Important changes are coming to the Emergency Alert System, changes that will affect your station.
For one thing, the FCC is exasperated by cyberattacks on EAS equipment that “continue to occur with disturbing frequency.” So it is getting ready to issue several new requirements this week.
At its meeting this Thursday, the commission is expected to mandate that radio stations, TV stations and other Emergency Alert System participants install network firewalls on EAS equipment as well as other potential weak links like STLs that carry EAS content.
If this order is approved (as I fully expect), stations also will be required to change default passwords on their EAS systems, and to test and install security patches and upgrades from equipment manufacturers promptly.
Maybe you already follow all of these practices. But it’s clear that many stations do not.
In its draft, the FCC writes that for years it has been urging EAS participants to implement basic cybersecurity hygiene but that some have still not done so.
“Despite our repeated efforts urging EAS participants to take basic steps to secure their networks … successful attacks have continued into 2026.”
It notes that bad actors have gained control of radio station systems “by exploiting improperly secured, remotely accessible equipment in the broadcast signal processing system to transmit unauthorized audio that included EAS alert tones, an offensive song that included racial slurs and promotional content.”
The expected order will require that “default passwords for EAS equipment, studio transmitter link equipment and any remotely managed equipment that routes, processes or inserts content into the EAS participant’s programming stream be changed prior to any use to broadcast to the public.”
Passwords would have to have a minimum of 15 characters, not use dictionary words and not be reused elsewhere (though the plan would also allow stations to use certain alternative authentication measures as highlighted by the National Institute of Standards and Technology).
The order will require stations to implement firmware and software patching promptly, to reduce the risk that someone can exploit vulnerabilities to infiltrate broadcast and cable systems to insert false EAS tones or alerts.
And it will require stations and other EAS participants “to use a network firewall or comparable network segmentation practices to limit remote management access to authorized devices and authorized users, which will secure EAS and other vulnerable equipment on a private network inaccessible to the public internet.”
It said that REC Networks had identified 730 EAS participant servers through which the password screen for Sage Alerting Systems’ ENDEC EAS device was directly exposed. Many of them operated on the default port for HTTP web services, making it “easy and cheap” for bad actors to find EAS equipment.
Stations would need to ensure that their EAS equipment is secured behind a firewall or other segmentation mechanism, “such as a dedicated Virtual Local Area Network (VLAN), demilitarized zone or physically isolated management network,” with access restricted to the internal systems and ports that are necessary for EAS operations.
EAS participants would have to either “deploy a hardware or software firewall with appropriate filters, reconfigure existing routers to block inbound public internet connectivity to EAS devices, or otherwise isolate EAS equipment from general-purpose business networks so that unauthorized external access is not possible.”
The FCC emphasized that these changes go beyond your EAS box. It said unprotected studio transmitter link equipment and remotely managed equipment that “routes, processes or inserts content into the EAS participant’s programming stream” also create opportunities to transmit false alerts or disrupt alerts.
Watch your daily Radio World SmartBrief for coverage of the expected FCC vote in late June. If you’re not already getting it, sign up now.
Separately the commission is exploring several other important changes to EAS and to Wireless Emergency Alerts. It’s doing so in a further notice of proposed rulemaking that it is expected to launch at the meeting in June.
One notable change would allow the implementation of EAS capabilities via software instead of hardware — though not in the cloud.
[Related: “Sage Alerting Presents Software-Based EAS to the FCC”]
“We believe that as the industry shifts toward IP-centric architectures, it is important that the commission consider whether there is an opportunity to modernize EAS processing better to support public safety and to improve operational efficiency for EAS participants,” the draft FNPRM states.
The National Association of Broadcasters has pressed the FCC to offer this option, and the idea has been a focus of much discussion among the broadcast alerting community. Now the FCC is taking the issue up officially, along with several other changes to EAS.
If the notice is approved, it will take public comment on a host of specific questions about how it all would work. We’ll be covering this in more detail soon.
Comment on this or any article. Email [email protected].