"I am therefore directing the entire [Defense Intelligence Enterprise] to mobilize every authorized asset, capability, and partnership under your command to defend our election infrastructure from foreign malign influence," Defense Secretary Pete Hegseth wrote.
What Hegseth ordered and how he framed it
On Sept. 22, Defense Secretary Pete Hegseth signed a memorandum directing U.S. Cyber Command and the defense intelligence enterprise to prioritize countering foreign threats to the upcoming elections. The memo, released publicly Monday, instructs the defense intelligence enterprise to gather and analyze information on foreign election threats and directs Cyber Command to use its existing authorities and capabilities to counter potential cyberattacks by foreign actors targeting the elections. The memo calls protecting elections a "no-fail mission."
Agencies named and the limits the memo sets
The memorandum is addressed to the leaders of U.S. Cyber Command, the National Security Agency (NSA), the Defense Intelligence Agency (DIA) and the National Geospatial-Intelligence Agency (NGA). It orders intelligence collection and coordination with the Department of Homeland Security, but does not identify particular adversaries or operations, specify additional staffing or funding, or set implementation deadlines. The directive tells intelligence work to comply with applicable laws and policies and instructs Cyber Command to operate under its existing authorities.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow the memo intersects with domestic cyberdefense at DHS and CISA
Hegseth's direction emphasizes cooperation with the Department of Homeland Security as DHS's civilian cyberdefense agency, the Cybersecurity and Infrastructure Security Agency (CISA), outlines a new plan for assisting election officials following prior staffing and program reductions. Two days after Hegseth signed the memo, CISA released an election security plan that identifies its 10 regional directors as election security advisers and describes a free threat‑sharing platform connecting election officials, state intelligence hubs and federal partners. That plan followed warnings from state officials that earlier cuts had weakened their access to federal security expertise.
Context: changes across federal foreign‑influence and election security efforts
The directive arrives amid broader shifts in how the federal government organizes and staffs counter‑influence work. The source describes that the second Trump administration has dismantled the FBI’s Foreign Influence Task Force, reorganized the intelligence community’s coordination of that work and reduced election security support at CISA. At the Office of the Director of National Intelligence (ODNI), an overhaul shifted many responsibilities of the Foreign Malign Influence Center to other offices; ODNI has since assigned two officials to coordinate election threat intelligence.
What this means for state election officials, CISA, and defense cyber‑intelligence organizations
- State election officials — The CISA plan aims to restore a conduit for federal expertise: its 10 regional directors are positioned as election security advisers and a free threat‑sharing platform is available to connect state officials with federal partners and state intelligence hubs. State officials who had warned that earlier cuts weakened their access to expertise will be watching whether those mechanisms restore timely assistance.
- CISA and DHS — CISA must implement the regional adviser model and sustain the threat‑sharing platform while responding to reported staffing and program reductions; the agency's plan is the explicit federal civilian response following the memo and the earlier cuts described in the source.
- Cyber Command, NSA, DIA, and NGA — The defense intelligence enterprise has been ordered to collect and analyze foreign election threat intelligence and to coordinate with DHS, while Cyber Command has been told to use existing authorities to counter cyberattacks. The memo does not create new authorities, nor does it commit new personnel or funding, leaving the agencies to mobilize under current legal and resourcing constraints.
The memo draws on tools long in the defense community's toolbox: NSA collects foreign signals intelligence and helps protect sensitive U.S. systems, while Cyber Command conducts military cyber operations that can include disrupting foreign hackers and the infrastructure they use. The organizations have previously combined those capabilities through a joint Election Security Group; in a description of its work during the 2022 midterms, NSA explained that intelligence about an attack originating abroad could be shared with domestic agencies to help them defend against it, while Cyber Command could use offensive operations to disrupt the foreign attacker. Hegseth’s memorandum does not specify whether that same organizational model will be used this year.
The memo also situates the upcoming elections in a technological environment the source describes as changing: rapid advances in artificial intelligence allow foreign influence operators to automate more of their work, potentially enabling larger campaigns run with fewer people and complicating efforts to identify coordinated manipulation ahead of the midterms.
With a defense secretary pressing the defense intelligence enterprise to treat election protection as a "no‑fail mission," the central unanswered operational questions are concrete and contained in the memo itself: which internal structures will be used, how work will be resourced within existing authorities, and how that activity will link day‑to‑day with the civilian election security mechanisms CISA has just outlined.




