Election offices operate complex, distributed systems involving hardware, software, vendors, temporary workers, and real-time decision-making under pressure. Any one of those elements, if compromised, can create downstream consequences for election administration and public trust. Securing elections means accounting for the full 360-degree view.
Earlier this year, in Palm Beach County, Florida, a long-time poll worker, who was training for the March primary, was arrested and charged with stealing computer equipment. After an electronic key to an e-pollbook kiosk was stolen, staff consulted the security video to identify a suspect. Though the key only provided access to a training database with no confidential data, the kiosk was taken out of service for that election.
In December 2024, the State of Texas decertified electronic pollbooks after a software issue in the 2024 General Election, forcing counties to adapt quickly for their elections in May 2025. No malice was required to create a significant operational problem. When certified equipment loses that status, or a software update introduces unexpected behavior, the consequences ripple out to offices that had no role in creating the problem.
These incidents offer a useful reminder: Election equipment security is not a single problem with a single solution.
In both cases, the system worked as intended. In Palm Beach, the alleged theft was detected because even items used for training were carefully inventoried and because the training was covered by security cameras. The office acted quickly to remove the suspect as a poll worker and reported the incident to law enforcement, leading to an arrest. The incident serves as a reminder that insider threats, whether opportunistic or premeditated, are a real risk. Temporary and seasonal team members, including poll workers, often have access to sensitive spaces and equipment, and the security risks must be managed through vetting and supervision.
In Texas, recognition of the incident and its cause led directly to decertification, again evidence of an election culture that values investigating and addressing errors. This incident also highlights the importance of knowing dependencies and building redundancy into election operations to mitigate the risk of downtime and inaccessibility.
The National Institute of Standards and Technology (NIST) approaches election security as a technical and operational systems problem. NIST focuses on security and usability standards for voting systems that address the full ecosystem (hardware, software, and human factors) rather than any single attack vector.
Key themes from NIST’s work include:
- System Integrity: Voting equipment should be verifiable, auditable, and resistant to both external attacks and internal manipulation.
- Software Assurance: Election technology should be developed and maintained with processes in place to detect and respond to failures.
- Supply Chain Risk: Election offices should understand where their equipment and software come from and what recertification or replacement processes exist if something goes wrong.
- Human Factors: Security is only as strong as the people implementing it. Training, access controls, thorough vetting, and clear procedures matter as much as the technology itself.
The demands of election administration make it easy to focus on the most visible threats. But resilience comes from building systems and cultures that are prepared for the full range of things that can go wrong.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.