Key takeaways
- CISA has lost about a third of its workforce since January 2025, and its election security team is gone.
- The intelligence community's annual threat assessment left out foreign threats to U.S. elections for the first time in nearly a decade.
- Claims of Iranian interference are being used to build a case for federal control of election administration.
- The monitoring system that worked was dismantled and can't be fully rebuilt before November 2026.
Talking with the machine again. This time the conversation was so good it needed a report.
The usual framing is that Iran is the main cybersecurity threat to the 2026 midterms, and the Trump administration has weakened our defenses. That's partly accurate, but it misses the bigger picture. The administration dismantled the election security system best able to detect foreign interference, while using the threat of Iranian interference as political cover to interfere in the election process itself.
Part 1: Has Trump gutted U.S. cybersecurity?
As a matter of fact, largely yes, though the administration disputes the framing.
- The FY2027 budget proposes cutting $707 million from CISA, about 30 percent of its $2.4 billion FY2025 budget.
- CISA has lost about one-third of its workforce, roughly 1,000 people, since January 2025.
- It has had no Senate-confirmed permanent director, and an internal memo confirmed nearly all senior officials have left.
- During the shutdown that began Feb. 14, 2026, it ran at about 38 percent staffing.
Eliminated: the election security team, the counter-ransomware initiative, Secure by Design, international partnerships, the stakeholder engagement division that connected CISA to state and local partners, and the offices that countered foreign misinformation.
The White House says the cuts refocus CISA on protecting federal networks and end "weaponization and waste," calling its election work censorship. Experts and lawmakers from both parties have repeatedly rejected that. Even analysts who wanted reform condemned the pace. As Stanford's Andrew Grotto put it, CISA "needed surgery with a scalpel, not a sledgehammer."
Part 2: Is Iran coming for the '26 elections?
That framing is more contestable, and the administration is using it.
- The U.S. and Israel launched Operation Epic Fury against Iran on Feb. 28, 2026, substantially degrading Iran's military and cyber capabilities. Supreme Leader Ali Khamenei was killed early in the conflict.
- For the first time in nearly a decade, the intelligence community's annual threat assessment left out foreign threats to U.S. elections. When Sen. Mark Warner asked DNI Tulsi Gabbard directly whether there was no foreign threat to the midterms, he got a non-answer.
Within hours of the strikes, Trump reposted a headline claiming Iran tried to interfere in the 2020 and 2024 elections. Historian Timothy Snyder and others noted the framing set up "federalization," an executive takeover of election administration.
- Trump allies have circulated a draft executive order that would use foreign interference claims to declare a national emergency and ban mail ballots and voting machines.
- Trump told podcaster Dan Bongino that Republicans should "nationalize the voting in at least 15 places."
- He floated canceling the 2026 midterms in remarks to House Republicans in January.
The inversion
The more accurate threat model for 2026 is domestic. The administration gutted election cybersecurity while building a legal case for executive control of the midterms on national security grounds. Iran's cyber threat is real in principle, but it's been degraded by war and elevated as political cover.
Part 3: What monitoring is left?
The Election Infrastructure Information Sharing and Analysis Center was the main real-time clearinghouse for election threats. It was created in 2018, during Trump's first term, after Russian interference in 2016. It was bipartisan and it worked. It's now defunded.
Rebuilding before November faces hard limits. Meta, X and others have rolled back election integrity teams. Attribution requires classified intelligence that no academic lab or nonprofit can replicate. CISA's international affairs office was among the first cut, and the DNI hasn't tasked anyone with monitoring foreign election interference.
What could still be tried: academic labs like the Stanford Internet Observatory and DFRLab are operating, though without classified feeds. State attorneys general could pursue their own data-sharing deals with platforms. And if Democrats flip a chamber, Congress could restore EI-ISAC funding quickly.
The blunt read: the monitoring system that existed worked, was deliberately dismantled and can't be fully rebuilt before November 2026. The real question is whether civil society, researchers and state election officials can patch together enough coverage to flag the worst of it.
Sources
- TechCrunch: Trump administration plans to cut CISA budget by $700 million
- Gizmodo: Trump's War on American Cybersecurity Ramps Up
- TechCrunch: CISA reportedly in dire shape amid Trump cuts and layoffs
- Cybersecurity Dive: Trump's FY2027 budget again targets CISA
- Axios: CISA shrinks under Trump budget, staff cuts
- Axios: One-third of CISA has left since Trump took office
- CyberScoop: Across party lines, the verdict is the same: CISA is in trouble
- Government Executive: Cuts hit CISA, NIST and IRS in Trump's FY27 budget
- Votebeat: CISA halts support for states on election security
- Defense One: DNI annual threat assessment omits foreign election interference
- Democracy Docket: Trump's attack on Iran and the plot against your vote
- Tech Policy Press: Despite Using Iranian Meddling to Justify War, Trump Axes Election Defenses
- Brennan Center: What Does War with Iran Have to Do with Elections?
- Al Habtoor Research Centre: How the US-Israel-Iran War Could Reshape the 2026 Midterms
Originally published on LinkedIn, April 22, 2026. Lightly edited.