This study aims to design a comprehensive cybersecurity profile for Indonesia’s electoral digital ecosystem using the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0. The research focuses on identifying vulnerabilities in election information systems, formulating mitigation controls, and strengthening the supervisory role of the Election Supervisory Agency (Bawaslu) toward the General Election Commission (KPU). This study employed a qualitative descriptive-diagnostic approach. Data were collected through qualitative observations, historical cyber incident reports, regulations, cybersecurity documents, and academic literature related to election governance and digital security in Indonesia. Data analysis followed five implementation phases of NIST CSF 2.0: prioritize and scope, orient, create current profile, conduct risk assessment, and create target profile. The findings indicate that Indonesia’s election information systems remain vulnerable to data breaches, access control weaknesses, insider threats, infrastructure failures, and disinformation attacks. The study proposes a dual-recording e-voting architecture integrated with Voter Verifiable Paper Audit Trail (VVPAT) to improve transparency, auditability, and election integrity. The findings imply that election cybersecurity governance requires integrated institutional oversight, technical mitigation, and forensic audit mechanisms to maintain democratic legitimacy and public trust
Copyrights © 2026