Kokkuvõte 2024–2025 riskianalüüsist ja metoodika muutustest. Dan Bogdanov

Kokkuvõte 2024–2025 riskianalüüsist ja metoodika muutustest. Dan Bogdanov

🎙 Dan Bogdanov 👥 1K 📅 September 26, 2025 ⏱ 26 min 👁 86 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

risk analysise-votingmethodologycybersecurityEstonia

Summary

Dan Bogdanov, a member of the Estonian Academy of Sciences cybersecurity committee, presents a summary of the committee’s 2024-2025 risk analysis on election technologies and the changes made to their methodology. He explains the committee’s approach: they define threat scenarios, assess likelihood and impact on scales of 1 to 5, and previously multiplied these to obtain a risk class. However, they found this multiplication method flawed, as it could mask high-impact, low-likelihood risks that might escalate. They consulted with academic Krista Fisher and committee member Jann Willemson, leading to a revised approach: they no longer use risk classes but instead highlight ’noteworthy’ risks and publish confidence intervals and dispersion of scores. They also present risks on a two-dimensional plot. Bogdanov discusses specific risks analyzed, including the distribution of voting apps via app stores vs. websites, the impact of Microsoft Recall, postal voting security, and the openness of the voter app’s source code. He notes that the committee’s assessments sometimes showed wide disagreement, justifying the new transparency. The analysis has been handed over to the State Electoral Office, and the committee is moving on to study digital sovereignty.

187 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation offers valuable insights into the practical application of risk analysis methodology in a high-stakes domain (e-voting). Bogdanov clearly explains the evolution of their methodology, providing concrete examples of how the old multiplication approach could mislead, and justifies the new approach with logical reasoning. He supports his arguments with specific risk scenarios and visualizations, making the case for transparency in risk assessment. The argumentation is solid, though it relies on the committee’s expert judgment rather than empirical data.

Scientific Rigor, Source Quality, Title Accuracy

The presentation demonstrates scientific rigor by openly discussing methodological limitations and changes, and by referencing consultations with experts. The quality of sources is high, as it is based on the committee’s work, which includes input from various institutions. The title accurately reflects the content, which is a summary of the risk analysis and methodology changes. No external sources are cited in the video, but the description mentions the conference and the committee’s work, which is credible.

170 words

Title / Content Match

The title accurately reflects the content: a summary of the 2024-2025 risk analysis and methodology changes.

Quality & Reliability

8/10

Presentation by a recognized expert in cybersecurity, based on a formal risk analysis methodology, with transparent discussion of methodological changes and limitations. The content is well-structured and grounded in the work of an academy committee.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The presentation provides an original contribution by detailing the evolution of a risk analysis methodology in a real-world context, specifically for e-voting. It offers transparency into the committee’s decision-making process and highlights the importance of considering uncertainty in risk assessments. The discussion of specific risks, such as app distribution channels and source code openness, adds practical value.

Pour aller plus loin :

98 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-balanced presentation that is both informative and credible, though it may require some technical background to fully appreciate.

Reliability 8/10