FCC Cybersecurity Workshop for Broadcasters: Key Takeaways and Practical Guidance On May 14, 2026, the Federal Communications Commission’s (FCC) Public Safety & Homeland Security Bureau (PSHSB) convened a Cybersecurity Workshop for Broadcasters, bringing together public- and private-sector stakeholders to discuss emerging cyber threats, share best practices, and explore opportunities for collaboration.[1] The broadcaster-focused workshop underscored the increasingly critical role of cybersecurity in safeguarding broadcast infrastructure. Below, we summarize the workshop and provide key takeaways for broadcasters in this ever-evolving landscape. Evolving Risks Workshop participants identified a broad and increasingly complex range of cyber threats facing broadcasters of all sizes. These include: - Infrastructure-targeted attacks, aimed at the broadcast air chain, including studio-to-transmitter link (STL) hijacking and manipulation of Emergency Alert System (EAS) equipment. - Ransomware and malware, which can disrupt operations, compromise sensitive data, and result in financial losses. - Social engineering attacks, including phishing campaigns targeting company employees and help desks. - Denial-of-service attacks, which can undermine a station’s ability to stay on air. Importantly, speakers emphasized that threat actors range from financially motivated criminals to politically motivated “hacktivists” and nation-state actors. The workshop also homed in on artificial intelligence’s (AI) role in reshaping the threat environment. Participants highlighted that while AI can enhance defensive capabilities such as real-time threat detection, it can also enable more sophisticated attacks, including deepfakes, automated phishing campaigns, and adaptive malware. How Broadcasters Can Develop a Risk Management Approach A consistent takeaway from the workshop was that there is no single solution to cybersecurity risk. Instead, broadcasters should adopt a layered, “defense-in-depth” strategy tailored to their specific systems and risk profiles. Key elements of a risk management approach to cybersecurity can include the following measures, as appropriate to risk: 1. Governance and Planning - Develop a written cybersecurity risk management plan before incidents occur.