When an emergency alert interrupts a radio or television program, the public sees a message and perhaps hears a tone. The machinery that delivers it is mostly invisible.
That machinery is now subject to a new cybersecurity requirement. Effective September 29, 2026, the Federal Communications Commission requires participants in the Emergency Alert System to change default passwords, use stronger authentication, install security updates and restrict remote access to EAS-related equipment and other systems that can route, process or insert content into a station’s programming stream.
The rule is sensible. It is also narrower than the word secure might suggest.
The alert system is not one computer
The Emergency Alert System is a distributed network involving broadcast radio and television stations, cable and satellite providers, wireline video services and other participating systems. An alert may pass through emergency-management agencies, alert-distribution platforms, EAS encoders and decoders, studio automation, transmitter links and relay systems before reaching the public.
The FCC’s Report and Order is important partly because it treats the alerting path as larger than the dedicated EAS device. The rule also covers studio-transmitter-link equipment and remotely managed equipment that can route, process or insert material into a participant’s programming.
That reflects how broadcast systems actually fail. An attacker does not necessarily need to compromise the government agency that originated an alert. A poorly secured remote-access device, vendor account or signal-processing system may be enough to insert unauthorized audio, transmit false alert tones or block legitimate programming.
What the new rule requires
The immediate requirements are basic forms of cybersecurity hygiene:
- Default passwords must be changed before covered equipment is used to broadcast to the public.
- Passwords must be changed when there is reason to believe they have been compromised.
- Participants must promptly test and install security patches and security-related software or firmware updates.
- Remote-management access must be restricted through a firewall or comparable network-segmentation practice.
The FCC adopted the requirements after repeated incidents involving improperly secured or remotely accessible broadcast equipment. In those cases, intruders gained control of systems and transmitted unauthorized audio that included alert tones, offensive material or promotional content. The Commission has also cited earlier incidents involving false emergency messages.
The danger is not limited to embarrassment. A false alert can cause panic. Repeated false alerts can make people less likely to trust the next one. A compromise that prevents or delays a genuine warning creates a different failure, but not a less serious one.
Securing the equipment is not the same as authenticating the message
The new rule makes equipment harder to commandeer. It does not create a cryptographically verifiable chain proving that every emergency message is authentic from its origin to its final audience.
The FCC is considering additional changes, including stronger authentication for Common Alerting Protocol messages, universal alert identifiers and improvements to geotargeting. Those proposals remain part of a separate rulemaking process. Wireless Emergency Alerts are also treated differently: the FCC concluded that best practices, rather than binding cybersecurity requirements, are currently appropriate for that system.
That distinction matters. A station can comply with the new password, patching and segmentation requirements while still depending on a message path that does not provide end-to-end authentication. The rule addresses several practical attack routes. It does not settle every question about whether an alert is genuine, correctly targeted or capable of reaching everyone who needs it.
The inventory problem
The hardest requirement may not be changing a password. It may be identifying every system that needs one.
A station may know where its EAS encoder is located while having less visibility into vendor-maintained devices, cloud-connected automation systems, shared credentials, remote-support accounts, backup signal paths or older equipment that can insert programming without being labeled internally as part of the alerting system.
“Change the password” is not the same as “know every place that password is used.” A password change can disrupt a vendor’s support process, leave an undocumented account active or provide limited protection if the surrounding network remains flat.
The FCC describes the new controls as relatively straightforward, and many broadcasters may already have them in place. But implementation costs will not be identical. Large station groups may have dedicated engineering and security staff. Small and rural broadcasters may depend on a contractor who configured the equipment years ago and remains the only person who understands the backup path.
The FCC’s own record acknowledges that broadcasters vary considerably in size, technical sophistication and system complexity. A uniform minimum requirement can establish a baseline, but it cannot supply the personnel needed to discover undocumented dependencies or test a recovery plan.
Who owns the failure?
Responsibility for an alerting chain may be divided among station engineers, corporate information-technology departments, broadcast-automation vendors, equipment manufacturers, managed-service providers and emergency-management agencies.
That division creates practical questions the rule cannot answer by itself. If the EAS encoder is secure but a vendor-managed studio device can insert unauthorized audio, who owns the gap? If a security update interrupts a backup transmission path, who decides when to install it? If a station loses access to its alerting system during an emergency, what alternative method is available, and when was it last tested?
A documented policy is useful. It is not the same as operational independence.
The real test is recovery
The best outcome is not that nobody ever attacks the Emergency Alert System. That is an unrealistic standard for any public communications network. The better outcome is that an intrusion produces a contained equipment failure rather than a trusted-looking false emergency message.
That requires more than passwords and patches. Stations need an accurate inventory, monitored vendor access, usable logs, clean backups, tested restoration procedures and a way to continue delivering warnings when a primary system or network has been compromised.
The FCC is right to treat emergency alerting as cybersecurity infrastructure. But the September 29 rule should be understood as a minimum-maintenance requirement, not proof that the national alerting system is resilient in every meaningful sense.
The central question is not whether a station changed its EAS password. It is whether the station knows every system that can alter, transmit or suppress an emergency message—and whether it can still warn the public when one of those systems fails.
Securing the box is necessary. Knowing where the wires go is harder.













