The countdown to readiness starts now! Learn how a testing error built trust, check out suggested testing guides, and plan your security timeline for the final two months. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
ESX News Header

September 2, 2026

TLP:CLEAR

In This Issue:

  • Situation Room: A Florida county turned a routine public testing error into a demonstration of safeguards working as intended.  
  • Resource Library: Featured testing guides can help validate your hardware, software, and workflows before voting starts. 
  • Planning Desk: Take time now to schedule pre-election security tasks for the final weeks leading up to Election Day. 
Header text: Situation Room

Turning a Failed Logic and Accuracy Test Into an Opportunity to Build Trust

 

Ahead of Florida's recent August primary, Lee County election officials, IT staff, and the canvassing board conducted standard public logic and accuracy testing on vote-by-mail scanners, early voting equipment, and election day tabulators.

 

During the process, a single piece of equipment exhibited an operational error. Newly appointed Supervisor of Elections Jenna Persons-Mulicka, working her first election in this role, confirmed to WINK News that the malfunctioning unit was promptly removed from service and would not be used in the election.

 

While logic and accuracy testing is a mandatory compliance procedure, its routine nature should not obscure its significance. It is easy to turn on autopilot: publishing notices, hosting observers, running test decks, and completing forms. However, Lee County’s transparent identification and immediate resolution of an equipment error ultimately reinforced public trust, possibly more effectively than a flawless execution would have.

 

As Persons-Mulicka noted, “The test worked as intended. That is why we test our equipment because we want to make sure they're operational and that they produce accurate results.”

 

Best Practices for Election Offices

  • Pre-draft incident communications. Draft the template you would use if a machine doesn’t perform as intended during the testing cycles. The Lee County response is an effective model: acknowledge it, highlight that the testing protocol successfully identified the issue, confirm the unit’s isolation, and reiterate the purpose of the protocol.
  • Emphasize systemic redundancies. Observers often lack technical knowledge of backup protocols. Demonstrating multi-layered safeguards provides greater reassurance than merely stating a final result.
  • Maintain chain of custody. Document every equipment removal using the “Who, What, When, Where, and Why” framework. Record the unit ID, serial number, error logs, witnessing officials, and replacement assets to ensure a clear audit trail.
  • Optimize observer engagement. Move beyond basic public notice compliance by actively inviting key stakeholders and providing clear context. Conducting a short introductory briefing to explain test decks, expected outcomes, and discrepancy protocols can help observers accurately report what they witness.
  • Anticipate follow-up questions. Sometimes, heightened transparency invites deeper scrutiny rather than reducing questions. Providing consistent, documented answers remains essential for maintaining institutional trust.

Election officials dedicate significant effort to explaining system safeguards. Public testing provides a rare, visible demonstration of these mechanisms operating as designed. Identifying and addressing an equipment anomaly presents an opportunity to demonstrate integrity, accountability, and operational rigor.

  

The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.

Header text: Resource Library

Equipment Testing Resources

 

Election officials rely on an interconnected framework of technologies, systems, and processes, and each layer needs to be verified before voting begins. Regular testing across all operational phases—from software configurations and hardware readiness to post-election workflows and records—is essential to maintaining system security and data integrity. It provides vital transparency, demonstrating to the public that election offices systematically verify that everything works as intended rather than assuming reliability.

 

Election offices seeking to strengthen or enhance their testing protocols can leverage several established, publicly available resources:

  • The Elections Group’s Systems Check: A Guide to Testing Election Technology outlines practical, step-by-step methodology for planning, conducting, and documenting system tests before and after an election.
  • The EAC’s Logic and Accuracy Testing Quick Start Guide provides an overview of how to prepare, conduct, and document logic and accuracy testing to demonstrate equipment reliability.
  • The EAC’s Resources on Election Technology page offers guidance on managing, securing, testing, and communicating about election technology.
  • The Exchange’s Planning Desk articles in our newsletter issues 23, 24, 25, and 26 deliver a four-part series detailing testing strategies for election technologies, systems, and processes.

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.

