Security of US Voting Systems
September 8, 2026
Topics
- cybersecurity
- voting
September 8, 2026
Topics
Voting is one of the most important parts of the democratic process in the United States. As technology has become more central to elections, voting systems now rely on computers, electronic voting machines, voter registration databases, election websites, electronic poll books, networks, and other digital systems. While these technologies can improve election administration and accessibility, they also introduce cybersecurity risks that election officials must address. Criminals can target election systems in a variety of ways. Instead of just trying to directly change votes, attackers could target voter registration databases, election websites, employee accounts, or networks used by election offices. A successful attack could interrupt election operations, expose sensitive information, or make the public lose confidence in the results. For this reason, securing voting systems is an important component of protecting the broader election infrastructure.
Election systems are attractive targets because they are connected to a large number of people and organizations. State and local governments are responsible for running elections, which means the technology and security practices can vary between jurisdictions. One major threat is phishing. Election employees can receive emails containing malicious links or attachments that are designed to steal login credentials or install malware. If an attacker gains access to an employee account, they could potentially use that access to move further into an organization’s network. Election websites can be targeted as well. A distributed denial-of-service (DDoS) attack can flood a website with traffic and prevent users from accessing it normally. Even if an attack does not change any votes, taking down an election website could prevent voters from finding important information like the polling locations, registration information, or election results.
Voting machines are one of the more obvious parts of election security, but protecting them involves more than installing cybersecurity software. Voting equipment needs to be protected against both cyber and physical threats. Election officials use measures such as locks, tamper-evident seals, security cameras, testing procedures, and physical access controls to help protect voting equipment. These protections are important because someone who gains unauthorized physical access to a machine or election facility could potentially create a security problem that would be difficult to detect through normal network monitoring.
Another important part of election security is protecting voter registration databases. These systems contain information that election officials need to determine voter eligibility and manage elections. An attacker who gains unauthorized access could attempt to modify information, steal data, or disrupt election operations. Attackers wouldn’t have to change the actual election results. Even disrupting voter registration information could create confusion for election workers and voters. To reduce these risks, election offices should use strong access controls and authentication along with network security, monitoring, and reliable backup procedures. Multi-factor authentication (MFA) is another important security measure. Instead of relying only on a password, MFA requires another form of verification before an account can be accessed.
Election offices also need to secure the networks that connect their computers and other systems. Network security can include firewalls, segmentation, endpoint protection, access controls, vulnerability management, logging, and continuous monitoring. Network segmentation can help contain an intrusion by limiting an attacker’s ability to move from a compromised computer to other systems. For example, an employee’s normal workstation should not automatically have unrestricted access to every system used by an election office.
Ransomware is another threat election offices have to prepare for. A ransomware attack could encrypt files or disrupt computers that election officials depend on for their daily operations. Even if attackers don’t change the votes, taking important systems offline during an election could create major operational problems. This is why backups and recovery plans are important. Election offices need to know what they will do if a computer, server, or network becomes unavailable. Backups should be isolated and protected from threats affecting the primary systems, and recovery procedures should be tested regularly to verify that the backups can be restored successfully.
Election cybersecurity depends on more than technology; employees and poll workers are also an important part of the security process. A highly secure system can still be compromised if someone accidentally gives an attacker their password, opens a malicious attachment, or connects an unauthorized device to a protected system. Election workers should receive cybersecurity training that covers phishing, password security, MFA, suspicious activity, physical security, and how to report potential incidents. Regular training is important because cyber threats change over time.
There is no single technology that can completely secure an election. Election security requires multiple layers working together. Voting machines need to be tested and protected, election networks need to be monitored, employee accounts need strong authentication, voter databases need access controls and backups, and election facilities need physical security. Additionally, audits and other verification procedures can be used to identify problems after votes are counted. Together, these safeguards provide multiple opportunities to prevent, detect, or identify problems within the election process. This layered approach is important because attackers do not always target the most obvious system. If a voting machine is heavily protected, an attacker may instead target an election employee’s email account or an election website. Protecting the entire infrastructure makes it harder for one compromised system to affect the larger election process.
The security of U.S. voting systems is a significant cybersecurity concern because elections depend on a combination of technology, people, networks, and physical infrastructure. Cybercriminals can target voting machines, voter registration systems, election websites, employee accounts, and networks in different ways. The goal of an attack does not always have to be changing votes. Disrupting election operations or creating uncertainty can also cause serious problems. Protecting elections requires a layered security strategy that includes strong authentication, network security, physical protections, employee training, system testing, backups, monitoring, and audits. Organizations such as CISA, NIST, and the EAC provide guidance and standards that help state and local election officials improve their security practices. As technology continues to play a larger role in elections, cybersecurity will remain an important part of protecting the voting process. The goal should be to make election systems as secure, resilient, and verifiable as possible so that technology strengthens the election process rather than becoming a weakness.
https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections
https://www.eac.gov/are-voting-systems-secure
https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines
https://www.eac.gov/voting-equipment/certified-voting-systems
https://www.nist.gov/itl/voting/election-security-guides
https://www.nist.gov/publications/cybersecurity-framework-election-infrastructure-profile
https://www.nist.gov/itl/voting/research-and-projects/election-security