<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.tvtechnology.com/feeds/tag/cybersecurity" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Tv Technology in Cybersecurity ]]></title>
                <link>https://www.tvtechnology.com/cybersecurity</link>
        <description><![CDATA[ All the latest cybersecurity content from the Tv Technology team ]]></description>
                                    <lastBuildDate>Thu, 30 Apr 2026 18:49:59 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ MPA’s Trusted Partner Network Issues Landmark Content Security Survey ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/infrastructure/mpas-trusted-partner-network-issues-landmark-content-security-survey</link>
                                                                            <description>
                            <![CDATA[ The first-of-its-kind industry analysis found that `inconsistent day-to-day execution of technical controls is creating systemic and exploitable risk’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcx47HwUz529ZTJYKZBqG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LL6S8Dh2LfuyuYdE4ktAU8-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Apr 2026 18:49:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/LL6S8Dh2LfuyuYdE4ktAU8-1280-80.png">
                                                            <media:credit><![CDATA[Trusted Partner Network]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TPN logo with the TPN Star Report]]></media:description>                                                            <media:text><![CDATA[TPN logo with the TPN Star Report]]></media:text>
                                <media:title type="plain"><![CDATA[TPN logo with the TPN Star Report]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LL6S8Dh2LfuyuYdE4ktAU8-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LOS ANGELES</strong>—The <a href="https://www.tvtechnology.com/tag/tpn" target="_blank">Trusted Partner Network</a> (TPN), the global content security initiative of the <a href="https://www.tvtechnology.com/tag/mpa" target="_blank">Motion Picture Association</a> (MPA), has released a major new industry wide survey and report on content security that finds a number of ongoing security risks and provides data showing that `inconsistent day-to-day execution of technical controls is creating systemic and exploitable risk.'</p><p><a href="https://www.tvtechnology.com/tag/trusted-partner-network" target="_blank">TPN</a> billed the new <a href="https://www.globenewswire.com/Tracker?data=VjsaNtsNdqmV4yKxrwZ1DHRSg0jk13b4kxPRDrh9CyFZBxRMkUCT9KcuG9WDtVq2uhVM-TLwMQaV20zodBOrgo1iHVnGiNO7itM_9rqtSRjIYbQIe9X1qJLmIKf14X7HNoXQdGFJ64KbXAciBDg0hRlqlrbo5dNrN0wHe737caA="><u>TPN STAR Report</u></a> as the first industry study to analyze large-scale security assessment data and track how cyber risks are evolving across the global content supply chain. </p><p>The TPN STAR Report data shows that while most organizations have foundational policies in place, inconsistent day-to-day execution of technical controls is creating systemic and exploitable risk. By analyzing validated TPN security assessments alongside incident-driven Security Alerts, the report shows a clear pattern of control failures that closely match real-world attacks.</p><p>“Content security today is inseparable from overall cybersecurity,” said Karyn Temple, senior executive vice president and global general counsel for the MPA. “Protecting intellectual property at scale requires the same rigor, operational discipline, and vigilance demanded in other critical, high-risk sectors.”</p><p>According to the report, in the first quarter of 2026, TPN issued more Security Alerts than in all of 2025, reflecting a sharp increase in credential-based attacks, misconfigurations, and exploitation of un-remediated vulnerabilities. While TPN provides the platform and standards for assessing security, fixing any issues is the responsibility of the organizations being assessed.</p><p>Recent security alerts consistently pointed to the same underlying technical weaknesses. Those include, the report found, compromised credentials, inconsistent multi-factor authentication (MFA), insecure system and cloud configurations, delays in patching and vulnerability remediation. </p><p>TPN STAR Report data reinforces this pattern with vulnerability management, cryptography, endpoint hardening, and access management emerging as the weakest-performing controls areas showing:</p><p>“The TPN STAR Report highlights a persistent disconnect between perceived security and actual operational performance,” said Terri Davies, president of TPN. “Organizations routinely overestimate that their controls are effective, especially those that require continuous attention, technical rigor, and operational ownership. Recent technological advances only heighten the urgency to address these gaps before they are exploited.”</p><p>The report also found that capabilities such as Zero Trust architectures, conditional access, continuous authentication, and automated compliance monitoring are not yet widely used across the entertainment ecosystem. In highly distributed production environments spanning cloud platforms, remote workforces, and a complex ecosystem of third-party vendors, these gaps can greatly increase the impact of a single compromised credential, the study reported. </p><p>In response to these findings, the report underscores the need for urgent industry action to ensure continuous monitoring of systems and access, faster remediation of known vulnerabilities, stronger ownership of operational controls, and consistent enforcement of identity and access protections, particularly across third-party environments.</p><p>The TPN Star Report also establishes a critical baseline for measuring control performance and tracking industry progress toward more resilient, operationally effective content security.</p><p>The report can be downloaded <a href="https://www.ttpn.org/star-access/"><u>here</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC Selects New Lead Administrator for U.S. Cyber Trust Mark Program ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/regulatory-legal/fcc-selects-new-lead-administrator-for-u-s-cyber-trust-mark-program</link>
                                                                            <description>
                            <![CDATA[ The ioXt Alliance (ioXt) to serve as the new Lead Administrator for the voluntary cybersecurity labeling program ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AbWhH2wz5rTmHMJyMhkcqK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eJMChnoyuu3RQBBHZ6Rm2Y-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Apr 2026 22:45:04 +0000</pubDate>                                                                                                                                <updated>Mon, 13 Apr 2026 22:45:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                    <category><![CDATA[FCC]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/eJMChnoyuu3RQBBHZ6Rm2Y-1280-80.png">
                                                            <media:credit><![CDATA[FCC]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FCC Chair Brendan Carr]]></media:description>                                                            <media:text><![CDATA[FCC Chair Brendan Carr]]></media:text>
                                <media:title type="plain"><![CDATA[FCC Chair Brendan Carr]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eJMChnoyuu3RQBBHZ6Rm2Y-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON</strong>—The <a href="https://www.tvtechnology.com/tag/fcc" target="_blank">Federal Communications Commission</a> has selected the ioXt Alliance (ioXt) to serve as the new Lead Administrator of its <a href="https://www.fcc.gov/document/fcc-adopts-rules-iot-cybersecurity-labeling-program" target="_blank">U.S. Cyber Trust Mark Program</a>, a voluntary cybersecurity labeling program for consumer wireless Internet of Things (IoT) products.  </p><p>This program, overseen by the FCC’s Public Safety and Homeland Security Bureau, builds on significant public and private sector work on IoT cybersecurity. </p><p>“The FCC’s U.S. Cyber Trust Mark Program was designed to help consumers make informed decisions about the products they bring into their homes,” FCC Chair <a href="https://www.tvtechnology.com/tag/brendan-carr" target="_blank">Brendan Carr</a> said. “With today’s decision, the FCC is ensuring that the Lead Administrator will implement the program in a way that is consistent with that vision, while advancing national and cyber security.”</p><p>In recent years, the Commission has worked to advance the U.S. Cyber Trust Mark Program with a greater emphasis on national security. </p><p>ioXt is an independent, U.S.-based non-profit organization, whose focus is on improving the security, privacy, and transparency of IoT products.  ioXt describes itself as the United States’ preeminent certification body dedicated to the security of IoT products and a leader in the relevant stakeholder community. </p><p>The FCC’s U.S. Cyber Trust Mark Program is supported by third party administrators, including a Lead Administrator, <a href="https://www.fcc.gov/document/fcc-adopts-rules-iot-cybersecurity-labeling-program" target="_blank">whose duties are spelled out in the FCC’s IoT Labeling Order</a>. </p><p>The FCC said that ioXt, as the new Lead Administrator, will be responsible for collaborating with stakeholders to develop a consumer outreach campaign and recommending to the Commission additional cybersecurity standards, testing procedures, and label design. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to Fortify Your Cloud Security Plan ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinion/how-to-fortify-your-cloud-security-plan</link>
                                                                            <description>
                            <![CDATA[ Stay protected with a unified approach to visibility, resilience and real-time response ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ZiXCoEtfBFHDLHnCbVKjm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DQkPA7ibX4a3GWqaTCmCbK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Dec 2025 13:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 15 Dec 2025 10:35:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Insights]]></category>
                                                                                                <author><![CDATA[ karl@ivideoserver.tv (Karl Paulsen) ]]></author>                    <dc:creator><![CDATA[ Karl Paulsen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3R2xuGTUy6q97vTscxAS5d.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DQkPA7ibX4a3GWqaTCmCbK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand touching padlock icon on cloud storage icon.]]></media:description>                                                            <media:text><![CDATA[Hand touching padlock icon on cloud storage icon.]]></media:text>
                                <media:title type="plain"><![CDATA[Hand touching padlock icon on cloud storage icon.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DQkPA7ibX4a3GWqaTCmCbK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.tvtechnology.com/features/multiple-threats-players-target-media-content">Threat protection</a> is a serious part of any organization’s network, storage or active workspace—especially if you’re invested in the cloud. While the basics are somewhat easy to follow or prescribe, the real-time monitoring and any aggressive corrective actions can be challenging for the individual(s) whose tasks in the organization include both IT administration and security, plus cloud-services management. </p><p>That is, it can or will become overwhelming to control without some secondary support or a built-in solution integrated by the cloud provider. Simply expecting an ISP to handle this is not a good answer.  </p><p><strong>Visibility Resilience and Rapid Response</strong><br>Being prepared is essential in the current cloud environment. Fig. 1 gives some of the suggestions for this preparedness from a Reactive, Proactive and Adaptive perspective.  </p><p>Breaches in security can and likely will become unmanageable without appropriate planning and active, real-time monitoring alongside aggressive enforcement of IT policies and practices.</p><p>In computer programming, a runtime system or runtime environment is a subsystem that exists in the computer where a program is created, as well as in the computers where the program is intended to be run.</p><p>A cloud runtime is the environment where cloud applications and services execute—including the operating system—language support and other necessary software.<strong> </strong>Furthermore, it is a commercial term (such as Google’s Cloud Run) that ranges from a platform of managed services to the specific software stack required to run serverless functions. </p><p>Noting that, a serverless platform is a cloud-based service that automatically manages the underlying infrastructure, allowing developers to deploy and run code without provisioning, scaling or maintaining servers and otherwise is a cloud-computing execution model that allocates machine resources on an as-used basis. Examples of serverless applications include chatbots, task schedulers and <a href="https://www.tvtechnology.com/news/iot-has-security-implications-for-connected-cars">Internet of Things (IoT)</a> applications.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1366px;"><p class="vanilla-image-block" style="padding-top:59.66%;"><img id="a2oL8yZn7ikbvKtwrsAcYX" name="TVT516.Karl.fig_1_dec_2025_cloudspotter" alt="Cloudspotters Journal December 2025 Fig. 1" src="https://cdn.mos.cms.futurecdn.net/a2oL8yZn7ikbvKtwrsAcYX.jpg" mos="" align="middle" fullscreen="1" width="1366" height="815" attribution="" endorsement="" class="expandable"><a href='https://cdn.mos.cms.futurecdn.net/a2oL8yZn7ikbvKtwrsAcYX.jpg' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text"> Fig. 1: Simplified components in preparing for cybersecurity defense. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Karl Paulsen)</span></figcaption></figure><p>Typically, in the serverless environment, any server management, configuration, scaling and billing activities are abstracted from the end user—i.e., the complex, underlying details are hidden and simplified, so the user need only interact with a higher-level, easier-to-understand interface.</p><p><strong>Set Up a Unified Platform</strong><br>One core solution to ensure adequate security precautions is to establish a unified platform that spans across development, operations and (real-time) runtime to provide continuous visibility, protection, simple and continuous detection and proactive response.</p><p>Some of the groundwork for building a modern cloud-security program is provided in the following, as outlined by a familiar cloud-support trendsetter who specializes in providing <a href="https://www.tvtechnology.com/tag/cybersecurity">cybersecurity</a> in an era of change and movement toward the cloud, regardless of business model.</p><p>One option is to take a proactive approach to cybersecurity (Fig. 2), which is critical to reducing risks and being prepared to address or prevent breaches. Examples follow:</p><p><strong>Container Runtime Security and Modeling</strong><br>One part of understanding and preparing for cloud security involves some of the actual code-centric and application development, such as understanding Container Runtime Security, a key aspect of Kubernetes (as an open-source container orchestration platform, with cloud computing services) and security. This prospect focuses on safeguarding containers (e.g., Docker) during their execution. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1366px;"><p class="vanilla-image-block" style="padding-top:51.46%;"><img id="UMZd5wR2LuHYWUiVzbVvyf" name="TVT516.Karl.fig_2_dec_2025_cloudspotter" alt="Cloudspotter's Journal December 2025 Fig. 2" src="https://cdn.mos.cms.futurecdn.net/UMZd5wR2LuHYWUiVzbVvyf.jpg" mos="" align="middle" fullscreen="1" width="1366" height="703" attribution="" endorsement="" class="expandable"><a href='https://cdn.mos.cms.futurecdn.net/UMZd5wR2LuHYWUiVzbVvyf.jpg' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text"> Fig. 1: Simplified components in preparing for cybersecurity defense.   </span><span class="credit" itemprop="copyrightHolder">(Image credit: Karl Paulsen)</span></figcaption></figure><p>When active, operational containers are most vulnerable to malicious activity since traditional security tools weren’t designed to monitor running containers. Runtime security is the only way to secure cloud-native applications at scale and in today’s environments, the use of AI and machine learning will necessitate runtime automating the processes for modeling of a healthy activity built against a model.</p><p>“Modeling” is the process of creating a representation of normal, safe behavior—for applications and services, especially when running in a cloud-native environment. Such a representation serves as a baseline to identify and detect deviations or anomalies that might indicate security threats.</p><p>When the system has an <em>established</em> model, and then uses continuous monitoring and lets software make comparisons of the runtime activities of applications and services against the <em>established</em> model, teams can then identify and respond to unauthorized actions, privilege escalations and other potential incidents. Major cloud-service providers offer managed Kubernetes services that simplify infrastructure management, allowing organizations to build and run modern applications on a hybrid or multicloud environment.</p><p><strong>Build a Strategy for Risk Prioritization </strong><br>Most security teams lack the time, experience or context to effectively handle and react to a deluge of security alerts that could come from various security tools or practices. As DevOps and engineering teams rely more on cloud technologies to achieve faster development cycle times, they may often prioritize development deadlines over security issues. </p><p>While they fundamentally understand the needs and values of security, they often don’t deem it highly important or may end up wasting their time and resources remediating vulnerabilities that seem impactful but don’t present an active risk in production. The organization’s administration should consider utilizing a tool set that correlates threat intelligence, business impact and data sensitivity to provide an accurate representation of <em>active risk</em>.This approach can then help in enabling alignment between DevOps and security teams as to which security issues to prioritize and when.</p><p>Avoid centralizing into one workstream that is sandwiched between DevOps, engineering (implementation/operations) and security teams. Avoid manifesting risks and mitigate the risk of a breach, since the functions of each workgroup then isolate (silo) the interdependency of each job function or task.</p><p>In the current age of cloud, one where all of your teams’ efforts are likely focused on innovation, it is crucial to leverage a solution (team, outside party or vendor) that can manage every stage of cloud detection and response for you.  </p><p>To maximize the investments in a security solution, those teams (internal or external) must have the expertise to leverage activities fully. If you don’t already have those teams in place (and properly structured), then look for a solution provider that can function as a partner and who you can rely on to guard your cloud assets 24 hours a day, 365 days a year. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UPDATED: Incoming FCC Chair Carr Blasts Agency’s Response to Salt Typhoon Cyberattacks ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/incoming-fcc-chair-carr-blasts-fccs-response-to-salt-typhoon-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Called the vote on new cybersecurity proposals ‘partisan, uncoordinated, and counterproductive’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mVdBY3BYyspJY5jcQBxfGo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YGxmAakHniT8ExokwR5pye-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jan 2025 21:18:24 +0000</pubDate>                                                                                                                                <updated>Fri, 17 Jan 2025 18:13:39 +0000</updated>
                                                                                                                                            <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YGxmAakHniT8ExokwR5pye-1280-80.jpg">
                                                            <media:credit><![CDATA[Chip Somodevilla/Getty Images]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Brendan Carr]]></media:description>                                                            <media:text><![CDATA[FCC chair designate Brendan Carr]]></media:text>
                                <media:title type="plain"><![CDATA[FCC chair designate Brendan Carr]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YGxmAakHniT8ExokwR5pye-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON</strong>—In response to a Jan. 15 Federal Communications Commission vote to impose new cybersecurity rules, Commissioner Brendan Carr, who is slated to become the agency’s chair in the new Trump administration, has issued an unusually harsh statement criticizing the vote.</p><p>“Today, just five days before we complete the transition to a new Administration—when the interests of bipartisan collaboration on matters of national security should be paramount for everyone in government—the Biden FCC decided to force a vote on a partisan, uncoordinated, and counterproductive approach to the Salt Typhoon cybersecurity threats,” Republican Carr said in a written statement. </p><p>The so-called Salt Typhoon cybersecurity attacks involved a major security breach of U.S. telecommunications infrastructure by Chinese intelligence services. In the fall of 2024, federal authorities said hackers had breached the infrastructure of nine major U.S. telecommunications companies. </p><p>Following the reports, <a href="https://www.fcc.gov/document/rosenworcel-proposed-requiring-telecom-carriers-secure-their-networks">FCC chair Jessica Rosenworcel highlighted the severity of the threat and issued a statement on Dec. 5 saying the FCC needed to take action</a>. She circulated a draft Declaratory Ruling to other FCC commissioners finding that section 105 of the Communications Assistance for Law Enforcement Act (CALEA) requires telecommunications carriers to secure their networks from unlawful access or interception of communications. </p><p>Based on that authority, <a href="https://www.fcc.gov/document/rosenworcel-proposed-requiring-telecom-carriers-secure-their-networks" target="_blank">Rosenworcel, a Democrat, proposed that communications service providers submit an annual certification to the FCC</a> attesting that they have created, updated, and implemented a cybersecurity risk management plan, which would strengthen communications from future cyberattacks.</p><p>“The cybersecurity of our nation’s communications critical infrastructure is essential to promoting national security, public safety, and economic security,” Rosenworcel wrote. “As technology continues to advance, so does the capabilities of adversaries, which means the U.S. must adapt and reinforce our defenses.  While the Commission’s counterparts in the intelligence community are determining the scope and impact of the Salt Typhoon attack, we need to put in place a modern framework to help companies secure their networks and better prevent and respond to cyberattacks in the future.”</p><p>FCC's materials relating to Salt Typhoon can be found <a href="https://www.fcc.gov/document/implications-salt-typhoon-attack-and-fcc-response" target="_blank">here</a>. The Declaratory Ruling and Notice of Proposed Rulemaking can be found <a href="https://www.fcc.gov/document/fcc-issues-cybersecurity-proposal-and-ruling">here</a>. </p><p>In response to the vote on the Declaratory Ruling, Carr called Salt Typhoon, “the worst cyber intrusion in our nation’s history. That intrusion, which the next  Administration will be left to address, represents an unacceptable risk to our national security. It should  never have been allowed to happen. It now requires a serious and effective response—this FCC action is neither.”</p><p>Carr provided no specific details on what he believed to be an appropriate response, saying in general terms that “we should be working closely with the intelligence  community officials and the network providers that have been targeted by this attack. We should be  conveying in real time the remedial steps that are necessary to restore the integrity of our networks—and  ensuring that providers are implementing them. And we should be taking a series of actions that will  restore America’s deterrence and harden our networks going forward.”</p><p>He did, however, say that the FCC had chosen to “issue a decision that it does not even have the authority to adopt” and criticized CALEA as a suitable legal basis for the FCC's actions.   </p><p>“Specifically, CALEA requires a covered provider to open their network within the ‘switching premises’— but only within the switching premises—to enable authorized intercepts by U.S. law enforcement,” Carr wrote. “Today,  the FCC reads CALEA as also imposing an affirmative obligation on a covered provider to take certain undefined cybersecurity actions across every portion of the network—meaning, both within and outside the switching premises. But the FCC and the court of appeals have already determined that CALEA’s  ‘switching premises’ language is key to the statute’s operation. The FCC’s unprecedented decision to  effectively read that language out of the statute not only undermines the action it takes today, it calls into  question every previous FCC action under CALEA too.”  </p><p>“The FCC has taken lawful, effective, and bipartisan actions on national security matters over the past four years,” Carr concluded. “Why depart from that at the eleventh hour? For a headline? To tie the hands of the incoming  Administration? … The Biden Administration has left a lot of messes for others to clean up. Add this one to the pile.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canadian Video Service Providers, Friend MTS Secure Court Order For Fast Shutdown Of Pirate Servers ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/canadian-video-service-providers-friend-mts-secure-court-order-for-fast-shutdown-of-pirate-servers</link>
