www.securityweek.com 25 Sept 2026, 12:39 UTC

CISA Warns Election Systems Face Patching Delays and Insider Risks

CISA Warns Election Systems Face Patching Delays and Insider Risks

THE US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, outlining cyber and physical threats to election systems and the free services available to election officials and partners. The plan says certification requirements can delay software patching, while inconsistent vendor disclosure and weak cyber hygiene in some state, local, tribal and territorial (SLTT) networks create additional obstacles.

Election systems are also often connected to wider enterprise networks, meaning attackers who compromise email or workstations may be able to move laterally.

CISA says voter registration databases remain attractive targets for foreign adversaries. Citing reports from the past decade, it says hackers have attempted to breach systems in all 50 states, with confirmed success in at least 20. Its recommended safeguards include multi-factor authentication, anomaly monitoring, least-privilege access, retaining critical logs for at least a year, and separating public registration and lookup services from master databases.

The agency also highlights insider risks involving staff, seasonal workers, volunteers, contractors and vendors, including unauthorised changes to registration data, ballot definitions, tabulation settings or reported results. It says 96 of 107 election-related security incidents tracked through open-source reporting since January 2022 were bomb threats.

For the 2026 cycle, CISA will support a no-cost information-sharing platform for fusion centres and election officials. It also offers vulnerability and web-application scanning, continuous penetration testing, risk assessments, and decoy systems and canary tokens.

View full article

Article by CyberSIXT