Download Privacy Needle App

Type to search

Cybersecurity

CISA Unveils Election Infrastructure Security Plan for 2026 Midterms

Share

CISA, the US Cybersecurity and Infrastructure Security Agency, has published a new Election Infrastructure Security Plan to guide state, local, tribal, and territorial election officials ahead of the November 2026 midterm elections.

The plan, released on 24 September 2026, provides resources to mitigate both cyber and physical threats to electoral processes. These threats target a range of assets, including polling places, centralised vote tabulation locations, and the information technology systems used to manage elections and report results.

Mitigating Vulnerability Exploitation

CISA warned that election infrastructure is often accessible via general enterprise networks, which allows malicious actors to exploit known vulnerabilities and move laterally through systems. The agency noted that many local election offices struggle with basic cybersecurity hygiene and timely vulnerability remediation.

To address these issues, officials are being urged to harmonise patch management and certification requirements for voting systems. This would allow cybersecurity updates to be applied in real-time without disrupting system certifications. CISA also recommended the use of paper ballots to facilitate error identification and verification.

Securing Voter Registration Databases

The agency highlighted significant risks to Statewide Voter Registration Databases (VRDB). According to CISA, threat actors have attempted to breach these databases in all 50 states, with successful intrusions confirmed in at least 20 states over the last decade.

To protect these systems, the plan recommends implementing phishing-resistant multi-factor authentication (MFA) for all privileged accounts. Additionally, officials should deploy continuous network monitoring, anomaly detection, and comprehensive logging to identify and reverse unauthorised database modifications.

Addressing Insider Risks

The report identified risks associated with the large temporary workforce required during election cycles, including volunteers and contractors. Because these individuals may not undergo the same vetting as permanent staff, they present both intentional and unintentional insider risks.

Potential threats include deliberate sabotage of ballot definitions or unauthorised changes to registration databases. Unintentional risks include staff falling victim to phishing attacks or introducing malware via removable media. CISA advised maintaining bipartisan handling of ballots and strict chain-of-custody procedures to mitigate these risks.

Funding and Resource Context

The release of this plan follows warnings from security experts regarding 2025 budget cuts that impacted CISA’s ability to secure critical infrastructure. Reports indicated that the termination of federal funding for activities supporting the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) was part of cost-saving measures.

In response to these cuts, Senator Alex Padilla and Representative Joe Morelle issued an open letter on 3 September 2026, calling for the immediate restoration of funding to the EI-ISAC ahead of the upcoming elections.

CISA is offering several no-cost services to assist election partners, including tabletop exercise packages, penetration testing, and access to its Known Exploited Vulnerabilities (KEV) catalogue. Regional security advisors and fusion centres are also available to help coordinate threat intelligence sharing.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.