                                                                            <description>
                            <![CDATA[ The order enables fast response and shutdown of access to servers hosting pirated video content ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9NbpfFrLmhpp5AT6Mxqhqk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3pNR5FYuhpUN2uZ6AVTBf-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Sep 2024 18:11:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Phil Kurz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/fioQsUoHKYn3b835FzG7nP.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/b3pNR5FYuhpUN2uZ6AVTBf-1280-80.png">
                                                            <media:credit><![CDATA[Friend MTS]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Friend MTS logo]]></media:description>                                                            <media:text><![CDATA[Friend MTS logo]]></media:text>
                                <media:title type="plain"><![CDATA[Friend MTS logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3pNR5FYuhpUN2uZ6AVTBf-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LONDON</strong>—Numerous Canadian video service providers have selected Friend MTS and its Dynamic Delivery Server Blocking (DDSB) solution to prevent piracy, the company said this week.</p><p>Forming an industry-first collaboration, these organizations have secured a nationwide court order to dynamically block access to any servers hosting broadcasters’ pirated content, including content from major sports leagues, such as FIFA, NBA, NHL and UFC, it said.</p><p>The court order allows Internet Service Providers to block access dynamically to servers attempting to distribute pirated content without requiring a new court order for each sporting event. This approach will save money and time in protecting content and billions of dollars in associated content rights, it said.</p><p>Friend MTS developed DDSB in 2017. It delivers large scale blocking of content while meeting strict legal standards required for court orders blocking servers. The solution gives users the intelligence and evidence needed to persuade ISPs to restrict access to illicit services, thereby cutting the number of illegal streams, it said.</p><p>As a result, viewers are encouraged to watch content from legitimate commercial sites, maintaining the value of the content, it said.</p><p>“This collaboration shows the powerful impact that results from video service providers, ISPs and video security specialists coming together to fight piracy,” said Shane McCarthy, CEO, Friend MTS. “Canadian operators are leading the global industry by setting the bar for piracy prevention in new, dynamic ways. We’re thrilled to have helped them not only implement security solutions but to obtain the blocking order as well. Our unique blend of expertise and blocking technology innovation is aiding their security teams, legal counsels, and business leaders with the right analytics and evidence to effectively stop piracy, without impacting legitimate websites.”</p><p>More information is available on the company’s <a href="https://www.friendmts.com/technology/blocking"><u>website</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sky News UK Among Global Broadcasters Hit by IT Outage ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/sky-news-uk-among-global-broadcasters-hit-by-it-outage</link>
                                                                            <description>
                            <![CDATA[ The issue is thought to have originated from cybersecurity company CrowdStrike when a flawed update was rolled out globally, shutting companies out of access to computers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XWsPbcZF4wfayRgZgs6tj5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kYWmzHS6XAscAp53sZ3dWg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jul 2024 15:01:52 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Jul 2024 16:07:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ jenny.priestley@futurenet.com (Jenny Priestley) ]]></author>                    <dc:creator><![CDATA[ Jenny Priestley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/PEnRhUyUEqKtJfTxc34DbN.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kYWmzHS6XAscAp53sZ3dWg-1280-80.jpg">
                                                            <media:credit><![CDATA[Sky News]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[In London Sky News, which is owned by Comcast, was among the global broadcasters taken off air for several hours by a global Microsoft outage.]]></media:description>                                                            <media:text><![CDATA[Sky News]]></media:text>
                                <media:title type="plain"><![CDATA[Sky News]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kYWmzHS6XAscAp53sZ3dWg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sky News UK and Sky Sports News have been taken off air by what’s being described as the ‘biggest IT outage of all time’.</p><p>Sky News began to experience problems around 5am and switched to broadcasting documentaries at 7am. It then went completely off-air about an hour later.</p><p>The channel returned to air at 8.50am with a much-changed backdrop, and no graphics, autocue or packages. It then went back off air again after a short news update and before resuming at 9am.</p><p>In a statement on X (formerly Twitter), Sky News chairman David Rhodes said that the network had “not been able to broadcast live TV this morning. Much of our news report is still available online, and we are working hard to restore all services.”</p><p>In its own post on X, Microsoft 365 said: “We’re investigating an issue impacting users ability to access various Microsoft 365 apps and services”.</p><p>Cybersecurity company CrowdStrike later released a statement in which it said it is “actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed.”</p><p>Australian broadcasters were also forced off air, with both Sky News Australia and ABC hit.</p><p>AWS, NOW, Virgin Media, and BT are also among the companies impacted, according to DownDetector.</p><p><em>This story first appeared in our sister publication </em><a href="https://www.tvbeurope.com/live-production/sky-news-uk-among-global-broadcasters-hit-by-it-outage"><u><em>TVBEurope</em></u></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japan’s NHK Joins IBCAP Anti-Piracy Coalition ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/japans-nhk-joins-ibcap-anti-piracy-coalition</link>
                                                                            <description>
                            <![CDATA[ The International Broadcaster Coalition Against Piracy’s monitoring lab impressed NHK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m6BZ2TNiWFnFvSotsYwefR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9P3e7MeF9s4f5VAUPg7hwG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jun 2024 22:24:48 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Jun 2024 13:52:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Phil Kurz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/fioQsUoHKYn3b835FzG7nP.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9P3e7MeF9s4f5VAUPg7hwG-1280-80.png">
                                                            <media:credit><![CDATA[IBCAP]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IBCAP logo]]></media:description>                                                            <media:text><![CDATA[IBCAP logo]]></media:text>
                                <media:title type="plain"><![CDATA[IBCAP logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9P3e7MeF9s4f5VAUPg7hwG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>DENVER</strong>—NHK (Japan Broadcasting Corp.) has joined the International Broadcaster Coalition Against Piracy (IBCAP). </p><p>The coalition is expanding the language content under its protection umbrella to include Japanese and has added a Japanese-speaking analyst to its anti-piracy lab to focus on protecting NHK content. The coalition already protects English, Hindi, Urdu, Arabic, Portuguese and French channels, among others, it said.</p><p>“We have been very impressed with the results achieved by IBCAP in controlling piracy for other members, and we are excited to join IBCAP and to bring our channels and VOD under IBCAP’s protection,” said Shigeki Sato, the head of NHK’s copyright and contracts division. “After visiting IBCAP’s state-of-the-art monitoring lab and meeting the legal and management teams, we were quickly convinced that joining this coalition was the right move for us to bolster the protection of NHK content not only in the U.S. but also worldwide.”</p><p>More information is available on the IBCAP <a href="https://connect.notified.com/Tracker?data=ZmKEl7FBgX4BOKNev6Mc2ZOhC2-ECx8X7Ntm9iPRw1k68MZjYOZjfep-D2lIv3fofO8tzsY8YOZgYAIXzsrNFzAz3kpCI3M007VKEJgOoNPZvwp6Si-3tSfYwlYrXvpW000000000000" target="_blank"><u>website</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC to Vote on LPTV Rules during June Open Meeting ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/fcc-to-vote-on-lptv-rules-during-june-open-meeting</link>
                                                                            <description>
                            <![CDATA[ The tentative agenda for the June meeting also includes votes on establishing a schools and libraries cybersecurity pilot program and broadband cybersecurity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LKcgT4EHm8du7tPreRK4bJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BpFYwGEcpnsz9bMoe8SVk6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 May 2024 17:48:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BpFYwGEcpnsz9bMoe8SVk6-1280-80.jpg">
                                                            <media:credit><![CDATA[SMITHGROUPJJR]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[FCC headquarters where the June Open Meeting will be held. ]]></media:description>                                                            <media:text><![CDATA[FCC]]></media:text>
                                <media:title type="plain"><![CDATA[FCC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BpFYwGEcpnsz9bMoe8SVk6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON, D.C.</strong>—Federal Communications Commission Chairwoman Jessica Rosenworcel has announced a tentative agenda for the June Open Commission Meeting scheduled for Thursday, June 6, 2024 that will include votes on new regulations for LPTV and broadband cybersecurity.</p><p><em>(A separate story on the proposed LPTV regulations is available </em><a href="https://www.tvtechnology.com/news/fcc-plans-to-revise-lptv-rules" target="_blank"><em>here</em></a><em>.) </em></p><p>The FCC described the items on the agenda as follows: </p><ul><li>Amendment of the Commission’s Rules to Advance the Low Power Television, TV Translator and Class A Television Service – The Commission will consider a Notice of Proposed Rulemaking regarding updates and amendments to the Commission’s rules to address advances in the LPTV Service. (MB Docket Nos. 24-147, 24-148)</li><li>Reporting on Border Gateway Protocol Risk Mitigation Progress – The Commission will consider a Notice of Proposed Rulemaking to increase the security of the information routed across the internet and promote national security by requiring broadband providers to report on their progress in addressing vulnerabilities in the Border Gateway Protocol.  (PS Docket Nos. 24-146; 22-90)</li><li>Establishing a Schools and Libraries Cybersecurity Pilot Program – The Commission will consider a Report and Order that would establish the Schools and Libraries Cybersecurity Pilot Program and provide up to $200 million in Universal Service Fund (USF) support available to eligible schools and libraries, over a three-year period, to defray the costs of eligible cybersecurity services and equipment and help the Commission evaluate the use of the USF to support these services and equipment.  (WC Docket No. 23-234)</li><li>Letters of Credit for Recipients of High-Cost Competitive Bidding Support – The Commission will consider a Notice of Proposed Rulemaking that would seek comment on changes to the rules for letters of credit required for recipients of high-cost support authorized through a competitive process.  (WC Docket Nos. 10-90, 18-143, 19-126, 24-144; AU Docket Nos. 17-182, 20-34; GN Docket No. 20-32)</li></ul><p>The FCC publicly releases the draft text of each item expected to be considered at the next Open Commission Meeting.  One-page cover sheets are included in the public drafts to help summarize each item.  All these materials will be available on the FCC’s Open Meeting page: <a href="http://www.fcc.gov/openmeeting" target="_blank"><u>www.fcc.gov/openmeeting</u></a>.  </p><p>The Open Meeting is scheduled to commence at 10:30 a.m. ET in the Commission Meeting Room of the Federal Communications Commission, 45 L Street, N.E., Washington, D.C.  While the Open Meeting is open to the public, the FCC headquarters building is not open access, and all guests must check in with and be screened by FCC security at the main entrance on L Street.  Attendees at the Open Meeting will not be required to have an appointment but must otherwise comply with protocols outlined at: <a href="https://www.fcc.gov/visit" target="_blank"><u>https://www.fcc.gov/visit</u></a>.  Open Meetings are streamed live at <a href="http://www.fcc.gov/live" target="_blank"><u>www.fcc.gov/live</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Low Latency and Capacity Will Be Priorities for M&E in 2024 ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinion/low-latency-and-capacity-will-be-priorities-for-mande-in-2024</link>
                                                                            <description>
                            <![CDATA[ Media and entertainment companies will seek tighter control of their network in the face of continuing threats and industry flux ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eBWtfZErSqT3nRVBa3U365</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/erCz98tmcmDZfbQRa4KVfK-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jan 2024 20:10:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Josh Arensberg ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/C4GBEkSasyNMZVTbiBQkE.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/erCz98tmcmDZfbQRa4KVfK-1280-80.jpeg">
                                                            <media:credit><![CDATA[Adobe]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Adobe]]></media:description>                                                            <media:text><![CDATA[Adobe]]></media:text>
                                <media:title type="plain"><![CDATA[Adobe]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/erCz98tmcmDZfbQRa4KVfK-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The direct-to-consumer revolution is not only transforming the consumer experience, but it’s also transforming how content is backhauled. The rapid expansion of high-definition video and livestreaming adds to the challenge of that transition. As such, more of an emphasis will be placed on producing anywhere and lowering latency in 2024. </p><p><strong>The Complexity of Multicloud Environments <br></strong>Cloud adoption had already been steadily climbing in the decade leading up to 2020, but during the lockdown it skyrocketed, owing in no small part to the need for remote collaboration across the media and entertainment supply chain. The benefits include tremendous flexibility, accessibility, processing power, affordable storage, and efficient collaboration on the production side, from editing to sound to animation. The advantages are great, which is why we’ll certainly see continued growth in cloud adoption in 2024, but there are associated challenges. </p><p>The architectural complexity of multicloud environments is hard to manage. Engineers can more easily familiarize themselves with a single cloud environment, which is simpler to mold to the needs of an organization. The more technologies are incorporated, the more of an undertaking implementation becomes, leading to delays, increased costs and more troubleshooting. </p><p>Additionally, managing a growing roster of SaaS providers has become more of a burden. As such, companies will increasingly look to partners that can offer multiple solutions on one platform as a way to reduce costs, boost productivity and streamline operations. </p><p>The explosion of FAST Channels, IP delivery, OTT and other bandwidth-intensive advancements only complicates matters further. As a result, companies will increasingly invest in technologies and solutions that will help address those capacity challenges. Edge technology, for example, enables organizations to process and analyze data much faster, while potentially bolstering security by reducing the distance that data travels from the production to the end consumer. </p><p><strong>The Cybersecurity Challenge of a Decentralized Supply Chain<br></strong>In 2017, hackers obtained the files of the yet-to-be-released fifth season of Netflix’s <em>Orange is the New Black</em>. Even though Netflix refused to comply with the ransom, the PR fiasco served as a reminder for the media and entertainment industry: Your cybersecurity is only as strong as your weakest link. </p><p>In this case Netflix felt the experience they already provided consumers was better than what any hacker could provide. As details emerged hackers didn’t steal the files directly from Netflix. They stole it from a post-production company working on Netflix’s signature series.</p><p>The decentralized nature of the media and entertainment industry means that exposure is often interconnected. Media and entertainment companies engage with a wide variety of third-party providers, particularly on big productions, which can include special effects, animation, sound, graphics, so on and so forth. </p><p>With so much data and intellectual property outsourced across a constellation of players, which may include smaller production studios, freelancers and other contractors, it can be difficult limiting the number of people who have access to business-critical information. Some vendors may be specialty studios that lack the resources for dedicated security personnel, which could effectively serve as a backdoor for hackers to obtain valuable data that wouldn’t have otherwise been able to get. </p><p><strong>The In-venue Use Case<br></strong>With more valuable content on the cloud, therefore, the need for robust cybersecurity solutions has emerged as a priority for the industry—a trend that will only accelerate in the following year. While investing in threat detection and perimeter security solutions goes a long way toward mitigating risk, how these organizations structure their networks will have a big impact on security. Consider the in-venue example. </p><p>Historically, venues have posed challenges both for venue operators and consumers with regard to internet access. Anyone who’s been to a large sporting event or concert, for example, can testify to the difficulty of accessing the internet. There’s just too many people trying to gain access at the same time—and often with highly bandwidth-intensive activities like livestreaming. Couple that with high-resolution video, interactive experiences, and broadcasting and/or livestreaming production setups on the venue side, and the bandwidth demands skyrocket. </p><p>As a result, more and more venue operators are investing in private networks, which deliver greater capacity, speed and security. Connecting a MEC solution to the private 5G network can accommodate applications with a requirement for ultra-low latency and can provide greater support for differentiated experiences, onsite analytics and AI applications. </p><p><strong>Controlling data and IP in 2024 <br></strong>This year, media and entertainment companies will continue to invest in IP connectivity, cloud, Edge and private network solutions. They’ll continue to invest in 5G because it provides the capacity they need to process and analyze large amounts of data. Investing in capacity and speed leads to more responsive systems and applications. <br><br>Keeping more data onsite and on the Edge generally helps reduce the security risk. Media and entertainment companies will seek tighter control of their network in the face of continuing threats and industry flux.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Comcast Data Breach May Have Impacted 35.8M User IDs ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/comcast-data-breach-may-have-impacted-358m-user-ids</link>
                                                                            <description>
                            <![CDATA[ Comcast is informing its Xfinity customers of a major data breach but says that it is not "aware of any customer data being leaked anywhere" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RziQ3MidMzgQ4RYy6ej58M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Dec 2023 18:54:19 +0000</pubDate>                                                                                                                                <updated>Tue, 19 Dec 2023 18:57:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>PHILADELPHIA</strong>—Comcast has been notifying its Xfinity customers that there was an unauthorized access to its internal systems in October that may have compromised data from 35.8 million user IDs. </p><p>The data breach may have given hackers access to such data as passwords, the last four digits of social security numbers, contact details and other information. </p><p>Comcast has about 32 million customers but noted that customers may have multiple user IDs. It is requiring users to change their passwords and is strongly recommending they implement two-factor authentication. </p><p>The problem was created by a previously announced security problem with Citrix software. Citrix announced the problem in October and the data breach occurred between October 16 and 19, prior to Citrix issuing additional mitigation solutions on October 23, 2023.   </p><p>Comcast issued a statement saying, “We are providing notice to customers about a data security incident which exploited a vulnerability previously announced by Citrix, a software provider used by Xfinity and thousands of other companies worldwide. We promptly patched and mitigated the vulnerability.  We are not aware of any customer data being leaked anywhere, nor of any attacks on our customers.  In addition, we required our customers to reset their passwords and we strongly recommend that they enable <a href="https://urldefense.com/v3/__https:/www.xfinity.com/support/articles/two-step-verification-xfinity-app-setup__;!!CQl3mcHX2A!BkS8L_zkA9RzDIIcw1qhFCzoZ9jvLrgmxd54ukUJu-Q_UfwjUU3bkOEiaxb-nsIvMTYQ98_4KPiybbKqQV8CRJknRw$" target="_blank"><u>two-factor or multi-factor authentication</u></a>, as many Xfinity customers already do.  We take the responsibility to protect our customers very seriously and have our cybersecurity team monitoring 24x7.”</p><p>In a letter to customers the company said: “At the time Citrix made this announcement, it released a patch to fix the vulnerability. Citrix issued additional mitigation guidance on October 23, 2023. We promptly patched and mitigated our systems. However, we subsequently discovered that prior to mitigation, between October 16 and October 19, 2023, there was unauthorized access to some of our internal systems that we concluded was a result of this vulnerability. We notified federal law enforcement and conducted an investigation into the nature and scope of the incident. On November 16, 2023, it was determined that information was likely acquired.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC Partners with State Attorneys General on Privacy, Data Protection, Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/fcc-partners-with-state-attorneys-general-on-privacy-data-protection-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ The FCC has signed MOUs with four states and are encouraging others to join the enforcement effort ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xfJoLAeUea693PRp39XywU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Dec 2023 18:33:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p> </p><p><strong>WASHINGTON, D.C.</strong>—FCC chairwoman Jessica Rosenworcel has announced a new initiative to strengthen and formalize the cooperation between the Commission and state Attorneys General on privacy, data protection, and cybersecurity enforcement matters.  </p><p>As part of the work of the FCC’s Privacy and Data Protection Task Force, the agency’s Enforcement Bureau has signed Memoranda of Understanding (MOU) with the Attorneys General of Connecticut, Illinois, New York, and Pennsylvania to share expertise, resources, and coordinated efforts in conducting privacy, data protection, and cybersecurity-related investigations to protect consumers. </p><p>The FCC is also encouraging other states to join the effort. </p><p>“Defending consumer privacy is an all-of-government responsibility and a shared challenge,” Rosenworcel said. “Today we take on evolving consumer threats with new formal partnerships with state law enforcement leaders, which have already been successful in obtaining record-breaking results in combatting illegal robocalls.  I am thankful to these four partners for prioritizing interagency cooperation, and we welcome other state leaders to join us in this effort to ensure we work together to protect consumers and their data.”</p><p>The FCC said that the new Memoranda of Understanding affirm that the FCC and State Attorneys General “share close and common legal interests in working cooperatively to investigate and, where appropriate, prosecute or otherwise take enforcement action in relation to privacy, data protection, or cybersecurity issues” under sections 201 and 222 of the Communications Act.</p><p>Coordinated action and information sharing will take place under all applicable Federal and State laws and privacy protections, the agencies said. </p><p>Connecticut Attorney General William Tong, co-chair of the National Association of Attorneys General’s (NAAG) Internet Safety/Cyber Privacy and Security Committee, said: “The Connecticut Office of the Attorney General was the first nationwide to form a dedicated privacy department in 2015.  This work, in coordination with state attorneys general nationwide, has remained a core priority of our office since then. Consumers have a right to know and control how their personal information is used, stored, and protected, and companies who violate that trust must be held accountable. This powerful new partnership between our states and the Federal Communication Commission is a recognition of the growing importance of this critical work.”</p><p>“I am proud to work with the FCC to safeguard the private information of Illinoisans,” added Illinois Attorney General and co-chair of the NAAG’s Consumer Protection Committee. “Similar state and federal partnerships have allowed us to successfully target perpetrators of illegal robocalls. This initiative gives Illinois access to more resources for investigating and holding accountable bad actors who fail to protect or misuse personal information.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Staying Ahead of the Hackers  ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/staying-ahead-of-the-hackers</link>
