Overview
- CISA published a 13-page Election Infrastructure Security Plan on Thursday that catalogs cyber, physical, and insider threats and targets protections for the November 3 midterm elections.
- The document lists no-cost offerings for state, local, tribal and territorial election officials, including Risk and Vulnerability Assessments, continuous vulnerability scanning, on-site penetration testing, and tabletop exercises.
- It urges use of paper ballots and post-election manual audits to preserve transparency and detect errors, and it recommends technical steps such as multifactor authentication and continuous network monitoring for voter registration systems.
- DHS Secretary Markwayne Mullin said the administration will implement the plan in full, but many election officials and reporting note that last year’s staff and funding cuts to CISA and the voluntary nature of the services could limit how much help jurisdictions actually receive before Election Day.
- The plan revives federal guidance and highlights regional directors as Election Security Advisors and fusion centers for intelligence sharing, yet it does not restore previously reported EI-ISAC funding and leaves uptake dependent on uneven state and local adoption.