In early July, we wrote about the FCC’s decision to require that all broadcasters take measures to secure their EAS operations – and in the process secure their entire program chain – to make sure that malicious actors can’t hack into their systems and send false alerts. The FCC today published in the Federal Register the order making those changes, which will require broadcasters to meet these security requirements in 60 days – by September 29.
By that date, the FCC requires that broadcasters have strong passwords for any part of their program chain that is connected to the internet, that they have the latest security updates installed in all hardware and software, and that they put all access to their program chain behind a firewall. We wrote about the FCC’s decision and what is required back in early July and, now that the deadline for compliance is set, we reprint below much of that article to remind broadcasters of the details of what they need to do by the September 29 deadline:
At its regular monthly open meeting [in June], the FCC adopted an Order meant to enhance the security of the Emergency Alerting System. Citing past hacks of the system that have resulted in false EAS alerts being transmitted to the public by broadcast stations, the FCC proposed in 2022 that broadcasters adopt a comprehensive cybersecurity plan with an annual filing requirement detailing how risks were managed and controlled (see our article here). The Order adopted this week did not go that far, but it did adopt a mandatory three-point plan to secure not only EAS equipment at a station, but also to secure the entire program chain to ensure that bad actors can’t access station programming to insert false emergency information or other malicious content.
While the first two requirements of the mandated plan should be relatively simple for broadcasters to quickly implement, the third may require some outside help – and the FCC has given broadcasters only a short time to implement this requirement. The Order requires implementation within 60 days of the date that the Order is published in the Federal Register (see the just-released FCC Erratum correcting the Order to reiterate that the effective date will be 60 days after Federal Register publication). As Federal Register publication should come soon, the Order requires quick action by broadcasters. Let’s look at the new obligations.
Continue Reading New Security Obligations for Broadcasters Required by September 29 – Strong Passwords, Updated Software and Hardware, and Firewalls to Protect All Parts of the Program Chain