                                                                            <description>
                            <![CDATA[ While content piracy can’t be entirely defeated, companies are adapting to increased threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CxtwVMU4Y6cKeF3P26287M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Nov 2023 18:42:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kevin Hilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The media and entertainment business is built on what it offers its viewers: programming, sports, news and other live events. While language purists may balk at the current use of the word “assets” instead of “programs,” it does convey the value of the material—both creative and commercial—shown on TV channels and streaming services. They are valuable commodities and have always needed to be protected. Unfortunately, the move to file-based production, with everything on computer servers and network or cloud access, has left assets—and their owners—extremely vulnerable.</p><p>This was starkly illustrated by the 2014 hack of files and data from Sony Pictures, which included staff details, emails, corporate information and copies of at-the-time unreleased films. Calls for heightened security in the aftermath of the breach ultimately led to the creation in 2018 of the Trusted Partner Network (TPN) by the Motion Picture Association (MPA) and the Content Delivery and Security Association (CDSA), with the MPA taking full control of TPN in 2021.</p><p><strong>Early Moves<br></strong>The MPA issued its first best practice guidelines for content security in 2009, in collaboration with member companies and consultancy Deloitte. Updates and revisions followed between 2011 and 2018, with authorship moving exclusively to the MPA and its membership.</p><div><blockquote><p>Automation can reduce the effort to maintain a consistent security posture in large-scale systems and to recover after an attack.”</p><p>John Footen, Deloitte</p></blockquote></div><p>Deloitte published its own report on the subject in 2018, highlighting the digital transformation of content in all its forms. Among its recommendations for securing material were digital fingerprinting, encryption, blockchain (a digital ledger for recording transactions and events), watermarking and plugging the “analog hole,” where programs are copied from legacy sources.</p><p>John Footen, managing director of Deloitte Consulting, acknowledges that the situation continues to evolve but says new technologies are now being used with established practices to further tighten security.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2396px;"><p class="vanilla-image-block" style="padding-top:150.25%;"><img id="ofBoqWiNKVqoy94CEmm8Bm" name="NOVEMBER_SECURITY_Footen.jpeg" alt="Footen" src="https://cdn.mos.cms.futurecdn.net/ofBoqWiNKVqoy94CEmm8Bm.jpeg" mos="" align="right" fullscreen="" width="2396" height="3600" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">John Footen </span><span class="credit" itemprop="copyrightHolder">(Image credit: Deloitte)</span></figcaption></figure><p>“Automation can reduce the effort to maintain a consistent security posture in large-scale systems and to recover after an attack,” he explains. “We’re also seeing greater integration of media technology with enterprise security systems. More products can work with single sign-on in zero-trust environments, for example. At Deloitte, we’re applying AI for cyber defense, not only for well-established uses such as detecting anomalous behavior and interdicting threats but also for assessment and visualization.”</p><p>The changing nature of the threat— hackers developing new viruses and ways of infiltrating systems—calls for content owners to be ever vigilant. This is reflected in the <a href="https://www.motionpictures.org/wp-content/uploads/2022/02/MPA-Best-Practices-Common-Guidelines-V4.10-FINAL.pdf">MPA/TPN Best Practice Guidelines</a>, which have been updated on an annual basis (sometimes twice in a year) since 2018. The most recent revision appeared in August this year, with new guidance on working from home and remote access to data centers, plus minor updates to cloud specific controls.</p><p>The recommendations from Crystal Pham, vice president of operations and product management for TPN are fairly universal no matter the process: Ensuring that content owners and facilities have secure connections— including not logging into applications from unsecured networks; keeping applications updated and patched; using strong passwords and authentication mechanisms; not sharing accounts or credentials; always installing applications from trusted sources; and adhering to MPA Best Practices, as well as completing an annual TPN assessment.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="6PTSCtpuaZcDucew6w7VVV" name="Crystal_Pham_TPN (1).jpeg" alt="TPN" src="https://cdn.mos.cms.futurecdn.net/6PTSCtpuaZcDucew6w7VVV.jpeg" mos="" align="right" fullscreen="" width="800" height="800" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Crystal Pham </span><span class="credit" itemprop="copyrightHolder">(Image credit: TPN)</span></figcaption></figure><p>Pham characterizes the security issue in M&E as “always evolving” and can be influenced by new technologies, the shortening of  release windows and emerging threats. </p><p>“Change is a constant,” she says. “I do think there’s more awareness about security, with better understanding of the constant change and the need to get ahead of it when possible. I believe it’s becoming more embedded in the process of creating, distributing and consuming content. It’s also becoming more ingrained in our culture.”</p><p><strong>New Methods Needed<br></strong>The ever-shifting landscape is summed up by Asaf Ashkenazi, chief executive of Verimatrix, who observes that as technology advances, so do the techniques used by pirates to illegally obtain, distribute and monetize content.</p><p>“DRM and other traditional security methods are no longer as effective against today’s savvy hackers,” he says. “New real-time detection and prevention systems that are layered on traditional protection methods are needed to combat modern piracy efforts—especially those that leverage AI/ML and cloud infrastructure to exploit at scale.”</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3280px;"><p class="vanilla-image-block" style="padding-top:139.97%;"><img id="bpgkjVXpmdv8AJV7pscbEh" name="NOVEMBER_SECURITY_Verimetrix.jpeg" alt="Verimetrix" src="https://cdn.mos.cms.futurecdn.net/bpgkjVXpmdv8AJV7pscbEh.jpeg" mos="" align="right" fullscreen="" width="3280" height="4591" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Asaf Ashkenazi </span><span class="credit" itemprop="copyrightHolder">(Image credit: Verimetrix)</span></figcaption></figure><p>To counter such threats, Verimatrix has developed Streamkeeper, which combines multi-DRM, forensic watermarking and “Counterspy,” which Ashkenazi describes as a “motion sensor” or “alarm” that detects piracy as it happens. “The goal, however, should not be to completely eliminate piracy but to disrupt the pirates’ business models,” he comments. “By increasing costs beyond potential profits, the motivation for piracy diminishes. Real-time detection, prevention and rapid response are key.”</p><p>Among the ways of disrupting the activities of pirates is to track down purloined programming to the sites where it is being offered illegally and shut them down. Another company providing such monitoring enforcement services is Friend MTS, which does this using both fingerprinting and watermarking technologies. </p><p>“A customer will give us a clean reference feed of their playout and we fingerprint that,” explains Nik Forman, vice president of marketing for the U.K.-based company. “This allows us to uniquely identify that clip of video. If the monitoring systems— which are all automated and crawling the web—then find a suspicious web site is playing that content, we fingerprint it so we can compare them. </p><p>“If they match, we know it is an illicit player and the client can send an enforcement notice or a takedown order,” Forman continues. “If they also take our watermarking services, the content is marked invisibly and basically sits like a QR code in the actual video. When we find the illicit content and we identify it, we match it with a fingerprint and can then say it is one of our watermarks and we extract that payload of subscriber information.”</p><p><strong>‘Never Trust, Always Verify’<br></strong>While the Sony hack made the M&E sector painfully aware of its vulnerabilities, the threats have only increased since then due to otherwise innocent technological developments. The threat landscape has evolved with emergent technologies such as the Internet of Things, 5G connectivity and advanced generative AI capabilities, according to Eric Elbaz, principal strategic engagement manager at Akamai.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="oT2vMYifBjPUDRAm8oKG65" name="NOVEMBER_SECURITY_Akamai.jpeg" alt="Akamai" src="https://cdn.mos.cms.futurecdn.net/oT2vMYifBjPUDRAm8oKG65.jpeg" mos="" align="right" fullscreen="" width="1280" height="1280" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Eric Elbaz </span><span class="credit" itemprop="copyrightHolder">(Image credit: Akamai)</span></figcaption></figure><p>“We’ve also seen state-sponsored attacks become more brazen,” he said. “Nation-state actors are believed to be behind some of the most sophisticated and persistent threats seen to date.”</p><p>This was the suspicion surrounding the attack on the supply chain of software company SolarWinds in 2020, while, as Elbaz points out, ransomware attacks have increased “dramatically.”</p><p>A recent example of this is the breach of MGM Resorts’ systems in Las Vegas, which reportedly cost the company approximately $100 million. But Elbaz does see progress in dealing with the threats: “On the defensive side, we’ve seen major strides being made across threat intelligence, a paradigm shift from ‘trust but verify’ to ‘never trust always verify’ architectures, which is zero-trust security. Deeper public-private sector collaboration and information sharing, as well as a catch up in privacy laws, regulations, and standards are also helping.”</p><p>The threat shows no signs of going away and future attacks are likely to be even more cunning and sophisticated. According to “Variety,” in 2022, hacking of popular entertainment content rose 18% YOY compared with 2021, with the U.S. having the largest share of film and TV demand (i.e., illicit streams, downloads and the like), with more than 13.5 billion visits to piracy sites.</p><p>But the tools to combat it are there and, when it comes down to it, the greatest weapons are probably vigilance and common sense. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC to Host Roundtable on Emergency Alert System Security ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/fcc-to-host-roundtable-on-emergency-alert-system-security</link>
                                                                            <description>
                            <![CDATA[ FCC and CISA will host the event on improving EAS security on Oct. 30, 2023 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VmQvCRibho2jwoz4NxtrFd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Oct 2023 19:32:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png">
                                                            <media:credit><![CDATA[Creative Commons]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EAS]]></media:description>                                                            <media:text><![CDATA[EAS]]></media:text>
                                <media:title type="plain"><![CDATA[EAS]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON, D.C.</strong>—Federal Communications Commission has announced that the FCC’s Public Safety and Homeland Security Bureau is working with the Cybersecurity and Infrastructure Security Agency to host a public roundtable on strengthening the cybersecurity of the nation’s public alert and warning systems. </p><p>At the October 30 event, the agencies will bring together those involved in Emergency Alert System and Wireless Emergency Alert to discuss topics including cybersecurity risk management and incident reporting for alerting. </p><p>“The Commission has recently taken a series of significant actions to improve the nation’s alerting systems, working closely with our government partners,” said FCC chairwoman Jessica Rosenworcel.  “As part of this ongoing effort, we are pleased to partner with CISA to sharpen the focus on the security of America’s alerting infrastructure.  It is critical that these essential systems function in emergencies and that the public can trust the warnings they receive.”</p><p>Last October, the Commission proposed rules to protect against cyberattacks of the Emergency Alert System and Wireless Emergency Alerts.  The roundtable will build upon the record in that proceeding, the FCC reported. </p><p>In the runup to the event, the FCC also outlined a number of steps that it has recently made to strengthen emergency alerting. Those include:  </p><ul><li>Adopted rules to make Emergency Alert System messages clearer and easier to understand on television.  </li><li>Entered into an unprecedented partnership with state and local governments to test Wireless Emergency Alerts on the local level, to help assess geographic accuracy. </li><li>Partnered with FEMA on the third nationwide test of Wireless Emergency Alerts and the seventh nationwide test of the Emergency Alert System.</li><li>Proposed rules to establish reliability, accuracy, and speed benchmarks to improve the performance of Wireless Emergency Alerts.</li><li>Announced that on October 19, the Commission will vote on new rules to enhance Wireless Emergency Alerts by making them available in numerous additional languages, including American Sign Language; supporting maps that show the location of an emergency; and providing the public with easy access to information about the availability of Wireless Emergency Alerts. </li></ul><p> Further information about the upcoming roundtable is available <a href="https://www.fcc.gov/document/fcc-and-cisa-host-alerting-security-roundtable-oct-30" target="_blank"><u>here</u></a>:  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G&D Adds 2 Factor Authorization to its KVM Systems ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/equipment/gandd-adds-2-factor-authorization-to-its-kvm-systems</link>
                                                                            <description>
                            <![CDATA[ 2FA enhances cybersecurity and ensures only authorized users have access ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GUhxswn7fZtvweptSM3gVH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YcP86Mr8XBZ2XZcSaR7Vt6-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Aug 2023 13:25:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Production]]></category>
                                                                                                <author><![CDATA[ tom.butts@futurenet.com (Tom Butts) ]]></author>                    <dc:creator><![CDATA[ Tom Butts ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/Ym75XZxKuaGiZGj7nMGeGM.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YcP86Mr8XBZ2XZcSaR7Vt6-1280-80.jpeg">
                                                            <media:credit><![CDATA[G&amp;D]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[G&amp;D]]></media:description>                                                            <media:text><![CDATA[G&amp;D]]></media:text>
                                <media:title type="plain"><![CDATA[G&amp;D]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YcP86Mr8XBZ2XZcSaR7Vt6-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>KVM manufacturer G&D has added a 2-factor authorization (2FA) security feature to its KVM systems to minimize the risk of cyberattacks. 2FA for KVM systems provides access control to critical data and systems, thus offering a higher standard of security, ensuring that only authorized users can access the systems. This additional security level contributes to protecting sensitive data and significantly reducing the risk of cyberthreats, G&D said.</p><p>Until now, user authentication for KVM systems involved a password query. The optional 2FA introduces a second, ownership-based factor that provides an additional level of security. A Time-Based-One-Time-Password (TOTP) is used for this, a password that is valid for a limited time and can only be used once.</p><p>2FA can be implemented either through authenticator apps or hardware tokens, depending on the user’s individual requirements and preferences. The user can select between using the device&apos;s internal authentication server or an external directory service such as LDAP, Active Directory, Radius, or TACACS+. G&D says the 2-factor authentication option for KVM systems “represents a further step towards a safer and more secure environment for critical infrastructures.”</p><p>In matrix installations, the feature ensures increased security by providing an optional additional layer of security for access to critical data and systems. In extender applications, in which 2FA is included by default, this feature also brings significant benefits. </p><p>Introduced to the public for the first time at ISE 2023 for KVM-over-IP systems, the feature is now being incorporated into all G&D products with a network connection. Existing customers will receive the extended system options with the next firmware release. Further information can be found at<a href="http://www.gdsys.com/"> <u>http://www.gdsys.com</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Broadcasters Push for Use of Software-Based EAS ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/broadcasters-push-for-use-of-software-based-eas</link>
                                                                            <description>
                            <![CDATA[ NAB says it will help with security and eliminate need for specific hardware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Mt2LbU49FRHSFPEcUtH6WX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Apr 2023 12:28:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ Randy J. Stine ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png">
                                                            <media:credit><![CDATA[Creative Commons]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EAS]]></media:description>                                                            <media:text><![CDATA[EAS]]></media:text>
                                <media:title type="plain"><![CDATA[EAS]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vi25hASYhrcjY83ApdGusE-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>The following article is from TV Tech sister brand Radio World:</em></p><p>A new optional approach to internal EAS operations is being advocated by the National Association of Broadcasters as a way to help broadcasters secure alerting equipment from cyberattack.</p><p>NAB says using software-based encoder/decoder technology would eliminate the need for physical EAS equipment and promote the aims of the FCC. </p><p>However, one EAS equipment manufacturer believes that “virtualization” proposals for EAS “would be inherently dangerous” and risk weakening both local and national EAS.</p><p>Using software-based tech for EAS is referred to as virtualization in the proponents’ comments. Broadly speaking, virtualization typically means that a particular function is no longer tied to a specific physical piece of equipment. </p><p>It’s common now for equipment providers to supply software that can run on a station’s servers. EAS functionality could be added to a piece of equipment in the air chain, observers say, similar to what Nielsen is doing by licensing its watermark technology to audio processor manufacturers, who put PPM encoding right in their products. Or the software could run in a standalone computer. </p><p>It presumably also could run in the cloud, although NAB did not specifically ask for that, according to a person familiar with the issue.</p><p><strong>&apos;Minor Policy Issue&apos;</strong><br>The FCC has advanced its own ideas to secure EAS equipment from cyber threats, but broadcasters say the commission’s proposal in MB Docket 22-329 is unduly burdensome and expensive and would not improve security. It would require stations to report incidents of unauthorized access to internet-connected EAS equipment within 72 hours and file annual reports certifying that they are prepared for a cyberhack attempt.</p><p>NAB and others want the FCC to look at flexible alternatives, which is where the proposal to allow software-based EAS comes into play.</p><p>“We have joined with leading engineers and technologists in the broadcasting industry to identify one minor policy change that would substantially promote the FCC’s goal of enhancing the security of EAS,” NAB wrote to the commission, asking that stations and other EAS participants be allowed to use software-based EAS encoder/decoder technology in place of a physical device.</p><p>A virtualized EAS platform would receive and create alert messages just like the existing hardware system, it said, functioning independently within a station’s infrastructure. </p><p>NAB wrote that its idea would promote the “consideration of efficient, secure technologies that could enable flexibility for future enhancements of emergency messaging and other aspects of EAS, including centralized virtualization.” It said this “voluntary modernization” will better align EAS components with other modern broadcast systems.</p><p><em>(Read More: </em><a href="https://www.tvtechnology.com/opinion/how-secure-is-your-alerting"><em>How Secure is Your Alerting?</em></a><em>)</em></p><p>“EAS is an unfortunate anomaly in the operation of today’s broadcast facilities, as nearly all other components of the broadcast operations chain are advanced, software-based virtualized technology, while the components that make up EAS do not currently have a clear roadmap out of a hardware-only based system,” NAB argued.