BlackTree Security · Infrastructure · Automation · AI

When Election Certification Gets in the Way of a Security Patch

Certification is supposed to establish trust in election technology. CISA now warns that the same process can make a security update harder to release and slower to install.

The agency’s new 2026 Election Infrastructure Security Plan says structural constraints in certification can limit a vendor’s ability to issue patches and prevent system owners from applying them quickly. That turns a familiar patch-management problem into a governance problem: changing the certified system may reduce one security risk while creating compliance or operational uncertainty.

A passed test is not permanent evidence of safety

CISA’s plan calls for patch management and certification requirements to be aligned so security updates can be applied in real time without invalidating certification. It also asks vendors to disclose vulnerabilities and patch status consistently, obtain CVE identifiers, report incidents and provide a software bill of materials with every product.

The recommendation recognises a basic limit of assurance. Certification evaluates a defined product, configuration and point in time. New vulnerabilities, leaked source code and changes in attacker capability arrive afterwards. If the process treats every security update as a threat to certification, the trusted baseline can become an obstacle to removing a known flaw.

Enterprise compromise can become election compromise

CISA says election infrastructure is often reachable from ordinary enterprise networks. An attacker who compromises email, a workstation or an administrative account may be able to move laterally towards registration, reporting or support systems even when the voting equipment itself is not directly exposed to the internet.

The agency says its assessments show that state, local, tribal and territorial election offices frequently struggle with basic cyber hygiene and vulnerability remediation. It highlights outdated certification regimes, inconsistent vendor transparency and uneven security maturity in the networks that host election functions.

Voter registration remains a high-value target

The plan says hackers have attempted to breach voter-registration systems in all 50 states and succeeded in at least 20. This is a historical risk statement, not evidence that an attacker has altered the 2026 vote.

CISA recommends multi-factor authentication, least privilege, anomaly detection, at least one year of critical log retention and separation between public registration or lookup services and the master database. The defensive objective is resilience as well as prevention: an office should be able to detect an unauthorised change, reconstruct it and recover a trusted record.

Paper provides an independent evidence path

The plan recommends paper ballots and manual post-election audits. This is not an argument that paper cannot be mishandled. It is an architectural response to digital uncertainty. A voter-verifiable physical record gives officials an evidence source that does not depend on the same software stack used to cast, tabulate or report results.

Formal chain-of-custody and bipartisan two-person procedures also address insider risk. CISA’s definition spans permanent staff, temporary workers, volunteers, contractors and vendors. Careless insiders may introduce removable media or fall for phishing, while malicious insiders may attempt unauthorised changes to registration, ballot definitions, tabulation or reporting.

Free services only help if offices can use them

CISA’s plan lists voluntary, no-cost support including vulnerability scanning, web-application scanning, risk and vulnerability assessments, continuous penetration testing, exercises, information sharing and defensive decoys. The agency also identifies its ten regional directors as election-security advisers for the 2026 cycle.

What authorities and suppliers should do

  • Define an emergency patch route before the next vulnerability. Assign who can approve, test, document and deploy a security update without losing the assurance that certification was meant to provide.
  • Separate public services from authoritative records. Registration and lookup portals should not provide a direct path to the master database.
  • Retain evidence for at least a year. Protect identity, administrative, database and network logs from the same accounts that operate the system.
  • Demand vendor transparency. Contracts should require vulnerability disclosure, fixed-version guidance, incident reporting, component inventories and support timelines.
  • Test the paper trail. Manual audit procedures, chain of custody and reconciliation must work under realistic staffing and time pressure.
  • Treat ordinary office IT as part of election security. Email, endpoints, remote support and identity infrastructure can become the first stage of a lateral movement path.

BlackTree recently analysed CISA’s guidance on cyber decoys and canary tokens. Those controls can improve detection, but they do not replace patching, segmentation, independent records or a tested recovery process.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *