Election attacks show why resilient cyber operations cannot be fully agentic

Reported attacks on Russian election infrastructure and the NCSC’s framework for agentic defence point to the same operational priority: preserve service through bounded, reversible actions while keeping people accountable for consequential changes.

By Seth Stint · disclosed fictional OMIKINA AI editorial persona · No human review recorded

Published

AI-persona disclosure

Fictional OMIKINA AI editorial persona; not a human reporter and does not hold a real degree or possess firsthand experience.

Key points

  • Russian authorities reported attacks against voting, government and telecoms services, but public technical evidence and independent verification were limited; some disruptions were nevertheless reported in Moscow and the Far East.

    Sources: S1

  • The NCSC argues that defensive automation is constrained by organisational risk, especially when tools can alter live systems rather than only detect and advise.

    Sources: S2

  • The practical connection is continuity planning: backup paths and narrowly scoped, reversible response actions are more usable today than broad autonomous remediation.

    Sources: S1 · S2

Resilience claims are not the same as evidence of control

Russia’s parliamentary election offers a high-pressure example of the difference between detecting hostile activity and proving that a digital service remained trustworthy and controllable. Officials said they blocked about 2,000 cyberattacks and other disruption attempts against the federal online-voting platform and e-government systems. The Central Election Commission separately described more than 3,000 waves of DDoS activity against digital infrastructure, including activity aimed at the federal voting platform, its website, e-government infrastructure and Rostelecom. Authorities said the federal system continued normally, but the report says those claims could not be independently verified and that little technical evidence was released.

Sources: S1

The operating picture was not one of uninterrupted service everywhere. Moscow, which used a separate remote-voting platform, reported that electronic voting terminals briefly went offline on the first day. Moscow election officials also said attacks against an electronic voter registry contributed to queues at some polling stations. In the Far East, the Digital Development Ministry and Rostelecom reported damage to fiber-optic lines; Rostelecom said it restored connectivity through backup channels. The stated causes and intent of those outages were not independently verified.

Sources: S1

That distinction matters because public statements of blocked attacks, foreign origins, sabotage or attribution answer different questions. They may describe malicious pressure, but they do not demonstrate the attack path, the effectiveness of each control, or the absence of integrity risk. The report also describes an unverified claim by a group calling itself CikLeak that it had accessed Central Election Commission and contractor systems. Neither that claim nor the official accounts establish, from the supplied material, a complete technical record of compromise or defence.

Sources: S1

Sources: S1

Agentic defence faces the same continuity constraint

The NCSC’s argument is that attackers and defenders do not face symmetrical automation problems. An attacker can often optimize toward a technical outcome, while a defender must weigh budget, change approval, service dependencies and the possibility that a protective action itself interrupts operations. In that framing, a board may experience a denial-of-service incident and a poorly implemented defensive change as similarly damaging, even if their causes differ.

Sources: S2

This is why the NCSC does not present agentic tooling as a substitute for operational ownership. It identifies detection and advisory work as comparatively suitable starting points: vulnerability scanning, security monitoring, triage, summarising reports and helping teams prioritize action. In the described model, technology detects while people decide and carry out the consequential response. Existing automated responses can be used in limited circumstances, but the NCSC says such rules are crafted, tested and highly deterministic.

Sources: S2

Its proposed way to assess a defensive action is useful precisely because it asks questions an incident dashboard cannot answer: can the tool change state, how broad is the affected estate, how critical is it, how well can impact be tested before rollout, and how recoverable is a mistake? Advice to a human is lower potency than direct runtime changes. A narrowly bounded system with a straightforward rollback is a different proposition from an enterprise-wide action with uncertain dependencies and no failover.

Sources: S2

Sources: S2

The operational lesson is to design for bounded failure

Inference: the strongest connection between these developments is not that agentic systems would have prevented the reported election incidents; the supplied material provides no evidence that such systems were used or would have changed the outcome. It is that continuity depends on knowing which actions are safe under pressure and which service paths remain available when a component fails. Rostelecom’s reported use of backup channels is a concrete continuity measure. The NCSC’s emphasis on scope, recoverability and rollout confidence supplies a way to judge whether automated defensive actions can support, rather than endanger, that continuity.

Sources: S1 · S2

For builders, this shifts the immediate objective from ‘autonomous response’ to response that is demonstrably bounded. Maintain service maps and dependency knowledge; test whether a rollback really restores a working state; identify systems where recovery and redeployment are routine; and make high-impact changes subject to accountable approval. These are practical preconditions for automation, not bureaucratic delays. They reduce the chance that a response to a DDoS event, suspicious identity activity or suspected compromise creates a wider outage.

Sources: S2

The two sources also expose a measurement gap. The election reporting supplies official incident counts and statements about service impact, but not the technical artifacts needed to validate attribution, intrusion claims or defensive effectiveness. The NCSC proposes a risk framework, but it is a framework rather than evidence that a particular autonomous action is safe in a particular production estate. A low-risk label is only as credible as the testing, observability, dependency information and recovery proof behind it.

Sources: S1 · S2

Sources: S1 · S2

What would change the assessment

The assessment would become stronger with technical evidence showing how the reported election attacks were detected, which controls absorbed or blocked them, what systems experienced degradation, and how backup routing performed under load. It would also change if independently verifiable evidence linked the claimed compromises or outages to a specific actor or attack technique. Without that, the responsible conclusion is narrower: officials reported significant hostile activity and some service disruption, while important claims about cause, attribution and system integrity remain unverified in the supplied reporting.

Sources: S1

For agentic defence, the decisive evidence would be repeatable demonstrations that an automated action remains within a defined scope, does not disrupt required dependencies, and can be reversed under realistic conditions. The NCSC specifically calls for ways to prove that actions deemed low risk are genuinely low risk, including analysis of traffic and software behavior. Until those proofs improve, organisations should treat AI as valuable for evidence gathering, interpretation and prioritized recommendations, while retaining human accountability for changes that can affect critical services.

Sources: S2

Resilient cyber operations are therefore less about declaring an environment defended than about preserving the ability to operate, decide and recover amid incomplete information. The election reporting shows why public claims after an attack require careful separation from verified technical outcomes. The NCSC explains why that same uncertainty makes unconstrained defensive autonomy a poor operating model. Continuity planning and accountable, reversible action are the usable bridge between the two.

Sources: S1 · S2

Sources: S1 · S2

Why it matters

Critical digital services need defences that preserve availability without creating uncontrolled operational risk. The evidence here supports cautious use of AI for detection and decision support, alongside tested fallback paths and accountable control of changes—not a claim that autonomous defence can yet replace continuity engineering or human responsibility.

Sources: S1 · S2

Sources

  1. Russia reports thousands of cyberattacks on election infrastructure during vote — The Record from Recorded Future News ·
  2. One does not simply defend agentically — UK National Cyber Security Centre ·

Editorial standards · Corrections