CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners.
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. State and local election officials have primary responsibility for protecting election infrastructure, with more than 10,000 local jurisdictions managing elections. The federal government, including CISA, provides information, tools, and resources to help.
Certification rules can hold back patching
According to CISA, election software can contain vulnerabilities that need to be fixed promptly. However, the agency notes that “structural constraints within the certification ecosystem can significantly limit vendors’ ability to release patches and prevent system owners from applying them quickly.”
CISA’s assessments also show that state, local, tribal and territorial (SLTT) election offices often struggle with basic cyber hygiene...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE