Think of the US voting system as a submarine built out of watertight compartments. Roughly 8,000 independent jurisdictions, different vendors, different procedures, no single point of failure by design. Flood one compartment and the boat still floats. That architecture is the reason “can someone deface a website” and “can an attacker silently change who wins” are two completely different questions, and most election-security coverage treats them as the same one. This post keeps them separate. The hull, as we’ll get into, is sound. What’s changed is how many people are watching the sonar.
Can attackers actually flip an outcome?
Start with the acknowledgment that the threat is real, not hypothetical. Gen. Joshua Rudd, head of US Cyber Command and the NSA, told the Senate Armed Services Committee in April 2026 that it’s reasonable to expect foreign adversaries will attempt interference in the midterms, based on past behavior. The Brennan Center’s assessment goes further, naming China, Iran, and Russia as poised to attempt influence operations, now armed with more capable AI tooling than in prior cycles, and this isn’t theoretical: in 2024, more than 100 bomb threats tied to Russian-linked actors targeted polling places. CISA and the EI-ISAC used intelligence sharing and a real-time operations center to warn officials in advance, which is a large part of why that campaign didn’t do much damage. That’s documented by CDT, and it’s worth sitting with, because it’s proof the coordination layer itself was doing load-bearing work.
Now the part that should calm practitioners down a little: the structural defenses are genuinely strong. Roughly 99% of 2026 voters will cast ballots with a voter-verifiable paper trail, every state runs post-election audits, and federal law requires 22 months of retention on ballots and election materials, per the Bipartisan Policy Center. Layer three things together and the picture gets clearer:
- Decentralization. Thousands of jurisdictions running different equipment means silently flipping a national outcome requires compromising many independent systems at once, not one central database.
- Paper. No internet voting, no paperless machines at scale. An attacker has to beat a physical record, not just a log file.
- Risk-limiting audits. RLAs hand-count a statistical sample of paper ballots to bound the odds that a wrong reported result goes undetected. The Brennan Center calls this the gold standard, and the ACM Technology Policy Council backs that up, noting RLAs are accurate, efficient, and economical, with the caveat that they only work if you have paper ballots to sample.
My read, stated as my own analytical call: direct, undetected vote manipulation at outcome-changing scale remains very unlikely anywhere paper and audits exist. The math doesn’t favor the attacker. Where I’d actually spend my worry budget is upstream and downstream of the ballot itself, meaning voter registration databases, e-pollbooks, election-night reporting websites, and public trust. An attacker doesn’t need to touch a single vote if they can convincingly claim they did. A 2025 intrusion that briefly defaced Arizona’s candidate portal touched zero votes and still generated exactly the kind of headline that fuels a perception attack, per Hoodline’s reporting citing Arizona PBS. That’s the actual attack surface in 2026: not the ballot box, the narrative around it.
The federal posture since January 2025
Lay out the administration’s own framing first, since that’s the fairest starting point. The White House told the New York Times in March 2026 that it is “laser-focused” on election safety and security. Then-DHS Secretary Kristi Noem told RSAC in April 2025 the goal was to “put CISA back on mission,” arguing the agency had drifted into work beyond its original charter, a position she also took at her confirmation hearing. She also publicly endorsed continuing the secure-by-design initiative started under the prior administration, a continuity point worth noting alongside the cuts. Acting CISA Executive Director Bridget Bean’s February 14, 2025 memo paused election security work pending an internal review meant to rescope the agency around cyber and physical security, according to CDT and CBS. The White House’s FY26 budget language framed the changes as refocusing CISA on federal network defense and critical infrastructure resilience while eliminating what it called weaponization and waste, per Democracy Docket, and CISA’s stated rationale for the ISAC cuts specifically was roughly $10M in annual savings from eliminating duplicated work, per CBS. Context matters here too: this follows sustained conservative criticism of CISA’s mis/disinformation work under the prior administration, and a January 20, 2025 directive to review activities inconsistent with ending what the administration termed online censorship.