</p><p>NAB listed several ways a software approach would promote the aims of the FCC: </p><ul><li>It would free stations from constraints of physical hardware, such as providing a safe, climate-controlled physical location for the box. </li><li>Broadcasters running modern, IP-based air chains would no longer have to convert media content and EAS control signals to either wired analog or digital to feed into EAS boxes and then re-convert the signals back into IP for their air chains. </li><li>Virtualization promotes reliability, NAB said, by providing flexibility for immediate fail-over using multiple instances of EAS software and enabling redundant, replicated systems to operate remotely in diverse geographic locations. </li><li>A software-based approach would facilitate improved system monitoring and alerting through near real-time, automated collection of activity data. </li><li>Software-based systems provide more flexibility to manage and route messaging to various broadcast streams, such as HD Radio main and multicast channels, for the benefit of public safety. </li></ul><p>Cox Media Group told the FCC it sides with NAB. “The permissive use of a virtual EAS encoder/decoder would provide station licensees with many benefits, including streamlined operations and improved remote maintenance and control,” CMG wrote.</p><p>“Software-based EAS systems could be upgraded and repaired quickly and easily, reducing downtime and increasing the operational readiness and security of EAS equipment.” </p><p>(Addressing other aspects of the NPRM, CMG wrote that instead of adopting new notice and certification requirements, a more “cooperative” approach between broadcasters and the FCC would strengthen the alerting program.)</p><p>REC Networks, an advocate for LPFM stations that often comments on FCC technical matters, supports NAB’s suggestion and agrees such software-based arrangements can better mesh with a radio station’s network.</p><p>“This type of change would also better encourage additional developers to enter the EAS arena,” REC wrote. “Such software-based infrastructure can better integrate with radio automation systems and streamline the methods for delivery to EAS information on HD multicast streams.”</p><p>National Public Radio also sees the benefits of a software-based EAS and believes it would permit stations with large coverage areas to better tailor alerts to those who really need them, guarding against EAS-alert fatigue while still being distributing alerts efficiently.</p><p>“And unlike the current dispersed approach, stations that chose to use software-based EAS could better tailor alerts without the significant additional costs,” NPR told the FCC.</p><p>“In addition, software-based EAS equipment could enable stations to pull from FEMA’s Integrated Public Alert and Warning System as the primary monitoring source, thereby enabling better audio quality and greater information in the broadcasted alerts.” </p><p><strong>&apos;Weakened Security&apos;</strong><br>NAB considers its proposal a minor change. But EAS equipment manufacturer Digital Alert Systems expressed strong misgivings.</p><p>“We contend that virtualization as suggested would not improve security — rather it would lead to much weakened security and reliability of local and national EAS,” it wrote.</p><p>“The NAB suggestion grossly underestimates — and in fact ignores — the complications and glaring added risks of this approach.”</p><p>The EAS equipment manufacturer goes further: “Virtualization (in the form of moving critical EAS operations into a software-only or cloud environment) presents multiple challenges. Many experts in network operations have discussed the potential drawbacks of using a cloud computing system and host provider for critical operations.”</p><p>Digital Alert Systems says depending on the cloud network and risking potential server downtime are a not a good combination for reliable EAS. </p><p>Among its concerns is network connectivity dependency. “A virtualization of EAS is useless if there is no working internet connection,” it wrote. </p><p>Other issues include server downtime; lack of support; the cost of cloud computing services over time; and security. “We note that — tellingly — no proposal for virtualized services have stated how this would enhance the actual security of EAS.” </p><p>It also said moving EAS into a software-only environment raises the risk of SOUP, or “Software of Unknown Pedigree.” Such solutions, it said, risk bringing uncertified applications entering the EAS ecosystem.</p><p>Asked by Radio World to expand on its comments, the company’s Ed Czarnecki said, “We continue to work with the broadcast industry to field approaches that are helping to address some of these underlying challenges. EAS devices such as the DASDEC remain critical for on-site EAS functions, which we are complementing with virtualized services for system monitoring, management, reporting and remote software updating.”</p><p>He referred to this as “hybrid virtualization” and said the approach is widely used in cable TV. He also said hundreds of DASDEC units in the broadcast industry are using the company’s Collector and Halo services. </p><p>Sage Alerting Systems, also an EAS equipment manufacturer, mentioned virtualization only briefly in its own comments to the commission.</p><p>“As to virtualization of EAS, Sage looks forward to working with the FCC and EAS participants to support future directions of the broadcast industry while continuing to meet the needs of FEMA for dissemination of the Emergency Action Notification, and the needs of the other ‘legacy’ backup components of EAS,” it wrote.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How Secure is Your Alerting? ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinion/how-secure-is-your-alerting</link>
                                                                            <description>
                            <![CDATA[ Recent cyberattacks on Russian emergency alerting underscore the timeliness of checking your EAS setup ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gtEhUbP7b4JANGySigHwCg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 12:37:52 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 13:13:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Phil Kurz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/sNtEgpne6F9EezmB5uHeVM.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Here’s an eye-opener. Three times in March, hackers targeted Russian broadcasters, taking over their emergency alert system to warn the public falsely of attacks. </p><p>The most recent as of this writing occurred on March 9, according to a story by William Mata on “The Independent”’s website.</p><p>“Radio and television broadcasts in Moscow and the western Sverdlovsk area were interrupted with a phony warning of a missile strike on the country,” the story said. The public was told to don gas masks, take potassium iodine and head quickly to shelters.</p><p>Given current geopolitical tension, perhaps it is a good idea to conduct regular security audits of the EAS system in this country—something the government regards as critical infrastructure. In August 2022, Homeland Security Today reported FEMA was advising of “certain vulnerabilities in EAS encoder/decoder devices” that did not have the latest software. Those vulnerabilities could make broadcasters susceptible to attacks from hackers, allowing them to take over the alerting system. </p><div><blockquote><p>At the moment, neither FEMA nor the FCC require security testing of EAS devices."</p></blockquote></div><p> </p><p>FEMA made three recommendations: Update systems to run the latest software; make sure EAS devices are behind firewalls; and regularly monitor EAS devices and supporting infrastructure and review audit logs to seek out unauthorized access.</p><p>At the moment, neither FEMA nor the FCC require security testing of EAS devices. Digital Alert Systems has strongly supported a FEMA suggestion to introduce a baseline security component to the evaluation and certification of EAS encoder/decoders in ex parte filings with the commission, said Edward Czarnecki, the company’s vice president for global and government affairs.</p><p>In October 2022, however, the agency launched a <a href="https://www.fcc.gov/document/fcc-proposes-strengthen-security-emergency-alert-systems"><u>rulemaking</u></a> to improve security and reliability of EAS and Wireless Emergency Alerts.</p><p>While the industry waits, now might be an excellent time to confirm EAS software is up-to-date, the efficacy of firewall protection and whether or not regular audits of access are occurring to see if bad actors have penetrated the system.</p><p>We all remember the panic that residents and tourists in Hawaii experienced five years ago when a miscommunication during a drill by the state’s emergency management agency caused a false missile attack alert.</p><p>With tensions running high, this country does not need hackers taking control of EAS and needlessly scaring people, and in the process jaundicing attitudes about future, legitimate warnings whether they are for severe weather or something else.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Irdeto Launches Upgraded Irdeto ActiveCloak for Media ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/irdeto-launches-upgraded-irdeto-activecloak-for-media</link>
                                                                            <description>
                            <![CDATA[ The enhanced solution is designed to protect vulnerable devices against the extraction of content encryption keys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9dA2hp7mTVeekgbGJKuY3f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nSEHCfsF2W7v3fvNzFYXuH-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Feb 2023 21:21:04 +0000</pubDate>                                                                                                                                <updated>Tue, 07 Feb 2023 21:26:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/nSEHCfsF2W7v3fvNzFYXuH-1280-80.png">
                                                            <media:credit><![CDATA[Irdeto]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Irdeto]]></media:description>                                                            <media:text><![CDATA[Irdeto]]></media:text>
                                <media:title type="plain"><![CDATA[Irdeto]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nSEHCfsF2W7v3fvNzFYXuH-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>AMSTERDAM</strong>—The cybersecurity provider Irdeto has launched a new and improved ActiveCloak for Media (ACM), a software digital rights management (DRM) software development kit (SDK). The enhanced solution includes multiple layers of security that are designed to ensure content encryption keys cannot be illegally extracted from devices, the company reported. </p><p>“With the relaunch of Irdeto ACM, we are listening and responding to our customers’ needs,” said Andrew Bunten, Irdeto’s new chief operating officer for video entertainment. “Irdeto ACM is a much-needed solution to address one of the biggest sources of piracy today, and we add another tool to our arsenal of anti-piracy services. Video service providers can pick and choose to meet a specific need or go for a broader solution set for “lens to screen” protection in their fight against piracy.”</p><p>Content key extraction is the biggest piracy issue facing video streaming services and pay-TV operators, the company said. </p><p>This is because many devices in use today lack hardware DRM protection and rely solely on its operating system software DRM, making them highly vulnerable to content key extraction. With content encryption keys in hand, pirates can create a host of problems, including the delivery of illegal services leading to missed revenue opportunities and increased CDN costs, Irdeto said. </p><p>Irdeto said that its ACM helps to avoid the reputational and operational impact by protecting the video applications themselves instead of relying on the device’s operating system DRM to secure the content on vulnerable devices. With Irdeto ACM, the content decryption will bypass the device’s operating system software DRM, taking place inside the video application itself instead, the company said. </p><p>Unlike proprietary DRM-based solutions in the market, Irdeto ACM works with any DRM server vendor, which eliminates costly custom integrations. Its renewable security provides increased agility to deploy fast and respond efficiently to piracy attacks. It protects against pervasive threats to software security, including reverse engineering, software tampering, copying/cloning, and automated attacks while safely encrypting and decrypting data and communications, the company said. </p><p>More information is available <a href="https://irdeto.com/video-entertainment/activecloak-for-media/" target="_blank">here</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No Laughing Matter: Comedy Is the Most Pirated Genre ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/no-laughing-matter-comedy-is-the-most-pirated-genre</link>
                                                                            <description>
                            <![CDATA[ Value of entertainment piracy is 300% greater than sports, according to Synamedia and Ampere Analysis ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dXoLiSnR73xrsJQmUJQXVL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Feb 2023 20:13:04 +0000</pubDate>                                                                                                                                <updated>Fri, 03 Feb 2023 20:13:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Pete Linforth from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LONDON</strong>—Video software provider Synamedia has unveiled research on piracy covering seven countries that found comedy is the most pirated entertainment genre. </p><p>Piracy was driven by such titles as “Ghostbusters: Afterlife”, and “Ted Lasso”, with half of all pirate viewers streaming comedy illegally. This is followed by the action and adventure genre, and the crime and thriller category respectively, the researchers reported. </p><p>The study, conducted by Ampere Analysis, finds the value of entertainment piracy is three times bigger than sports piracy and that the fragmentation of rights across more services is now affecting piracy in the entertainment market as it has for sports.</p><p>If piracy was stopped, sports would create $9.8 billion in potential revenue in the seven surveyed markets, however this figure is dwarfed by the possibility of unlocking an additional $21.8 billion in revenue by converting movie and TV pirates to legal services, the researchers reported. </p><p>The study covers the impact of sports and entertainment piracy across seven countries and the potential revenues that would result from converting pirate viewers to legal subscribers. </p><p>“Unless the industry takes action, the fragmentation of premium content compounded by the current economic climate will continue to drive viewers to both paid and free piracy services,” explained Avigail Gutman, vice president of intelligence and security operations at Synamedia. “This represents a real risk to rights holders, broadcasters and streaming providers. As well as using tools and techniques to protect content and services, operators can counter the rise in piracy by ensuring content is easy to find and meeting consumers’ demands for mobile-first services, as well as more aggregated services and billing.”</p><p>The data shows that stopping piracy of a single Hollywood major movie release can trigger revenues of between $130m and $280m in the U.S. alone, with super-hero blockbusters offering the biggest opportunities. For a popular title like “Spider Man: No Way Home”, stopping piracy would lead to potential revenue for a studio streaming service of over $400m, based on the true annual lifetime value of streaming subscribers.</p><p>Of the seven countries surveyed, Synamedia’s report finds that the market with the most to gain is the US, with the potential of $13.7 billion in new revenue annually by stopping movie and TV piracy and an additional $5 billion related to sports. This would generate $5.9 billion in annual income for US streaming providers, with the 28 most heavily pirated movies and TV titles alone contributing up to $1.8 billion in new revenues.</p><p>According to the research, Germany, Italy and the UK have the lowest levels of piracy. But, by stopping piracy and converting pirate viewers to legal subscribers in the UK for example, video providers and content owners have the potential to unlock a whopping $1.36 billion for entertainment and $1.17 billion for sports annually, the companies said.</p><p>Football is the star sports piracy attraction and, despite being available on free-to-air TV, FIFA World Cup it is the most pirated league according to the findings. This reflects its popularity globally but indicates that even free content can suffer from piracy if fans are already using illegal sites to access other sports content. </p><p>UEFA Champions League and the English Premier League are second and third respectively. The only non-football league in the top 10 is the NBA. After football, the most popular sports to watch on pirate services in the seven countries surveyed are cricket and kabaddi, driven by piracy in the Indian sub-continent, and badminton, driven by piracy in Asia, the researchers said. </p><p>The study also found that pirate viewers using both free and paid for services are more likely to be male with paying pirates more likely to be to be men under 35 with young children. The research finds that 44% of affluent consumers pay to pirate live sports, despite most pirates falling into lower income groups, indicating a desire to cut costs and watch all the leagues in one place.</p><p>As fragmentation of content rights continues, the research finds that pirate viewers tend to be those who are most engaged with content. As consumers increase the number of legal subscriptions they have, they also become increasingly likely to watch pirate content with 91% of respondents who have access to five or more legal video subscription services have also watched illegal content.</p><p>“There is a persistent myth that the pirate consumer won’t pay and will never pay,” noted Guy Bisson, executive director and co-founder of Ampere Analysis: This research overturns this received wisdom, with more than half of all pirate viewers paying for pirate TV services and 54% also paying for legal services. We already knew sports piracy was a big-money issue, but what surprised us most about this study was the true scale of impact on the US major studios and Hollywood as a whole.”</p><p>Building on Synamedia’s research report into sports piracy in 2021, this survey involved 16,000 consumers in Brazil, Italy, India, Germany, Thailand, UK, and US.</p><p>Synamedia and Ampere Research will host a fireside chat, ‘No laughing matter: pirates enjoy comedy’ to discuss the findings in more depth on Tuesday 28th February 2023 at 4pm UK / 5pm CET / 11 am ET / 8 am PT. More information is available <a href="https://event.on24.com/wcc/r/4084694/97DEEEF7F88D487DB8CD1B231648F02E" target="_blank">here</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TAG Cyber Issues Detailed Report on Deepfakes ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/tag-cyber-issues-detailed-report-on-deepfakes</link>
                                                                            <description>
                            <![CDATA[ News organizations are increasingly grappling with ways to both cover the issue and protect themselves from deepfakes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mSd5XJkdYWad2cqHXgXqJo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jan 2023 19:53:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Pete Linforth from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NEW YORK—Broadcasters, news organizations and entertainment companies struggling to deal with the growing problem of deepfakes now have a new resource to help them better understand the problem and protect themselves from deepfakes thanks to TAG Cyber, which has issued a detailed analysis of the issue. </p><p>The 100-plus-page report, which is TAG Cyber’s 2023 Q1 edition of the TAG Cyber Security Annual, includes a wide ranging series of articles and interviews exploring the impact of deepfakes and the problems they are creating for governments, businesses and individuals as well as a host of potential solutions and technologies that can help mitigate the problem. </p><p>In the report, TAG Cyber, which is a leading provider of cyber security research, analysis, and training, takes a nuanced approach to the problem, exploring both the positive and negative uses of the technology. </p><p>It includes a number of case studies in how deepfakes are being used by criminal organizations for identity theft and bank fraud and by governments and political movements to disseminate propaganda. </p><p>The publication also explores how deepfakes have become increasingly prevalent in politics and the entertainment industry in recent years and how they are now threatening business and enterprise as well. </p><p>The articles and interviews with security experts also explore the latest deepfake technologies and how they are being used to spread defamation, disinformation and propaganda as well as some of the potential positive uses of deepfakes, such as in education.</p><p>While much of the attention on deepfakes has focused on video and photos, the publication complements its analysis of video deepfakes with a deep dive into audio deepfakes, which have become increasingly prevalent in recent years. </p><p>Audio deepfakes are being used now to hack into company networks to steal large sums of money, impersonate individuals, and even manipulate stock prices. The edition explores the latest audio deepfake technologies and how they are being used to spread misinformation and propaganda.</p><p>"Deepfakes are a rapidly evolving technology that has the potential to cause significant harm," said Dr. Edward Amoroso, CEO of TAG Cyber. "This edition of the TAG Cyber Security Annual provides readers with the information they need to understand the dangers of deepfakes and how to protect themselves and their organizations."</p><p>The TAG Cyber Security Annual is available for free download on the <a href="https://www.tag-cyber.com/advisory/quarterly" target="_blank"><u>TAG Cyber website</u></a>.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three in Four Americans Admit to Unsafe Online Behavior ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/three-in-four-americans-admit-to-unsafe-online-behavior</link>
                                                                            <description>
                            <![CDATA[ Many underestimate the threat of cyberattacks at a time when the average home has 15 connected devices according to the latest Comcast Cyber Health Report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hBptm5RoxYndt7AQfLrToV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Dec 2022 18:00:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Pete Linforth from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JVRAAVxv9A5yc5YXxSpmGG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>PHILADELPHIA</strong>—With a record number of connected devices expected to flood into homes during this holiday season, Comcast’s newly released Xfinity Cyber Health Report indicates that the vast majority of Americans are not taking proper precautions to deal with the cybersecurity threats these devices can pose. </p><p>The new Comcast survey found that more than three in four Americans (78 percent) admit to risky online behaviors that open them up to cyber threats, such as reusing or sharing passwords and skipping software updates. And despite widespread publicity regarding the problems cyberattacks can create, that alarming level of unsafe behavior up 14% from just two years ago, Comcast reported. </p><p>The report, which combines data from a new consumer survey with actual threat data collected by Xfinity’s xFi Advanced Security platform, also reveals that the service, which is free for Xfinity customers who lease a capable Xfinity gateway, has blocked nearly 10 billion cybersecurity threats since launching less than five years ago.</p><p>"Our Xfinity Cyber Health Report demonstrates that, despite more awareness about the prevalence of cybersecurity risks, we have to continue to be diligent to ensure our devices in homes, and the people using them, stay safe,” said Noopur Davis, executive vice president, chief information security officer and product privacy officer, Comcast. “The digital security of our customers is our top priority. As the number and complexity of cyber threats grow each day, we use smart tools and technologies across our network to offer multiple layers of protection to help keep our customers safe.”</p><p>The Xfinity Cyber Health Report summarizes cyber threat trends from Xfinity’s xFi Advanced Security, the growing list of devices in connected homes, and a view into consumers’ attitudes and behaviors around cyber protection. Key findings include:</p><ul><li>Connected Homes Are Expanding and So Is Attack Volume: Xfinity xFi homes average 15 connected devices, up 25 percent from 2020. Power users average 34 devices. And 58 percent of consumers plan to buy at least one connected device this holiday season. xFi Advanced Security blocks an average of 23 unique threats per home each month – with the total number of attacks at least three-to-four times that number, since many attacks are repeated.</li><li>Consumers Still Underestimate Threats: Nearly three fourths (74 percent) of Americans believe less than 10 attacks hit their home network every month. 61 percent believe devices are protected from threats right out-of-the-box at purchase. This leaves many new devices open to potential threats without protection.</li><li>Consumers Unsure They’d Know They’ve Been Hacked: When asked how soon they would know whether they were a victim of a cyberattack, only 20 percent said immediately. Another 32 percent said they aren’t sure they’d ever know if they were a victim of a cyberattack. And 51 percent of respondents noted they are not confident that they would know if a non-screen device was hacked, such as a robot vacuum or a smart plug.</li><li>Emerging Device Vulnerabilities Misunderstood: Computers and smartphones remain the top two targeted devices consistent with findings in 2020. While consumers recognize the risks associated with these two device types, they underestimate the risk with emerging devices in their homes. In fact, xFi Advanced Security blocked threats to smart watches, lighting, thermostats, doorbells, garage openers, sports and fitness equipment, sprinkler systems and even cars, drones and pet accessories.</li><li>Generational Cyber Divide: 70 percent of Boomers admit to unsafe behaviors compared with Gen X (82 percent), Millennials (83 percent) and Gen Z (87 percent). Gen Z had the lowest awareness of common threats such as phishing and malware. 77 percent of Millennials are likely to buy a connected device this holiday season, the most for any segment surveyed.</li></ul><p>In addition to the network and consumer data, the 2022 Xfinity Cyber Health Report includes insights from Asad Haque, Comcast’s executive director of security architecture, regarding connected home security with Matter and xPKI; a technology primer on Comcast’s threat analytics platform from David White, vice president, security engineering at Comcast; an overview of the role of Comcast’s xGitGuardTM software in data privacy from Bahman Rashidi, Ph.D., director, cybersecurity & privacy engineering research; and five actionable tips for consumers on securing their connected home.</p><p>As the largest broadband provider in the U.S. serving more than 32 million internet customer households, Comcast provides the xFi Advanced Security service to protect home networks from cyber threats and is free to all internet customers with the xFi Gateway who sign in through the Xfinity app. </p><p>The survey, conducted by Wakefield Research, polled 1,000 nationally representative U.S. adults ages 18 and older in November 2022, using an email invitation and an online survey. </p><p>The full 2022 Xfinity Cyber Health Report is available <a href="https://update.comcast.com/wp-content/uploads/sites/33/dlm_uploads/2022/12/2022-Xfinity-Cyber-Health-Report-12.13.22-5pm-reduced.pdf" target="_blank"><u>here</u></a>.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC Poised to Address Cybersecurity of EAS Equipment ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/fcc-poised-to-address-cybersecurity-of-eas-equipment</link>
