The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials.
The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.
CISA also designated its 10 regional directors as Election Security Advisors responsible for connecting state and local officials with federal cybersecurity resources. The plan comes after staffing and program reductions affected CISA’s election security operations, with some state election officials raising concerns about reduced federal support ahead of the midterms.
Ted Miracco, CEO, Approov:
“CISA’s new 2026 Election Infrastructure Security Plan is right to insist on paper ballots and hand audits. But it never once mentions mobile devices, apps or APIs, which is a strange gap given how much of American voting now runs through them.
“Most US jurisdictions check voters in on electronic poll books, and the most widely used one runs on Apple iPads. Forty-two states and D.C. let people register online, and millions of voters track their mail ballots by text message.
“Bangladesh, which went to the polls in February, took a clearer-eyed approach. Its Election Commission built a mobile app that registered more than 450,000 overseas voters and let them follow their ballots. Then it had every one of them mark a paper ballot and mail it home. The same commission had already scrapped electronic voting machines for all future elections. That is the right design: phones for access and tracking, paper for the vote itself, and serious security for the digital layer in between. Nobody can hack a paper ballot from abroad. They can hijack the phone number that gets a county clerk into the voter rolls. America already has the paper half. What it lacks is a federal plan that treats the phone in a voter’s pocket, and in an election official’s hand, as election infrastructure. While the ballot itself can stay analogue, the threat model cannot.”
Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security:
“My firsthand work as an offensive security tester has taught me that election security extends beyond voting equipment to the people, infrastructure, vendors, and processes supporting elections. A plan or scan is a starting point; the safeguards need to be tested in practice.”
Cyber and physical threats are clearly present when it comes to the midterms. And I am glad that someone is securing them from being tampered with. I hope that true with any threat that comes along.



Edinburgh Napier and Approov team up on smartphone security innovation
Posted in Commentary with tags Approov on September 25, 2026 by itnerdA new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security.
The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK.
Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as ‘blue team’ and ‘red team’.
The project, which received the highest rating in Innovate UK’s assessment for this funding round, will involve the ENU-hosted Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology.
It builds on Edinburgh Napier’s strong record in cyber security and digital trust technology. It has been recognised by the UK’s National Cyber Security Centre and Department for Science, Innovation and Technology (DSIT) as an Academic Centre of Excellence in Cyber Security Education (ACE-CSE) – and was the starting point for several successful cybersecurity spin out companies.
Background:
Edinburg Napier holds early accreditation from the National Cyber Security Centre (NCSC), is recognized as a leader in cyber skills and training. It’s globally ranked in Computer Science and Electrical and Electronic Engineering by U.S. News & World Report, and the UK’s Research Excellence Framework (REF) ranked Edinburgh Napier as the top modern university in Scotland for both research power and research impact, with nearly 70% of evaluated research deemed world-leading or internationally excellent.
Leave a comment »