Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

Head of US Cybersecurity Agency Sees Progress on Election Security, With More Work Needed for 2024

CISA Director Jen Easterly says more is needed to defend the integrity and resiliency of the election process ahead of the 2024 election.

CISA known exploited vulnerabilites

Efforts to protect the nation’s election systems have grown exponentially since the 2016 presidential election, but more is needed to defend the integrity and resiliency of the election process ahead of next year’s vote, the head of the nation’s cybersecurity agency said Tuesday.

Jen Easterly, director of the U.S. Cybersecurity and Infrastructure Security Agency, known as CISA, announced plans to boost resources within the agency, hiring 10 additional election security specialists who will be across the country to interact directly with state and local officials. Easterly made the announcement at the summer conference of the National Association of State Election Directors in Charleston, South Carolina.

“Our capabilities and posture in this area is simply night and day when you compare it to 2016,” Easterly told the officials gathered for her speech. “Despite this progress, we know there is more we have to do and that we must remain vigilant in the face of new and evolving risk.”

CISA is charged with protecting critical infrastructure, including the nation’s dams, banks and nuclear power plants. U.S. voting systems were added after the 2016 election and Russia’s multipronged effort to meddle.

Since then, state and local election officials have been working to shore up cybersecurity defenses around U.S. voting systems with the help of millions of dollars allocated by Congress over the years. In its efforts to secure elections, CISA works across government, partnering with federal, state and local agencies on various initiatives and providing direct support through cybersecurity reviews, assessments of physical security protocols, remote testing to look for vulnerabilities and other services.

Meanwhile, the threats to elections keep increasing, with the newest concern centered on the emergence of generative artificial intelligence tools that can be used by those seeking to meddle in U.S. elections to create false and misleading content. That’s on top of financially motivated, criminal ransomware groups and the potential for sophisticated cyberattacks waged by countries hostile to the U.S.

Easterly, in an interview after her speech, said she was particularly concerned about the potential for bad actors to utilize generative AI, but expressed confidence that the public, with guidance from their state and local election officials, will be able to sort through manipulation attempts. She emphasized that the vote itself will be protected and secure.

“All of the reasons why people should trust the integrity and security of elections remain the same: the physical security safeguards, the cybersecurity safeguards, all of the defense-in-depth mechanisms, the segmentation, the training that goes on,” Easterly said. “Nothing will change all these safeguards and measures that are put in place to ensure the integrity and resilience of elections.”

Advertisement. Scroll to continue reading.

Since then, state and local election officials have been working to shore up cybersecurity defenses around U.S. voting systems with the help of millions of dollars allocated by Congress over the years. In its efforts to secure elections, CISA works across government, partnering with federal, state and local agencies on various initiatives and providing direct support through cybersecurity reviews, assessments of physical security protocols, remote testing to look for vulnerabilities and other services.

Meanwhile, the threats to elections keep increasing, with the newest concern centered on the emergence of generative artificial intelligence tools that can be used by those seeking to meddle in U.S. elections to create false and misleading content. That’s on top of financially motivated, criminal ransomware groups and the potential for sophisticated cyberattacks waged by countries hostile to the U.S.

Easterly, in an interview after her speech, said she was particularly concerned about the potential for bad actors to utilize generative AI, but expressed confidence that the public, with guidance from their state and local election officials, will be able to sort through manipulation attempts. She emphasized that the vote itself will be protected and secure.

“All of the reasons why people should trust the integrity and security of elections remain the same: the physical security safeguards, the cybersecurity safeguards, all of the defense-in-depth mechanisms, the segmentation, the training that goes on,” Easterly said. “Nothing will change all these safeguards and measures that are put in place to ensure the integrity and resilience of elections.”

After Easterly’s speech, state election officials from Pennsylvania and Ohio said they welcomed the additional resources focused on election security and spoke about the importance of having good relationships with the federal government.

“The relationship needs to evolve and grow because our threat evolves and grows,” said Mandi Grandjean, senior adviser and deputy assistant to Ohio Secretary of State Frank LaRose, a Republican. “And the general landscape of what we do is evolving and growing. And so it’s great to hear what CISA is doing.”

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Searchlight Cyber has appointed Tim Warner as VP of Global Enterprise Sales.

Morgan M. Adamski has been named the Executive Director of USCYBERCOM.

Passwordless authentication firm Hawcx has appointed Lakshmi Sharma as Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Cyberwarfare

US National Cybersecurity Strategy pushes regulation, aggressive 'hack-back' operations.

Government

Companies have announced securing billions of dollars in cybersecurity-related contracts with the United States government in 2022.

Funding/M&A

Private equity giant plans to buy Forcepoint’s Global Governments and Critical Infrastructure (G2CI) business unit for $2.5 billion.

Government

NIST releases Cybersecurity Framework 2.0, the first major update since the creation of the CSF a decade ago.

Cloud Security

Redmond is accused of “negligent cybersecurity practices” that enabled a successful Chinese hack of the United States government.

Government

CISA has described and published a set of principles for the development of security-by-design and security-by-default cybersecurity products.

Government

The proposed UK Online Safety Bill is the enactment of two long held government desires: the removal of harmful internet content, and visibility into...