Broadcasters should begin preparing now to comply with the FCC’s vision for cybersecurity in EAS operations.
In a Nautel webinar that’s available to watch on YouTube or at the bottom of this article, several experts said many stations will need to assess and modify current systems, security practices and operational procedures to ensure compliance before the new rules that we told you about earlier become effective on Sept. 29.
The webinar, hosted by Nautel’s Jeff Welton, looks at the FCC’s recent report and order. (That order was accompanied by a Further Notice of Proposed Rulemaking, laying out possible additional changes, as we have described in a separate series of articles.)
The order introduces requirements for components of the broadcast technology chain that connect to the internet. For stations, this includes EAS equipment, transmitters, studio-to-transmitter links, audio processing systems and other network-connected infrastructure.
The webinar, part of Nautel’s Transmission Talk Tuesday series, features attorney David Oxenford and Shane Toven, chief engineer for Cumulus Media in San Francisco.
The implications for broadcasters are significant, the participants said, and the technical nature of the updates means critical training for technology staff.
Oxenford said incidents of hacking of broadcast air chains have gained the FCC’s attention, and the new rules present the commission with more opportunities to monitor the efforts of broadcasters to prevent them.
“I think (the FCC) was getting tired of it because it’s happening … every couple of years. This gives the FCC the ability to hold the station to account, should they get hacked,” he said.
“Right now, if anything bad goes out over the air, whether it’s emergency information or not, the FCC doesn’t really have much that they can do to a broadcaster.”
The rules give the FCC “the ability to look at what you’ve done to secure your systems, and fines will be possible as the result.”
Toven said broadcasters must realize that if they can remote-control their airchain and it’s on the public internet, someone can find it.
Outdated hardware is a major concern. A statistic often cited by the FCC, Oxenford said, is that in the 2023 nationwide alert test, 23% of equipment units, representing about 4,500 EAS participants, were either using outdated software or were using equipment no longer supported by regular software updates.
“Doing patching and upgrades of both your software and hardware, whenever those patches come out or those updates come up, are critical. Making sure that they get implemented right away is going to be crucial,” Oxenford said.
The change that is likely to bring the most questions from broadcasters is a requirement to use a firewall around program airchains, “specifically around your EAS equipment, to give you an extra layer of security so that it can’t be hacked.”
There is ambiguity in the wording of the FCC’s order, Oxenford says, as to whether firewalls are mandatory only for EAS equipment or the entire program airchain.
“The rule does seem to say that the entire program chain should be behind this firewall, and I think that’s probably the best practice. But whether that’s actually the obligation, it’s a little bit unclear from the order. That’s something that will hopefully be clarified at some point.”
Toven says that at a minimum, broadcasters must install a firewall to protect EAS equipment,
“There are some inexpensive solutions, even buying just the smallest cheapo small home office firewall you can get from the big box store. Then don’t poke holes in it like Swiss cheese. And try to learn tools like VPN,” he said.
“And again, it’s just another tool in the arsenal, and there are a bunch of there are about a million different ways to do this.”
In addition, Toven says, eliminate default or weak credentials. Use strong authentication.
He said the order requires default passwords for EAS equipment to be changed and new passwords to have a minimum of 15 characters, with no dictionary words.
The FCC states that broadcasters need to segment the EAS system from the rest of the office operations, Oxenford said.
“For example, if you’re at a TV station, the news guys who are downloading all sorts of stuff from the internet to prepare their stories and accidentally download something that they shouldn’t have downloaded. That can corrupt your entire system, including your EAS equipment.”
The cybersecurity order also requires stations to change any password that they suspect has been compromised.
“One aspect that stations ought to be thinking about is changes in employees, if you’ve got any disgruntled former employees,” Toven said.
“When one of your employees leaves, no longer part of your system, no longer bound by contract or any obligation to you, they’ve got the password. Change it so that nobody else can access that equipment.”
Among other recommendations made during the webinar are to establish separate admin and user accounts on hosts; segment a network with multi-layer security zones; use packet filtering to control host access; disable unused services and close unused ports; use secure access; and use VPN for off-site access.
Compliance enforcement of these rules is an unknown.
“Is the FCC going to be out there probing everybody’s networks to see if they can get in? They don’t have the people to do that, so I find that doubtful,” Oxenford said. “I don’t think the FCC is going to be out there auditing stations to find out what they’ve got.”
So how might broadcasters run into trouble?
“One is if you get hacked and suddenly those zombie alerts are going out over your station. The FCC is going to say, ‘Hey, what did you do for our three required obligations? Did you have your passwords? Did you update your equipment? Did you have EAS behind the firewall?’ And if you can’t provide that answer, you’re looking at some fines,” Oxenford said.
If a station does get hacked, broadcaster responsibilities go beyond FCC obligations.
“There are state and federal obligations if people get into your systems, get into your accounting systems, or get into other systems that have personal information about your listeners or viewers,” he said.
“You just want to avoid those situations because there are liability issues, notice issues and trust issues that arise.”
The webinar also covered the further proposed changes explored in the Radio World series, including one that would allow EAS participants to use software-based encoder/decoder technology to process alerts instead of hardware boxes.
The webinar is available on Nautel’s YouTube page or you can view it below.