                                                                            <description>
                            <![CDATA[ Broadcasters would be required to report cyber threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vvcA6ubpoVY8wG6TdHLmiK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Oct 2022 14:36:21 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Oct 2022 14:37:15 +0000</updated>
                                                                                                                                            <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ Randy J. Stine ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A public draft of proposed EAS rules being circulated by the FCC would require EAS participants, including broadcasters, to certify annually that they have implemented a cybersecurity risk management plan for their EAS system.</p><p>If adopted, the new rules would require broadcasters to report incidents of unauthorized access of its EAS equipment within 72 hours of when it knew or should have known the incident occurred. According to the Notice of Proposed Rulemaking (NPRM) being considered, this would bolster the security of the nation’s public alert and warning systems.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:525px;"><p class="vanilla-image-block" style="padding-top:66.67%;"><img id="NB8CTMkXutprpYo7P6VCPi" name="EAS eas_logo_rev1_3.png" alt="FEMA" src="https://cdn.mos.cms.futurecdn.net/NB8CTMkXutprpYo7P6VCPi.png" mos="" align="right" fullscreen="" width="525" height="350" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: FEMA)</span></figcaption></figure><p><br></p><p>The proposal to strengthen the operational readiness of EAS equipment would require broadcasters to employ “sufficient security measures to ensure the confidentiality, integrity, and availability of their respective alerting systems.” </p><p>The draft NPRM is not a final adopted action, but it shows the commission is giving tentative consideration for the changes, which could be approved at the FCC’s Oct. 27 monthly meeting.  </p><p>FCC Chairwoman Jessica Rosenworcel has been pushing for a more solid EAS foundation: “It is critical that these public safety systems are secure against cyber threats, which means that we must be proactive.” </p><p>The FCC says there have been several occasions of cyber attacks on EAS equipment. Notably, a 2013 attack on equipment at TV stations in Michigan, Montana, Utah, New Mexico and California notified viewers of a “zombie attack” hoax.</p><p> The commission says that the hack could have been prevented had the EAS participants involved changed manufacturer default passwords on their EAS equipment, installed firewalls, or taken other appropriate security measures. </p><p>In addition, in 2020 hackers compromised the EAS systems of an EAS participant in Jefferson County, Wash., and caused the transmission of false EAS alerts describing a fake Radiological Hazard Warning that affected approximately 3,000 homes.</p><p>The FCC has previously warned broadcasters their EAS equipment connected to the Internet were potentially vulnerable to IP-based attacks due to inadequate network security or unsecure device settings. At the time the commission urged them to secure their EAS equipment by installing current security patches, and using firewalls.</p><p>Most recently, on August 1, 2022, FEMA issued an advisory on a potential vulnerability in certain EAS encoder/decoder devices that have not been updated to most recent software versions.</p><p>The FCC draft also addresses the overall operational readiness of EAS equipment. Currently, broadcasters and cable providers may continue operations for a period of 60 days despite having defective EAS equipment that preclude their participation in EAS. The FCC notes that, according to the last nationwide EAS test report, “an appreciable number of EAS participants were unable to participate in testing due to equipment failure — despite advance notice that such test was to take place — suggesting that equipment failures are not addressed by EAS participants as swiftly as reasonably possible and that more needs to be done to improve EAS operational readiness.”</p><p>The FCC also addresses the security of Wireless Emergency Alerts (WEA) in the public draft and is likely to require wireless providers to take steps to ensure only valid alerts are displayed on consumer devices.   </p><p>If adopted, the new rules would clearly increase compliance and the amount of effort and paperwork on behalf of broadcasters, according to observers. The FCC says in the draft: “We believe that EAS participants will, on average, require 10 hours annually to initially draft a plan and then update the plan and submit their certification annually.”</p><p>The commission says it expects to consider the economic impact and alternatives for small entities following the review of comments filed in response to the NPRM, including costs and benefits analyses.</p><p>“We believe that the benefits of this proposal outweigh the costs. However, we [expect to] seek comment on any measures that the commission could take to reduce burdens on EAS participants if it were to take further steps to promote the operational readiness of EAS equipment,” according to the FCC document.</p><p>If the commissioners vote “yes” this week then a comment period will commence 30 days after the date of publication in the Federal Register.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Report: Film Piracy Up Nearly 50% in 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/report-film-piracy-up-nearly-50-in-2022</link>
                                                                            <description>
                            <![CDATA[ MUSO says visits to piracy websites up 22% ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">knY82ZoCWSut67Hcp4R3R5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Oct 2022 12:19:12 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Oct 2022 21:15:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ tom.butts@futurenet.com (Tom Butts) ]]></author>                    <dc:creator><![CDATA[ Tom Butts ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/Ym75XZxKuaGiZGj7nMGeGM.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A report from U.K. data research firm MUSO says that traffic to piracy websites in 2022 has increased 22% with TV content—the largest media sector—representing 46.6% of pirated content. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:450px;"><p class="vanilla-image-block" style="padding-top:72.89%;"><img id="wggSvKh62MF8ASXvzMAShT" name="1-Oct-04-2022-06-59-19-31-PM.png" alt="MUSO" src="https://cdn.mos.cms.futurecdn.net/wggSvKh62MF8ASXvzMAShT.png" mos="" align="middle" fullscreen="" width="450" height="328" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Piracy by sector, Jan-Aug 2022. Data from MUSO.com </span><span class="credit" itemprop="copyrightHolder">(Image credit: MUSO)</span></figcaption></figure><p>The report—which measured traffic to piracy websites from January to August 2022—said that piracy has increased in  every industry sector with film piracy traffic showing the highest growth by 49.1%. Music saw the lowest increase of 3.87%. As far as delivery of this unlicensed content is concerned, 53.9% of traffic is for unlicensed streaming sites vs 46.1% for download sites (which includes torrents and cyberlockers). </p><a target="_blank"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:879px;"><p class="vanilla-image-block" style="padding-top:60.30%;"><img id="sg3jfFFHv8huqCNbHjn69K" name="2-Oct-04-2022-07-01-53-03-PM.png" alt="MUSO" src="https://cdn.mos.cms.futurecdn.net/sg3jfFFHv8huqCNbHjn69K.png" mos="" align="middle" fullscreen="1" width="879" height="530" attribution="" endorsement="" class="expandable"><a href='https://cdn.mos.cms.futurecdn.net/sg3jfFFHv8huqCNbHjn69K.png' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Piracy % increase by industry, Jan-Aug 2022 vs Jan-Aug 2021. Data from MUSO.com </span><span class="credit" itemprop="copyrightHolder">(Image credit: MUSO)</span></figcaption></figure></a><p>MUSO measured visits to the entire piracy eco-system for desktop and mobile visits as well as tracking direct piracy consumption on over 388,000 TV and film titles across both the torrent network and unlicensed streaming websites.</p><p>In terms of analyzing each media sector directly to get a truer picture of delivery trends, MUSO said streaming accounts for 95.1% of traffic for TV content whereas downloads accounted for 99% of Publishing traffic and 100% of software piracy traffic.</p><p>Viewed by geographic distribution, the United States accounts for 10.9% of piracy between Jan-Aug 2022 and is 87.3% higher than Russia in second place. The highest European country is France in fifth place, followed by the U.K. in 7th place.</p><p>According to MUSO, the increase in piracy measured year on year to date, has been driven by various factors. These include:</p><ul><li>More content being released following the Covid-19 delay.</li><li>Proliferation of global and regionalised easy to access piracy websites.</li><li>Increased exclusive content behind various VoD platforms.</li><li>Geo-restricted content, where titles are not available in every country.</li></ul><p>“What is clear is global audience demand for media and entertainment content is increasing and piracy remains an accessible and perhaps preferred method of consumption,” the researcher said. “Audience measurement data is critical for optimum enforcement strategies but can also be used to better understand the audience for business intelligence.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity Group XDR Alliance Expands Membership ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/cybersecurity-group-xdr-alliance-expands-membership</link>
                                                                            <description>
                            <![CDATA[ Banyax, Deloitte, and ReliaQuest are latest members to join XDR Alliance and its work to advance an open XDR framework in cybersecurity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">owjHqZi8m5o2DFLuEwTshK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Sep 2022 19:34:46 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Sep 2022 19:36:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>FOSTER CITY, Calif.</strong>—The XDR Alliance has announced that Banyax, Deloitte, and ReliaQuest have joined the group, which is committed to advancing collaboration and an open, inclusive and collaborative extended detection and response (XDR) framework for advancing cybersecurity. </p><p>“We are pleased to have these providers join and augment the representation in the MSSP/MDR space, and offer their extraordinary API integration expertise across all alliance member technologies and the industry at large,” said Gorka Sadowski, founder of the XDR Alliance and chief strategy officer at Exabeam. “These new members represent joint customers all over the world and have vast expertise in helping end customers benefit from tightly integrated best-of-breed technology stacks in the spirit of being open, inclusive and collaborative. They built and operate some of the world’s largest security operations centers (SOCs).”</p><p>This membership expansion follows the recent XDR Alliance release of a new Common Information Model (CIM) that was created through collaboration with several XDR Alliance members over the last 12 months, since the alliance’s formation. </p><p>Now that the CIM is released as open source via an Apache 2.0 license, the alliance said it will now focus on building a new set of bi-directional APIs to ensure interoperability between all alliance member products and other relevant products across cybersecurity and XDR Alliance member categories.</p><p>“Even with the best of security training for employees, the odds are high that someone will eventually fall prey to a sophisticated cyber scam. It’s up to the cybersecurity industry as a whole to partner together to come up with automated solutions to protect individuals and organizations from adversaries,” said Carlos Alanis, CEO and co-founder, Banyax. “Together with the other members of the XDR Alliance, we can work together to provide next-generation tools to organizations in need of the resources to bolster security posture.”</p><p>“At Deloitte, we know that delivering measurable, sustainable results for our clients and our communities takes teamwork and fresh, innovative thinking. Our Deloitte Managed Extended Detection and Response (MXDR) services help customers benefit from threat hunting, detection, response and remediation capabilities with a best-of-breed, multi-vendor approach built on an open framework ,” says Curt Aubley, MXDR by Deloitte leader and a Deloitte Risk & Financial Advisory managing director, Deloitte & Touche LLP. “We understand the power of collaboration and we are thrilled to participate in the XDR Alliance.”</p><p>“At ReliaQuest, we are committed to making security possible. We believe that security is a team sport and therefore we are excited to join the XDR Alliance,” said Brian Foster, chief product officer at ReliaQuest. “Working with others at the XDR Alliance will help us enable organizations to move at the speed of their business. Ultimately, this is how we help customers increase visibility, reduce complexity, and manage risk in their environment.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious DDoS Attacks Jump By 203% in First Half of 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/malicious-ddos-attacks-jump-by-203-in-first-half-of-2022</link>
                                                                            <description>
                            <![CDATA[ Russian invasion of Ukraine dramatically boosted cyber attacks and shifted the threat landscape, according to Radware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tc7hjb6kmp3QAfCubv9Kda</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Aug 2022 20:01:47 +0000</pubDate>                                                                                                                                <updated>Fri, 26 Aug 2022 14:33:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pixabay]]></media:description>                                                            <media:text><![CDATA[Pixabay]]></media:text>
                                <media:title type="plain"><![CDATA[Pixabay]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>MAHWAH, N.J.</strong>—A new cyber security study from Radware is reporting a dramatic increase in attacks during the first half of 2022, with DDoS or distributed denial of service attacks jumping 203% in the first half of 2022 compared to a year earlier. </p><p>“First Half 2022 Global Threat Analysis Report” from Radware relies on intelligence provided by network and application attack activity sourced from Radware’s Cloud and Managed Services, Global Deception Network, and threat research team.</p><p>“The threat landscape saw a marked shift in the first half of 2022,” said Pascal Geenens, director of threat intelligence for Radware. “As Russia invaded Ukraine, the cyber focus changed. It shifted from the consequences of the pandemic, including an increase in attack surfaces driven by work from home and the rise of underground crime syndicates, to a ground swell of DDoS activity launched by patriotic hacktivists and new legions of threat actors.”</p><p>The first six months of 2022 were marked by a significant increase in DDoS activity across the globe, the company reported. Attacks ranged from cases of hacktivism to terabit attacks in Asia and the United States.</p><p>The number of malicious DDoS attacks climbed 203% compared to the first six months of 2021.</p><p>That means there were 60% more malicious DDoS events during the first six months of 2022 than during the entire year of 2021.</p><p>The company also reported that in May 2022, Radware mitigated a volumetric carpet-bombing attack, which represented a total volume of 2.9 PB. The attack lasted 36 hours, peaking at 1.5 Tbps with a sustained attack rate of more than 700 Gbps for more than eight hours. The combination of duration, volume, and average/sustained attack rates makes this one of the most significant DDoS attacks on record.</p><p>During the first half of 2022, patriotic hacktivism increased dramatically, Radware said. Both established and newly formed pro-Ukrainian and pro-Russian cyber legions aimed to disrupt and create chaos by stealing and leaking information, defacements, and denial-of-service attacks. </p><p>In addition, DragonForce Malaysia, a hacktivist operation targeting Middle Eastern organizations in 2021 made a return in 2022. Its recent campaigns were political responses to national events. OpsBedil Reloaded occurred following events in Israel, and OpsPatuk was launched in reaction to public comments made by a high-profile political figure in India.</p><p>Major information and communication networks in the Philippines, including CNN, news network ABS-CBN, Rappler, and VERA Files, were the target of DDoS attacks in connection with the country’s 2022 general elections.</p><p>“No organization in the world is safe from cyber retaliation at this time,” Geenens warns. “Online vigilantes and hacktivists could disrupt wider security efforts driven by nations and authorities. New legions of actors could introduce extreme unpredictability for intelligence services, creating a potential for spillover and wrongful attribution that could eventually lead to an escalation of the cyber conflict.”</p><p>Outside of the war realm, other cybercrime groups re-emerged and went on with business, the report said. </p><p>During the first half of 2022, a renewed campaign of RDoS or Ransom Denial of Service attacks by a group claiming to be REvil emerged. This time the group was not only sending warning notes for ransom before the attack started, but also embedded the ransom note and demands within the payload.</p><p>In May 2022, Radware discovered several ransom demand letters from a group posing as Phantom Squad.</p><p>During the first six months of 2022, Radware also observed an increase in malicious transactions targeting online applications, dominated by predictable resource location and injection attacks.</p><p>The number of malicious web application transactions grew by 38%, compared to the first six months of 2021, surpassing the total number of malicious transactions recorded in 2020.</p><p>Predictable resource location attacks accounted for almost half (48%) of all attacks followed by code injection (17%) and SQL injection (10%).</p><p>The most attacked industries were retail and wholesale trade (27%) and high tech (26%). Carriers and SaaS providers ranked third and fourth, shouldering 14% and 7% of the attacks respectively.</p><p>Radware’s complete First Half 2022 Global Threat Analysis Report can be downloaded <a href="https://www.radware.com/pleaseregister.aspx/?returnurl=18bf850e-6320-44a7-85e3-65f9ef072dc8" target="_blank"><u>here</u></a>.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World Broadcasting Unions Updates Cybersecurity Recommendations ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/world-broadcasting-unions-updates-cybersecurity-recommendations</link>
                                                                            <description>
                            <![CDATA[ The recommendations involve media vendors’ system, software and services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZWNuhwfTcBHMEJAsguYW89</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vkzdtTrj8m5wE9YMZcigKj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 16:46:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vkzdtTrj8m5wE9YMZcigKj-1280-80.jpg">
                                                            <media:credit><![CDATA[WBU]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WBU]]></media:description>                                                            <media:text><![CDATA[WBU]]></media:text>
                                <media:title type="plain"><![CDATA[WBU]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vkzdtTrj8m5wE9YMZcigKj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>TORONTO</strong>—At a time when broadcasters are facing increased security risks, the World Broadcasting Unions (WBU) has issued updated cybersecurity recommendations for media vendors’ systems, software and services.</p><p>Based on the original work by the European Broadcasting Union (EBU) and North American Broadcasters Association (NABA), these recommendations are intended to create a dialogue with media vendors with the goal of achieving more consistent and effective compliance with cybersecurity best practices, the WBU said. </p><p>These recommendations can be used as an attachment to any equipment or service RFP, RFI, or RFQ to help potential buyers ascertain the cyber maturity of the product and supplier.</p><p>In releasing the new recommendations, the WBU thanked NABA members Grass Valley, Imagine Communications and Ross Video for leading part of NABA’s negotiating team and in working with Lucille Verbaere and her Cybersecurity team at the EBU on the changes.</p><p>The full Cybersecurity Recommendations are available <a href="https://worldbroadcastingunions.org/updated-wbu-cybersecurity-recommendations-for-media-vendors-system-software-and-services/" target="_blank"><u>here</u></a>.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Addressing Security Issues in the Competitive FAST Marketplace ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinion/addressing-security-issues-in-the-competitive-fast-marketplace</link>
                                                                            <description>
