The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released its 2026 Election Infrastructure Security Plan to address cyber and physical threats ahead of the midterms. Tasked by Homeland Security Secretary Markwayne Mullin, the plan highlights critical vulnerabilities, including patching delays caused by certification rules and persistent foreign threats to voter databases. CISA offers free services like vulnerability scanning and a real-time information-sharing platform to assist local jurisdictions.
Development of the 2026 plan
- ▪The U.S. Cybersecurity and Infrastructure Security Agency released its 13-page 2026 Election Infrastructure Security Plan on 24 September 2026, detailing physical and cyber threats to voting systems.
- ▪Department of Homeland Security Secretary Markwayne Mullin tasked the Cybersecurity and Infrastructure Security Agency in July 2026 with developing the 2026 Election Infrastructure Security Plan.
Cybersecurity weaknesses in election offices
- ▪The Cybersecurity and Infrastructure Security Agency warned that election infrastructure is often accessible from general enterprise networks, allowing attackers to move laterally after compromising email systems or workstations.
- ▪The Cybersecurity and Infrastructure Security Agency's assessments in its 2026 Election Infrastructure Security Plan show that state, local, tribal, and territorial election offices often struggle with basic cyber hygiene and vulnerability remediation
Improving software vendor security
- ▪The Cybersecurity and Infrastructure Security Agency recommends aligning patch management with certification requirements under the 2026 Election Infrastructure Security Plan to overcome structural constraints that limit software vendors' patch releases and prevent quick system updates
- ▪The Cybersecurity and Infrastructure Security Agency recommends that election software vendors ship a software bill of materials with every product to improve transparency.
- ▪The Cybersecurity and Infrastructure Security Agency suggests election officials encourage software providers to assign CVE identifiers to flaws and notify customers promptly if source code is leaked or stolen.
Securing voter registration databases
- ▪The Cybersecurity and Infrastructure Security Agency recommends that election offices retain critical database logs for at least one year and limit user access to only what is needed for their jobs.
- ▪To protect voter registration databases, the Cybersecurity and Infrastructure Security Agency's 2026 Election Infrastructure Security Plan prioritizes multi-factor authentication, network monitoring, and keeping public online registration tools walled off from master databases
- ▪The Cybersecurity and Infrastructure Security Agency reported that hackers have attempted to breach voter registration systems in all 50 U.S. states, with confirmed success in at least 20 states.
Mitigating insider threats
- ▪The Cybersecurity and Infrastructure Security Agency's 2026 Election Infrastructure Security Plan identifies contractors and third-party vendors as growing insider risks capable of making unauthorized changes to ballot definitions and tabulation settings
- ▪The Cybersecurity and Infrastructure Security Agency recommends that election offices formalize bipartisan two-person ballot handling and chain-of-custody procedures into documented insider threat programs.
- ▪The Cybersecurity and Infrastructure Security Agency's 2026 Election Infrastructure Security Plan warns that careless, malicious, or poorly vetted internal personnel—including permanent, seasonal, and volunteer workers—could make unauthorized database changes or fall victim to phishing
CISA support and free services
- ▪For the 2026 election cycle, the Cybersecurity and Infrastructure Security Agency is supporting a no-cost information-sharing platform for fusion centers and state and local election officials.
- ▪The Cybersecurity and Infrastructure Security Agency provides election officials access to its 10 regional directors, who serve as Election Security Advisors to support state and local partners.
- ▪The Cybersecurity and Infrastructure Security Agency's free offerings for election offices include vulnerability scanning, web application scanning, continuous penetration testing, and decoy systems.
Debatable claims
- ▪Paper ballots are more secure than fully electronic voting systems
- ▪CISA is an appropriate agency to lead national election security efforts
- ▪Allowing real-time security patches without full recertification compromises voting system integrity
Story comments
Loading comments…