Broadcasters preparing for new cybersecurity rules taking effect Sept. 29 are being warned not to view the requirements as simply an EAS equipment upgrade. Experts say stations may need to examine virtually their entire air chain to ensure equipment that could be used to hijack programming is adequately protected.
That was one of the takeaways from a webinar hosted by the National Association of Broadcasters and the National Alliance of State Broadcasters Associations, offering practical guidance on complying with the Federal Communications Commission’s new Emergency Alert System cybersecurity rules. The requirements call for strong passwords, prompt installation of security patches and updates, and firewalls or comparable network segmentation to limit unauthorized remote access.
The requirements apply not only to EAS equipment, but also to studio-transmitter links and other remotely managed equipment capable of routing, processing or inserting content into a station’s programming stream.
“You have to look at that entire air chain and effectively every device,” said Wayne Pecena, Associate Director of Engineering for KAMU-FM & TV Austin. While a simple facility might only need to secure its EAS encoder-decoder, Pecena said the typical modern broadcast plant is considerably more complicated. “From a simplistic standpoint, it’s far more than just the EAS box,” he said.
Passwords Are Only The Beginning
The FCC adopted the requirements in June as a minimum cybersecurity baseline designed to prevent hackers from gaining control of broadcast systems to transmit bogus emergency alerts or other unauthorized programming.
EAS equipment must have its default password changed before deployment and use passwords at least 15 characters long. Stations also can’t reuse passwords across different accounts and equipment.
Sage Alerting Systems President Harold Price said changing credentials should also be part of employee departure procedures. “When an employee is terminated and they knew any of those passwords, you’ve got to change those passwords, and you’ve got to do it right away,” Price said.
Software is another potential compliance issue. National EAS testing has indicated that as many as one-quarter of stations may be operating EAS equipment with outdated software. Vendors are urging stations to check software versions and ensure they are registered to receive security and update notices.
Digital Alert Systems said DASDEC 3 users should currently be on version 6.0, while DASDEC 2 users should be on version 5.4-2. Sage said version 96.0 is currently the minimum required version for its blue ENDEC units.
Firewall Challenges
The requirement likely to pose the biggest challenge for some stations is protecting equipment through firewalls or comparable network segmentation. Pecena said the goal is to prevent equipment from being directly exposed to the public internet while isolating critical broadcast systems from other portions of a station network.
Panelists said the approach is accessible to smaller broadcasters, with firewall hardware available for less than $1,000 and many options below $500.
The panel also offered guidance for stations operating older STLs and other equipment that cannot accommodate the FCC’s new password standards. Replacement may not always be necessary. Pecena said legacy equipment can potentially be isolated and protected through a firewall.
Simply putting equipment on a different subnet, however, may not be enough. Stations need controls that actually restrict communications between systems, with VLANs and properly configured firewalls among the potential solutions.
“Every time a new device gets added, every time somebody leaves the building, every time something else gets reconfigured, it can have cascading effects on everything,” Price said. “You’ve got a constant vigilance.”
Questions Remain
Remote access is another area where broadcasters were urged to be cautious. Common remote-desktop products can create risks if access is continuously available or stations do not understand how the connection is secured. Digital Alert Systems VP Edward Czarnecki said he would “advocate more strongly for VPN usage” when remotely accessing broadcast systems.
Questions remain about how some portions of the new FCC requirements should be interpreted, particularly for older equipment throughout the broadcast chain. But with the Sept. 29 deadline approaching, the panel’s message was that broadcasters should not wait for every outstanding question to be resolved.
Stations should already be reviewing passwords, checking software and firmware versions, updating contact information with equipment manufacturers, identifying remotely accessible equipment throughout the program chain and determining whether those devices are properly isolated from unauthorized access.
