October 2, 2026 | Policy Brief

Defense Department’s Public Election Security Directive Sends Important, but Belated, Signal to U.S. Adversaries

October 2, 2026 | Policy Brief

Defense Department’s Public Election Security Directive Sends Important, but Belated, Signal to U.S. Adversaries

With the U.S. midterm elections fast approaching, the Department of Defense (DOD) has released an apparently unprecedented directive on election security.

The directive, signed by the secretary of defense on September 22, makes election defense a “no-fail mission” for U.S. Cyber Command, the National Security Agency (NSA), the Defense Intelligence Agency (DIA), and the National Geospatial-Intelligence Agency (NGA). While the statement is highly positive in terms of both policy prescription and the signal it sends to adversaries of the United States, its arrival is belated.

Countering foreign malign influence must be a continuous effort, not a seasonal one.

DOD Urged To Prioritize Election Security

The directive calls for DOD to mobilize “all assets, capabilities, and partnerships” to counter threats to the upcoming U.S. midterm elections, including both cyberattacks against election infrastructure and foreign malign influence. It calls for Cyber Command to use DOD “intelligence and cyber capabilities” to prevent foreign meddling. It also calls on the broader Defense Intelligence Enterprise (DIE) to execute collection on election threats.

Notably, it directs Cyber Command to coordinate with the Department of Homeland Security (DHS). The Trump administration substantially scaled back election security operations at DHS’s Cybersecurity and Infrastructure Security Agency (CISA) in 2025. CISA did release its election security plan on September 24, but it focuses almost exclusively on cyber and physical threats rather than foreign malign influence. The directive therefore leaves unclear what, if any, role CISA will play in DOD’s broader effort to counter foreign influence operations.

A Public Signal Directly From the Secretary of Defense Appears Unprecedented

A public signal coming directly from the secretary of defense concerning election security is unprecedented, although the Pentagon has previously supported election security efforts.

In a 2018 nonpublic agreement, DOD and DHS clarified their roles in responding to cyber threats to U.S. critical infrastructure, while DOD separately approved DHS’s request for cyber-incident-response support for that year’s midterms. Similarly, in 2019, the secretary of defense and Cyber Command’s commander joined five other agencies in a joint statement describing a “whole-of-government approach” to securing elections.

Lastly, NSA and Cyber Command released a command-level announcement in 2022 for the Election Security Group (ESG), a joint team that coordinates intelligence and cyber operations against foreign threats to U.S. elections. There was also a robust election security interagency effort in 2024, with CISA, the FBI, and the Office of the Director of National Intelligence as the primary leads. However, never before has a secretary of defense been recorded publicly directing election security preparations.

The Signal Is Belated

Americans benefit from assurances that their government will combat election threats, especially since the administration closed multiple government agencies dedicated to countering foreign malign influence and protecting U.S. elections. However, a public directive coming so late in the cycle has limited benefit.

Elections are targets of opportunity for our adversaries, but foreign malign influence is a persistent threat. Russia, China, and Iran are continuously launching influence operations attempting to shape the beliefs and behaviors of Americans. The assets deployed in influence operations often take time to mature: months or years before an election, bots might post clickbait to build a following, and fake news websites might attempt to build trust with local communities.

Moreover, disruption efforts are largely symbolic if not conducted continuously. Cyber Command disrupted internet access for the notorious Russian troll farm known as the Internet Research Agency (IRA) on Election Day during the 2018 midterms, sustaining the disruption into the immediate vote-counting period. Though it is unclear how long it took the IRA to recover, it went on to target the 2020 U.S. elections.

Continuous threat identification and disruption should be combined with other actions, such as sanctions, that impose costs on adversaries. Beyond imposing costs, deterrence should deny benefits to adversaries by increasing Americans’ awareness of the threat through public communications.

Max Lesser is a senior analyst on emerging threats at the Foundation for Defense of Democracies’ (FDD’s) Center on Cyber and Technology Innovation (CCTI), where Pavneet Kaur is an intern. Jacob Breach is a senior advisor at FDD focusing on foreign influence operations. For more analysis from the authors and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. Follow Jacob on X @JBreach. FDD is a Washington, DC-based, nonpartisan research institute focusing on foreign policy and national security.