Nevada voters should not have to take anyone’s word that an election system is secure. They deserve clear safeguards, paper records, trained local officials, and public reporting that shows how threats are identified and addressed. A Nevada election cybersecurity plan must protect the vote without making the process harder for eligible citizens to use.
Election security is not a partisan slogan. It is a basic duty of public administration. From Clark County to Ely, every voter deserves confidence that registration records are accurate, ballots are protected, results are verified, and election offices can keep operating when technology fails or a cyberattack is attempted.
Security Begins Before Election Day
Cybersecurity is often discussed as though it begins when votes are counted. In reality, the work starts much earlier. Voter-registration databases, ballot-design systems, county networks, election-worker email accounts, voting equipment, and public results websites all need protection.
A serious plan recognizes that these systems do not carry equal risk. A public-facing website may be targeted to create confusion or prevent voters from finding information. An employee email account may be targeted through a fraudulent message. A voter database may be targeted for theft, alteration, or disruption. Each risk requires a specific response, not one vague promise that a system is “secure.”
The first responsibility is to know what systems exist, who has access to them, and whether that access is still necessary. Election offices should maintain current inventories of devices, software, vendors, administrator accounts, and data connections. Access should be limited to the people who need it for their work, and elevated access should require stronger verification.
After 20 years as a systems analyst, I can tell you where most failures start. It is rarely an exotic attack. It is an unmanaged account, an unpatched system, or a procedure nobody wrote down.
That may sound technical, but the principle is straightforward: no election system should depend on a forgotten account, outdated software, or a single employee’s personal knowledge. Good administration creates procedures that can be reviewed, repeated, and improved.
A Nevada Election Cybersecurity Plan Must Protect Paper Evidence
Technology helps elections run efficiently, but technology alone should never be the final proof of an outcome. Nevada needs secure, voter-verifiable paper records for every ballot cast. Paper is not a step backward. It is the independent evidence that allows voters, candidates, election officials, and courts to verify that electronic totals reflect actual votes.
Electronic systems can fail. Networks can go down. Software can contain errors. Bad actors can attempt to create doubt even when they cannot change a vote. A durable paper record gives Nevada a way to check results without relying entirely on a screen, a vendor, or an assurance from government.
Post-election audits should compare a meaningful sample of paper ballots with reported results before certification. Where the margin is close or an irregularity appears, the review should expand according to clear, public rules. Audits should be designed to find mistakes, not merely to confirm a conclusion already reached.
There is a practical trade-off. Thorough audits require time, trained staff, secure handling procedures, and clear deadlines. Nevada should not sacrifice accuracy for speed, but neither should voters be left in uncertainty because procedures were poorly planned. The answer is preparation: statewide audit standards, trained county teams, and published timelines that explain what happens after the polls close.

County Flexibility Should Not Mean Uneven Security
Nevada’s counties face different conditions. Clark and Washoe counties manage large voter populations and complex operations. Rural counties may have smaller staffs, longer travel distances, limited broadband access, and fewer technology specialists. Those differences are real and should shape implementation.
They should not produce different standards for protecting the vote.
The Secretary of State’s office should establish baseline cybersecurity requirements for every county, then provide the tools, training, and funding needed to meet them. A county should not have to choose between securing an election system and paying for another essential public service.
Common statewide standards should cover secure account access, timely software updates, encrypted backups, incident reporting, vendor oversight, physical security, and recovery planning. Counties should be able to select solutions that fit their operations, but the public should know that every county meets the same minimum expectations.
A statewide approach also makes training more effective. Election workers and county staff should receive recurring instruction on phishing attempts, password practices, handling voter data, incident escalation, and continuity procedures. Many cyber incidents do not begin with a sophisticated attack on voting equipment. They begin with a convincing email, a reused password, or an employee who was never given the tools to recognize a threat.
Public Reporting Is Part of Election Security
Security cannot mean secrecy. Some details must remain confidential because publishing them would expose systems to greater risk. But voters have a right to know whether election offices are prepared, whether required reviews occurred, and whether problems were addressed.
The Nevada election cybersecurity plan should include quarterly public reporting on statewide readiness. Reports can identify completed training, system assessments, audit status, unresolved funding needs, and the steps taken after an incident. They should not reveal passwords, network diagrams, or operational details that would assist an attacker.
This balance matters. Government sometimes uses “security” as a reason to provide too little information. Critics sometimes demand technical details that should not be released. Responsible leadership draws a clear line: protect sensitive systems while giving the public enough evidence to judge whether officials are doing their jobs.
Election offices should also communicate quickly when disruptions occur. Silence creates rumors. Rumors spread faster than corrections. If a county website is unavailable, if a voter information tool has a problem, or if officials are investigating suspicious activity, the public deserves prompt, factual updates about what is known, what is not known, and what voters should do next.

Secure Voter Rolls Protect Both Access and Integrity
Cybersecurity and voter-roll accuracy belong together. An inaccurate or poorly protected voter file can create real harm: eligible voters may encounter errors, deceased or relocated registrants may remain on the rolls, and personal information may be exposed or misused.
This is not theoretical. In Barnhill v. Aguilar, the federal lawsuit I filed on September 4, 2026, the data identify 9,607 individuals with duplicate active voter registrations, each showing a recorded 2024 General Election vote under both registration numbers. I am not accusing anyone of fraud. I am asking for an audit, reconciliation, and public reporting so that Nevada can find and fix these records.
Maintenance must follow the law and protect eligible voters. That means using reliable data sources, notifying voters before removals when required, providing a clear correction process, and preserving records of significant changes. It does not mean careless purges or policies that place the burden on seniors, students, military families, rural residents, or citizens who move frequently.
A secure system should make it easier to correct legitimate mistakes. Voters need simple ways to check their registration status, update an address, understand identification requirements, and receive help when records do not match. Security that blocks eligible voters is not good security. Access without verification is not good administration. Nevada can and should do both.

Prepare for Disruption, Not Just Prevention
No responsible official can promise that an attempted cyberattack will never occur. The standard should be whether Nevada is prepared to detect, contain, recover from, and explain an incident.
Every county should maintain and test an election continuity plan. That includes offline backups of critical data, secure alternative communications, documented chain-of-custody procedures, replacement equipment options, and designated contacts for state and federal partners. Tabletop exercises before an election can reveal gaps that are far easier to fix in advance than during a crisis.
Vendor accountability belongs in that preparation. Election technology companies should meet clear security requirements, disclose significant vulnerabilities promptly, support independent testing where appropriate, and provide realistic recovery commitments. Nevada taxpayers and county officials should not be locked into opaque systems that cannot be examined, supported, or replaced responsibly.
My approach is built on a simple expectation: election administration should be calm, competent, and open to verification. That means less political theater and more measurable work: stronger training, consistent county standards, paper-backed audits, accurate voter rolls, and honest public communication.
Trust Is Earned Through Verifiable Work
The strongest election system is not the one that asks citizens for blind trust. It is the one that gives them reasons to trust: records that can be checked, procedures that are followed, audits that are meaningful, and officials who explain their work plainly.
Nevada can protect voter access and election integrity at the same time. It can respect local county realities while holding every jurisdiction to serious statewide standards. And it can replace noise with the steady work of proving that every lawful vote is handled fairly, securely, and transparently.
Voters should keep asking practical questions of every election official: What is protected? Who verifies it? What happens when something goes wrong? Clear answers are not a political luxury. They are how public trust is built and kept.


1 thought on “A Nevada Election Cybersecurity Plan Voters Can Trust”