IndiaFocal.

India, in focus.

World

CISA Releases Election Security Plan 40 Days Before Midterms

CISA released its election infrastructure security plan 40 days before the midterms, listing threats and services amid criticism that federal support has dwindled.

The nation's cybersecurity agency on Thursday published an election infrastructure security plan, arriving 40 days ahead of November's midterms. The document sets out potential threats to election systems and details the services the agency will offer election officials to safeguard the vote.

The plan had originally been promised by Homeland Security Secretary Markwayne Mullin for release by mid-August. Its arrival comes as the Trump administration seeks to restart efforts to help states protect voting systems — a push that election officials have described as too little, too late, after the administration dismantled much of the agency's election security work last year. That dismantling prompted many officials to hire private vendors to prepare for the upcoming elections.

"Election security is national security," Mullin said in a statement. "This plan, which will be implemented in full, is crucial to the security, freeness, and fairness of choosing the leaders of our country."

The document flags a range of threats, including software vulnerabilities, intrusions into voter registration databases, insider risks and physical security incidents such as the bomb threats that hit several polling places during the 2024 elections. It also affirms that many established election practices can counter these dangers, stating the agency's aim is to ensure the public can trust voting systems and know that physical safety measures will be in place at polling locations.

The plan's release follows Mullin's recent efforts to promote unsubstantiated claims about hundreds of thousands of noncitizens on voter rolls. In July, he threatened election officials with fines, penalties or prison time if they did not take part in a now-blocked federal voter database intended to identify noncitizens on the rolls. President Donald Trump continues to assert that noncitizen voting is widespread, though research shows it is extremely rare.

The Cybersecurity and Infrastructure Security Agency, part of the Department of Homeland Security, has since its 2018 founding helped warn state and local election officials about potential foreign threats. But CISA was largely absent from that role in last year's elections after the administration cut roughly 1,000 employees and slashed $10 million from two cybersecurity initiatives, including one dedicated to assisting state and local election officials. The agency has also gone the entirety of Trump's second term without a Senate-confirmed director, instead cycling through acting leaders.

The 13-page document says DHS has "consistently supported CISA's delivery of cybersecurity and physical security services to election officials," and that these services are provided at no cost to state and local officials upon request.

Many state election officials dispute that account. They say services historically provided by CISA — such as live tabletop exercises and penetration tests to evaluate system security — were unavailable in the run-up to this year's midterms. Minnesota Secretary of State Scott Simon said in August that his office expects to spend about $250,000 on private vendors for penetration testing. Maine's Democratic secretary of state, Shenna Bellows, said the same month that communications with CISA had been "sporadic and irregular, to say the least," and that restoring intelligence briefings on foreign threats would help, though trust with federal officials had been broken by the cuts.

Thursday's plan does not mention specific 2026 threats from adversaries such as Russia, Iran or China, all of which have sought to meddle in U.S. elections through hacking or influence campaigns.

West Virginia's Republican secretary of state, Kris Warner, said some CISA assistance to his state had been continuous throughout the Trump administration, including no-cost reviews of public-facing websites for cybersecurity issues. He acknowledged the agency had scaled back but said he views it "as a resource and not as a service provider," adding that his office last year hired a departing CISA election security adviser who has helped fill any gaps.

Nevada's Democratic secretary of state, Cisco Aguilar, said he had not yet reviewed the report but that its lateness signaled a "complete, absolute failure of leadership." He said he would have preferred more federal funding for cybersecurity rather than Nevada taxpayers bearing the cost.

The document says CISA's support to election officials is led by 10 "regional directors," a structure that David Becker, executive director of the Center for Election Innovation and Research, said departs from past practice, when state and regional advisers existed. Becker called the report a positive but perhaps performative step, given that states have already turned elsewhere. "The reality is that no state, red or blue, is relying upon the federal government for this assistance at this point," he said.

In early August, two CISA officials — acting director Nick Anderson and assistant director for integrated operations Jim Harrell — joined a National Association of Secretaries of State call attended by a bipartisan group of secretaries of state. Simon said the officials seemed interested in rebuilding relationships and previewing future plans, which he appreciated, but that the outreach came later than needed. Arizona's Democratic secretary of state, Adrian Fontes, said he told the officials he did not trust them and that they acknowledged on the call it was too late to do anything for 2026. Still, he said he is confident November's elections will be secure. "We're going to have a good election whether or not we have a partner in CISA or the Department of Homeland Security," he said.