• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

New Security Obligations for Broadcasters Required by September 29 – Strong Passwords, Updated Software and Hardware, and Firewalls to Protect All Par

Commonground

Senior Moderator
July 31, 2026


In early July, we wrote about the FCC’s decision to require that all broadcasters take measures to secure their EAS operations – and in the process secure their entire program chain – to make sure that malicious actors can’t hack into their systems and send false alerts. The FCC today published in the Federal Register the order making those changes, which will require broadcasters to meet these security requirements in 60 days – by September 29.

By that date, the FCC requires that broadcasters have strong passwords for any part of their program chain that is connected to the internet, that they have the latest security updates installed in all hardware and software, and that they put all access to their program chain behind a firewall. We wrote about the FCC’s decision and what is required back in early July and, now that the deadline for compliance is set, we reprint below much of that article to remind broadcasters of the details of what they need to do by the September 29 deadline:

continued: https://www.broadcastlawblog.com/20...ls-to-protect-all-parts-of-the-program-chain/

 
Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats


A Rule by the Federal Communications Commission on 07/31/2026


snip


Today, we adopt three targeted measures that aim to ensure that EAS Participants secure their equipment to prevent cyberattacks that could result in the transmission of false EAS alerts or disrupt the transmission of legitimate alerts. Specifically, we require EAS Participants to do the following with respect to EAS equipment, studio transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the EAS Participant's programming stream: (1) prior to operation, change any default password, use strong passwords, and change any password if the EAS Participant has reason to believe that the password has been compromised; (2) test and install security patches and security-related software and firmware upgrades issued by equipment manufacturers promptly after those patches or upgrades become available; and (3) use a network firewall or comparable network segmentation practice to limit remote management access to authorized devices and authorized users.



These three requirements represent a subset of the six basic cybersecurity hygiene requirements that the Commission proposed to require EAS Participants to implement as part of their cybersecurity risk management plans in the Alerting Security NPRM. In the Alerting Security NPRM, the Commission proposed to require EAS Participants to implement these cybersecurity measures in the context of their implementation of broader cybersecurity risk management plans. The Commission sought comment on whether that approach “strik[es] the appropriate balance between improving EAS security, complementing EAS Participants' existing cybersecurity activities, and reducing burdens on small EAS Participants?” In response, commenters express concern that compliance with precise cybersecurity risk management requirements would be costly, could hinder their ability to adapt to changing cybersecurity needs, and could subject them to strict liability enforcement in the event an EAS Participant is victimized by a cyberattack. The approach we adopt today responds to those concerns by eliminating the broader cybersecurity risk management and threat assessment components of the proposed requirement, as well as the proposed requirements that EAS Participants employ “sufficient security controls to ensure the confidentiality, integrity, and availability of the EAS.”​

snip

more....https://www.federalregister.gov/doc...cting-the-nations-communications-systems-from
 
Back
Top