The Cybersecurity and Infrastructure Security Agency (CISA) has introduced its 2026 Election Infrastructure Security Plan, highlighting potential cyber and physical threats to election processes. The plan also outlines free services CISA offers to election officials and collaborating partners to bolster security.
Challenges in Patching Vulnerabilities
In July, Homeland Security Secretary Markwayne Mullin directed CISA to create this comprehensive plan. In the United States, over 10,000 local jurisdictions handle election management, primarily shouldered by state and local officials. The federal government, through agencies like CISA, aids these efforts by providing crucial information and resources.
CISA identifies significant barriers to timely patching of election software vulnerabilities. Certification procedures often delay the release and application of necessary patches, leaving systems potentially exposed. Furthermore, basic cyber hygiene and vulnerability remediation remain challenging for many state, local, tribal, and territorial (SLTT) election offices.
Often, election systems are integrated within general enterprise networks, making them vulnerable to lateral attacks if a hacker gains access through compromised emails or workstations. CISA recommends syncing patch management with certification processes, enabling real-time updates without jeopardizing system certification.
Securing Voter Registration Databases
Voter registration databases are frequently targeted by foreign entities, according to reports covering the last decade. CISA notes that hackers have attempted breaches in all 50 states, succeeding in at least 20.
To safeguard these databases, CISA emphasizes multi-factor authentication and network monitoring to detect anomalies. Restricting user access to essential functions, maintaining critical logs for at least a year, and isolating public-facing registration tools from the main database are key strategies proposed.
Addressing Insider Threats
Insider threats, involving permanent staff and temporary or volunteer workers, are growing concerns for election security. These individuals may not always receive the same vetting process, increasing the risk of malicious or accidental insider activities.
Potential insider threats include unauthorized alterations to voter databases and mishandling of election equipment. CISA advocates for practices such as bipartisan handling of ballots and establishing chain-of-custody procedures to mitigate these risks. Formalizing these practices into a documented insider threat program is recommended.
Additionally, CISA has tracked 96 election-related security incidents, primarily bomb threats, since January 2022, underscoring the physical risks involved.
Enhancing Information Sharing and Free Services
For the 2026 election cycle, CISA plans to provide a no-cost information-sharing platform to fusion centers and election officials. This platform will facilitate near real-time communication with peers and federal partners, a model successfully employed during the FIFA World Cup 2026.
CISA’s plan also details free services available to election offices, including vulnerability scanning, penetration testing, and the deployment of decoy systems to detect intrusions, enhancing overall security defenses.
