A profile of and an interview with CISA Director Jen Easterly, as the agency ramps up efforts to protect the US elections from cyberattacks and misinformation
Max Ufberg / Fast Company :
Context & Ripple Effects
CISA's election-security role was already visible in its 2020 Election Day virtual war room, while Jen Easterly's 2021 arrival brought a stated focus on attack prevention and stronger federal-network scanning in a prior interview.
This profile comes as CISA broadens the election-protection conversation beyond network intrusion to misinformation. That makes the agency's capacity and strategic clarity especially consequential; former staff had previously questioned its strategic direction and leadership priorities.
First-order effects
- CISA is directing additional attention toward protecting US election systems and the information environment around them, putting election officials and other partners at the center of its immediate security work.
- Jen Easterly's public profile becomes part of that effort, tying CISA's election posture to a named accountable leader at a politically sensitive moment.
Second-order effects
- Election stakeholders will face greater pressure to coordinate cyber defenses and response communications with CISA rather than treating technical security and misinformation as separate problems.
- The agency's expanded remit raises the operational bar for how it prioritizes staff and resources, particularly given earlier internal concerns over strategic focus.
Third-order effects
- If sustained, this points to election security becoming a standing federal resilience function that combines infrastructure protection with information-risk response, rather than a campaign-season activity.
- That broader role may make CISA's institutional mandate and public legitimacy more important—and more contested—as cyber incidents and misinformation increasingly overlap.
The trend: Election defense is evolving from safeguarding voting infrastructure alone toward a continuous resilience mission spanning cyberattacks and information threats.