FCC mandates EAS cybersecurity baseline after years of broadcast hijacks
The FCC has adopted new cybersecurity rules for broadcast equipment (EAS encoders/decoders, STLs) mandating strong passwords, firewalls, and prompt security patching. A Further Notice of Proposed Rulemaking also explores EAS geotargeting improvements and software-based alerting. Compliance is required 60 days after Federal Register publication.
Key Takeaways
- Three mandates: 15-character minimum passwords with no dictionary words, prompt manufacturer patch installation, and firewalls or comparable network segmentation for all EAS and STL equipment.
- Compliance deadline: 60 days after Federal Register publication; NPRM comments due 30 days after, reply comments 30 days after that.
- Rules scale back a 2022 proposal that would have required comprehensive cybersecurity risk management plans — a burden REC Networks argued was excessive for small stations.
- NPRM proposes allowing software-based EAS instead of dedicated FCC-certified hardware, potentially including open-source solutions built by broadcasters themselves.
- Equipment manufacturers Digital Alert Systems and Sage have not indicated whether firmware updates related to compliance will be free of charge.
Why It Matters
Broadcasters now face a federal cybersecurity floor for EAS and STL equipment — covering everything from DASDEC encoders to Barix streaming boxes that have been repeatedly hijacked to air false alerts and obscene content. The scaled-back approach replaces a broader risk-management-plan requirement that small stations opposed, landing on three specific controls instead. The NPRM's proposal to allow software-based EAS could eventually reduce dependence on purpose-built hardware from vendors like Digital Alert Systems and Sage, potentially lowering costs and accelerating patch deployment. Watch whether manufacturers charge for compliance-related firmware updates.
Additional Context
The FCC's June 26 vote follows a November 2025 Public Safety and Homeland Security Bureau notice that urged broadcasters to adopt basic cybersecurity practices after a string of hijacks. Per Radio World (November 2025), two high-profile incidents saw Houston's ESPN 97.5 KFNC(FM) and Richmond's Radio IQ affiliate WRIQ(FM) compromised through improperly secured Barix STL equipment, resulting in the broadcast of false EAS tones and a song containing racist lyrics. Barix CEO Johannes Rietschel told Radio World that stations failing to use VPNs or exposing the Barix configuration interface to the internet would continue to be targeted. Earlier incidents in September 2025, also reported by Radio World, hit smaller stations including KRLL(AM) in California, Missouri, and KPOG(LP) in Des Moines, Iowa, where a listener called in to report obscene music and a fake EAS message airing over a religious broadcast. KPOG's Bob Carr said the station's Barix Exstreamer was port-forwarded and password-protected, but the attacker changed the password and forced a factory reset. The FCC's circulation draft, released June 4, 2026, notes that REC Networks identified 730 EAS servers with exposed Sage ENDEC login pages, 288 of them on port 80 — underscoring how easily discoverable the equipment remains. The National Association of Broadcasters, which petitioned the FCC in March 2025 to allow software-based EAS implementations, praised the adopted rules as "reasonable safeguards." NAB President Curtis LeGeyt said in a June 26 statement that software-based systems would help stations deploy security updates more quickly and reduce equipment downtime. Chairman Brendan Carr noted at a post-meeting press conference that moving EAS from expensive bespoke hardware to software could reduce costs, per Newscast Studio (June 2026).
Read full article at recnet.substack.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source