TEXAS VOTER REGISTRATION HISTORY: THE DECENTRALIZED SYSTEM BEFORE HAVA AND THE DANGERS OF CENTRALIZATION
EXECUTIVE SUMMARY
Before the Help America Vote Act (HAVA) of 2002, Texas operated with 254 independent county voter registration systems. Each county maintained its own voter rolls locally, providing redundancy, local control, and distributed risk. The federal mandate to centralize voter registration created a single point of failure that cybersecurity experts warn makes the entire state vulnerable to catastrophic system failures, ransomware attacks, and security breaches.
---
TEXAS VOTER REGISTRATION BEFORE HAVA (Pre-2002)
The Decentralized System: TVRS
Before TEAM, Texas used the Texas Voter Registration System (TVRS), and the 2007 State Audit found that for 6 (60 percent) of 10 performance benchmarks, the new TEAM system was actually slower than the previous TVRS system.
Source: https://sao.texas.gov/reports/main/08-012.html
Historically, routine voter registration has been a county function, and registration lists were maintained at the county level, with the Texas State Archives noting that "Routine voter registration is a county function, and such registration lists may also be found at the county level."
Source: https://www.tsl.texas.gov/arc/votersreg.html
How the County-Based System Worked
Before HAVA mandated centralization in 2002, Texas operated with 254 independent county voter registration systems. Each county maintained its own voter rolls locally. The county voter registrar in each county was responsible for:
- Processing voter registration applications
- Maintaining local voter rolls
- Conducting list maintenance
- Managing their own records and systems
The transition from 254 separate voter registration lists at the county level to one statewide list was described by the Texas Secretary of State's office as "a huge undertaking."
Source: https://www.govtech.com/archive/texas-election-management-system.html
---
THE DANGERS OF CENTRALIZATION: EXPERT WARNINGS
Single Point of Failure - Current Election Officials' Concerns
Frank Phillips, the elections administrator in Denton County (one of the 32 counties that currently use third-party systems representing collectively roughly 75% of registered voters in the state), testified about relying on a single centralized system: "If something catastrophic were to happen — ransomware, software failure — at least 75% of the voters in Texas would be fine. If all counties are on the state system and something goes wrong, the whole state is paralyzed. That's dangerous."
Source: https://www.votebeat.org/texas/2025/04/18/team-voter-registration-software-senate-bill-2382/
Source: https://www.texastribune.org/2025/04/18/texas-voter-registration-software-team/
Real-World Ransomware Attacks on Centralized Voter Databases
In October 2020, Hall County, Georgia experienced a ransomware attack that targeted a database used to verify voter signatures, with the DoppelPaymer gang taking credit for the attack, and the database was still not fully functional weeks later, representing what may have been the first successful ransomware attack that affected part of election infrastructure.
Christopher Krebs, CISA's director, stated that because state districts' voter databases are stored in highly centralized networks, these repositories are vulnerable to hacking and ransomware attacks by nation-state actors as well as cybercrime gangs.
Source: https://www.bankinfosecurity.com/ransomware-knocks-out-voter-database-in-georgia-a-15235
Centralized Systems Create Catastrophic Risk
According to CISA's cybersecurity toolkit, for elections, a ransomware attack could leak or deny access to voter registration data, unofficial results reporting, and other sensitive information, and could also inhibit access to important election systems during critical operational periods, such as registration and candidate filing deadlines.
Source: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections
Breaches of voter registration databases and systems represent the biggest challenges in election security, including attacks targeting the IT infrastructure used to manage election processes, storage systems that contain voting data, and polling locations.
Source: https://www.fortinet.com/resources/cyberglossary/election-security
Historical Security Breaches of Centralized Systems
In August 2016, a security failure in the Georgia voter registration database left the records of more than 6.7 million people vulnerable to cyberattacks and data breaches, and in 2016, hackers gained access to voter registration data in California and changed voters' party affiliations, leaving people unable to vote in the California primary.
Source: https://www.fortinet.com/resources/cyberglossary/election-security
---
THE CURRENT MANDATE: ALL COUNTIES MUST CONNECT TO CENTRALIZED SYSTEM
Even counties that use software from one of two state-approved private vendors to manage their voter rolls are required by state law to sync their data with TEAM daily, and have to use TEAM to verify a voter's identity and their eligibility to cast a ballot.
Source: https://www.votebeat.org/texas/2025/09/25/team-voter-registration-system-problems-county-election-officials/
Source: https://www.texastribune.org/2025/09/25/texas-voter-registration-system-TEAM-county-election-officials/
This means that even counties with functioning private vendor systems are still dependent on the centralized TEAM system's availability and security. A failure at the state level affects all 254 counties regardless of their local systems.
---
KEY RISKS OF CENTRALIZED VOTER REGISTRATION SYSTEMS
1. Single Point of Failure
All 254 counties now required to sync with TEAM. One catastrophic event at the state level could take down voter registration statewide, as warned by Denton County's election administrator.
2. Increased Attack Surface
A centralized database creates one high-value target for nation-state actors and cybercriminals instead of 254 separate, smaller targets that would require distributed attacks.
3. Cascading Failures
When the centralized system fails, it affects all counties simultaneously. The July 2025 TEAM rollout demonstrated this with counties across the state unable to process voter registrations, leaving tens of thousands of applications in limbo.
4. Loss of Local Control
County election officials who best know their communities lose autonomy and must depend on state-level systems and vendors over which they have no control.
5. Vendor Dependency
The entire state becomes dependent on a single vendor (currently Civix with a $17 million contract). If that vendor fails or experiences financial difficulties, all 254 counties are affected simultaneously.
