It doesn't really matter in terms of the election itself because the system was abandoned and was never intended to be the definitive basis of results.
However, saying that attacks were stopped in real time is already bad news. The fact that he was changing passwords and taking the "SQL server" off the network (I presume he means on some sort of public or unsafe network) just days before the election is pretty bad. The system could have been hijacked before he set up the IDS and did that work. It sounds like he did the best job possible but a penetration test is just one of many layers needed for security so this really does appear to be a textbook example of a failed implementation of an important technology system.
However, many best practices and lessons could come out of this. It almost seems like a book-length project.
-Adam