Skip to content
Security & Trust

CISA Election Security Plan Flags Patching Barriers, Voter Database Risk

Certification rules can delay patches while voter registration systems face persistent attempts across all 50 states

K
Kannan SP
· 4 min read
Share on X LinkedIn
CISA Election Security Plan Flags Patching Barriers, Voter Database Risk
Key finding

Local jurisdictions responsible for election infrastructure: 10,000+ (Source: CISA 2026 Election Infrastructure Security Plan, via SecurityWeek (Sept. 27, 2026))

A federal plan for a system it doesn't own

The Cybersecurity and Infrastructure Security Agency has published its 2026 Election Infrastructure Security Plan, drafted after Homeland Security Secretary Markwayne Mullin tasked the agency with the work in July. The plan's starting premise is one budget-holders in any distributed organization will recognize: CISA doesn't run election systems. More than 10,000 local jurisdictions do, each responsible for its own infrastructure, with the federal government limited to offering tools, assessments and information.

10,000+
Local jurisdictions responsible for election infrastructure
Source: CISA 2026 Election Infrastructure Security Plan, via SecurityWeek (Sept. 27, 2026)

Certification rules can outlast the threat they were built for

CISA's central finding is structural rather than technical. The agency states that "structural constraints within the certification ecosystem can significantly limit vendors' ability to release patches and prevent system owners from applying them quickly." In plain terms: a compliance regime designed to lock down a product's configuration can also lock out the fix for a known flaw, because applying it risks tripping a recertification requirement. CISA's assessments separately found that state, tribal and local election offices often struggle with basic cyber hygiene and vulnerability remediation, and that election systems are frequently reachable from general enterprise networks — meaning a compromised email account or workstation can become a path to systems that were assumed to be isolated.

The agency's recommended fix is to align patch management with certification requirements so security updates can be applied in real time without forcing a product back through recertification. It also wants vendors held to practices already familiar to enterprise security teams: assign CVE identifiers to flaws, disclose promptly if source code is leaked or stolen, report incidents to authorities, and ship a software bill of materials with every product.

Voter databases remain a standing target

Citing reports spanning the past decade, CISA says voter registration databases continue to draw attention from foreign adversaries. The agency's own language is direct about the scale of the attempts and the fraction that have succeeded.

50 of 50
States where breaches of voter registration systems have been attempted
Source: CISA 2026 Election Infrastructure Security Plan (Sept. 27, 2026)
20+
States with confirmed successful breaches of voter registration systems
Source: CISA 2026 Election Infrastructure Security Plan (Sept. 27, 2026)

CISA's prescribed defenses for these databases read like a baseline enterprise checklist: multi-factor authentication, network monitoring for anomalies, access limited to what each role actually needs, log retention of at least a year, and a hard separation between the public-facing registration and lookup tools and the master voter database itself.

Insider risk widens with seasonal and volunteer staff

The plan treats insider risk as a growing concern that extends well past permanent employees to temporary and seasonal workers, volunteer poll workers, contractors and vendors — categories that, CISA notes, may not go through the same vetting as full-time staff. A malicious insider could alter voter registration data, ballot definitions, tabulation settings or results reporting; a careless one could fall for phishing, plug unauthorized removable media into election equipment, or mishandle it. CISA's recommended countermeasures — bipartisan two-person ballot handling, counting observers, chain-of-custody procedures — are not new, but the agency says they hold up better when formalized into a documented insider threat program rather than left as informal practice.

Physical threats concentrate in one category

On physical security, CISA's plan draws on open-source incident tracking rather than internal reporting alone, and the resulting picture is narrow rather than broad-based.

96 of 107
Election-related security incidents since January 2022 that were bomb threats
Source: CISA 2026 Election Infrastructure Security Plan (Sept. 27, 2026)

For the 2026 cycle, CISA is also offering a no-cost information-sharing platform for fusion centers and state and local election officials, a model the agency says was used during the 2026 FIFA World Cup, alongside free vulnerability and web application scanning, continuous penetration testing, and decoy systems for detecting intrusions.

What a budget-holder should ask

Any organization operating under a certification or compliance regime — not just election offices — can use this plan as a prompt for its own governance review. Worth asking a security team directly: Do vendor contracts require CVE disclosure and a software bill of materials, as CISA recommends here? Does the patch approval process force a full recertification cycle for a security-only fix, or can one be applied without retriggering it? Is there a written insider-threat program that explicitly covers seasonal, volunteer and contractor access, not only permanent staff? And are logs retained for at least a year, with public-facing lookup systems logically separated from the systems of record they reference?

Share this insight