directive, the EU's updated cybersecurity law, and to tighten enforcement of content-moderation rules on large social-media platforms.
It singles out X, the platform owned by Elon Musk, over what it describes as insufficient moderation and weak mechanisms for detecting coordinated manipulation. Cidadãos pela Cibersegurança says it has filed a formal complaint with the Irish regulator — the lead authority for many tech companies' European operations — on those grounds.
Portugal has long favoured paper ballots counted by hand, a system widely seen as robust precisely because it is analogue. But the transmission and aggregation of results, the public registers and the campaign environment online are all digital, and it is those layers the group wants scrutinised before voters return to the polls. Whether the Government and Parliament take up the recommendations, the intervention frames a question that democracies across Europe are increasingly being forced to answer out loud: how do you prove an election is secure without revealing how it is defended?