6. Proven Vulnerability
Historical precedent from multiple states shows that centralized voter databases have been successfully breached, compromised by ransomware, or rendered non-functional by cyberattacks.
---
THE PRE-HAVA DECENTRALIZED SYSTEM ADVANTAGES
The county-based system that existed before HAVA provided critical safeguards:
Redundancy
Failure in one county didn't affect the other 253 counties. Each county maintained independent systems and backups.
Local Control
County officials who knew their communities were directly responsible for voter registration without depending on state-level systems or remote vendors.
Distributed Risk
254 separate systems meant no single point of catastrophic failure. An attacker would need to compromise 254 separate systems to affect the entire state.
Resilience
Local backups and local management meant counties could continue operations even if other counties experienced problems.
Accountability
Local officials were directly responsible to local voters and could be held accountable by their communities.
Performance
The 2007 audit showed that the previous TVRS system actually performed better than the new centralized TEAM system on 60% of benchmarks tested.
---
CURRENT CRISIS: CENTRALIZED SYSTEM FAILURE IN ACTION
The July 2025 TEAM rollout provides a real-world example of centralization dangers:
Statewide Impact
Counties across Texas simultaneously affected, unable to process voter registrations, with some counties reporting 600+ applications in backlog.
No Local Alternatives
Counties dependent on the centralized system had no backup options when it failed. Even counties with private vendors must sync with TEAM daily.
Systemic Vulnerability
Problems described as "one day it works and we can get stuff done, and the next day it doesn't and nothing gets done" - the unreliability affects all users simultaneously.
Critical Timing
Failures occurring during voter registration deadline periods, with tens of thousands of Texans waiting to have their applications processed.
Sources:
https://www.votebeat.org/texas/2025/09/25/team-voter-registration-system-problems-county-election-officials/
https://www.texastribune.org/2025/09/25/texas-voter-registration-system-TEAM-county-election-officials/
---
CYBERSECURITY EXPERTS' WARNINGS ABOUT CENTRALIZATION
CISA (Cybersecurity and Infrastructure Security Agency) identifies voter registration databases as critical election infrastructure vulnerable to:
- Ransomware attacks that deny access to voter data
- Data breaches that expose millions of voter records
- System failures during critical registration periods
- Insider threats with access to centralized systems
- Nation-state actors targeting high-value centralized databases
Source: https://www.cisa.gov/topics/election-security
Source: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections
The FBI and CISA have warned that centralized voter registration systems are prime targets for cyberattacks and have issued multiple advisories about protecting these systems.
Source: https://www.ic3.gov/PSA/2024/PSA240912
---
CONCLUSION: THE CASE FOR DECENTRALIZATION
The pre-HAVA county-based system provided inherent security through decentralization. While HAVA was enacted with good intentions to prevent voters from being "erroneously omitted from voter registration rolls," the federal mandate for centralization created a cure worse than the disease.
Current Texas law requires all 254 counties to connect daily to a single centralized system that:
- Has a documented history of performance problems since 2007
- Currently experiencing catastrophic failures preventing voter registration processing
- Creates a single point of failure that could paralyze the entire state
- Provides a high-value target for nation-state actors and cybercriminals
- Eliminates local control and accountability
- Depends on a single vendor with a $17 million contract
Pending legislation (Senate Bill 2382) would eliminate even the limited redundancy of private vendor systems, forcing all 254 counties onto the failing centralized system exclusively.
Election security experts, county election administrators, and cybersecurity professionals all warn that this centralization creates dangerous vulnerabilities. The decentralized county-based system that existed before HAVA provided superior resilience, security, and accountability.
---
RECOMMENDATIONS
1. Restore County Autonomy
Allow counties to maintain independent voter registration systems with voluntary data sharing rather than mandatory centralization.
2. Reject Mandatory Centralization
Oppose Senate Bill 2382 and similar legislation that would force all counties onto a single system.
3. Maintain Redundancy
Preserve the option for counties to use certified private vendors as backup systems.
4. Implement True Backups
Require that counties maintain complete local backups independent of the state system.
5. Learn from History
Recognize that the pre-HAVA decentralized system provided better security through distributed architecture.
6. Prioritize Resilience Over Control
Security and resilience should take priority over centralized state control and monitoring.
---
KEY SOURCES
Historical Context:
- Texas State Auditor Report 08-012 (2007): https://sao.texas.gov/reports/main/08-012.html
- Texas State Library Archives: https://www.tsl.texas.gov/arc/votersreg.html
- Government Technology Archive: https://www.govtech.com/archive/texas-election-management-system.html
Current TEAM System Problems:
- Votebeat Texas (September 2025): https://www.votebeat.org/texas/2025/09/25/team-voter-registration-system-problems-county-election-officials/
- Texas Tribune (September 2025): https://www.texastribune.org/2025/09/25/texas-voter-registration-system-TEAM-county-election-officials/
- Votebeat on SB 2382 (April 2025): https://www.votebeat.org/texas/2025/04/18/team-voter-registration-software-senate-bill-2382/
Cybersecurity Warnings:
- CISA Election Security: https://www.cisa.gov/topics/election-security
- CISA Cybersecurity Toolkit: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections
- FBI/CISA Joint Alert: https://www.ic3.gov/PSA/2024/PSA240912
- Georgia Ransomware Case: https://www.bankinfosecurity.com/ransomware-knocks-out-voter-database-in-georgia-a-15235
- Fortinet Election Security Analysis: https://www.fortinet.com/resources/cyberglossary/election-security

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.