Skip to content
Search

Latest Stories

cipherbrief

Welcome! Log in to stay connected and make the most of your experience.

Input clean

Election Security: Keeping Our Disagreements Our Own

About one month before Election Day, Americans deserve to know how their government is protecting elections from foreign threats. The Pentagon’s recent directive assigns military intelligence and cyber capabilities to that mission. I welcome that commitment. Americans also need to understand how it fits into the national effort and how federal agencies are supporting the state and local officials who administer elections.

As a former Election Threats Executive at the Office of the Director of National Intelligence, I would have preferred an ODNI-led announcement explaining the foreign threat and the coordinated response, with the FBI, Defense Department, and Department of Homeland Security alongside it. Most of my career was spent at the intersection of combat support and intelligence. My preference comes from ODNI’s role in integrating intelligence across agencies and explaining what it tells us about foreign threats.


Election security depends on accurate ballot counts and public confidence grounded in credible information. An announcement centered on Defense risks giving a military cast to the mission and leaving the public with an incomplete picture. Americans need to understand how federal agencies use their authorities and resources to support elections administered by state and local officials.

An Old Threat Comes Into Focus

Foreign efforts to influence American elections did not begin in 2016. Soviet operations against President Ronald Reagan’s 1984 reelection campaign included a forged letter intended to discredit him. The FBI publicly exposed the forgery. The technology was different, but the purpose is familiar: manipulate Americans’ perceptions through concealed foreign activity.

The 2016 election brought that threat into the center of American public debate and forced a reassessment across the Intelligence Community. The January 2017 intelligence assessment described Russia’s campaign as an escalation in the scope, intensity, and directness of its efforts. Hacking and influence operations could reinforce one another, reaching Americans through channels they used every day.

Identifying a foreign operation is only part of the job. The people it targets need enough information, soon enough, to protect themselves.

By the 2020 election cycle, the government had developed a more deliberate answer. It involved intelligence collection and analysis, investigations, cyber defense, support to election officials, and decisions about what information could be shared beyond classified channels.

Russia is part of a broader challenge that includes China, Iran, and countries with varying relationships with the United States. We need the full national security team to understand what these governments are doing and why, and to inform the operations and policies needed to counter interference, regardless of who is behind it.

What the 2020 effort taught us

The Executive Branch Notification Framework, adopted in 2019, established a process for deciding when and how to notify people about foreign election influence and interference. It complemented existing victim-notification requirements. An interagency group organized by ODNI evaluated threats; DHS handled notifications concerning critical infrastructure, while the FBI handled other notifications.

The framework recognized that different threats require different forms of communication. Some call for a private warning to a targeted candidate or organization. Others justify informing the American public. Decisions were intended to be coordinated and nonpartisan, while respecting protected speech.

Public communication in 2020 extended beyond that framework. In July, National Counterintelligence and Security Center Director William Evanina described intelligence briefings for presidential campaigns, political committees, and Congress. His July 24 public statement and August 7 update also provided unclassified information about the evolving foreign threat. These were complementary channels: detailed briefings for particular audiences and information the broader public could use.

There were also coordinated announcements about specific threats. On October 21, the DNI and FBI director appeared together at an election-security press conference. FBI Director Christopher Wray explained the Bureau’s investigative responsibilities, described cooperation with government and private-sector partners, and urged Americans to seek reliable voting information from state election officials.

Private notifications, classified briefings, unclassified threat updates, and public statements serve different needs. A public attribution can expose an adversary; a private warning can help a target respond without unnecessarily amplifying the operation.

Public confidence depends on evidence and competent election administration. Officials should explain what they know and what remains uncertain. Otherwise, foreign actors have more room to supply their own explanations.

Finland’s Lesson: Prepare Together

I had the privilege of traveling to Finland to discuss and learn about its election preparedness. What struck me was how far the Finns took the team sport concept: they connected responsibilities across government and practiced working together.

Finland calls its approach comprehensive security. Government agencies, businesses, organizations, and citizens all have a part to play. Its election preparations have included training for authorities and political parties. Its broader government preparedness exercises combine work within individual ministries with shared crisis scenarios. These are practical ways to build relationships and understand responsibilities before a crisis.

Finland’s experience with Russian disinformation shows why this matters. Years before the 2016 U.S. election, Russian state-controlled media and pro-Kremlin figures spread claims that Finnish authorities were taking children from Russian families without legitimate reasons. EUvsDisinfo documented a recurring campaign around child protection and custody cases. This was a broader attack on trust in public institutions, rather than an election-specific operation.

Finnish officials answered publicly. On October 12, 2012, the social affairs minister met Russian journalists in Helsinki, while Finland’s ambassador in Moscow held a press conference to correct unfounded claims and explain Finnish child welfare. When another case attracted attention in 2016, the Ministry of Social Affairs and Health issued a public statement explaining that children were not removed because of nationality, that taking a child into care was a last resort, and that parents could appeal decisions. It also provided links to Russian-language information.

