Key Takeaways
- The FCC’s new cybersecurity order targets any broadcast‑technology component that connects to the internet, including EAS gear, transmitters, STL links, audio processors and related network infrastructure.
- Stations must keep software and firmware up‑to‑date, applying patches as soon as they are released; outdated or unsupported equipment was a factor in the 2023 nationwide alert test, where 23 % of EAS units fell short.
- A firewall (or equivalent network‑segmentation device) is required to protect the EAS airchain; the exact scope—whether it covers only EAS equipment or the entire program chain—remains ambiguous but is considered best practice to protect the whole chain.
- Default or weak credentials must be eliminated; new passwords for EAS equipment must be at least 15 characters long and contain no dictionary words, and any suspected‑compromised password must be changed immediately.
- Broadcasters should segment the EAS system from office IT networks to prevent malware introduced by routine activities (e.g., news‑room downloads) from reaching critical alert equipment.
- Additional hardening steps include creating separate admin and user accounts, using packet filtering, disabling unused services/ports, employing VPNs for remote access, and enforcing strong authentication mechanisms.
- While the FCC may not proactively audit every station, non‑compliance will become evident if a hack occurs; fines can be imposed for failing to meet the three core obligations (patch management, firewall protection, and credential security).
- Beyond FCC penalties, a breach can trigger state and federal data‑protection laws, create liability exposure, and damage audience trust.
- The order also opens the door for software‑based EAS encoder/decoder solutions, potentially reducing reliance on legacy hardware boxes.
- Practical, low‑cost measures—such as installing a modest SOHO firewall, changing default passwords, and using VPNs—can satisfy many of the requirements when implemented consistently.
FCC’s Evolving Cybersecurity Vision for EAS
The Federal Communications Commission has moved from advisory guidance to enforceable rules aimed at securing the Emergency Alert System (EAS) against cyber threats. In a recent Nautel webinar, attorney David Oxenford and Cumulus Media chief engineer Shane Toven explained that the FCC’s Report and Order—paired with a Further Notice of Proposed Rulemaking—responds to a pattern of hacking incidents that have repeatedly compromised broadcast air chains. The commission now seeks to hold stations accountable for the security of any internet‑connected link in the broadcast technology chain, recognizing that outdated or poorly protected equipment can be leveraged to send false alerts or disrupt service.
Scope of the New Requirements
The order explicitly covers components that connect to the public internet: EAS encoders/decoders, transmitters, studio‑to‑transmitter links (STLs), audio processing systems, and any other network‑ed infrastructure that forms part of the broadcast signal path. By defining the scope this broadly, the FCC intends to close gaps where a vulnerability in a seemingly peripheral device (e.g., a poorly secured STL router) could be used to reach the EAS encoder. Stations must therefore inventory all internet‑facing assets and assess their patch levels, configuration, and exposure.
Why the FCC Is Acting Now
Oxenford noted that the commission has observed a recurring cycle of broadcast‑air‑chain hacks roughly every few years, prompting frustration over the lack of enforcement tools. “Right now, if anything bad goes out over the air… the FCC doesn’t really have much that they can do to a broadcaster,” he said. The new rules give the agency the authority to examine a station’s security posture and levy fines if required safeguards are missing or improperly implemented. This shift transforms cybersecurity from a voluntary best‑practice effort into a regulatable obligation with clear financial consequences.
Patch Management and Firmware Updates
A cornerstone of compliance is timely software and hardware patching. Oxenford cited the FCC’s statistic that 23 % of EAS units in the 2023 nationwide alert test were running outdated or unsupported software, representing roughly 4,500 participants. He stressed that “doing patching and upgrades of both your software and hardware, whenever those patches come out or those updates come up, are critical. Making sure that they get implemented right away is going to be crucial.” Stations should establish a change‑management process that tests patches in a lab environment before deployment and documents the update timeline for potential audits.