                            <![CDATA[ The popularity of live-streamed content, especially sports, has been a major factor in the evolution of pirate tactics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w8EzLbmwkSdjdEcUe3dJFU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 May 2022 18:18:30 +0000</pubDate>                                                                                                                                <updated>Tue, 03 May 2022 18:48:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bo Ferm ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/kSwt57ftY7t6zeDyjuNQg9.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Competitive pressures toward free ad-supported streaming TV (FAST) service differentiation with higher value content have been further intensified by the entry of leading smart TV brands into the crowded field. </p><p>With global smart TV ownership now representing 32% of the TV market base, <a href="https://www.flatpanelshd.com/news.php?subaction=showfull&id=1628582499#:~:text=Smart%20TVs%20on%20the%20rise&text=%2D%20%22More%20than%20665%20million%20homes,will%20reach%201.1%20billion%20homes."><u>according to Strategy Analytics</u></a>, these suppliers have amassed enough viewers to make it worthwhile for FAST service providers to gain exposure on their platforms through revenue-sharing partnerships. By 2026, smart TVs will be in 1.1 billion homes representing 51% of the market, the researcher says.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:66.72%;"><img id="nbVx449QhhPtDCratA4dxN" name="streaming remote.jpg" alt="Pixabay" src="https://cdn.mos.cms.futurecdn.net/nbVx449QhhPtDCratA4dxN.jpg" mos="" align="right" fullscreen="" width="1920" height="1281" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Pixabay)</span></figcaption></figure><p>Most of the FAST content offered through these smart TV platforms is drawn from the same pool of providers. For media companies and multichannel video programming distributors (MVPDs), the key in their use of FAST channels to prevent the TV suppliers from drawing their viewers away from their brands is to differentiate their FAST lineups with high-value content.</p><p><strong>The Realities of a Piracy-Saturated Marketplace<br></strong>That, in turn, increases pressure on all FAST providers to take similar steps toward enhancing their content portfolios. Consequently, everyone in the FAST market not already equipped to support application of sophisticated digital rights management (DRM) processes on an as-needed basis should prepare themselves to do so. </p><p>Moreover, increased content protection, even when licensing policies don’t require it, is becoming essential in light of how the vast online piracy ecosystem has evolved in tandem with the emergence of linear ad-supported OTT content as a major revenue-driver in the legal domain.</p><p>Total global losses to piracy from all types of content theft, including pay TV as well as OTT, will hit $67 billion in 2023, <a href="https://www.digitaltveurope.com/2020/01/16/piracy-to-exceed-us67-billion-by-2023/"><u>according to Parks Associates</u></a>. <a href="https://deadline.com/2019/07/password-sharing-piracy-will-cost-streaming-companies-12-5b-by-2024-report-1202647160/"><u>Parks has also reported</u></a> that 20% of broadband households in the US acknowledge using a piracy device, app or website. </p><p>The popularity of live-streamed content, especially sports, has been a major factor in the evolution of pirate tactics. <a href="https://advanced-television.com/2021/03/15/report-28bn-anti-piracy-sports-rights-bonus/"><u>According to Ampere Analysis</u></a>, as of early 2021 illegal OTT sports streaming worldwide was costing service providers $5.4 billion annually.</p><p>Pirates have capitalized on streaming trends through ad-supported websites offering service bundles mimicking legitimate streaming services. These multichannel services, offered for free or at cut-rate subscription prices, feature professional-caliber EPGs and generate subtitles in multiple languages, supporting delivery to global audiences from anywhere in the world. </p><p>Often people don’t even realize the sites are illegal or, if they do, consider the theft to be of little consequence. <a href="https://www.ibtimes.com/illegal-streaming-more-half-millennials-are-still-watching-content-illegally-2524775"><u>A study by marketing firm LaunchLeap</u></a> surveying North American millennials aged 18-35 found that out of the 53% who admitted to having used illegal providers to stream TV shows and movies during the previous month, nearly two thirds said that streaming seemed “less wrong” than downloading.</p><p>Of course, FAST providers don’t incur subscription losses to piracy, and pirates don’t benefit from interstitial dynamic ad insertion (DAI). Nevertheless. they garner revenue from impressions registered by pre-roll and post-roll ads and ads placed on their EPGs and in other locations external to the content. But viewers’ access to content through these sites hurts FAST providers by diminishing the number of interstitial ad impressions tabulated through legal channels. </p><p>Where premium content is concerned, the losses are far greater. As the scale of global theft mounted over the past decade, providers of premium content, led by the motion picture studios, stiffened their licensing requirements. Today they require the highest-caliber public/private key DRM protection and, in many instances, use of forensic watermarking as well in order to identify and shut down piracy websites. </p><p><strong>A Viable Path to Addressing Emerging FAST Service Security Needs<br></strong>Efforts to accommodate these requirements through home-grown platforms and workflows are very costly and especially out of reach for providers like FAST operators who only need to make intermittent use of such protection. </p><p>But, fortunately, it’s now possible to benefit from both multi-DRM and watermarking services on a pay-as-you-go basis through cloud-based security-as-a-service providers such as Intertrust ExpressPlay, among others.</p><p>By enabling video service providers to implement robust rights management on a usage-driven cost basis without requiring new infrastructure or incurring extraneous setup costs, cloud-based multi-DRM services make it possible for even the smallest FAST providers to cost effectively fulfill stringent studio licensing requirements. </p><p>FAST providers need to be able to act on any opportunities to license premium content they deem relevant to their success as ever more producers see the benefits of making such content available in the FAST market. Cloud-based multi-DRM services enable FAST providers to act quickly at minimal costs. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Bolsters Cloud Security with $5.4B Deal For Mandiant ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/google-bolsters-cloud-security-with-dollar54b-deal-for-mandiant</link>
                                                                            <description>
                            <![CDATA[ The cybersecurity firm Mandiant will join Google Cloud ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bFpiXqwWZsgZZcfYrui4SB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hYagyQShHLyuZ4wkY2sTqg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Mar 2022 19:18:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hYagyQShHLyuZ4wkY2sTqg-1280-80.jpg">
                                                            <media:credit><![CDATA[Mandiant]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mandiant]]></media:description>                                                            <media:text><![CDATA[Mandiant]]></media:text>
                                <media:title type="plain"><![CDATA[Mandiant]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hYagyQShHLyuZ4wkY2sTqg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>RESTON, Va</strong>.—At a time when cloud providers are facing heightened security risks, the cybersecurity firm Mandiant, Inc. has announced that it has entered into a definitive agreement to be acquired by Google LLC for approximately $5.4 billion. </p><p>Upon the close of the acquisition, Mandiant will join Google Cloud.</p><p>Mandiant has more than 600 consultants who currently respond to thousands of security breaches each year and more than 300 intelligence analysts. Those consultants and analysts provide insights for its cyber defense solutions delivered through the managed multi-vendor XDR platform, Mandiant Advantage.</p><p>The acquisition will complement Google Cloud’s existing strengths in security, which Google has said are a cornerstone of its cloud-based offerings. Together with Mandiant, Google Cloud will deliver an end-to-end security operations suite with even greater capabilities as well as advisory services helping customers address critical security challenges and stay protected at every stage of the security lifecycle, the companies said. </p><p>“Cyber security is a mission, and we believe it’s one of the most important of our generation. Google Cloud shares our mission-driven culture to bring security to every organization,” said Kevin Mandia, CEO, Mandiant. “Together, we will deliver our expertise and intelligence at scale via the Mandiant Advantage SaaS platform, as part of the Google Cloud security portfolio. These efforts will help organizations to effectively, efficiently and continuously manage and configure their complex mix of security products.”</p><p>“The Mandiant brand is synonymous with unmatched insights for organizations seeking to keep themselves secure in a constantly changing environment,” said Thomas Kurian, CEO, Google Cloud. “This is an opportunity to deliver an end-to-end security operations suite and extend one of the best consulting organizations in the world. Together we can make a profound impact in securing the cloud, accelerating the adoption of cloud computing, and ultimately make the world safer.”</p><p>The acquisition is subject to customary closing conditions, including the receipt of Mandiant stockholder and regulatory approvals, and is expected to close later this year, the companies said.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCC Takes Steps to Protect Against Cyberattacks From Russia and its Agents ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/fcc-takes-steps-to-protect-against-cyberattacks-from-russia-and-its-agents</link>
                                                                            <description>
                            <![CDATA[ FCC Chairwoman wants public input on protecting against vulnerabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6yg8XtotUaZxjHhCfHhsyR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Feb 2022 14:34:27 +0000</pubDate>                                                                                                                                <updated>Mon, 28 Feb 2022 14:34:31 +0000</updated>
                                                                                                                                            <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ TVT Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hGwyx84o98sF4GpZ7Yhayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON—</strong>In light of Russia’s attack on the Ukraine last week, FCC Chairwoman Jessica Rosenworcel has proposed action to help protect America’s communications networks against cyberattacks. Earlier in the week, the Department of Homeland Security warned U.S. organizations at all levels that they could face cyber threats stemming from the Russia-Ukraine conflict; the FCC said Chairwoman Rosenworcel’ss proposal would begin an inquiry into the vulnerabilities of the internet’s global routing system.</p><p>If adopted by a vote of the full commission, the Notice of Inquiry would seek public comment on vulnerabilities threatening the security and integrity of the Border Gateway Protocol (BGP), which the FCC says is central to the internet’s global routing system. The inquiry would also examine the impact these vulnerabilities would have on the transmission of data through email, e-commerce, bank transactions, interconnected Voice-over Internet Protocol (VoIP), and 911 calls—and how best to address these challenges.</p><p>BGP is the routing protocol used to exchange reachability information among independently managed networks on the Internet. BGP’s initial design, which remains widely deployed today, does not include explicit security features to ensure trust in this exchanged information. </p><p>As a result, the FCC said, a bad network actor may deliberately falsify BGP reachability information to redirect traffic. Russian network operators have been suspected of exploiting BGP’s vulnerability to hijacking in the past.  “BGP hijacks” can expose Americans’ personal information, enable theft, extortion, and state-level espionage, and disrupt otherwise-secure transactions.</p><p>Working with its federal partners, the commission has urged the communications sector to defend against cyber threats, while also taking measures to reinforce the nation’s readiness and to strengthen the cybersecurity of vital communications services and infrastructure, especially in light of Russia’s actions inside of Ukraine. </p><p>Chairwoman Rosenworcel also recently shared with her colleagues a Notice of Proposed Rulemaking that would begin the process of strengthening the commission’s rules for notifying customers and federal law enforcement of breaches of customer proprietary network information (CPNI). The inquiry under consideration would build on those efforts, the FCC said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ News Corp. Hit by Cybersecurity Hack ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/news-corp-hit-by-cybersecurity-hack</link>
                                                                            <description>
                            <![CDATA[ In January 2022 it was hit by “persistent cyberattack activity” that may have involved a foreign government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2sDVCp27BgExeSfmgRjnkC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Feb 2022 18:15:30 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Feb 2022 18:16:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NEW YORK—News Corp. told investors on Friday that in “January 2022, the Company…was the target of persistent cyberattack activity” and that it is working with an outside cybersecurity firm, to conduct "an investigation into the circumstances of the activity to determine its nature, scope, duration and impacts.”</p><p>“The Company’s preliminary analysis indicates that foreign government involvement may be associated with this activity, and that data was taken,” the company reported in <a href="https://investors.newscorp.com/node/11716/html"><u>a filing with U.S. regulators</u></a>.</p><p>The filing provided few details of the attack, but it noted that to “the Company’s knowledge, its systems housing customer and financial data were not affected” and that the “Company is remediating the issue, and to date has not experienced any related interruptions to its business operations or systems. Based on its investigation to date, the Company believes the activity is contained.”</p><p>The attack is comes at a time when a number of media companies have been subjected to cyberattacks. In 2021 those included ransomware attacks on Cox Media and Sinclair that impacted a variety of operations, including their TV stations. </p><p>CNN has reported that <a href="https://www.cnn.com/2022/02/04/tech/news-corp-chinese-hackers/index.html"><u>News Corp (NWS) hired cybersecurity firm Mandiant (MNDT)</u></a> to investigate the breach.</p><p>In a statement cited by CNN, Mandiant "assesses that those behind this activity have a China nexus, and we believe they are likely involved in espionage activities to collect intelligence to benefit China&apos;s interests," David Wong, vice president of consulting at Mandiant, said in a statement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Webinar To Examine How To Secure Hybrid Workplaces ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/webinar-to-examine-how-to-secure-hybrid-workplaces</link>
                                                                            <description>
                            <![CDATA[ A panel of IT experts will discuss the findings of a recent Teradici survey of 8,000 people ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JbPDxTeqmjZJabPv5Sdp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ak4UeU5Sqjfq7CtndZFaJJ-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Nov 2021 16:37:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Phil Kurz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/sNtEgpne6F9EezmB5uHeVM.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Ak4UeU5Sqjfq7CtndZFaJJ-1280-80.png">
                                                            <media:credit><![CDATA[Teradici]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Teradici]]></media:description>                                                            <media:text><![CDATA[Teradici]]></media:text>
                                <media:title type="plain"><![CDATA[Teradici]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ak4UeU5Sqjfq7CtndZFaJJ-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>BURNABY, Canada</strong>—A panel of IT experts will discuss key findings from a recent survey on hybrid workflows and examine the shift to working from home, security concerns on the horizon and an anticipated move away from virtual private networks (VPNs) to Zero Trust Architectures during a Dec. 9 webinar sponsored by Teradici.</p><p>The survey results, presented in a 13-page <a href="https://connect.teradici.com/security-report" target="_blank"><u>report</u></a> from Teradici called “Securing the Hybrid Workplace in 2022 and Beyond,” show nearly total support for hybrid workflows post pandemic. </p><p>Ninety-nine percent of the 8,000 survey respondents, including more than 1,100 Media & Entertainment professionals, said their companies’ workforces will be “hybrid” –working remotely at least part of the week after the pandemic. Close to 40% expect at least half of their workforce to work remotely at least twice a week.</p><p>The panel will discuss the differences in how security is managed in Zero Trust, VPN and Desktop-as-a Service deployments as well as an endpoint security strategy. </p><p>Among the findings likely to be examined are:</p><ul><li>A continuation of the shift to BYOD—bring your own devices—and the security implications; </li><li>The high level of dissatisfaction with the performance of VPNs with regards to disconnections and speed;</li><li>Broad agreement that Zero Trust adoption will phase out use of VPNs over the next year;</li><li>The desire for granular control over endpoint device authorization; </li><li>What methods of user authentication will be popular over the next two to three years.</li></ul><p>“The pandemic has caused a fundamental shift in how people work, and the ‘office’ will never be the same,” said Ziad Lammam, global head of Teradici product management, HP. [HP completed its acquisition of Teradici in October.] “As a result of the enormous security concerns associated with unmanaged devices, as well as BYOD, organizations are changing how they think about securing their corporate assets. Expect to see companies move away from traditional VPNs to Zero Trust architectures to shore up their endpoints and protect their data.”</p><p>The webinar, Thursday, Dec. 9, begins at 10 a.m. Pacific Standard Time. Register <a href="https://event.on24.com/wcc/r/3530365/8A423E756EC52776A5DFFCB796D65CE5?_ga=2.48589158.1704176009.1638192565-752697980.1638192565" target="_blank"><u>online</u></a> to attend.</p><p>More information is available on the Teradici <a href="https://www.teradici.com/" target="_blank"><u>website</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keeping Pirates at Bay ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/keeping-pirates-at-bay</link>
                                                                            <description>
                            <![CDATA[ Protecting digital content is a 24/7 challenge ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N5JYqeXxFUvFH95GXWEtRA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Oct 2021 16:16:34 +0000</pubDate>                                                                                                                                <updated>Thu, 21 Oct 2021 14:24:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dan Meier ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Getty Images]]></media:description>                                                            <media:text><![CDATA[Getty Images]]></media:text>
                                <media:title type="plain"><![CDATA[Getty Images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JPYvxo46gNbAdVHhyjzhBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LONDON—</strong>The summer’s tentpole movie was more than a box office disappointment and lawsuit catalyst for Scarlett Johansson; Marvel’s <em>Black Widow</em> was also the most pirated movie of the pandemic era, as reported by TorrentFreak. One possible culprit (apart from the temptation to see Ray Winstone attempt a Russian accent) is simultaneous digital distribution, the practice of releasing a film on VoD and in theaters at the same time. </p><p>Not only is this potentially harming earnings (the complaint behind Johansson’s legal action), it arguably makes the most valuable assets the most vulnerable. </p><p>“The opportunity for cyberattacks to occur is elevated as the risk of disruption from these digital releases increases during high-profile events, mainly if a film is available to download and stream at the same time as a cinema release,” says Eric Elbaz, strategic engagement manager—Broadcasting Media, Akamai. “Pirates and threat actors are opportunistic in nature and will take advantage of high-profile releases to maximize their impact and return on investment. Companies must be aware of this trend and take action to mitigate the risks.”</p><p>Looking outside the Hollywood bubble, cyberattacks are on the rise the world over; ransomware attacks in particular were up 151% in the first half of 2021 (compared to the same time in 2020), according to data from Atlas VPN. And yet the media industry is under unique pressure to keep its materials under wraps, according to Christopher J. Chan, Partner at international law firm Eversheds Sutherland.</p><p>“While ransomware attacks and breaches in customer data privacy have been well publicized in other industries,” Chan said, “the reliance of the media industry on maintaining confidentiality in a motion picture product makes the media industry particularly prone to the adverse effects of a successful cyberattack which may compromise the details of an otherwise motion picture product, such as a plot or storyline, or surprise ending to a movie.” </p><p><strong>SHIELDING CONTENT<br></strong>Without a team of superheroes to protect them, how can media companies defend this content from increasingly sophisticated forms of piracy? The trend towards content protection offers something in the way of security, a combination of authentication, encryption and watermarking to prevent assets from being copied.</p><a target="_blank"><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:684px;"><p class="vanilla-image-block" style="padding-top:149.71%;"><img id="4HuBbR92VNwvMAHGP7qPvc" name="October n_CYBER_Lepke.jpeg" alt="Edgecast" src="https://cdn.mos.cms.futurecdn.net/4HuBbR92VNwvMAHGP7qPvc.jpeg" mos="" align="right" fullscreen="1" width="684" height="1024" attribution="" endorsement="" class="pull-right expandable"><a href='https://cdn.mos.cms.futurecdn.net/4HuBbR92VNwvMAHGP7qPvc.jpeg' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Darren Lepke, head of video product management at Edgecast. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Edgecast)</span></figcaption></figure></a><p><br></p><p>“We see greater investment than ever in protecting content, especially as the nature of how content is delivered continues to evolve,” confirms Darren Lepke, head of video product management at Edgecast. “As content availability increases, we’re likely to see content providers apply more pressure on OTT platforms to support advanced solutions like watermarking and proactive monitoring, in addition to standard methods like DRM, encryption, and user authentication.</p><p>“We anticipate that watermarking solutions will become crucial, particularly for live sports,” Lepke continued. “Forensic watermarking will enable platforms to identify unauthorized traffic and determine which streams are being compromised so that security professionals can quickly shut them down.”</p><p>Even with this increased investment, content protection is a far from perfect solution, as Chan explains: “No content protection technology has yet proven 100% effective against video and streaming piracy, and the sophistication of pirates and infringers appears to increase with each advance of new content protection technology... It is still an open question as to whether content protection technology will ever be strong enough to prevent the unauthorized pirating and distribution of video and streaming content.” </p><a target="_blank"><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:660px;"><p class="vanilla-image-block" style="padding-top:113.64%;"><img id="efsMSEU9mxgENtfDcYdrcN" name="October n-CYBER_Chan.jpeg" alt="Eversheds Sutherland" src="https://cdn.mos.cms.futurecdn.net/efsMSEU9mxgENtfDcYdrcN.jpeg" mos="" align="right" fullscreen="1" width="660" height="750" attribution="" endorsement="" class="pull-right expandable"><a href='https://cdn.mos.cms.futurecdn.net/efsMSEU9mxgENtfDcYdrcN.jpeg' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Christopher Chan, partner at Eversheds Sutherland. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Eversheds Sutherland)</span></figcaption></figure></a><p><br></p><p>Deploying content protection in tandem with other cybersecurity protocols makes for more robust defences, both prior to and after a product’s release.</p><p>“Content protection and cybersecurity need to cooperate with each other to provide effective protection against bad actors as well as convenient and easy access to video and streamed content by authorized consumers,” notes Chan. “During development and production, as well as after the public release of video and streamed content, such content should be sufficiently protected with both content protection measures as well as effective cybersecurity for associated networks and computers. The lapse in sufficient protection of video and streamed content by either content protection or by cybersecurity will likely jeopardize the economic value in the video and streamed content.”</p><p>On the network side, regular testing of a system’s defenses adds another layer of protection against piracy. Wayne Pecena, director of engineering at KAMU TV/FM at Texas A&M University, and past president of SBE, advocates “penetration testing,” which seeks to discover and exploit security flaws in an IT system.</p><a target="_blank"><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:778px;"><p class="vanilla-image-block" style="padding-top:95.50%;"><img id="vNWeb5PJowfTey2qfXC33m" name="October n-CYBER_Pecena.jpeg" alt="KAMU TV/FM at Texas A&M University" src="https://cdn.mos.cms.futurecdn.net/vNWeb5PJowfTey2qfXC33m.jpeg" mos="" align="right" fullscreen="1" width="778" height="743" attribution="" endorsement="" class="pull-right expandable"><a href='https://cdn.mos.cms.futurecdn.net/vNWeb5PJowfTey2qfXC33m.jpeg' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Wayne Pecena,  director of engineering at KAMU TV/FM at Texas A&M University. </span><span class="credit" itemprop="copyrightHolder">(Image credit: KAMU TV/FM at Texas A&M University)</span></figcaption></figure></a><p><br></p><p>“A pen test is executed by an ‘ethical’ hacker or ‘white hack’ hacker,” he explains. “The goal is to proactively find security flaws and correct in lieu of system flaws discovered by an actual cybersecurity event. Pen testing is a key aspect of a security audit.” Employing hacking tools such as NMAP or METASPLOIT, the would-be hacker carries out network reconnaissance, uncovers points of vulnerability and tests default logins. </p><p>“I view penetration testing as the ‘proof of performance’ for the broadcast IT environment to verify the cybersecurity prevention measures that you think are in place really work,” says Pecena.</p><p><strong>NEW POWERS<br></strong>Emerging technologies such as AI and 5G will also have a key role to play in cybersecurity operations, and could be particularly powerful tools when combined.</p><p>Elbaz uses the following example: “AI can monitor shifts in internet traffic that may signal the start of an attack. 5G technologies can enable the fastest response possible by allowing AI to perform at-the-edge inference analysis and mitigation within milliseconds of detecting an oncoming attack.” </p><p>By accelerating the speed of data analysis and enriching the granularity of detection, the efficiency of cybersecurity could be considerably enhanced. But so too could the attacks themselves; just as supervillains come in evil versions of their nemeses’ armor, hackers will harness the same technology used by media companies and the arms race wages on.</p><p>In the end these villains are thwarted when the heroes work together in ways that are unavailable to the forces of greed, and Philip James, Partner at Eversheds Sutherland, sees an opportunity for companies to provide something communal that pirates cannot, by using technology creatively.</p><p>“There is nothing like the shared experience of the theater,” he argues. “The more unique or distinct a theatrical performance can be, whether via virtual reality, 3D, in-theatre special effects, hospitality, exclusive content, trailers and interviews with directors and actors, the better opportunity there is for content creators to maintain an edge over hackers... by making the official content the best experience it can be.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New HP Cybersecurity Threat Report Finds “A Boom” in Hacking Tools ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/new-hp-cybersecurity-threat-report-finds-a-boom-in-hacking-tools</link>
