US officials and experts say a crippling cyberattack on election infrastructure did not come to pass due to the pre-emptive steps taken by the US Cyber Command
The 2020 election was the biggest test yet of a new approach of pre-emptive action against adversaries trying to hack election infrastructure … Tweets: @ohra_aho , @nytimes , @ericgeller , and @john_sipher Tweets: Harri Ohra-aho / @ohra_aho : The Commander of Cyber Command and the Director of the NSA General Nakasone's aggressive new posture - which Cyber Command describes with terms like “persistent engagement” and “defend forward” - may be working. https://www.nytimes.com/... @nytimes : Foreign adversaries may have been deterred from interfering in the 2020 U.S. election, officials said, but domestic election interference was heightened by President Trump's efforts to undermine confidence in the system's integrity. https://www.nytimes.com/... Eric Geller / @ericgeller : “Mr. Trump and his allies, it turns out, were the chief purveyors of the kind of election misinformation that the F.B.I., [DHS] &...intelligence officials were warning about. He was also the one actor they could not mention, much less try to neutralize. ” https://www.nytimes.com/... John Sipher / @john_sipher : “Trump did more to undermine confidence in the system's integrity than America's rivals could have done themselves...leaving the Russians and the Iranians with the relatively easy task of bouncing his messages back into the echo chamber of social media.” https://www.nytimes.com/...
Context & Ripple Effects
This verdict closes a three-year arc of contested election defense. After Russian hackers mostly sat out the 2018 midterms, analysts still judged the US response to 2016 inadequate as tactics evolved into 2020. The missing piece was pre-emption: weeks before the vote, Cyber Command and the NSA took unspecified actions against Iranian hackers under General Nakasone's 'defend forward' doctrine, and officials now say that posture — not luck — is why a crippling attack never materialized.
The caveat matters: officials credit deterrence for election infrastructure specifically, while the same season produced a massive government-wide intrusion that Trump downplayed, and officials had flagged 'perception hacks' designed to undermine confidence if exaggerated as the harder-to-stop threat.
First-order effects
- Iranian and Russian operatives targeting election systems faced active disruption rather than post-incident forensics, and the named beneficiaries are state election officials whose infrastructure went uncrippled.
- Cyber Command and the NSA gain the strongest public validation yet for 'persistent engagement' — officials and experts, not the command itself, are making the deterrence claim for them.
Second-order effects
- Adversaries priced out of infrastructure attacks shift toward cheaper confidence-eroding moves — the perception-hack scenarios election officials were already watching — where attribution and deterrence are weaker.
- Other agencies facing foreign intrusion now have a template to demand the same pre-emptive treatment, pressuring the administration to extend defend-forward operations beyond election cycles.
Third-order effects
- If the pattern holds, US cyber doctrine institutionalizes continuous offensive operations as standard defense, moving the baseline from 'investigate breaches' to 'disrupt adversaries on their networks' — with the unresolved question of whether that posture extends to supply-chain espionage, which the December government breach suggests it did not.
- Deterrence claims built on undisclosed actions create an accountability gap: success is asserted by officials, but the public record cannot verify what was deterred, inviting political fights over credit — as the dueling narratives around the later government breach already show.
The trend: US cyber defense is shifting from reactive forensics to pre-emptive 'defend forward' disruption, with the 2020 election as the doctrine's first high-stakes test.