The recent FCC order on “EAS cybersecurity” reaches much further into the air chain than its alerting origins suggest.

The phrase “EAS cybersecurity” makes this sound like a rule about one box.

It requires strong authentication, prompt installation of security updates and a firewall or comparable segmentation practice that restricts remote management to authorized devices and users.

New paragraph 47 CFR 11.35(d) contains the three basic controls: authentication, security updating and restricted management access.

Add codecs, processors, remote controls, automation servers and EAS units, and password management becomes a job of its own.