That makes the most sense on the face of it, especially in the preceding context of "Barnes testified that the server that holds the data that Georgia's 159 counties use to build their ballots". It's possible that the reporter conflates this "ballot data" on the "Dropbox-like site" with actual voting tallies. Such a site for the election center to upload ballot proofs sounds reasonable, although I question why such a site would need to be "air-gapped". The data to build ballots would presumably contain entirely public information (e.g. the serialized info of which candidates are running for which parties in which races).
But even if these details about ballot proofs isn't relevant to the main point, Mr. Barnes's testimony is still concerning. He's the director of the state's centralized elections system, after all. Last year, when Lamb notified the state of the data breach, Barnes "wrote of blacklisting Lamb from accessing the website before changing his mind and ordering scans of the system". [0] That the vulnerability stemmed from Drupalmageddon is even more troubling, because it's not as if Lamb's claims were hard to verify, given how well-publicized Drupalmageddon had been at that point.
It's also worth noting that I haven't seen any read about how the elections center receives the actual vote data. The stories I've read so far -- including this WaPo article -- have only referenced voter registration data. Having this data breached via arbitrary code execution is still a big deal, if the site is used to verify voter eligibility, but AFAIK, it's (hopefully) not the same system and database that holds vote data.
(Voter registration data contains personal info, but some states actually publish it online. in machine-readable format even)
[0] https://www.mcclatchydc.com/news/politics-government/article...