Security News

CISA Releases Election Security Plan Ahead of 2026 US Midterms

Infosecurity Magazine · 25 Sept 2026
Key Takeaway Organisations connected to election-related networks or systems should treat network segmentation and prompt patching of known vulnerabilities as a priority to prevent attackers from moving from general IT systems into sensitive infrastructure.

The US Cybersecurity and Infrastructure Security Agency (CISA) has released an Election Infrastructure Security Plan to help state, local and federal bodies prepare for cyber and physical threats ahead of the November 2026 midterms. The agency warned that election infrastructure, including polling places, vote tabulation centres, voter registration databases and voting machines, remains an attractive target for threat actors seeking to manipulate systems or steal sensitive data.

CISA highlighted that election systems are often connected to general enterprise networks, which can let attackers exploit known vulnerabilities to gain a foothold and then move laterally into more sensitive systems. The agency said the plan relies on collaborative partnerships, strong cyber defences and ongoing threat intelligence sharing to keep stakeholders prepared for evolving risks.

The plan's release comes amid concerns from security experts and lawmakers that funding cuts to CISA in 2025 weakened election security support, including the termination of federally funded activities for the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC), which was not mentioned in the new plan. Democrat legislators Senator Alex Padilla and Representative Joe Morelle have since publicly called on the administration to restore that funding before the midterms.

election security CISA critical infrastructure government cybersecurity United States

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.