“By leveraging collaborative partnerships, robust cyber defenses, and ongoing threat intelligence, the plan ensures that all stakeholders are prepared to address evolving risks. Continued vigilance, adaptability, and transparency will be essential as we work together to protect the foundations of our Constitutional Republic and maintain public trust in our elections,” CISA wrote in the Plan, published on September 24.
CISA’s Election Infrastructure Security Plan: scope and timing
On September 24, the US Cybersecurity and Infrastructure Security Agency (CISA) published an Election Infrastructure Security Plan intended for state, local, tribal and territorial (SLTT) election offices as well as federal bodies and private-sector partners, ahead of the November 3, 2026 midterm elections. The document frames electoral infrastructure as a dual set of assets: physical sites such as storage facilities, polling places and centralized vote tabulation locations, and the information and communications technology elements — voter registration databases, voting machines, and the systems used to manage and report results.
Primary cyber threats CISA expects before November 3
CISA sets out three recurring threat vectors it expects in the run-up to the midterms. First, vulnerability exploitation: many election systems are reachable from general enterprise networks, which can allow actors to exploit known vulnerabilities and move laterally. Second, attacks on voter registration databases: threat actors have attempted breaches in all 50 states, with confirmed success in at least 20 states over the last decade. Third, insider risks: the seasonal and volunteer workforce used during elections can increase both intentional and unintentional insider threats, including unauthorized changes to voter databases and the introduction of malicious files via removable media.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMitigation steps CISA recommends
The plan lays out concrete defensive measures for SLTT election offices and partners. CISA urges harmonized patch management and certification requirements for voting systems so cybersecurity updates can be applied in real time without invalidating system certification. The agency advocates the continued or expanded use of paper ballots that can be reviewed to verify system function and detect errors. For voter registration databases, CISA recommends multifactor authentication (MFA) for all access and phishing-resistant methods for privileged accounts where possible, along with continuous network monitoring, anomaly detection, and comprehensive logging and audit trails to detect and reverse unauthorized changes.
To address insider threats, CISA points back to longstanding election procedures: handling ballots in bipartisan teams of two, allowing observers during ballot counting, and maintaining chain-of-custody practices. The plan explicitly flags the uneven vetting of seasonal personnel and the risk that temporary workers may fall for phishing or introduce removable media that contains malicious files.
No-cost CISA services election officials can deploy
- Tabletop exercise packages and penetration testing services;
- Workshops and briefings on specific security topics;
- Vulnerability and web scanning services to identify exposures;
- Use of CISA’s Known Exploited Vulnerabilities (KEV) catalog to track active threats;
- Coordination with CISA’s cadre of regional security advisors;
- Information-sharing and risk assessment coordination with state and regional fusion centers.
Funding cuts, the EI‑ISAC, and congressional pressure
The publication comes against a backdrop of reported budgetary decisions. Security experts previously warned that reported cuts by President Trump’s administration to CISA in 2025 affected the agency’s ability to secure critical election infrastructure. Those reports said CISA terminated federally funded activities supporting the Election Infrastructure Information Sharing and Analysis Center (EI‑ISAC) as part of cost-saving measures; the EI‑ISAC is not specifically mentioned in the new Election Infrastructure Security Plan. Separately, on September 3, 2026, Senator Alex Padilla and Representative Joe Morelle published an open letter demanding that the Trump Administration immediately restore funding to EI‑ISAC ahead of the 2026 midterms.
What this means for SLTT election offices, election system vendors, and voters
- SLTT election offices — Many are singled out in the plan as struggling with basic cybersecurity hygiene and vulnerability remediation. The document directs them to harmonize patch and certification practices, adopt MFA and continuous monitoring, and to take advantage of CISA’s no-cost services.
- Election system vendors — CISA calls out inconsistent transparency from vendors as a barrier to timely remediation; vendors will be under pressure to align on certification and permit security updates without disrupting certified systems.
- Voters and the public — CISA’s recommendation to use paper ballots and preserve bipartisan handling, observers, and chain-of-custody procedures is framed as a measure to verify voting-system integrity and preserve public trust in election outcomes.
CISA’s plan ties technical defensive measures to a broader appeal for collaboration and transparency. It also leaves an explicit policy tension in the foreground: the agency is offering services and standards-oriented fixes while a previously funded information‑sharing body, the EI‑ISAC, is not referenced and has been the target of calls for restored funding. Whether those budget and coordination questions are resolved in time for November 3 will shape how readily the plan’s recommendations can be applied on the ground.
https://www.infosecurity-magazine.com/news/cisa-election-security-midterms/




