CISA Releases 2026 Election Infrastructure Security Plan Amid Rising Threats
The Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, outlining the cyber and physical threats to U.S. election systems and detailing the free resources it provides to election officials. The plan was developed under a directive from Homeland Security Secretary Markwayne Mullin issued in July. It emphasizes that while state and local election officials bear primary responsibility for securing election infrastructure—managed across more than 10,000 local jurisdictions—the federal government, including CISA, offers critical support through information, tools, and services.
Certification Rules Delay Critical Patching
CISA identifies structural limitations in the software certification ecosystem as a major obstacle to timely vulnerability remediation. According to the plan, election software often contains flaws requiring urgent patching, but certification requirements significantly restrict vendors’ ability to release updates and hinder system owners from applying them quickly. The agency states: “Structural constraints within the certification ecosystem can significantly limit vendors’ ability to release patches and prevent system owners from applying them quickly.”
Assessments reveal that many state, local, tribal, and territorial (SLTT) election offices struggle with basic cyber hygiene and vulnerability remediation. Furthermore, election systems are frequently connected to general enterprise networks, allowing attackers who compromise email or workstations to move laterally into election environments.
To address these challenges, CISA recommends aligning patch management with certification processes so security updates can be deployed in real time without jeopardizing certification status. It also urges software vendors to assign CVE identifiers to vulnerabilities, promptly notify customers if source code is leaked or stolen, report incidents to authorities, and include a software bill of materials (SBOM) with every product.
Voter Registration Databases Remain Prime Targets
Citing historical incident data, CISA warns that voter registration databases continue to be high-value targets for foreign adversaries. The agency states: “Hackers have attempted to breach voter registration systems in all 50 states, with confirmed success in at least 20 states.” This conclusion is based on reports spanning the past decade.
To mitigate these risks, the plan prioritizes multi-factor authentication, continuous network monitoring for anomalous behavior, strict access controls based on job roles, retention of critical logs for at least one year, and isolating public-facing voter registration and lookup tools from the master database.
Insider Threats Expand Across Election Workforce
CISA identifies insider risk as a growing concern encompassing permanent employees, temporary and seasonal workers, volunteer poll workers, contractors, and vendors. Seasonal and volunteer personnel often lack the same level of background vetting as full-time staff.
Malicious insiders could alter voter registration data, ballot definitions, tabulation settings, or results reporting, while negligent individuals might fall for phishing attacks, introduce unauthorized removable media, or mishandle election equipment. The agency notes that existing safeguards—such as bipartisan two-person ballot handling, presence of counting observers, and chain-of-custody procedures—were designed to reduce such risks but should be formalized into documented insider threat programs.
Physical Threats Dominate Incident Reports
Addressing physical security, CISA reports that of the 107 election-related security incidents tracked via open-source reporting since January 2022, 96 were bomb threats. This highlights the disproportionate volume of non-cyber threats affecting election infrastructure.
CISA Launches Free Information-Sharing Platform for 2026 Cycle
For the 2026 election cycle, CISA is deploying a no-cost information-sharing platform accessible to all fusion centers and state and local election officials. The platform enables near real-time communication among peers and federal partners. CISA notes that this model was successfully used during the FIFA World Cup 2026.
The agency also promotes its suite of free services, including vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, and decoy systems such as canary tokens for intrusion detection.
Source: SecurityWeek