Radio stations and other EAS participants now have additional cybersecurity rules to follow that may affect their EAS and STL equipment.
We reported earlier that these changes were pending. Now the FCC has approved them by unanimous vote. It also has put forth several additional possible changes for public discussion.
“Requiring stronger password practices, timely software updates and improved security controls will help reduce opportunities for bad actors to exploit weaknesses in alerting equipment,” Chairman Brendan Carr said.
He reminded people of the time years ago when some television viewers received a fake alert about a zombie apocalypse.
“While the FCC has worked to ensure that vulnerabilities in EAS and Wireless Emergency Alerts are addressed, there have been additional instances of alerting and broadcast systems being compromised or manipulated, including recent attacks that used emergency alert tones and related broadcast equipment to transmit unauthorized content,” he said in a statement.
“These attacks are a stark reminder that threats continue to evolve and our work must continue.”
The FCC has said that for years it has been urging EAS participants to implement basic cybersecurity hygiene but that some have still not taken adequate precautions.
This is a scaled-back version of an earlier proposal that included broader reporting and threat assessment components. The National Association of Broadcasters called the new standards “reasonable safeguards.”
The requirements are described below, based on the text of the draft that was issued before the FCC meeting. The rules take effect 60 days after pending publication in the Federal Register.
Passwords — The order requires that “default passwords for EAS equipment, studio transmitter link equipment and any remotely managed equipment that routes, processes or inserts content into the EAS participant’s programming stream be changed prior to any use to broadcast to the public.”
Passwords will have to have a minimum of 15 characters, not use dictionary words and not be reused elsewhere.
The plan allows stations to use certain alternative authentication measures as highlighted by the National Institute of Standards and Technology.
Firmware and Software Patching — “Prompt firmware and software patching are key to reducing the risk that bad actors will exploit known vulnerabilities to infiltrate broadcast and cable systems to insert false EAS tones or alerts.”
The order makes EAS participants responsible for ensuring that their devices are properly patched and updated, “regardless of the devices’ provenance.”
Use of a Firewall or Comparable Network Segmentation — The order requires stations and other EAS participants “to use a network firewall or comparable network segmentation practices to limit remote management access to authorized devices and authorized users, which will secure EAS and other vulnerable equipment on a private network inaccessible to the public internet.”
Stations will need to ensure that their EAS equipment is secured behind a firewall or other segmentation mechanism, “such as a dedicated Virtual Local Area Network (VLAN), demilitarized zone or physically isolated management network,” with access restricted to only those internal systems and ports necessary for EAS operations.
Participants will have to either “deploy a hardware or software firewall with appropriate filters, reconfigure existing routers to block inbound public internet connectivity to EAS devices, or otherwise isolate EAS equipment from general‑purpose business networks so that unauthorized external access is not possible.”
The FCC emphasized that these changes go beyond EAS hardware. “[U]nprotected studio transmitter link equipment and remotely managed equipment that routes, processes or inserts content into the EAS participant’s programming stream create similar opportunities to transmit false alerts or disrupt the transmission of real alerts.”
Here is a link to the approved report and order.
More possible changes
The FCC also has opened a further notice of proposed rulemaking to discuss additional changes, including the idea of allowing EAS to be implemented in software (though not in the cloud) and possibly expanding the use of geotargeting in EAS.
We reported earlier on this plan, and now the commission officially has opened the FNPRM.
Chairman Carr said that these additional proposed reforms “can improve the integrity, resilience and effectiveness of emergency alerts, including improving geographic accuracy of alerts, improving the detection and blocking of duplicate alerts, and removing outdated and unnecessary alerting requirements to help encourage broader participation in alerting.”
The text states: “We believe that as the industry shifts toward IP‑centric architectures, it is important that the commission consider whether there is an opportunity to modernize EAS processing better to support public safety and to improve operational efficiency for EAS participants.”
“We propose to allow EAS participants to install EAS software in a single device (e.g., a server or computer) that manages EAS functions within the EAS participant’s signal processing system,” the FCC wrote.
“Alternatively, we propose to allow EAS software to be installed across multiple components within that system, thus enabling integration of different EAS functions across multiple system components.”
The National Association of Broadcasters had petitioned the FCC to explore a software option. President/CEO Curtis LeGeyt said on Thursday, “By allowing broadcasters to deploy security updates more quickly, reduce equipment downtime and strengthen system redundancy, this proposal can help ensure stations are better positioned to deliver critical emergency information when communities need it most.”
The FCC proposes to require that EAS software be located at the participant’s local facility, which for broadcasters will mean the studio or transmitter site associated with its licensed service area. It would not allow cloud-based EAS.
The FNPRM also proposes to:
Require the authentication of EAS alerts before they are transmitted — “To better secure EAS against cyberattacks, we propose to require EAS participants to reject CAP EAS messages that do not include a valid digital signature.”
Establish a universal alert identification number — This would be “to improve the detection and blocking of duplicate alerts and ensure that WEAs are consistently sent to members of the public who newly enter an alert’s delivery area until the emergency ends.”
Eliminate “outdated WEA geotargeting exceptions that often cause alerts to be received in the wrong locations”
Expand geotargeting options for EAS — “We propose to improve the accuracy of EAS geotargeting by permitting, but not requiring, EAS participants to take advantage of detailed location information that is often available in CAP EAS messages.”
Alerting authorities and EAS equipment manufacturers, the FCC said, believe EAS is being underutilized because of its limited geotargeting capabilities. Improvements to EAS geo-targeting could reduce alert fatigue and make alerts more relevant. The notice also proposes to consider new EAS location codes to make messages more understandable to local communities.
Require EAS and WEA to display symbols that match the type of emergency and improve the effectiveness of earthquake alerts to grab the public’s attention — “We expect that the use of symbols could potentially improve comprehension for people with disabilities and people with limited English reading proficiency, hasten public reactions to alerts and reduce milling.”
Retire the 90-character maximum versions of WEA messages.
In the final text, the further notice of proposed rulemaking begins on page 26, paragraph 41.
Public comments can be filed in the FCC’s online system in PS Dockets 25-224, 15-94 and 15-91.