CISA Unveils Election Infrastructure Security Plan for 2026 Midterms
Share
CISA, the US Cybersecurity and Infrastructure Security Agency, has published a new Election Infrastructure Security Plan to guide state, local, tribal, and territorial election officials ahead of the November 2026 midterm elections.
The plan, released on 24 September 2026, provides resources to mitigate both cyber and physical threats to electoral processes. These threats target a range of assets, including polling places, centralised vote tabulation locations, and the information technology systems used to manage elections and report results.
Mitigating Vulnerability Exploitation
CISA warned that election infrastructure is often accessible via general enterprise networks, which allows malicious actors to exploit known vulnerabilities and move laterally through systems. The agency noted that many local election offices struggle with basic cybersecurity hygiene and timely vulnerability remediation.
To address these issues, officials are being urged to harmonise patch management and certification requirements for voting systems. This would allow cybersecurity updates to be applied in real-time without disrupting system certifications. CISA also recommended the use of paper ballots to facilitate error identification and verification.
Securing Voter Registration Databases
The agency highlighted significant risks to Statewide Voter Registration Databases (VRDB). According to CISA, threat actors have attempted to breach these databases in all 50 states, with successful intrusions confirmed in at least 20 states over the last decade.
To protect these systems, the plan recommends implementing phishing-resistant multi-factor authentication (MFA) for all privileged accounts. Additionally, officials should deploy continuous network monitoring, anomaly detection, and comprehensive logging to identify and reverse unauthorised database modifications.
Addressing Insider Risks
The report identified risks associated with the large temporary workforce required during election cycles, including volunteers and contractors. Because these individuals may not undergo the same vetting as permanent staff, they present both intentional and unintentional insider risks.
Potential threats include deliberate sabotage of ballot definitions or unauthorised changes to registration databases. Unintentional risks include staff falling victim to phishing attacks or introducing malware via removable media. CISA advised maintaining bipartisan handling of ballots and strict chain-of-custody procedures to mitigate these risks.
Funding and Resource Context
The release of this plan follows warnings from security experts regarding 2025 budget cuts that impacted CISA’s ability to secure critical infrastructure. Reports indicated that the termination of federal funding for activities supporting the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) was part of cost-saving measures.
In response to these cuts, Senator Alex Padilla and Representative Joe Morelle issued an open letter on 3 September 2026, calling for the immediate restoration of funding to the EI-ISAC ahead of the upcoming elections.
CISA is offering several no-cost services to assist election partners, including tabletop exercise packages, penetration testing, and access to its Known Exploited Vulnerabilities (KEV) catalogue. Regional security advisors and fusion centres are also available to help coordinate threat intelligence sharing.




Leave a Reply