Header text: Planning Desk

Week E-9: Peak Security—Your September & October Action Plan

 

As the general election approaches, election officials face a non-stop juggling act of technical, physical, and operational demands, including testing, training, and securing. By aligning strategic guidance with operational timelines, pre-election security efforts can be scheduled within clear, targeted windows throughout September and October—ensuring the necessary tasks are addressed when they matter most.

 

When building your election security checklist for the next nine weeks, keep in mind:

  1. Which tasks may take longer or require several people to complete, such as:
    1. Implementing a .gov website
    2. Hardware and software testing
    3. Verifying redundancies and testing backups
    4. Poll worker and staff de-escalation training
    5. Convening your Election Security Working Group (ESWG)

  2. What types of tasks may require two actions, now and right before the election, such as:
    1. Changing passwords
    2. Updating election information online
    3. Polling place and drop box inspections
    4. Ensuring detective measures (e.g., alarms, cameras, tamper-evident seals) are in place and working
    5. Evaluating physical and role-based user access controls

Next, consider organizing those security tasks by category and assigning each category to a window of time that suits your office and jurisdiction. One example is the following outline:

 

September: Testing Infrastructure, Hardening Systems, & Change Freeze 

  • Early September - Foundational Cyber & Operational Controls
    • Implementing .gov
    • Hardware and software testing
    • Updating election information online
    • Evaluating user access controls
    • Changing passwords
    • Freezing non-essential updates to ensure environment stability
  • Late September - Physical Readiness
    • Polling place and drop box inspections
    • Ensuring detective measures are in place and working

October: Training, Active Monitoring, & Execution

  • Early October - Physical & Operational Readiness
    • Poll worker and staff de-escalation training
    • Verifying redundancies & testing backups
    • Convening ESWG for final tabletop review of Incident Response Plan
  • Late October - Cyber & Operational Monitoring
    • Changing passwords
    • Evaluating user access controls
    • Verifying election information is accurate and current online
    • Double-checking that alarms, cameras, locks, and seals are in place and working

Ongoing Through September & October 

  • Threat Monitoring
    • This is a peak time for information sharing. Keep an eye out for alerts, intelligence, and threat briefings, or connect through informal check-ins and touchpoints, with partners like the Exchange, Center for Internet Security, Center for Democracy & Technology, State Fusion Centers, and other security partners.
  • Chain of Custody Tracking
    • It’s imperative that every piece of equipment, data, and paper record is accounted for by documenting who had custody. Review our issue 27 Planning Desk and the resources cited for shoring up your chain of custody processes.

Another option is to schedule tasks by the date or week. The Elections Group has a task management tool in a calendar-style spreadsheet for assigning and managing tasks that can be modified as needed.

 

As the most trusted source of election information, election officials bear the responsibility of safeguarding the vote. Aligning your physical, operational, and cyber tasks across September and October helps ensure nothing falls through the cracks. Integrating risk planning and security protocols with time-tested management calendars can ensure readiness on all fronts and provide confidence that the election remains secure and resilient.

 

The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.

 

Header text: Election Security News


Want to get daily updates on election news? Subscribe to electionline.

  • Managing the cyber risk of agentic AI | National Cyber Security Centre (August 20, 2026) // International
  • The 2026 Midterms Are Coming. Political Deepfakes Are Already Here | CNET (August 28, 2026) // National
  • OpenAI, Anthropic issue dire cyber threat warning | Axios (August 27, 2026) // National
  • Thumb drive locked in wrong box delays final Bessemer election results for a week | ABC 33/40 News (August 26, 2026) // Alabama
  • Colorado election website error exposes personal data of confidential voters | Colorado Politics (August 28, 2026) // Colorado
  • State Board of Elections hosts election security workshop series | Daily Sentinel (August 21, 2026) // New York
  • Past hack helped Delaware County prepare for recent one | Daily Times (August 21, 2026) // Pennsylvania

LinkedIn
YouTube
Email
Website

Copyright © 2026 Election Security Exchange. All rights reserved. TLP:CLEAR

 

You are receiving this email because you subscribed to the Election Security Exchange Newsletter.

 

Find this useful? Pass it along and invite other election teams to subscribe.

Subscribe

Election Security Exchange

712 H Street NE, Suite 2456

Washington, DC, 20002, United States

Unsubscribe Manage Preferences