Now the documented actions, dated, without editorializing on intent. In February 2025, 17 CISA election-security employees went on administrative leave and election security work paused pending review. In March 2025, roughly $10M was cut from two cybersecurity initiatives, including one dedicated to state and local election officials; EI-ISAC federal funding was terminated because it “no longer supports Department priorities,” per a CISA letter; MS-ISAC funding was heavily reduced; and the FBI disbanded its foreign influence task force, per reporting via Yahoo and Governing. Over the course of 2025, CISA’s staffing fell from roughly 3,400 to roughly 2,500, about a third of the workforce, and the FY26 budget request came in around $2.4B against the prior administration’s roughly $3B FY25 ask. ODNI’s Foreign Malign Influence Center was eliminated, leaving no designated official coordinating election threat response for a stretch, per a Small Wars Journal hearing summary. In March 2026, the intelligence community’s annual threat assessment omitted foreign threats to US elections for the first time in nearly a decade, according to Nextgov. By April 2026, the joint NSA/CyberCom Election Security Group, which normally would already be activated and briefing Congress by this point in a cycle, had not been stood up; Gen. Rudd told senators he’d follow up, and the NSA said separately it had identified an election lead supporting ODNI’s broader effort, per CNN. During November 2025 bomb threats at New Jersey polling places, CISA issued no public guidance and didn’t activate its real-time ops center, a sharp contrast with the 2024 response. Arizona’s Secretary of State told reporters his office stopped leaning on CISA after the 2025 portal defacement because the agency had become uncommunicative. The FY27 budget proposal floated in April 2026, meanwhile, would cut fourteen more CISA election security positions and the associated program budget, including the state information-sharing program and election security advisors, per a Warner letter, though as of that reporting it remained a proposal, not enacted policy.
This isn’t purely an executive-branch story either. The Cybersecurity Information Sharing Act of 2015, the legal foundation for private-sector threat-indicator sharing with CISA and a mechanism election vendors rely on, lapsed on September 30, 2025 during congressional negotiations, with Sen. Rand Paul’s proposed amendments cited as a sticking point, and has since only been reauthorized in short-term increments, currently running through September 30, 2026, per CDT. CISA’s leadership has also sat vacant: Sean Plankey’s nomination as director stalled in the Senate, a shared-branches problem rather than a unilateral executive action.
Named observers have weighed in with their own assessments, worth flagging as exactly that: assessments, not facts in themselves. Sen. Mark Warner (D-VA), Senate Intel vice chair, says the cuts could leave states more exposed, and points to states reporting reduced training, intel sharing, and assistance compared to prior cycles, per Defense One. Nearly 40 chief election officials, under bipartisan NASS leadership, wrote DHS urging that CISA services to states be maintained, calling them a priority defense against nation-state and cybercriminal threats. Maine Secretary of State Shenna Bellows said the federal pullback removed services state and local officials had relied on. The Brennan Center called the threat-assessment omission a significant vulnerability heading into the midterms. Rep. Lauren Underwood (D-IL), for her part, questioned in House appropriations whether eliminating election security support squares with a stated refocus on critical infrastructure.
Put the two halves next to each other and the honest summary is this: the administration frames its actions as a mission refocus and an elimination of disinformation-policing functions it considers outside CISA’s lane. Critics, including bipartisan state election officials, say the cuts also removed core cyber-defense services, threat intel, vulnerability scanning, incident response, that have nothing to do with content moderation. Both sets of claims are documentable. Whether the stated rationale matches the observed scope of the reductions is something readers can weigh for themselves.
What would actually move the needle
Five things, all technically concrete, all deliberately administration-agnostic since most have drawn bipartisan support at one point or another:
- Close the paper gap and mandate RLAs everywhere. Risk-limiting audits make silent vote-flipping statistically detectable regardless of what happens upstream, a detection control compensating for imperfect prevention, the same philosophy as running a SOC. This requires voter-verifiable paper; internet and paperless voting need to stay off the table, a point on which the ACM, Brennan Center, and Verified Voting all agree. Congress already has draft legislation for RLA technical assistance and grants sitting in committee, per Congress.gov’s CRS summary.
- Stabilize the information-sharing layer. Permanent, not stopgap, reauthorization of the 2015 info-sharing law, plus restoring or replacing EI-ISAC-equivalent threat sharing in whatever funding structure actually sticks, federal, state-consortium, or hybrid. States are already improvising through fusion centers, private vendors, and informal interstate relationships. Formalize what’s already working instead of leaving it ad hoc.
