# What CISA published
On 24 September 2026 the Cybersecurity and Infrastructure Security Agency (CISA) released the Election Infrastructure Security Plan for the run-up to the 3 November midterm elections. The document targets state, local, tribal and territorial (SLTT) election bodies and federal partners and provides both threat assessments and operational guidance for securing physical and digital election assets.
# Core threats CISA highlights
CISA separates threats into broad, actionable categories:
- Voter registration databases (VRDB): adversaries have attempted breaches in all 50 states, with confirmed success in at least 20 states over the last decade. CISA urges prioritizing these databases for protection.
- Insider threats: seasonal staff, volunteers, contractors and vendors expand the insider-risk footprint. Risks include deliberate tampering (changes to databases or ballot definitions) and accidental introduction of malware via removable media or phishing.
# Concrete defensive recommendations
CISA prescribes a list of controls and operational practices election officials should adopt:
- Harmonize patch management and certification requirements so cybersecurity updates can be applied without jeopardizing voting-system certification.
- Use paper ballots to provide an auditable trail for verification and error detection.
- Apply multifactor authentication (MFA) to all access to VRDB and connected systems, preferring phishing-resistant methods for privileged accounts.
- Implement continuous network monitoring, anomaly detection, and comprehensive logging and audit trails to surface and reverse unauthorized changes quickly.
- Maintain long-standing election operational safeguards against insider risk: bipartisan teams for ballot handling, observers during counts, and strict chain-of-custody procedures.
# Services CISA offers at no cost
The plan catalogs voluntary, no-cost services that SLTT officials and private-sector partners can request. Examples listed in the coverage include tabletop exercise packages, penetration testing services, workshops, and briefings. CISA frames these services as tools to improve preparedness and operational resilience ahead of the election.
# Political and funding context
The plan appears after reported cuts to CISA in 2025 that affected election-related activities. Coverage says CISA terminated federally funded efforts supporting the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) as a cost-saving measure. The EI-ISAC is not mentioned in the new plan. Earlier in September 2026 two Democratic legislators — Senator Alex Padilla and Representative Joe Morelle — issued an open letter calling for immediate restoration of EI-ISAC funding ahead of the midterms.
# What to expect for officials and partners
Election offices should inventory which recommendations and services they have already implemented and request applicable CISA support promptly given the short timeframe before Election Day. Priority actions include locking down VRDB access with MFA, accelerating patching where feasible, enabling logging and monitoring, and validating paper-ballot processes and chain-of-custody procedures through tabletop exercises or penetration testing.
# Bottom line
CISA's plan is a tactical, operational document aimed at reducing the attack surface across both physical and digital election infrastructure. It couples specific technical controls with offers of no-cost services, while existing political and funding controversies over EI-ISAC remain unresolved.