The lesson for the United States is that coordination has to be practiced before it is needed. Agencies must know who will establish the facts, who can act, and who will explain the response to the public. Finland’s example also shows the value of answering false claims with clear information about how institutions work and what protections people have. For election security, that means helping Americans understand both the threat and the safeguards protecting their vote.

AI makes coordination more urgent

In September 2024, ODNI reported that Russian and Iranian actors were using generative AI in election influence efforts. Russia had generated election-related text, images, audio, and video. Iranian actors used AI for social media posts and articles on websites posing as legitimate news outlets.

During my tenure, we were beginning to consider how to respond to deepfakes in foreign influence campaigns. We struggled with how to flag them quickly and explain the threat publicly while protecting intelligence sources.

ODNI assessed that AI was accelerating and improving aspects of these operations, but had not yet revolutionized them. Producing deceptive material does not establish that it persuaded voters or changed an election outcome.

In September 2026, Anthropic reported disrupting operations that used its tools to build fake social media identities and news sites, prepare campaign plans, and conceal who was behind the material. Much of the content it discovered attracted little or no genuine engagement. Those findings concern the operations the company observed, rather than all foreign influence activity. Public warnings should distinguish an adversary’s capabilities from an operation’s reach and effects.

Defenders need to determine whether AI is making impersonation more convincing or allowing foreign actors to exploit local incidents more quickly. They also need to establish who is behind an operation and warn its targets before the deception spreads.

These are intelligence and operational questions that cross agency boundaries. They also require clear limits. A false claim is not automatically a foreign operation. Americans’ political speech remains protected, including speech officials find objectionable. Election defense must establish the foreign nexus and act within lawful authorities.

Make the Full National Response Clear

Secretary Pete Hegseth’s September 22 memorandum directs the defense intelligence enterprise to collect and produce intelligence on foreign election threats, consistent with law and departmental policies. It also directs Cyber Command to use its existing authorities in coordination with DHS to counter foreign cyber threats. Addressed to Cyber Command, NSA, DIA, and NGA, the memo explicitly describes Defense as supporting a whole-of-government effort.

The memo does not name ODNI or the FBI, but that does not establish that they are excluded from the wider effort. Nor does it designate Defense as the national lead. My concern is how its departmental instructions connect to the full response, and how that response is explained to Americans.

The Washington Post reported on October 4 that state officials, including Republicans, described gaps in federal threat information and support. It also reported recent steps, including CISA’s September 24 security plan and the restoration of NSA’s Election Security Group. Those steps deserve acknowledgment. The practical test is whether assistance reaches election officials in time, through relationships they trust.

The Pentagon has an important role. NSA’s account of its work with Cyber Command during the 2022 midterms described sharing foreign intelligence with domestic partners and using cyber capabilities to disrupt foreign attackers. Those capabilities belong in the national effort. My concern is how the overall effort is explained and led. ODNI should provide a coordinated assessment of the foreign threat. The FBI should explain its investigative role. DHS should explain its support to the officials responsible for administering elections. Defense should explain how its capabilities support those missions. Together, they should tell Americans how warnings and public attributions will be handled.

There is precedent. In November 2019, Justice, Defense, DHS, ODNI, the FBI, NSA, and CISA issued a joint statement describing preparations for the 2020 election. They emphasized sharing actionable information and working with state and local officials and private-sector partners. We do not need sensitive operational details. We do need to know who integrates the intelligence, who alerts a target, and who speaks when a foreign operation requires a public warning. Those arrangements should be tested before an incident forces a rushed decision. They should also remain in place through the counting and certification of results.

No agency sees every part of this problem. Election officials need information they can act on, and the public needs explanations it can trust. Federal leadership must connect the intelligence, investigations, cyber defense, and support to those administering the vote.

With one month to go, the message should be clear: vote and have confidence in doing so. A healthy democracy makes room for vigorous disagreement. The government’s role is to ensure that the rightful tensions of our democracy are our own.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Make us preferred on Google

Related Articles

AI Is Coming for the Chain of Command

The voice belonged to Gen. Tareq Saleh. It was telling his men to fall back. Or so it seemed.“Advances and retreats are a normal part of war,” the [...] More

The Nations That Don’t Appear on the Map

The most influential media network operating inside a dozen allied countries today has no masthead, no headquarters and no country of incorporation. [...] More

Heads They Win, Tails They Win: The CMMC Trap and the Way Out

Here is a prediction from inside the compliance trenches: the CMMC Reform Task Force closed its sixty-day review on September 11 and is now [...] More

Not the Destroyer of Worlds: Why Compute is Humanity’s Most Vital Defense

Eighty years ago, the architects of our first dual-use revolution whispered that they had “become Death, the destroyer of worlds.” Today, a new power [...] More

When Policy and War Collapse Into One: Fighting in the Sixth Domain

We may soon face conflict with nation-states in a new model of warfare—one not defined by geography, but instead defined by AIs competing directly [...] More

The Compute We Cannot Power

On September 9, Oracle reported a cloud backlog of $664 billion — up $209 billion from a year earlier, an order book the size of a mid-cap national [...] More

{{}}