WASHINGTON, D.C. — Broadcasters have until September 29 to meet new Federal Communications Commission cybersecurity requirements affecting far more than the box that receives Emergency Alert System messages.
The Federal Communications Commission (FCC) has clarified that the deadline can reach remotely accessible equipment used to route, process or insert a station’s public program stream. That can include studio-to-transmitter links, audio processors, advertising-insertion systems and remotely managed AM, FM and digital television transmitters.
The rule does not automatically cover every internet-connected device inside a station. The key question is whether compromised equipment could prevent, alter or interrupt the transmission of an Emergency Alert System (EAS) message.
A six-day security checklist
Stations should immediately identify remotely accessible systems, replace default or shared passwords, disable unused accounts, confirm firewall restrictions, document vendor access and determine whether unsupported equipment can still receive security updates.
Management should also know who can reach each critical device, whether multifactor authentication is available and how a compromised remote connection can be isolated without taking the station off the air.
The FCC’s clarification is especially consequential for smaller broadcasters that may have treated alerting equipment as a narrow compliance function. Modern broadcast plants connect automation, transmitters, processors and remote-control systems across the same operating chain.
Internet-only radio stations are not listed as EAS Participants under the current rule. Licensed broadcast stations, however, remain responsible for their regulated over-the-air operations even when they also distribute programming online.
Read the FCC cybersecurity requirements FAQ and Radio World’s technical report.
