Expanding Election Protection: Cloudflare Adds Area 1 Email Security to Athenian Project
Securing elections goes far beyond protecting voting machines. State and local governments also have to defend election office networks, voter registration databases, and the internal systems that keep the electoral process running. Since the 2022 US midterm elections, Cloudflare has focused on the biggest cyber threats facing these entities. Citing CISA Director Jen Easterly's observation that the threat environment for elections is more complex than ever, the company has now expanded its free Athenian Project offering to include Area 1 email security.
A Broader Security Net
The Athenian Project, launched in 2017, was originally built around protecting public-facing election websites. It provides an Enterprise plan for free to state and local governments, including DDoS protection, a Web Application Firewall, and SSL encryption. This helps ensure that sites providing voter information remain fast and reliable—even under attack—when budgets are scarce. Currently, Cloudflare reports protecting 359 election entities across 31 states under this program.
However, election officials face threats that extend beyond their public web properties. In discussions with both new and existing Athenian participants, Cloudflare identified significant concerns about the security of internal networks and communications. Fears of DDoS attacks on election night and zero-day exploits persist, but for smaller counties in particular, phishing and ransomware stand out as top worries. These attacks often begin with a malicious email, making email security a critical frontline defense that can stop threats long before they reach an official's inbox or spread laterally across a network.
Real-World Impact: Rowan County Case Study
Months before the 2022 midterms, Cloudflare collaborated with state and local governments already using its Zero Trust products to test this expansion. One eager participant was Rowan County, North Carolina. County CIO Randy Cress was looking to improve on his existing email protection system. His team had previously used Office 365 email protection but found it offered limited insight into quarantined messages. Cress sought to reduce complexity and bolster security layers within their environment.
"Prior to Area 1 Security, we were using Office 365 email protection with limited insight for the specifics for messages that were quarantined."
The deployment proved straightforward. Cress noted that his team was able to fully onboard in under 30 minutes, well before the scheduled onboarding call. This was aided by the county's existing use of Cloudflare for DNS and DDoS protection, which allowed for an easy transition with no disruption to mail delivery. With implementation handled quickly, his team could focus on learning the product's features rather than troubleshooting configuration.
Leading up to the 2022 US midterm elections, the county saw immediate value. Dashboard reports showed twice as many inbound malicious emails compared to the same period in October 2022. Credential harvesting was the top threat, and the tools provided clear visibility into which users were being targeted for email compromise. This preemptive defense gives officials confidence that a crucial first line of protection is in place, allowing them to focus on ensuring a secure voting process for constituents.
Bringing Email Security to the Athenian Project
Cloudflare worked with external stakeholders—including civil society groups under Project Galileo and agencies like CISA's Joint Cyber Defense Collaborative (JCDC)—to understand how to responsibly offer these tools.
Area 1 email security is a cloud-native service designed to stop phishing attacks and is now available as part of the Athenian Project for state and local government entities with Enterprise accounts. Governments interested in learning more about the program or applying can do so at the Athenian Project website.