Firewall Protection for the EAS Airchain
The order’s most discussed provision mandates a firewall around the EAS equipment. Oxenford highlighted ambiguity in the rule’s wording: it is unclear whether the firewall must shield only the EAS box or the entire program airchain. He advised treating the whole chain as the protected zone, noting that “the rule does seem to say that the entire program chain should be behind this firewall, and I think that’s probably the best practice.” Toven added that even an inexpensive SOHO firewall from a big‑box store can satisfy the requirement, provided administrators avoid “poking holes in it like Swiss cheese” and complement it with tools such as VPNs for secure remote access.
Credential Hygiene and Password Policies
Default or weak credentials remain a common attack vector. The FCC now requires that all default passwords on EAS gear be changed and that new passwords meet a minimum length of 15 characters, with no dictionary words permitted. Stations must also change any password they suspect has been compromised—especially when personnel depart. Toven warned that a former employee who still knows a password can become an insider threat, so immediate credential rotation upon termination is essential. Additionally, creating separate administrative and user accounts on hosts reduces the risk of privilege escalation.
Network Segmentation and Isolation from Office IT
To prevent malware introduced by everyday office activities (e.g., news‑room downloads) from reaching critical alert systems, the order obliges stations to segment the EAS system from the rest of the office network. Oxenford illustrated the risk: “If you’re at a TV station, the news guys who are downloading all sorts of stuff from the internet to prepare their stories and accidentally download something that they shouldn’t have downloaded. That can corrupt your entire system, including your EAS equipment.” Implementing VLANs, access‑control lists, or dedicated physical routers creates a security boundary that limits lateral movement should a workstation become compromised.
Additional Hardening Measures
Beyond firewalls and password policies, the webinar highlighted a suite of best practices: employing packet filtering to control which hosts can communicate with EAS devices; disabling unused services and closing unnecessary ports; using strong authentication mechanisms (e.g., multi‑factor authentication where feasible); and utilizing VPNs for any off‑site access to the broadcast chain. Toven emphasized that “there are about a million different ways to do this,” encouraging stations to adopt a layered‑defense approach where each control mitigates a different class of threat.
Compliance Enforcement and the Risk of Fines
While Oxenford doubts the FCC will launch broad, proactive network‑probing campaigns, he warned that enforcement will become apparent after an incident. “If you get hacked and suddenly those zombie alerts are going out over your station… the FCC is going to say, ‘Hey, what did you do for our three required obligations? Did you have your passwords? Did you update your equipment? Did you have EAS behind the firewall?’ And if you can’t provide that answer, you’re looking at some fines.” Thus, the practical test of compliance is the ability to demonstrate adherence to patch management, firewall placement, and credential security when an actual breach occurs.
Broader Liability Beyond FCC Penalties
A cyber intrusion can trigger obligations far exceeding FCC fines. Oxenford pointed out that state and federal data‑protection laws may apply if attackers gain access to accounting systems, listener/viewer personal information, or other sensitive databases. Consequently, stations face potential civil liability, mandatory breach‑notification requirements, and reputational harm that could erode audience trust. Investing in robust cybersecurity not only satisfies the FCC but also mitigates these wider risks.
Future‑Looking Changes: Software‑Based EAS Solutions
The webinar also touched on the Further Notice of Proposed Rulemaking, which explores allowing EAS participants to replace traditional hardware encoder/decoder boxes with software‑based alternatives. Such a shift could lower costs and increase flexibility, but it would also introduce new security considerations—particularly around securing the host operating system and ensuring software integrity. Stations considering this path must evaluate how the proposed changes interact with the existing firewall, patching, and segmentation requirements.
Practical Steps and Resources
In summary, broadcasters should begin by inventorying all internet‑connected broadcast assets, establishing a rigorous patch‑management workflow, installing a firewall (preferably protecting the entire program chain), enforcing strong, unique credentials, segmenting the EAS network from office IT, and adopting additional hardening techniques like packet filtering, VPNs, and disabling unused services. The Nautel webinar—available on Nautel’s YouTube channel and embedded below—offers a detailed walk‑through of these concepts and serves as a valuable starting point for stations aiming to meet the FCC’s September 29 deadline. By acting now, broadcasters can avoid penalties, reduce the likelihood of false alerts, and protect both their operations and their audiences from the growing threat of cyber attacks.

