The FCC, exasperated by cyberattacks on EAS equipment that “continue to occur with disturbing frequency,” appears ready to issue several new requirements.
It is expected to mandate that radio stations, TV stations and other Emergency Alert System participants install network firewalls on EAS equipment as well as other potential weak links like STLs that carry EAS content.
Stations would also be required to change default passwords on their EAS systems, and to test and install security patches and upgrades from equipment manufacturers promptly.
These requirements are in a draft report and order. The FCC plans to vote on it at its June 25 meeting.
According to the draft, the order “aims to preserve the public’s trust in EAS by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation’s adversaries.”
This is a scaled-back version of an earlier proposal that included broader cyber management and threat assessment components. But it still has teeth.
In the draft, the FCC writes that for years it has been urging EAS participants to implement basic cybersecurity hygiene but that some have still not taken adequate precautions.
“Despite our repeated efforts urging EAS participants to take basic steps to secure their networks … successful attacks have continued into 2026.”
The draft notes that bad actors have gained control of radio broadcasters’ systems “by exploiting improperly secured, remotely accessible equipment in the broadcast signal processing system to transmit unauthorized audio that included EAS alert tones, an offensive song that included racial slurs and promotional content.”
Here’s more on the pending requirements:
Passwords — If adopted, the order will require that “default passwords for EAS equipment, studio transmitter link equipment and any remotely managed equipment that routes, processes or inserts content into the EAS participant’s programming stream be changed prior to any use to broadcast to the public.”
Passwords would have to have a minimum of 15 characters, not use dictionary words and not be reused elsewhere.
The plan would allow stations to use certain alternative authentication measures as highlighted by the National Institute of Standards and Technology.
Firmware and Software Patching — “Prompt firmware and software patching are key to reducing the risk that bad actors will exploit known vulnerabilities to infiltrate broadcast and cable systems to insert false EAS tones or alerts.”
If adopted, the order will make EAS participants responsible for ensuring that their devices are properly patched and updated, “regardless of the devices’ provenance.”
Use of a Firewall or Comparable Network Segmentation — If adopted, the order will require stations and other EAS participants “to use a network firewall or comparable network segmentation practices to limit remote management access to authorized devices and authorized users, which will secure EAS and other vulnerable equipment on a private network inaccessible to the public internet.”
It said this requirement addresses a widespread EAS vulnerability. It noted that REC Networks had identified 730 EAS participant servers through which the password screen for Sage Alerting Systems’ ENDEC EAS device was directly exposed. Many of those operated on the default port for HTTP web services, making it “easy and cheap” for bad actors to find EAS equipment.
Stations would need to ensure that their EAS equipment is secured behind a firewall or other segmentation mechanism, “such as a dedicated Virtual Local Area Network (VLAN), demilitarized zone or physically isolated management network,” with access restricted to only those internal systems and ports necessary for EAS operations.
EAS participants would have to either “deploy a hardware or software firewall with appropriate filters, reconfigure existing routers to block inbound public internet connectivity to EAS devices, or otherwise isolate EAS equipment from general‑purpose business networks so that unauthorized external access is not possible.”
More details
The FCC emphasized that these proposed changes go beyond EAS hardware. “[U]nprotected studio transmitter link equipment and remotely managed equipment that routes, processes or inserts content into the EAS participant’s programming stream create similar opportunities to transmit false alerts or disrupt the transmission of real alerts.”
The draft also acknowledges that many participants already follow good security practices. “But EAS is only as secure as its weakest link,” it states, and a false alert could be passed to other participants.
The commission wrote that the pending requirements are particularly important to protect participants that are small- and medium-sized businesses that may not have significant cybersecurity resources. “Smaller broadcasters with fewer security protections in place are often a more attractive target for bad actors, as the recent attacks on small radio broadcasters demonstrate.”
The FCC did not agree with the NAB’s suggestion that the commission focus on doing targeted outreach to participants that use outdated software or unsupported equipment.
The commission believes the changes won’t be burdensome to broadcasters and others in the EAS ecosystem. It estimated the industry-wide cost at $26 million, noting that some participants may incur costs to implement firewalls or comparable network segmentation practices.
The draft does not apply these rules to Wireless Emergency Alerts. “While a 2016 report on WEA’s security found risks of blocking valid WEA messages, changing the content of a valid WEA message, injecting false WEA alerts into operator equipment, and sending false alerts from false base stations, there have been no reported instances of those kinds of attacks on WEA being successful.”
The draft also does not propose that EAS participants must report incidents of unauthorized access of their systems, as proposed earlier. It said such a rule may be premature in light of pending rules from the Cybersecurity and Infrastructure Security Agency implementing new cyber incident reporting requirements.
Here’s a link to the draft report and order, along with a pending notice of proposed rulemaking with additional important changes for EAS and WEA. Read our companion story about those possible changes here.