                                                                            <description>
                            <![CDATA[ New report for first half of 2021 finds “significant increase” in cybercrime ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rUDNbs2B67Daz3gNvxsnn6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Jul 2021 17:33:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Winslow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/DpfRvfTR4a9YTrjyaV72ze.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pixabay]]></media:description>                                                            <media:text><![CDATA[Pixabay]]></media:text>
                                <media:title type="plain"><![CDATA[Pixabay]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nC3uUEhpRjJEPbjY4WcXbg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>PALO ALTO, Calif.</strong>—In a year when cybersecurity threats have already shut down websites and operations at some TV stations, the newest HP global Threat Insights Report finds “increasing cybercrime sophistication and a boom in monetization and hacking tools, while end users are still vulnerable to old tricks.”</p><p>The report from HP Wolf Security threat research team found a 65% rise in the use of hacking tools downloaded from underground forums and file sharing websites from the second half of 2020 to the first half of 2021. </p><p>Cybercrime is more organized than ever, with underground forums providing a perfect platform for threat actors to collaborate and share attack tactics, techniques and procedures, the report noted.</p><p>“The proliferation of pirated hacking tools and underground forums are allowing previously low-level actors to pose serious risks to enterprise security,” says Dr. Ian Pratt, global head of security, Personal Systems, HP Inc. “Simultaneously, users continue to fall prey to simple phishing attacks time and time again. Security solutions that arm IT departments to stay ahead of future threats are key to maximizing business protection and resilience.”</p><p>The report also found that cybercriminal collaboration is opening the door to bigger attacks against victims with Dridex affiliates selling access to breached organizations to other threat actors, so they can distribute ransomware. The drop in Emotet activity in Q1 2021 has led to Dridex becoming the top malware family isolated by HP Wolf Security.</p><p>Information stealers have also launched nastier malware. CryptBot malware – historically used as an infostealer to siphon off credentials from cryptocurrency wallets and web browsers – is also being used to deliver DanaBot – a banking trojan operated by organized crime groups, the researchers explained. </p><p>“The cybercrime ecosystem continues to develop and transform, with more opportunities for petty cybercriminals to connect with bigger players within organized crime, and download advanced tools that can bypass defenses and breach systems,” observed Alex Holland, senior malware analyst, HP Inc. “We’re seeing hackers adapt their techniques to drive greater monetization, selling access on to organized criminal groups so they can launch more sophisticated attacks against organizations. Malware strains like CryptBot previously would have been a danger to users who use their PCs to store cryptocurrency wallets, but now they also pose a threat to businesses. We see infostealers distributing malware operated by organized criminal groups – who tend to favor ransomware to monetize their access.”</p><p>Currently, about 75% of malware detected was delivered via email, while web downloads were responsible for the remaining 25%. Threats downloaded using web browsers rose by 24%, partially driven by users downloading hacking tools and cryptocurrency mining software, the researchers found. </p><p>The most common email phishing lures were invoices and business transactions (49%), while 15% were replies to intercepted email threads. Phishing lures mentioning COVID-19 made up less than 1%, dropping by 77% from the second half of 2020 to the first half of 2021.</p><p>The most common type of malicious attachments were archive files (29%), spreadsheets (23%), documents (19%), and executable files (19%). </p><p>In addition unusual archive file types – such as JAR (Java Archive files) – are being used to avoid detection and scanning tools, and install malware that’s easily obtained in underground marketplaces.</p><p>“As cybercrime becomes more organized, and smaller players can easily obtain effective tools and monetize attacks by selling on access, there’s no such thing as a minor breach,” concluded Pratt. “The endpoint continues to be a huge focus for cybercriminals. Their techniques are getting more sophisticated, so it’s more important than ever to have comprehensive and resilient endpoint infrastructure and cyber defense. This means utilizing features like threat containment to defend against modern attackers, minimizing the attack surface by eliminating threats from the most common attack vectors – email, browsers, and downloads.”</p><p>The data for the report was gathered within HP Wolf Security customer virtual-machines from January to June 2021.</p><p>The Threats Insight Report can be accessed <a href="https://threatresearch.ext.hp.com/wp-content/uploads/2021/07/HP_Wolf_Security_Threat_Insights_Report_H1_2021.pdf"><u>here</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IP Production Is the Future, Here’s How We Can Secure It ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/ip-production-is-the-future-heres-how-we-can-secure-it</link>
                                                                            <description>
                            <![CDATA[ Protecting the entire consumption path is key. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gr7Vq9RyEGM57hbxKu1WNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Oct 2019 18:25:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ritika Tandon ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the television industry in a transition to live production over IP, the benefits of such a change are clear. Most notably, IP production can offer a more dynamic, agile and, in some cases, cost-efficient content creation process compared to its more rigid predecessor, SDI.</p><p>However, amid this transition, the industry is also beginning to better understand some of the potential drawbacks of IP production and what obstacles stand in the way. For example, as the consumption path has widened and become more complex, so has the surface for security attacks and threats. Spanning service disruption, loss of data and even loss of content through piracy or unauthorized viewership, security risks are among the biggest hurdles to overcome during this transition to IP.</p><p>So how can the industry not only mitigate these emerging risks but also stay ahead of the curve to take full advantage of IP live production? Content distributors will be best suited for what lies ahead by focusing on infrastructure security, protecting viewer data and securing the content itself.</p><p><strong>BOLSTERING INFRASTRUCTURE SECURITY</strong></p><p>It’s important to remember that with such a broad attack surface inherent to IP delivery, securing the entire consumption path is key. Attacks can originate at multiple touchpoints, from content acquisition to the customer experience itself.</p><p>Preventing service outages or disruptions along this path is often the main goal. For example, quality of service can be jeopardized by distributed denial-of-service (DDoS) attacks, which is a type of cyberattack that attempts to make a service unavailable. Malware, which is designed to maliciously disrupt the normal operation of a service, and ransomware attacks, which force victims to pay a ransom to cybercriminals to regain access to content, are other examples of common cyberattacks that can disrupt content delivery.</p><p>Regardless of the type of attack, media organizations should consider security protocols that have massive scale and multiple layers of protection given these complexities. For example, for companies with cloud-based workflows, storage and other assets, the ability to stop attacks in the cloud is key. By doing so, threats can be mitigated before they reach an organization's critical applications or data centers, a point where significant disruptions can occur.</p><p>With bots playing a growing role in cyberattacks, a thorough bot management program is important to consider. However, because not all bots are created equal, flexible management strategies for the different types of bots that an organization could come across can be important for overall success when it comes to mitigating bot-based threats.</p><p>Regardless of the specific solution, it’s important to remember the complexity of these security risks and the need to focus on each stage of the content delivery process, including the acquisition, production and distribution stages.</p><p><strong>PROTECTING TROVES OF VIEWER DATA</strong></p><p>Today’s consumers expect a flawless viewing experience. But with data breaches becoming far too common and personal data often exposed as a result—not to mention an increased focus on data privacy—ensuring that such information is protected is now a crucial part of this overall experience.</p><p>In the age of social media, users are not shy about expressing their dissatisfaction with a service or product, meaning a single instance of compromised user information can permanently tarnish a brand’s reputation. In a world with so many content distributors and services to choose from, it doesn’t take much to lose a viewer or subscriber.</p><p>One growing trend is the credential stuffing attack, in which hackers use bots to access stolen login information to access user accounts. The scope of these attacks is massive—<a href="https://www.akamai.com/us/en/multimedia/documents/state-of-the-internet/soti-security-web-attacks-and-gaming-abuse-report-2019.pdf">Akamai</a> reported 55 billion credential stuffing attacks between November 2017 to March 31, 2019. Investing in modern bot detection and blocking solutions that leverage AI and machine learning can greatly reduce these threats.</p><p><strong>KEEPING CONTENT SECURE</strong></p><p>The value of content is skyrocketing in today’s competitive industry. Just look at Amazon, which is paying $130 million for two years of rights to stream the NFL on Thursday nights, separate from the rights other broadcasters are paying to air games over traditional network and pay television. It’s evident that content is becoming more valuable than ever, but with this trend comes growing security risks.</p><p>In fact, the content itself is only becoming a bigger target for cybercriminals—from hackers to content pirates—who see dollar signs in exploiting such a growing market. With IP delivery, the attack surface for tapping into this content is much wider and thus content distributors should consider strong safeguards to secure their most valuable asset.</p><p><a href="https://www.theglobalipcenter.com/wp-content/uploads/2019/06/Digital-Video-Piracy.pdf">Recent data</a> suggests that piracy can cost the industry as much as $71 billion annually. And while the industry recognizes the problem, an <a href="https://www.akamai.com/us/en/multimedia/documents/white-paper/the-state-of-media-security-white-paper.pdf">Akamai survey</a> of media technology influencers and decision-makers found that only 1% are “very confident” in their current security measures to address the issue.</p><p>Media encryption can be a great place to start to address content protection challenges. Investing in this approach ensures a unique encryption key is established for each delivered media segment and can offer message integrity verification data to prevent the theft of content during delivery. Tokenization can also make sure that only viewers that have been properly authenticated can access content, while geo and IP-based blocking can guarantee the same. Additionally, watermarking can be an effective strategy to prevent piracy. By adding unique watermarking to identify the source or recipient of content, each copy can be differentiated from stolen content, allowing organizations to find the true source of the piracy.</p><p><strong>SECURING THE INDUSTRY’S FUTURE</strong></p><p>By prioritizing investments into infrastructure security, protecting consumers and their data, and ensuring the content itself is secure, the industry will not only allow for a smooth transition to IP live delivery but will also ensure that IP delivery has the right foundation to securely succeed for years to come.</p><p>IP live delivery is the future, but only if we safeguard it.</p><p><em>Ritika Tandon is solutions engineering manager at Akamai.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MediaKind Launches Cygnus Director for Content Protection at 2019 NAB Show ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/show-news/mediakind-launches-cygnus-director-for-content-protection-at-2019-nab-show</link>
                                                                            <description>
                            <![CDATA[ Cygnus Director 128 enables broadcasters and content owners to secure and manage the primary distribution of their content to secondary broadcast operators. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sFEknoKbth7yCYs4ZWrThD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9mvhUi95N8EQKRqCv9TT6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Apr 2019 18:28:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Events]]></category>
                                                                                                                    <dc:creator><![CDATA[ Posted by Tom Butts ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9mvhUi95N8EQKRqCv9TT6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9mvhUi95N8EQKRqCv9TT6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LAS VEGAS—</strong>At the 2019 NAB Show, MediaKind launched Cygnus Director 128, a control and conditional access management software product. The newest generation of MediaKind’s Cygnus Primary Distribution platform, Cygnus Director 128 enables broadcasters and content owners to secure and manage the primary distribution of their content to secondary broadcast operators, by identifying and helping to prohibit the unauthorized streaming and broadcasting of their live and on-demand content to consumers.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X9mvhUi95N8EQKRqCv9TT6" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/X9mvhUi95N8EQKRqCv9TT6.jpg" mos="https://cdn.mos.cms.futurecdn.net/X9mvhUi95N8EQKRqCv9TT6.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>MediaKind’s Cygnus Primary Distribution solution utilizes advanced 128-bit encryption coupled with forensic watermarking technology to deter and help prevent piracy of high value content from the broadcaster/content owner’s distribution network, as well as better protecting subsequent copies or streams.</p><p>Coupled with the newly enhanced encryption, Cygnus Director 128 provides a management platform for further control, upgrade and standards alignment with the following benefits:</p><ul><li>Individual and group management of remote professional receivers including entitlements, forced tuning to avoid satellite sun outages, and forced channel selection for automated blackout management, and over-air software download for network wide updates.</li><li>The advanced reporting system will give broadcasters and content owners new operational visibility on the configuration status of their entire network of professional receivers.</li><li>Offers the ability to deter, detect and prohibit piracy of high value content, coupled with control over who can view content, including affiliate networks that wish to receive and access their high value content.</li><li>Cygnus Primary Distribution security solution can be applied over either an IP, Satellite or hybrid Primary Distribution environment, and will also support the BISS2 conditional access to ensure support for open industry based standards.</li><li>The current global deployed list of Cygnus Director customers will be able to easily upgrade to the newly enhanced security from their existing systems utilizing an IP return path.</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity for Broadcasters ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/cybersecurity-for-broadcasters</link>
                                                                            <description>
                            <![CDATA[ A conversation with Cynthia Brumfield on NAB's new Broadcast Cybersecurity Certificate. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fJVPncJQ8qku1KumfiWtPS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Feb 2019 14:21:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                <author><![CDATA[ tom.butts@futurenet.com (Tom Butts) ]]></author>                    <dc:creator><![CDATA[ Tom Butts ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/Ym75XZxKuaGiZGj7nMGeGM.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As our industry transitions to IP, perhaps the most common concern (after cost and interoperability) among broadcasters is security. Today’s headlines are full of cyberattacks, both in the private and public sectors. When content is king, securing that content and protecting your investment are paramount.</p><p>Even the road to ATSC 3.0 is pockmarked with concerns over security. In a <a href="https://www.tvtechnology.com/atsc3/mark-aitken-ponders-where-tv-standards-are-headed-part-2">recent interview</a> with TV Technology, Mark Aitken, senior vice president of advanced technology for Sinclair Broadcast Group and one of the most vocal proponents of the Next Gen TV standard, addressed this issue.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UCdwdDSYeoUv8V8A5mRBDn" name="" alt="Cynthia Brumfield" src="https://cdn.mos.cms.futurecdn.net/UCdwdDSYeoUv8V8A5mRBDn.jpg" mos="https://cdn.mos.cms.futurecdn.net/UCdwdDSYeoUv8V8A5mRBDn.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Cynthia Brumfield </span></figcaption></figure><p>“I think in a couple of months there will be an announcement of industry alignment and cohesion around a content protection solution” for ATSC 3.0, he said. “And I would venture to say it will be supported by the consumer electronics industry, broadcasters and the MVPDs. If you don’t have that, you’re not going to sell ATSC 3 sets into a marketplace.”</p><p>The NAB has been involved in cybersecurity issues for broadcasters for several years and last year launched an online Broadcast Cybersecurity Certificate Program intended for engineering and IT staff.</p><p>The program is designed by DCT Associates Senior Analyst and President Cynthia Brumfield in order to reflect the National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity released last year.</p><p>The six courses will cover:</p><p>• Cyber Risk Planning and Management<br/>• User and Network Infrastructure Planning and Management<br/>• Developing a Continuity of Operations Plan<br/>• Tools and Techniques for Detecting Cyber Attacks<br/>• Incident Response and Management During a Cyber Attack, and<br/>• Lessons Learned: Recovering From a Cyber Incident</p><p>I had a chance to talk with Brumfield recently about the new program and what unique challenges face broadcasters in protecting their assets—including both content and distribution—in an IP world.</p><p>For broadcasters, protecting your content first requires a thorough inventory of what you’re protecting, particularly on the hardware side, she said.</p><p>“You can’t make secure what you don’t know you have,” she said. “Every organization needs to figure out which of their assets would be pertinent to protecting, from a cybersecurity perspective.</p><p><strong>[Read: <a href="https://www.tvtechnology.com/opinions/cybersecurity-what-execs-should-know">Cybersecurity: What Execs Should Know</a>]</strong></p><p>“There is a host of assets that are unique to the broadcasting industry, which we outline and list in the course,” she continued. “You might not think of certain pieces of broadcast equipment as being part of a cybersecurity set of assets, but we want to make sure the broadcasters understand that in addition to making sure you have your PCs and your printers and your modems and everything else secured, you also want to make sure you have cameras secured and controllers and audio log equipment and all kinds of things that would be unique to broadcasters.”</p><p>Brumfield emphasized that the courses cover the entire chain that is affected by IP, meaning protecting content and hardware within the broadcast plant as well as when it leaves the facility.</p><p>The FCC too has been involved with helping to establish cybersecurity “best practices” for broadcasters for several years. It took its cue from the NIST, which in 2015 released guidelines that put cybersecurity into a <a href="https://www.nist.gov/industry-impacts/cybersecurity">comprehensive framework</a> that applies to the public sector but are also being adopted by many in the private sector as well. Brumfield noted that the guidelines are “not a requirement, just a recommendation.”</p><p>The complexity and fast-changing world of cybersecurity can present challenges to every enterprise, particularly for small and mid-market broadcasters, who may not have the financial resources of its larger market brethren. While it won’t get into the intricate details of protection of cyber attacks, the NAB course will provide the framework for broadcasters to understand the priorities, she said.</p><p>“You need to know what you have; you need to know how you’re protecting it; you need to keep all of the stuff updated; you need to make sure there’s communication in house when incidents occur,” Brumfield said. “You need to establish practices before an incident occurs on how you’re going to manage it.”</p><p><em>For more information on this program for both television and radio broadcasters, visit</em><a href="https://www.pathlms.com/nab/courses/9683" data-original-url="http://www.pathlms.com/nab/courses/9683">www.pathlms.com/nab/courses/9683</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Akamai Report Notes Increase in Scale and Automation of Security Attacks ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/akamai-report-notes-increase-in-scale-and-automation-of-security-attacks</link>
