CISA’s 2026 Election Plan Targets the Gaps Between IT Networks and Voting Systems

CISA's 2026 election plan secures voter databases, IT networks, patching and insider risks across 10,000+ US jurisdictions.

CISA’s 2026 Election Plan Targets the Gaps Between IT Networks and Voting Systems
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

The US Cybersecurity and Infrastructure Security Agency has published its 2026 Election Infrastructure Security Plan, focusing on weaknesses that can expose election operations even when core voting equipment remains isolated.

The plan addresses cyberattacks, insider activity, software patching delays, and physical threats. It also outlines free federal services available to election officials during the 2026 cycle.

CISA’s central concern is broader than voting machines. Voter databases, public registration websites, office email accounts, employee workstations, vendors, contractors, and temporary personnel can all create paths toward sensitive systems.

More than 10,000 jurisdictions share the security burden

State and local authorities retain primary responsibility for election security in the United States. More than 10,000 local jurisdictions administer elections, producing a highly decentralized environment with uneven staffing, budgets, technology, and cybersecurity maturity.

The federal government provides resources and technical assistance rather than directly securing every local system. Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July; the year of that instruction has not been disclosed.

CISA assessments indicate that election offices frequently struggle with basic cyber hygiene and vulnerability remediation. The problem is especially acute where election-related infrastructure shares connectivity or trust relationships with ordinary state, local, tribal, and territorial networks.

An attacker may not need to compromise specialized election software directly. Access to an employee mailbox or workstation could become an initial foothold, followed by lateral movement through the enterprise network toward registration or election-management systems.

The plan does not identify a specific hacking group, active campaign, or recent intrusion. Foreign adversaries, hackers, and malicious insiders are discussed as broad threat categories.

Certification can turn routine patching into a security dilemma

Election technology is subject to certification requirements intended to establish that systems operate correctly and reliably. Those controls can create a conflict when a vendor releases a security update after certification.

Applying the update may alter the approved configuration. Delaying it may leave a known weakness exposed.

CISA calls for patch-management procedures that work alongside certification rules, allowing security updates to be deployed promptly—including in real time where necessary—without automatically invalidating a system’s certification.

This is a process problem as much as a technical one. Election authorities need to know whether a vulnerability affects their deployed configuration, whether a patch exists, and whether installing it changes the system’s certified status. Delays or incomplete vendor notifications can obstruct each step.

Software providers are therefore encouraged to:

  • Assign CVE identifiers to security flaws.
  • Inform customers quickly if source code is stolen or leaked.
  • Report security incidents to the appropriate authorities.
  • Supply a software bill of materials with every product.
  • Clearly communicate vulnerability exposure and patch status.

No vendor, product, software build, or affected version is named. The plan also contains no CVE identifier, CVSS score, formal severity rating, workaround, or product-specific indicator of compromise.

This is not a CISA Known Exploited Vulnerabilities catalog notice. There is no KEV addition date or federal remediation deadline because the plan addresses systemic election-security risks rather than a single confirmed software vulnerability.

Voter databases remain an attractive point of attack

CISA says attempted intrusions have targeted voter-registration systems in all 50 states, with attackers succeeding in at least 20. That assessment draws on reporting from the past decade, but the affected states, attackers, techniques, and incident dates have not been identified.

Registration databases are valuable because they contain the records used to determine voter eligibility and polling information. Unauthorized access could enable changes to those records or interfere with election administration.

Public-facing services add another layer of exposure. Online registration portals and voter-lookup tools must accept internet traffic, while the master registration database requires substantially tighter protection.

CISA recommends separating those public services from the authoritative database. A compromise of an externally accessible website should not provide a direct route to the underlying records.

Recommended protections include:

  • Multi-factor authentication for database and administrative access.
  • Least-privilege permissions for employees, contractors, and service providers.
  • Network monitoring capable of identifying anomalous activity.
  • Retention of critical security logs for at least one year.
  • Segmentation between public applications and master registration systems.

The plan does not provide specific log queries, malicious IP addresses, file hashes, domains, or other detection indicators. Election offices must therefore rely on behavioral monitoring, access reviews, and their own environment-specific telemetry.

Insiders include temporary workers, contractors, and vendors

Election operations depend on a workforce extending beyond permanent government employees. Seasonal staff, temporary workers, volunteer poll workers, contractors, and technology vendors may all handle equipment or access sensitive processes.

Some of those personnel may receive less screening than permanent staff. Access can also expand quickly during busy election periods, making consistent identity management and supervision harder.

A malicious insider could attempt unauthorized changes to voter-registration records, ballot definitions, tabulation settings, or reported results. Accidental actions present a separate risk: an employee might respond to phishing, connect unapproved removable media, mishandle equipment, or expose credentials.

CISA recommends a documented insider-risk program rather than relying solely on informal supervision. Existing procedural safeguards can support that program, including bipartisan two-person ballot handling, observers during counting, and documented chains of custody.

Technical controls should complement those measures. Least-privilege access, strong authentication, detailed logging, and prompt removal of unnecessary accounts can reduce what any single person can do without detection.

Paper ballots and manual post-election audits provide an additional safeguard. They create evidence that can be checked independently of electronic records and tabulation processes.

Bomb threats dominate reported physical incidents

Cybersecurity is only one part of the plan. Of 107 election-related security incidents tracked through open-source reporting since January 2022, 96 were bomb threats.

That figure shows why election security planning must cover buildings, personnel, equipment movement, communications, and continuity procedures alongside network defense. Even when a threat does not damage election technology, it can disrupt polling or counting operations and place workers and voters at risk.

The plan does not provide a breakdown of the remaining incidents or detailed information about the bomb threats. It also does not identify perpetrators or establish a common campaign behind them.

Physical and cyber procedures need to remain coordinated. An evacuation, for example, can alter who has access to equipment or interrupt normal chain-of-custody controls. Continuity plans must preserve those controls under pressure.

Free CISA services can expose weaknesses before attackers do

For the 2026 election cycle, CISA is supporting a no-cost information-sharing platform for fusion centers and state and local election officials. The platform enables near-real-time communication among peers and federal partners.

CISA says the model was successfully deployed during FIFA World Cup 2026. For election administrators, such a channel could accelerate warnings about suspicious activity, recurring attack patterns, and operational threats across jurisdictions.

The agency is also offering vulnerability scanning, web-application scanning, continuous penetration testing, and broader risk and vulnerability assessments. Decoy systems and canary tokens can help defenders detect unauthorized access or movement inside a network.

Election officials should prioritize a few immediate actions: map connections between office networks and election infrastructure, review privileged access, enforce multi-factor authentication, verify log retention, and separate public registration services from authoritative databases.

They should also establish how emergency patches can be evaluated without becoming trapped between certification rules and active exposure. Vendor contracts should require timely disclosure, clear patch-status information, incident reporting, and an SBOM.

The reported findings surrounding the plan describe broad risks rather than evidence of one current nationwide intrusion. The security challenge is structural: thousands of independently operated jurisdictions must defend interconnected technology, public services, sensitive records, and a large temporary workforce under strict operational deadlines.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →