At its regular monthly open meeting last week, the FCC adopted an Order meant to enhance the security of the Emergency Alerting System.  Citing past hacks of the system that have resulted in false EAS alerts being transmitted to the public by broadcast stations, the FCC proposed in 2022 that broadcasters adopt a comprehensive cybersecurity plan with an annual filing requirement detailing how risks were managed and controlled (see our article here).  The Order adopted this week did not go that far, but it did adopt a mandatory three-point plan to secure not only EAS equipment at a station, but also to secure the entire program chain to ensure that bad actors can’t access station programming to insert false emergency information or other malicious content. 

While the first two requirements of the mandated plan should be relatively simple for broadcasters to quickly implement, the third may require some outside help – and the FCC has given broadcasters only a short time to implement this requirement.  The Order requires implementation within 60 days of the date that the Order is published in the Federal Register (see the just-released FCC Erratum correcting the Order to reiterate that the effective date will be 60 days after Federal Register publication).  As Federal Register publication should come soon, the Order requires quick action by broadcasters.  Let’s look at the new obligations.

Continue Reading FCC Adopts Order to Secure EAS System – Broadcasters’ Program Chain Must Be Behind Firewall Soon

Here are some of the regulatory developments of significance to broadcasters from the past week, with links to where you can go to find more information as to how these actions may affect your operations.

At each of the last two of the FCC’s recent regular monthly open meetings, the Commission addressed EAS issues that affect broadcasters. In one case, it adopted new rules that will, among other things, require that broadcasters use on-air the “IPAWS” internet-delivered emergency message in the CAP format, if the broadcaster receives the alert in both the CAP and traditional over-the-air formats.  The second action starts a rulemaking to look at imposing on broadcasters an obligation to secure their EAS systems from hacking and other electronic intrusions – and to regularly report to the FCC about what they are doing in connection with such security measures.  Let’s look in a little more depth at these actions (which we have previously briefly summarized in our weekly updates, here and here).

At its September 29 open meeting, the FCC adopted a Report and Order with the announced intention of making emergency alerts delivered over television and radio stations more informative and easier to understand by the public, particularly people with disabilities. The updated rules require broadcasters, cable systems, and other Emergency Alert System participants to transmit the Internet-based version of alerts when available (those transmitted through the internet based Integrated Public Alert and Warning System, “IPAWS,” using the Common Alerting Protocol or “CAP” protocol)  rather than transmitting the legacy over-the-air “daisy chain” version of alerts which often contain less information or have lower quality than that of CAP-delivered alerts.  As noted by the FCC, the CAP format allows for more information, including video clips (for TV), augmented warning information, and even foreign-language versions of alerts to be transmitted – information not available from alerts that are transmitted over-the-air.
Continue Reading FCC Looks at EAS Rules – Requires That Broadcast Alerts Default to CAP, and Seeks Comments on Securing the System

Last week, both the FCC and FEMA issued notices to broadcasters, cable and other EAS participants that there was a vulnerability in the EAS technologies that could make those systems subject to hacking, potentially allowing bad actors to send out messages to the public using the alerting system (see FCC notice here and FEMA notice