Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Election Security topic
No spam. Unsubscribe anytime.
Secretary of State warns CISA review could disrupt federal election-security services
Summary
Secretary of State Steve Simon told the Senate Elections Committee on Feb. 27 that recent personnel moves and a contract termination at CISA could put election-security services used by Minnesota at risk. He urged preservation of specific services while a March 6 review is completed.
Get email alerts on the Election Security topic
No spam. Unsubscribe anytime.
Steve Simon, Minnesota secretary of state, told the Senate Elections Committee on Feb. 27 that a Department of Homeland Security review of election-related services at the Cybersecurity and Infrastructure Security Agency, and a recent termination of the EI‑ISAC contract with the Center for Internet Security, could reduce federal supports Minnesota relies on to protect elections.
Simon, who testified first at the committee’s hearing, said the services in question include cybersecurity monitoring and response, physical-security assessments for county and local election offices, device-level protections such as endpoint detection and response (EDR), and an elections-focused information‑sharing operation known as the EI‑ISAC. “We don’t know what comes next,” Simon said. “They have terminated that contract and they are conducting a review. We will know a lot more after March 6.”
Why it matters: Minnesota election officials and counties use the federal services Simon described for threat intelligence, incident response and voluntary security assessments. If those services are reduced or withdrawn, Minnesota officials told the committee, counties may face higher costs for private consultants and could lose access to classified briefings and coordinated federal threat information that federal agencies provide to CISA.
Simon outlined the federal support that grew after 2016, when the U.S. Senate Intelligence Committee reported “Russian government‑affiliated cyber actors conducted an unprecedented level of activity against state election infrastructure.” He said DHS designated election systems as critical infrastructure, CISA was later created and that CISA-funded services have been provided at no cost to state and local election offices. “These services do not just support the state, but support local election offices as well,” Simon said.
Simon and his staff described specific resources that may be affected: a national elections information‑sharing center (EI‑ISAC) operated by the nonprofit Center for Internet Security under contract with the federal government; a 24/7 security operations capability that provides threat detection and reporting; technical tools such as malicious‑domain blocking and endpoint detection; physical‑security assessments and trainings; and short‑term incident response support in the event of a cyber or physical incident.
Committee members pressed officials on likely impacts. Senator Kirsten Bolden asked whether a reduction in services would make election workers less safe; Simon responded that a “potentially serious impact” could result, particularly if physical‑security consulting is reduced. Bill Ekblad, the secretary of state’s security navigator, said federal partners have “a monopoly” on some threat intelligence and that private vendors can’t connect classified threat information the way federal agencies can.
Committee members with technical backgrounds asked about the security of vote‑tabulation uploads and equipment. Larry Olsen, chief information security officer for the secretary of state, described an annual risk and vulnerability assessment that includes an off‑site week and an on‑site week of testing; he said Minnesota had moved toward red team/blue team exercises. Ekblad and Olsen both urged discretion during the public hearing about operational details, saying the committee should not publicly describe operational defenses.
Simon cited incidents that underline the role of federal coordination: Minnesota and other states received threatening mailings containing white powder in late September 2024 that triggered evacuations and FBI testing; some states experienced swatting and DDoS attacks; other states faced doctored videos intended to undermine confidence in results. Simon said CISA’s ability to coordinate a whole‑of‑government response and to provide classified briefings is part of its added value.
What officials said they know now: Simon told the committee that CISA has placed election‑sector personnel on administrative leave, ended its contract with the Center for Internet Security (the EI‑ISAC operator) and is conducting an internal evaluation with a report due on or near March 6. “Our letter of secretaries of state is focused on the services,” Simon said, describing a bipartisan letter from the National Association of Secretaries of State asking DHS leadership to preserve the services.
Next steps and requests: Committee members and Simon agreed to follow up after the March 6 report. Simon offered technical staff — Bill Ekblad and Larry Olsen — as follow‑up contacts for more detailed questions. Several senators signaled concern and asked the secretary to return when more information is available.
Ending: No formal committee action was taken at the hearing; members moved on to other bills after questioning. The committee will have the secretary and his technical staff available for follow‑up briefings after the federal review is complete.

