Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

Election cybersecurity

The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners.

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. State and local election officials have primary responsibility for protecting election infrastructure, with more than 10,000 local jurisdictions managing elections. The federal government, including CISA, provides information, tools, and resources to help.

Certification rules can hold back patching

According to CISA, election software can contain vulnerabilities that need to be fixed promptly. However, the agency notes that “structural constraints within the certification ecosystem can significantly limit vendors’ ability to release patches and prevent system owners from applying them quickly.”

CISA’s assessments also show that state, local, tribal and territorial (SLTT) election offices often struggle with basic cyber hygiene and vulnerability remediation.

In addition, election infrastructure is often accessible from general enterprise networks. Attackers who compromise email systems or workstations can use that access to move laterally.

The agency names three issues, including vulnerability management limited by outdated certification regimes, inconsistent vendor transparency about vulnerabilities and patch status, and the cybersecurity immaturity of many SLTT networks that host election systems.

Advertisement. Scroll to continue reading.

CISA recommends aligning patch management with certification requirements, so that security updates can be applied in real time without affecting system certification. It also recommends paper ballots and manual post-election audits.

The agency suggests that election officials encourage software providers to assign CVE identifiers to flaws, tell customers promptly if source code is leaked or stolen, report incidents to authorities, and ship a software bill of materials (SBOM) with every product.

Voter registration databases remain a target

Citing reports from the past decade, CISA says voter registration databases are attractive targets for foreign adversaries.

“Hackers have attempted to breach voter registration systems in all 50 states, with confirmed success in at least 20 states,” CISA says.

To protect these databases, the plan prioritizes multi-factor authentication, network monitoring to spot anomalies, limiting access to what each user needs for their job, retaining critical logs for at least a year, and keeping the online registration and lookup tools used by the public walled off from the master database.

Insider risks span staff, volunteers and vendors

CISA says insider risk is a growing concern that involves permanent staff, temporary or seasonal workers, volunteer poll workers, contractors and vendors. Seasonal and volunteer personnel may not undergo the same vetting as permanent staff.

According to CISA, malicious insiders could make unauthorized changes to voter registration databases, ballot definitions, tabulation settings or results reporting, while careless ones could fall for phishing, plug unauthorized removable media into election systems or mishandle equipment.

Practices such as bipartisan two-person ballot handling, counting observers and chain-of-custody procedures were designed to reduce this risk. CISA says election offices benefit from formalizing them into a documented insider threat program.

Addressing physical risks, CISA noted that 96 of the 107 election-related security incidents tracked through open source reporting since January 2022 were bomb threats.

Information-sharing platform for the 2026 cycle

For the 2026 election cycle, CISA is supporting a no-cost information-sharing platform for all fusion centers and state and local election officials. The platform supports near real-time communication with peers and federal partners.

“This model was successfully deployed and utilized during FIFA World Cup 2026,” the agency notes.

The plan also highlights free services, including vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, and decoy systems and canary tokens for detecting intrusions. 

Related: OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Related: CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.