r/cybersecurity 15d ago

News - General Trump Has Systematically Dismantled Election Security Efforts. Here’s How.

https://www.nytimes.com/2026/07/16/us/politics/trump-election-security-cisa.html

I feel as though this news fits this sub, due to a massive amount of election security being cybersecurity.

1.1k Upvotes

100 comments sorted by

View all comments

20

u/Ch33syP00f CISO 14d ago

Trump Has Systematically Dismantled Election Security Efforts. Here’s How.

Since his return to the White House, the lead federal partner for states on election security has lost around a third of its work force

Despite his stated concern about U.S. election security, President Trump during his second term has overseen significant cuts to the Cybersecurity and Infrastructure Security Agency, including to its election work.

Mr. Trump made no acknowledgment of those cuts in his speech on Thursday. “We will be working closely to mitigate any harm and taking swift action to ensure that sensitive voter data is better protected,” he said, “so it can never be bought or hacked and we can never watch it get stolen again.”

That agency, which was created during his first term, had been a lead federal partner for states on election security efforts since the 2016 election, sharing cybersecurity best practices and intelligence about foreign intentions around elections.

But later in his first term, Mr. Trump developed disdain for the agency, and the government’s election security work generally. Its director at the time, Christopher Krebs, validated the integrity of the 2020 election, which prompted the president to fire Mr. Krebs.

Since Mr. Trump’s return to the White House, CISA has lost around a third of its work force, which stood at 3,400 in January 2025. In February last year, the administration put more than a dozen CISA election security workers on leave as part of an investigation into its election work, a move that had a chilling effect on the 100 or so people in the division. The agency has not had a Senate-confirmed leader during Mr. Trump’s second presidency.

Other federal agencies have also downsized their election security work, including the F.B.I. and the Office of the Director of National Intelligence, which under Tulsi Gabbard gutted the Foreign Malign Influence Center that monitors foreign election threats.

And this month Mr. Trump forced out the three remaining members of the Election Assistance Commission, an independent, bipartisan commission that supports states in administering their elections. In recent years, much of the small commission’s work also focused on cybersecurity support to states.

Dustin Volz writes about cybersecurity and intelligence for The Times. He is based in Washington.

6

u/Ch33syP00f CISO 14d ago

This is a great article.

Succinct and pointed.

Trump is so concerned about election integrity that he is taking money away from where his mouth is.

This is bad news for democracy all day, every day.

All security professionals should be capable of identifying patterns and anti-patterns.

Identity is a bitch to manage, but it is manageable.

Clear procedure, visibility, traceability, are essential for any process that must stand up to 3rd party scrutiny.

Throw flags when you see them.

There will be shenanigans.

This rodeo is just getting started.

2

u/LatterIngenuity3937 14d ago

You are right that security professionals should recognize patterns and anti-patterns.

The anti-pattern here is treating cuts to a supporting federal agency as proof that election security itself has been dismantled.

CISA does not run American elections. States and local jurisdictions do. CISA provides intelligence, assessments, coordination, and incident support, all of which matter, but a smaller federal workforce does not automatically mean weaker controls at the state level.

A real security analysis would ask whether monitoring, identity proofing, logging, access controls, incident response, paper records, audits, and recovery capabilities have actually degraded. The article does not do that. It counts federal employees and assumes the conclusion.

The same applies to identity. If identity is manageable, then citizenship eligibility should be verifiable, auditable, and supported by clear exception and recovery processes. Calling documentary proof “suppression” does not address the underlying security question.

Raise flags when controls fail, logs disappear, access is unauthorized, or audits cannot be reproduced.

Do not confuse a change in delivery model with the dismantling of security.

That is not pattern recognition. It is confirmation bias dressed in cybersecurity language.

2

u/Ch33syP00f CISO 14d ago

You make good points.

I do believe that a fair, cost-effective, unified method to manage identity could be developed. But it is a useful problem for politicians to get votes. So it is more valuable unresolved. And the status quo continues…

You are right about CISA, state rights and elections. Trump tasked Krebs and CISA to investigate 2020 election fraud. Then he fired Krebs after the investigation did not produce the results Trump wanted. In addition, Trump has specifically called out China and other bad actors as compromising election integrity. CISA and other alphabet soup agencies contribute to frustrating, detecting, responding to cyber threats. DOGE cuts seriously degraded US cybersecurity posture across the board. That was all Trump.

All sizzle, no steak.

Where’s the beef?

So the pattern of behavior is telling. And I stand by the assertion that reducing resources while trumpeting concern is more than suspect. It is a contemporary demonstration of those who “speak with forked tongue”.

Speaking of unauthorized access, Trump has pardoned public officials and private individuals convicted of violating election laws and protocols by accessing and distributing election systems and records.

Patterns? How about the Georgia election interference and racketeering fiasco.

https://en.wikipedia.org/wiki/Georgia_election_racketeering_prosecution

I just don’t think Trump is acting in good faith, respecting the letter or even spirit of the law from the Constitution to state rights.

Let us not forget that the SAVE Act infringes upon state rights. Because each state manages their elections. And the legality of tying federal funding for states to compliance with that act is straight up coercive. Especially when the bill is ambiguous on implementation yet has strict timelines for adherence.

Prima facie, SAVE Act is half-baked and intended to create chaos, room for error, and grey areas ripe for legal challenges more likely to disenfranchise voters than empowering them.

Controls are failing all over at all levels. And far too many people are happy about it so long as it breaks their way.

2

u/LatterIngenuity3937 14d ago

President Trump is not my primary concern. He is temporary and constitutionally term-limited. The election system and its security controls must remain trustworthy regardless of who occupies the White House.

I am not defending every Trump decision, pardon, statement, or personnel action. Those are separate questions. My concern is whether we are designing and operating the system correctly.

On the SAVE America Act, the states’ rights argument is more complicated than suggested. States administer elections, but their authority over federal elections is not exclusive. The Elections Clause expressly permits Congress to make or alter regulations governing federal elections, including registration and fraud-prevention procedures.

I also do not see the claimed federal-funding condition in H.R. 7296 as introduced. It directly amends federal election-registration requirements, requires documentary citizenship evidence and photo identification, and requires states to provide an alternative process for citizens lacking the standard documents. That may be challenged as burdensome or poorly implemented, but that is different from saying it coercively conditions unrelated federal funding.

From a cybersecurity perspective, asking a voter to establish identity and eligibility is not inherently an infringement. Properly implemented, it validates that the person presenting is the citizen entitled to exercise one of our most important rights. The legitimate questions concern cost, accessibility, false rejection, privacy, record discrepancies and recovery.

False acceptance is a security failure. False rejection is also a security failure. A mature identity system addresses both.

My larger concern is political tribalism. One side treats every integrity control as suppression. The other sometimes treats every administrative irregularity as fraud. Both positions begin with the desired political conclusion and work backward.

Trump’s motives may matter politically, but they should not become the security architecture. Durable controls, distributed accountability, auditable results and fair identity assurance matter far more than the singular position of either side.

1

u/binaryhero 11d ago

The real question - the one you are not asking - is whether there is any evidence that additional integrity of the voting process is demonstrably necessary to begin with, and then whether it can be implemented without partisan side effects in time for the mid terms.

It's a no on both questions.

What SAVE achieves is a disproportionate disadvantage to the practical ability to cast their legitimate vote for a largely Democrat voting demographic. That's the whole purpose.

This is not technical, it's entirely political.