Infosecurity Magazine iconInfosecurity MagazineSep 25, 2026 ~6 min source read

CISA Releases 2026 Election Infrastructure Security Plan Ahead of Midterms

The Cybersecurity and Infrastructure Security Agency published a playbook for state, local, tribal and territorial election officials outlining cyber and physical threats, mitigation steps, and no-cost services to deploy before the November 2026 midterms.

Share this story

Send the public story page.

Useful takeaways from this story.

CISA identifies primary cyber threats to election systems—including vulnerability exploitation, attacks on voter registration databases, and insider risk—and prescribes concrete mitigations.

The plan lists free, voluntary CISA services for election offices such as tabletop exercises, penetration testing, workshops, and threat information sharing.

# What CISA published

On 24 September 2026 the Cybersecurity and Infrastructure Security Agency (CISA) released the Election Infrastructure Security Plan for the run-up to the 3 November midterm elections. The document targets state, local, tribal and territorial (SLTT) election bodies and federal partners and provides both threat assessments and operational guidance for securing physical and digital election assets.

# Core threats CISA highlights

CISA separates threats into broad, actionable categories:

  • Voter registration databases (VRDB): adversaries have attempted breaches in all 50 states, with confirmed success in at least 20 states over the last decade. CISA urges prioritizing these databases for protection.
  • Insider threats: seasonal staff, volunteers, contractors and vendors expand the insider-risk footprint. Risks include deliberate tampering (changes to databases or ballot definitions) and accidental introduction of malware via removable media or phishing.

# Concrete defensive recommendations

CISA prescribes a list of controls and operational practices election officials should adopt:

  • Harmonize patch management and certification requirements so cybersecurity updates can be applied without jeopardizing voting-system certification.
  • Use paper ballots to provide an auditable trail for verification and error detection.
  • Apply multifactor authentication (MFA) to all access to VRDB and connected systems, preferring phishing-resistant methods for privileged accounts.
  • Implement continuous network monitoring, anomaly detection, and comprehensive logging and audit trails to surface and reverse unauthorized changes quickly.
  • Maintain long-standing election operational safeguards against insider risk: bipartisan teams for ballot handling, observers during counts, and strict chain-of-custody procedures.

# Services CISA offers at no cost

The plan catalogs voluntary, no-cost services that SLTT officials and private-sector partners can request. Examples listed in the coverage include tabletop exercise packages, penetration testing services, workshops, and briefings. CISA frames these services as tools to improve preparedness and operational resilience ahead of the election.

# Political and funding context

The plan appears after reported cuts to CISA in 2025 that affected election-related activities. Coverage says CISA terminated federally funded efforts supporting the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) as a cost-saving measure. The EI-ISAC is not mentioned in the new plan. Earlier in September 2026 two Democratic legislators — Senator Alex Padilla and Representative Joe Morelle — issued an open letter calling for immediate restoration of EI-ISAC funding ahead of the midterms.

# What to expect for officials and partners

Election offices should inventory which recommendations and services they have already implemented and request applicable CISA support promptly given the short timeframe before Election Day. Priority actions include locking down VRDB access with MFA, accelerating patching where feasible, enabling logging and monitoring, and validating paper-ballot processes and chain-of-custody procedures through tabletop exercises or penetration testing.

# Bottom line

CISA's plan is a tactical, operational document aimed at reducing the attack surface across both physical and digital election infrastructure. It couples specific technical controls with offers of no-cost services, while existing political and funding controversies over EI-ISAC remain unresolved.

More context around this story.

DHS releases election security plan
Homelandprepnews iconHomelandprepnewsSep 28, 2026

DHS releases election security plan

The Cybersecurity and Infrastructure Security Agency (CISA) recently released its 2026 Election Infrastructure Security Plan: Securing the Next 250. The plan provides information about free voluntary services for securing the election infrastructure and addresses threats to election technologies, processes, facilities

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app