- Reconstitute cycle-standard coordination. Stand up the Election Security Group every cycle as a matter of routine rather than a discretionary call, and restore election threats to the annual public threat assessment so state officials and voters have a shared baseline to work from.
- Harden the actual attack surface. Voter registration databases, e-pollbooks, and election-night reporting sites: MFA, offline backups, DDoS protection, tested incident response. This is where an attacker gets the most disruption per unit of effort, and it’s boring, unglamorous infrastructure work that doesn’t make headlines until it fails.
- Pre-bunk the trust attack. Transparent audits, public observation, fast official communication. Perception manipulation is the exploit with no patch. The mitigation is a verifiable process paired with credible, quick comms before a false narrative sets.
Where this lands
Three questions, three answers. Can attackers flip an outcome? Not silently, not at scale, not anywhere paper and audits exist, though registration systems, reporting infrastructure, and public trust remain live targets. What has the federal defensive layer done since January 2025? Contracted substantially, by the administration’s own account a refocus, by state officials’ account a loss of core services, with the staffing, funding, and coordination reductions themselves not in dispute even as their interpretation is. What would actually help? Paper plus RLAs, stable information sharing, and hardened registration and reporting systems: technical, cheap relative to the stakes, and historically bipartisan.
The hull is sound. The compartments hold. The open question for November isn’t whether the boat can take a hit. It’s how much sonar coverage the crew still has when something pings.
Sources
- The Record, “Cyber Command, NSA chief warns foreign adversaries likely to target midterms” (April 2026)
- Brennan Center for Justice, “The Threat of Foreign Influence in US Elections Remains as Federal Defenses Recede”
- Center for Democracy & Technology, “Countdown to the Midterms: Mapping the Rapid Evolution of Election Security”
- Bipartisan Policy Center, “United in Security: How Every State Protects Your Vote (2026)”
- Brennan Center for Justice, “Post-Election Audits”
- ACM Technology Policy Council brief via Homeland Security News Wire, “Risk-Limiting Audits: Efficient Means of Confirming Accuracy of Election Results”
- Hoodline (citing Arizona PBS), “Trump Takes Ax to Election Cyber Cops as Washington Sweats 2026 Midterms”
- Sen. Mark Warner press release, quoting New York Times reporting, “Ahead of Midterm Elections, Warner Presses DHS on Reports That CISA Is Failing to Provide Election Security Support”
- Cybersecurity Dive, “DHS Secretary Vows to Refocus CISA, Saying It Strayed from Mission” (April 2025)
- Center for Democracy & Technology, “With Outcome of CISA Election Security Review Looming, Agency Must Protect Critical Infrastructure”
- CBS News, “Trump Administration Firings Threaten Election Systems” (February 2025)
- Democracy Docket, “Trump Administration Proposes More Drastic Election Security Cuts”
- CBS News, “Trump Election Security: CISA, Justice Department, FBI Federal Worker Cuts”
- Yahoo News (AP), “Big Changes at the Agency Charged with Securing US Elections”
- Governing, “The Feds Cut Funding for Election Cybersecurity. How Will Public Officials Adapt?”
- Small Wars Journal, “2026 Worldwide Threats Hearing” summary
- Nextgov, “Annual Intelligence Assessment Doesn’t Address Foreign Threats to US Elections” (March 2026)
- CNN, “US Cyber Team Hasn’t Been Activated Yet to Protect Midterm Elections from Foreign Meddling” (April 2026)
- Defense One, “CISA Election Security Vulnerable” (May 2026)
- Congress.gov, Congressional Research Service In Focus, “Risk-Limiting Audits”
Additional facts (17 CISA employees on leave, NASS letter, Maine SOS Shenna Bellows, Sean Plankey’s stalled nomination, the 2015 information-sharing law’s lapse and short-term reauthorizations) are drawn from CBS News and CDT reporting cited above; where a single outlet covered multiple data points, it’s linked once rather than repeated.
This post is based entirely on publicly available reporting as of July 2026. No internal or non-public information has been used.