CISA warnings expose America’s election security gaps

CISA warnings expose America’s election security gaps

Picture a break-in where the burglars are the good guys.

From 2019 through 2024, federal cybersecurity teams were invited to probe election software and networks. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) conducted penetration tests and red-team operations against state and local networks, while CISA and the Idaho National Laboratory worked with election vendors to tear into election software.

Their mission was straightforward: Find the weak points before real adversaries could exploit them.

Newly released government documents — including a retrospective CISA report and declassified intelligence records — reveal both how vulnerable some election systems have been and how long the government has known about the threats.

The CISA report reveals that “in multiple cases, CISA assessors gained full network control within hours or days.” Many state and local partners, it warned, “remain soft targets incapable of stopping even moderately skilled adversaries.”

The break-ins were possible for a simple structural reason. Election systems that were supposed to be isolated often were not. Get into an ordinary government office network — the network carrying email and office applications — and in some cases, you could reach election systems.

Translation: The walls that everyone assumes separate election systems from ordinary office computers can be porous. CISA found election systems reachable from enterprise networks, with firewall gaps and supposedly “isolated” equipment quietly still connected.

Worse still, CISA says some election systems are “locked down” against changes for weeks or months before Election Day, and in some cases, those lockdown periods are mandated by state law.

Certification requirements can also delay security updates. CISA does not identify the states. But its warning is explicit: Some certification regimes “require that no patches be applied for months before an election.”

Read that again. In some jurisdictions, rules meant to protect election systems can prevent officials from fixing a known security hole during the very period an adversary has the greatest incentive to exploit it.

The result, according to CISA: “known, documented vulnerabilities persist for months or years” on production election systems.

Then there are the voting machines themselves, the third rail of election-denier politics — the Voldemort words that one dares not speak.

Read more at The Washington Times.

SHARE THIS: