CISA Appoints Regional Directors as Election Security Advisers Amid Unutilized EI-ISAC Funds
In a significant move to bolster election security in the United States, the Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a comprehensive election security plan, even as it faces ongoing budgetary cuts and mounting political pressure. This announcement comes only weeks ahead of the crucial midterm elections scheduled for November 3, 2026.
On September 24, CISA published its 2026 election infrastructure security initiative, highlighting a variety of voluntary cybersecurity and physical security services available for state and local election offices. The urgency of this plan is underscored by lawmakers’ concerns that CISA has not yet deployed approximately $40 million allocated by Congress earlier this year for an election threat-sharing hub. Such a hub would facilitate better intelligence sharing regarding election vulnerabilities between federal and state entities.
Homeland Security Secretary Markwayne Mullin emphasized the necessity of this plan during its introduction in July. In his statement, he indicated that CISA is recommitting itself to its primary mission: the protection of critical infrastructure across the nation. The plan, titled "Securing the Next 250," designates CISA’s ten regional directors as election security advisers, while the agency’s field-based cybersecurity and protective security experts are designated to conduct on-site cyber assessments and physical security reviews. This multifaceted approach aims to enhance the readiness and resilience of election systems nationwide.
Congress took a proactive stance in its fiscal 2026 spending package by mandating that CISA continue funding election security advisers across its regions. In May, Senator Mark Warner (D-Va.) raised alarms over budget proposals for fiscal 2027, which could potentially eliminate funding for 14 election security employees at CISA, alongside crucial initiatives designed to facilitate information-sharing for state officials and support for election security advisers.
Senator Warner previously articulated that states are often ill-equipped to independently procure the necessary intelligence and real-time incident reporting required to safeguard elections from both physical and cyber threats. The complexity and scale of these challenges demand coordinated responses that exceed the capabilities of individual state entities.
In a bid to enhance collaboration and information-sharing, the newly unveiled plan proposes a complimentary platform linking fusion centers and election offices with federal partners. This platform builds upon a model CISA successfully implemented during the FIFA World Cup earlier this year. It also encourages state election officials to utilize CISA’s services for scanning internet-facing systems and web applications, as well as employing penetration testing, intrusion detection decoys, and tabletop exercises to better prepare against potential threats.
Furthermore, the plan systematically addresses various potential risks, including attacks targeting voter registration databases, insider threats, and physical dangers to election workers and polling locations. It reinforces the importance of established protocols, such as two-person ballot handling teams and poll observers, in mitigating insider risks and urges election offices to formally incorporate these practices into their insider threat programs.
Additionally, the blueprint integrates findings from a retrospective report on election system testing conducted from 2019 through 2024. This report, made public in July, received bipartisan accolades for its actionable recommendations, which include suggestions to synchronize voting system patch management with existing certification rules.
The findings of research conducted on the global election cycle in 2024 highlight an alarming trend. Adversaries appear to maintain persistent access to election networks, rather than merely launching attacks around Election Day. This underscores the need for concerted efforts in cybersecurity that extend beyond merely preparing for high-profile voting days.
Notably, this proactive approach marks a marked shift from the previous year when CISA halted all activities connected to election security amid an internal review and suspended federal funding for the Elections Infrastructure Information Sharing and Analysis Center. This prior pause raised red flags among lawmakers concerned about election integrity and security.
CISA’s involvement in election-related matters has been a politically charged subject since the contentious events surrounding the 2020 elections. The agency’s former director, Chris Krebs, was famously dismissed by then-President Trump after he publicly stated that the 2020 election was among the most secure in U.S. history.
With the 2026 elections approaching, the newly established security measures by CISA signal a renewed commitment to safeguarding the nation’s electoral processes in an era marked by digital vulnerabilities and political scrutiny. As the agency prepares to implement its planned services and resources, both state and local election officials are urged to engage actively with these initiatives to ensure secure, fair, and trustworthy elections in the coming months.

