The FCC’s New Cybersecurity Rules: It’s Time to Audit Your Airchain
The FCC’s new cybersecurity requirements for broadcasters take effect September 29, 2026, which is now less than one week away.
If you’ve been treating this as just an EAS encoder password change, it’s time to look a little deeper.
The FCC says the new requirements apply to EAS equipment, studio-transmitter link equipment, and remotely managed equipment that routes, processes, or inserts content into the programming stream. The FCC’s FAQ also gives examples like audio processors, ad insertion systems, and remotely managed AM, FM, and DTV transmitters.
So no, this doesn’t mean every single thing with an Ethernet jack suddenly falls under the rule. But it definitely goes beyond the EAS box.
The easiest way I can think to approach this is pretty simple: walk your airchain and verify everything that can affect what goes over the air.
We Had Plenty of Warning
I also think this part needs to be said.
Broadcasters had chance after chance to take care of a lot of this ourselves.
This isn’t a new problem.
Back in 2016, stations using poorly secured Barix equipment had audio feeds hijacked. Barix was already telling broadcasters to use long passwords, put devices behind firewalls, and stop exposing them directly to the internet.
Then it happened again.
And again.
Radio World reported another round of apparent Barix compromises in 2025, including unauthorized programming and fake EAS-style audio making it to air. Similar incidents kept showing up into 2026.
At some point, the excuse that nobody knew better stops working.
We’ve been warned for years about default passwords, exposed web interfaces, port forwarding, outdated firmware, and broadcast gear sitting directly on the public internet.
In my opinion, we had plenty of chances to clean this up ourselves and didn’t do a good enough job of it. Eventually, the FCC stepped in and made some of these basic security practices mandatory.
What You Need to Check
The password requirements are pretty specific. Covered equipment using passwords needs to have:
- Default passwords changed before the equipment is used for broadcasting
- Passwords at least 15 characters long
- No dictionary words
- No password reuse across other accounts, equipment, applications, or services
- Passwords changed when there is reason to believe they’ve been compromised
I will say this plainly: I think the dictionary-word requirement is dumb.
A long, unique passphrase can be very strong when it’s generated and managed properly. But whether I agree with that part or not doesn’t really matter here. It’s the directive, so covered equipment needs to meet it.
The FCC also requires prompt security-related software and firmware updates, plus a firewall or comparable network segmentation for covered equipment.
Audit the Airchain
I would start at the studio and follow the signal all the way to the transmitter.
Depending on your facility, that may mean checking:
- EAS encoder/decoders
- STL and IP audio codecs
- Automation systems
- Audio processors and AoIP gear
- Audio routers and switchers
- Remote controls
- RDS equipment
- Satellite or network receivers
- Remotely managed transmitters
- Anything else that can insert, route, or process programming
Then actually log into the stuff.
Don’t assume somebody changed the password five years ago and everything is fine.
Look for factory credentials, reused passwords, old employee accounts, forgotten vendor logins, exposed management ports, outdated firmware, and devices where nobody seems to know who has access anymore.
If something has a public IP or a port forward, ask why.
Management access should be behind a firewall, VPN, ACL, segmented management network, or another controlled access method instead of just hanging out on the public internet.
Use a Password Manager
Unique passwords get annoying fast when you manage dozens or hundreds of devices. That’s exactly what password managers are for.
Two I personally like are Bitwarden and 1Password.
I’m not affiliated with either company, and I’m not being paid to recommend them. I’ve used both, and currently use password managers like these because they make this kind of credential management a lot easier.
Both can generate random passwords, store them securely, and give engineering teams shared vault or organization features.
Whatever product you choose, the important part is having a system where credentials are unique, securely shared, updated when staff leave, and recoverable during an emergency.
That’s a whole lot better than a spreadsheet called transmitter-passwords.xlsx.
This Should Have Happened Anyway
The FCC deadline is what is forcing the issue, but most of this should already be normal broadcast engineering practice.
We’ve spent years connecting once-isolated broadcast hardware to IP networks. That makes facilities easier to manage, but it also turns processors, codecs, remote controls, and transmitters into potential attack surfaces.
Before September 29, verify the passwords, check the firmware, review the firewall rules, look for old port forwards, and find forgotten accounts.
Most importantly, know what is actually in your airchain and how somebody could remotely access it.
If a device can affect what goes over the air, you should know what it is, who can access it, how they authenticate, and how that access is protected.
Sources and Further Reading
- FCC FAQ via Radio World: FCC Posts FAQ About the New Cybersecurity Rules
- Radio World: Apparent Barix Hacks Highlight Gaps in Cybersecurity
- Radio World: Station Hacks Put Focus on Passwords, Security Vulnerabilities
- Radio & Television Business Report: Barix Addresses a Long String of Audio Feed Seizes
- DysruptionHub: A String of Radio Hijacks Exposes a Deeper Broadcast Weakness
- Radio & Television Business Report: MaxxKonnect Helps Broadcasters on New FCC Password Needs
- Inside Radio: New EAS Cybersecurity Rules Expand Beyond Equipment