CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

The US government’s Cybersecurity and Infrastructure Security Agency (CISA) has issued a comprehensive plan to secure election infrastructure ahead of the 2026 elections. The plan, developed in response to a directive from Homeland Security Secretary Markwayne Mullin, highlights significant cyber and physical threats facing election systems.

At the heart of CISA’s plan is the recognition that state and local election officials are on the front lines of protecting election infrastructure, with over 10,000 jurisdictions managing elections across the country. The federal government, including CISA, provides critical support in the form of information, tools, and resources to help these officials stay ahead of emerging threats.

One key issue identified by CISA is the patching process itself. Election software can contain vulnerabilities that need to be fixed quickly, but certification rules often limit vendors’ ability to release patches and prevent system owners from applying them promptly. This structural constraint can have serious consequences, allowing attackers to exploit known weaknesses in election systems. To address this issue, CISA recommends aligning patch management with certification requirements, enabling security updates to be applied in real-time without affecting system certification.

Another area of concern is the cybersecurity maturity of many state and local networks that host election systems. These networks often struggle with basic cyber hygiene and vulnerability remediation, leaving them vulnerable to attacks. In some cases, election infrastructure is even accessible from general enterprise networks, allowing attackers who compromise email systems or workstations to move laterally and access sensitive data.

CISA’s plan also highlights the importance of voter registration databases, which have been targeted by foreign adversaries in the past decade. To protect these databases, CISA recommends implementing multi-factor authentication, network monitoring, limiting access to authorized personnel, retaining critical logs for at least a year, and keeping online registration tools isolated from the master database.

Furthermore, CISA emphasizes the growing concern of insider risks, which can arise from both malicious and careless actions by staff, volunteers, contractors, and vendors. To mitigate this risk, election offices are encouraged to formalize existing practices into documented insider threat programs, including bipartisan two-person ballot handling and chain-of-custody procedures.

The plan also addresses physical risks, noting that 96 of the 107 election-related security incidents tracked since January 2022 were bomb threats. CISA is supporting a no-cost information-sharing platform for the 2026 cycle, which will enable near real-time communication between fusion centers, state and local election officials, and federal partners.

In conclusion, CISA’s Election Infrastructure Security Plan offers valuable insights and practical advice to help election officials protect their infrastructure from cyber and physical threats. As the 2026 elections approach, it is essential for these officials to prioritize cybersecurity maturity, patch management, voter registration database security, and insider risk mitigation. By taking proactive steps to address these areas of concern, election officials can ensure the integrity and reliability of our democratic processes.


Source: SecurityWeek — 2026-09-25