                                                                            <description>
                            <![CDATA[ A more specific portfolio of threats exists for broadcasters, who are heavily invested in the Internet of Things, which are also vulnerable. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ynuacnDSd8SK4TCxXD4dy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Jan 2019 15:31:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Vernon ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If there is a single truth about trends in the Internet security space, it’s that every year brings more of the same. Akamai’s <a href="https://www.akamai.com/us/en/multimedia/documents/state-of-the-internet/2018-state-of-the-internet-security-a-year-in-review.pdf?mkt_tok=eyJpIjoiT1ROaVpXSTJOMlUxWm1JeCIsInQiOiJsUWo0WVJaOUVuYzhOeEg0STFwZFU0bFVaaEx2dFpqWVVvMUhmQVBQZzNtVjgzbmhnSks5b0ZCclhoSkNLMTZzQW9yY2lFY1pjbFNITE1FZG12R0c4OEN4bVg3VGlJT0lQVCtNUHJHVzRyWFUwaTFTU3pzczM4YkZSalE0VGR2SyJ9">2018 State of the Internet (SOTI) report</a> looks forward to 2019 by describing ongoing patterns from the past few years, and suggests they’ll likely continue to evolve in the ways that they already have. Broadcasters, like other internet users, should continue to expect threats in the form of brute force DDoS attacks, application level attacks, credential stuffing and the theft and sale of credentials.</p><p>A more specific portfolio of threats exists for broadcasters, who are heavily invested in the Internet of Things, which are also vulnerable. A recent Gartner report estimates that by 2020 there will be over 26 billion connected devices, excluding PCs, tablets, and smartphones.</p><p><strong><em><a href="https://www.radioworld.com/industry/need-to-know-cybersecurity">[</a>Read: <a href="https://www.tvtechnology.com/opinions/cybersecurity-what-execs-should-know">Cybersecurity: What Execs Should Know</a>]</em></strong></p><p>There are a number of weaknesses in IoT devices, which make them vulnerable to hackers.</p><ul><li>Very little security is built into the device itself, often as an economy measure, but also because some safeguards may impede operation.</li></ul><ul><li>Because of poor network segmentation, the device may be directly exposed to the web. It can act as a pivot to the internal network, opening up a backdoor to let criminals in.</li></ul><ul><li>Developers of IoT devices sometimes leave behind code or features developed in beta that are no longer relevant. This hidden functionality can provide a way in for hackers.</li></ul><ul><li>Default credentials are often hard coded. That means that the software won't force you to create a unique password. Typing “1-2-3-4-5” can get you into a surprising number of devices.</li></ul><p>A glimpse at best practices might be gleaned by looking at the U.S. government, which introduced the <a href="https://www.congress.gov/bill/115th-congress/senate-bill/1691/text?format=txt">Internet of Things Cybersecurity Improvement Act</a>. It requires that any devices sold to the American government be patchable, not have any known security vulnerabilities, and allow users to change their default passwords. If you’re not working for the government, you’re on your own to figure all of this out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Best Practices for ST 2110 Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/best-practices-for-st-2110-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ They begin with network design. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">juzce1bBXSGzBSYbGv3xpm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Dec 2018 16:48:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Wayne M. Pecena ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>COLLEGE STATION, TEXAS—</strong>The television broadcast technical plant is changing or has changed for many. The traditional baseband based serial digital interface (SDI) commonplace since the inception of digital television is being replaced by an IP-based infrastructure. The migration to an all-IP infrastructure brings several advantages, including:</p><ul><li><em>Cost savings by using commercial, off-the-shelf (COTS) IT hardware.</em> Enterprise routers and switches have enormous economies of scale compared to the broadcast world’s purpose-built, industry-specific infrastructure.</li></ul><ul><li><em>Greater system workflow flexibility.</em> The inherent architecture flexibility provides for a change in workflow processes without a system re-wire commonly found in the baseband SDI plant. With a COTS Ethernet switch, high-capacity, non-blocking signal routing can be implemented in far less space than the traditional matrix SDI router.</li></ul><ul><li><em>Format and resolution agnostic.</em> Enterprises and streaming video service providers already use COTS infrastructure for a wide variety of formats and resolutions, from 720p through 1080p at 60fps and 4k. The use of IT industry standards also enables the high levels of interoperability commonly found among COTS equipment manufacturers.</li></ul><ul><li><em>Simplified interconnection wiring.</em> Installation costs are significantly reduced because less interconnection cabling means less labor. The SDI plant’s fixed signal path is replaced with a “star” architecture found in enterprise IT networks. System changes also are implemented by software configuration rather than facility re-cabling.</li></ul><p>The use of an IP network in a broadcast facility has been commonplace for some time now. One example is the familiar RJ-45 Ethernet jack on many broadcast devices. Use of the IP network has been primarily for command and control, monitoring or file transfer.</p><p>But when an IP network is mentioned in the context of transporting real-time broadcast media, an instant lack of trust is often a common response. Many broadcast professionals are simply unable to accept the perceived risk involved for mission-critical content transmission. The “belt and suspenders” mindset of the broadcast engineer simply does not permit the perceived unreliable operation found in the IP environment. Reinforcement for this mindset is often obtained from one’s personal experience with the Internet.</p><p><strong>ENABLING PROFESSIONAL MEDIA OVER MANAGED IP NETWORKS</strong></p><p>To enable interoperability between system components from different manufacturers, the Society of Motion Picture and Television Engineers (SMPTE) established the ST 2110 standard. SMPTE 2110 is considered an umbrella standard, or a family of individual functional standards, that allow for the transmission of uncompressed audio and video over an IP network.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zVsEUxBHr8faG8if75TuPX" name="" alt="Fig. 1: SMPTE 2110 Standard Diagram" src="https://cdn.mos.cms.futurecdn.net/zVsEUxBHr8faG8if75TuPX.jpg" mos="https://cdn.mos.cms.futurecdn.net/zVsEUxBHr8faG8if75TuPX.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fig. 1: SMPTE 2110 Standard Diagram </span></figcaption></figure><p>SMPTE 2110 is a suite of standards for transmission of “professional media over managed IP networks.” Audio, video and ancillary data are treated as separate, uncompressed essence data streams. Individual standards focus upon functional components of the suite, such as video (ST 2110-20) or audio (ST 2110-30). Ancillary data may include captioning data (ST 2110-40) that is associated with the media essence streams. A unique feature of ST 2110 allows essence data streams to be sent or routed over different physical paths and re-assembled at a destination end point by the incorporation of a synchronization mechanism (ST 2110-10).</p><p>Several SMPTE standards incorporate established Internet Engineering Task Force (IETF) Request for Comments (RFC) provisions into the standards. Examples include the ST 2110-20 standard incorporating the IETC RFC #4175 for uncompressed video transmission and the ST 2110-10 system standard incorporating the IETF RFC #3550 Real Time Protocol (RTP). The IETF RFC’s are considered the “Bible” of IP networking.</p><p>It is important to make a couple of critical distinctions regarding the SMPTE ST 2110 standard. First, what is known as the public “Internet” is not the intended physical transport platform. By definition stated in the ST 2110 title, a “managed” IP network is the transport platform. A managed IP network is a private network that is built on private physical facilities or more likely a telco common carrier provided Multiprotocol Label Switching (MPLS) network. Performance can be specified in a Service Level Agreement (SLA) to ensure reliable delivery of real-media content such as high-definition, uncompressed video. Differentiated services are utilized to meet and maintain a contracted Quality of Service (QoS).</p><p>In contrast, the public Internet is a maze of independent interconnected networks with no end-to-end performance coordination or governance. Thus, the term “best effort” is used to describe the QoS of the public Internet. This is simply not an appropriate network choice in which to implement SMPTE ST 2110.</p><p><strong>THE CIA TRIAD OF CYBERSECURITY</strong></p><p>The private nature of the physical network platform also becomes a first step in mitigating cybersecurity vulnerabilities. Nevertheless, ST 2110 is an IP-based data network, so the IT industry’s accepted security practices should be deployed in any implementation.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hUBUoq56Bst8rSMFRy8qPd" name="" alt="Fig. 2: The “CIA” Triad" src="https://cdn.mos.cms.futurecdn.net/hUBUoq56Bst8rSMFRy8qPd.jpg" mos="https://cdn.mos.cms.futurecdn.net/hUBUoq56Bst8rSMFRy8qPd.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fig. 2: The “CIA” Triad </span></figcaption></figure><p>Network cybersecurity mitigation involves a number of individual steps or practices rather than one single step. Overall, the goal of network security is to meet the attributes defined by the “CIA Triad” as illustrated by Fig. 2. The triad is based upon the three attributes of: Confidentiality, Integrity and Availability. It should be noted that the phrase “AIC Triad” may also be used to avoid confusion with a US government agency of the same acronym.</p><p>Confidentiality refers to the ability of the network infrastructure to not allow disclosure of the data or information traversing the network infrastructure to any unauthorized user or host. Integrity refers to the ability of the network to ensure that the data has not been altered by an unauthorized user or host. And availability refers to the ability of the network infrastructure to ensure that resources are available only to authorized users or hosts.</p><p><strong>[Read: <a href="https://www.tvtechnology.com/opinions/need-to-know-cybersecurity">Need To Know: Cybersecurity</a>]</strong></p><p>Cybersecurity events such as a Denial of Service (DoS) attack or a Distributed Denial of Service (DDoS) attack target the availability attribute by impacting access to the network resources by legitimate users. A Man in the Middle (MITM) attack seeks to destroy the integrity attribute by altering the data or information traversing the network.</p><p>Industry best practices begin with network design as the first step in cyber-security threat mitigation. The network is segmented or layered into functional areas as dictated by the business case use, regulatory policy or organizational policy. Each layer or segment has unique use or purpose with an established security access policy. Inner layers are considered the core network segments and are the most secure.</p><p>The characteristics of an MPLS network provide an economical platform for ST 2110 implementation.</p><p>Other security attributes involve physical network infrastructure equipment protection from tampering through locked enclosures, cabinets or cages. Implementation of Ethernet switch port security is another capability that a managed switch offers to control what host device can be attached to a switch port. Packet filtering can be implemented by an Access Control List (ACL) to allow select host interoperability between network segments. The ACL filtering can be based upon several IP header fields such as addresses, protocol and port number.</p><p>Infrastructure equipment management should be implemented in an out-of-band manner. Out-of-band management also allows the use of the public Internet for accessibility implemented in a secure manner such as an encrypted Virtual Private Network (VPN) connection to the management network. This approach provides an air-gap between content transport network segments and the management network.</p><p>All of these outlined practices come together to define a secure network rather than complying with a single attribute. Cybersecurity can’t be ignored or left as an afterthought. At the end of the day, the broadcast engineer should have trust and confidence in a SMPTE ST 2110 network that is implemented as intended by the published standard utilizing established industry security practices.</p><p><em>Wayne M. Pecena is a IEEE BTS Distinguished Lecturer and Director of Engineering, Texas A&M University, KAMU FM & TV.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blockchain’s Role in TV ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/blockchains-role-in-tv</link>
                                                                            <description>
                            <![CDATA[ Rebuilding trust among advertisers, content creators and consumers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6sVthmsvSEeFf35bpN3Tpj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cz7UPkSoVLuiUPieeLbfgG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Dec 2018 14:09:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gavin Douglas ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cz7UPkSoVLuiUPieeLbfgG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cz7UPkSoVLuiUPieeLbfgG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>VENICE, CALIF.—The future of advertising on television and video needs a reality check. Privacy breaches, fraudulent metrics, fake reviews, questionable data analytics, loss of trust between the platforms and the brands—the complexity of advertising on TV and video content continues to gain momentum in 2018 with very few points of light in the chaos. It’s not news that the current digital media ecosystem is rife with these problems; a landscape heavily marked by a confluence of players, not just the creators and viewers, but also by the middlemen and their respective financial interests.</p><p>Since data has become equal to currency in the media environment, there has been a shift in society’s outlook on privacy. With eyes on the proverbial prize of user data, a marked decline in regard for user privacy has come to the forefront—a fact that has led to a culture with little or no regard for audience privacy.</p><p><strong>EROSION OF USER CONTROL</strong></p><p>We’ve all seen this movie before. Say you’re looking at an online forum for weight loss. Consequently, and paradoxically, you’ll be the first one targeted by junk food companies who are going to assume you have been, or will continue to be, a major consumer of their products. While users often give consent by checking a box, it is not really “informed consent.” They’ll say “yes” to get to the next screen or to download the new app, but they probably don’t fully understand the degree to which they’re sacrificing their privacy. This creates an ecosystem where users have little control over their own data and how that data is used and monetized.</p><p>Fortunately, there is a solution to the erosion of user control. Blockchain technology can be leveraged to safeguard user privacy, thereby restoring trust between viewers, advertisers, and content creators. I’m certainly not saying that you can simply take a jar full of blockchain and just smear it on everything to fix the problem. However, just as blockchain is being employed to transform the healthcare industry by eliminating the middlemen, the correct use of the best technologies available can do the same for the media landscape by utilizing tokenization.</p><p>By creating direct relationships between the advertisers and the viewers, tokenization can support the formation of direct avenues for data and value exchange between advertisers, consumers, and content creators. The elimination of intermediary platforms means that all parties can retain more value, because no percentage of transactions is being captured by third parties. Additionally, such peer-to-peer interactions are drastically more streamlined than the complex webs of media players seen today. In a win-win, advertisers earn greater return on their investments while users gain more control over their data.</p><p>The process of tokenization, or the monetization of trackable actions, takes the evolution of this ecosystem one step further to include viewers among those benefiting economically. In other words, users can make money simply by watching and engaging with their favorite TV and video content.</p><p><strong>HOW DOES THIS WORK IN PRACTICE?</strong></p><p>During a show, viewers are prompted with a call to action to participate in some way with the content they are watching. Viewers can respond to the call to action directly on the device on which they are watching the content or, if they are viewing on their TV, through the app on their phone. Once viewers sign up to begin earning rewards, they can interact with specific elements of the show or commercial and accumulate tokens, provided by the advertisers, for their time and attention. These tokens have real-world value and can then be used to buy other goods and services within the ecosystem, most importantly connecting viewing habits directly to purchase data.</p><p>The fact that on-screen graphics containing tokens can be applied to any TV or video content on any screen means that, not just the viewers, but all participants in the media ecosystem, including ad agencies, TV networks, and brands can benefit from tokenization. A particular viewer may decide to keep her medical and financial records private but make information about her favorite hobbies available to advertisers. By allowing advertisers to see that she enjoys travel and cooking, she’s not only likely to see more relevant (and less annoying) ads, but with tokenization, she will earn rewards for her loyalty and engagement.</p><p>Historically, brands and content providers have needed to sort through multiple disparate data sources to make conjectures about which TV and video content led to purchase and ROI. By employing tokenization, content providers would no longer need to guess about what is working and what isn’t, as tokens boldly connect the dotted lines between viewing habits and product purchases.</p><p>If employed effectively in the TV and video industry, tokenization of content built on blockchain technology could form the foundation for a new digital order wherein all parties benefit from improved efficiency, transparency, and security.</p><p><em>Gavin Douglas, the CEO of iPowow and the HIT Protocol, is an award winning media producer and TV format developer with 20 years experience in TV content production and new format development. iPowow is an established leader in interactive TV and is launching the HIT Protocol to tokenize linear television and VOD using smart contracts and blockchain technology.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five Steps for Securing Broadcast Content ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/five-steps-for-securing-broadcast-content</link>
                                                                            <description>
                            <![CDATA[ How media organizations can identify potential risks, improve their security posture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t8jwFSLqJq5LCNcDM5wQm3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Dec 2018 22:54:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Vinit Duggal, VP of Network Engineering and CISO, Intelsat ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For broadcasters and programmers, there is nothing more important than the quality, reliability and unique nature of their content. A cyberattack can disrupt streaming services, slow video performance and enable hackers to steal unique content. The availability of connected devices on a broadband network is changing the way people consume content — and posing new security challenges.</p><p><strong><em><a href="https://www.tvtechnology.com/news/nab-debuts-cybersecurity-certificate-program-for-broadcasters">[Read: NAB Debuts Cybersecurity Certificate Program For Broadcasters]</a></em></strong></p><p>These current trends — as well as the trends toward cloud-based streaming and linear programming — require that media companies rethink their approach to cybersecurity. While there are no simple solutions, the following five steps can help media organizations identify potential risks and significantly improve their security posture.</p><p><strong>1. Harden Your Network at Every End-Point</strong></p><p>The same new opportunities that enable programmers to contribute content, and enable customers to obtain content, have opened new inroads for malicious actors to steal or disrupt content. Every end-point across the distribution cycle needs to be assessed, tested and secured. Companies need to consider how their content data stores are protected, whether their transit is secure, and if everything is protected by encryption.</p><p>For satellite operators, it is critical to use multiplatform, layered controls to establish proactive security that limits opportunities for content and other data to be compromised on the ground or in orbit.</p><p><strong>2. Use Layered Security</strong></p><p>Multiple layers of security make it harder to breach your system and give your team valuable time to detect and respond before any data is compromised.</p><p>In the satellite industry, the most progressive operators utilize a pervasive security framework that includes layered controls, a mature compliance program, extensive audit and assessment initiatives, and a coordinated incident-response process.</p><p><strong>3. Insist Your Partners Follow Best Practices</strong></p><p>Even if you secure all the end-points you manage and employ layered-security measures, your content remains at risk if your partners do not follow best practices and are not transparent in their security posture. Media companies need to ensure that each ecosystem partner has the right security requirements in place and has regular communication to keep up with the threat environment and maintain security in orbit and on the ground.</p><p>The most progressive satellite operators maintain secure flight operations for all wide-beam and spot-beam satellites via a segmented control network that ensures key assets are being managed in a proactive way. Those operators also have multiple levels of cybersecurity in place for their partners, segmented by need of network access.</p><p>It is critical for satellite operators to proactively work with media customers to ensure their connected ecosystem is protected against active threats at all stages of uplink, downlink and terrestrial transport.</p><p><strong>4. Practice Rapid Incident Response</strong></p><p>Rapid incident response is what distinguishes an advanced cybersecurity program from others — and prevents an incident from becoming a significant breach. Breaches will occur, but the ability to rapidly detect, thwart and recover is what can make all the difference in the world.</p><p>Advanced digital payloads, such as those on Intelsat <a href="https://www.intelsat.com/global-network/satellites/epicng/" data-original-url="http://www.intelsat.com/global-network/satellites/epicng/">EpicNG</a> satellites, can rapidly identify, communicate, move and mitigate interference issues – thus limiting the scope and severity of the breach.</p><p><strong>5. Conduct Independent Security Audits</strong></p><p>Cybersecurity is too complex and disruptive to rely solely on internal security reviews. Many companies have engaged outside cybersecurity firms and sought accreditations to ensure their current program and security posture is current and effective. If an outside firm identifies security issues, they can provide recommendations to further harden internal controls.</p><p>When evaluating satellite operators, media organizations should select only those that have been audited by a major, independent auditing firm. Also, insist that your satellite operator has completed a Service Organization Control 3 (SOC 3) review of security controls.</p><p><strong>Conclusion</strong></p><p>Cybersecurity will become a greater challenge as more content is distributed over multiple platforms. As media organizations become increasingly connected, the demand for cybersecurity solutions will increase significantly.</p><p>There are no simple solutions to ensure broadcast security. However, the five steps outlined above can substantially improve the security of your media content.</p><p><em>About the Author: Vinit Duggal is Vice President of Network Engineering and CISO at Intelsat, the world’s largest satellite operator.</em></p><p><em><strong><a href="https://www.b2bmediaportal.com/nbmedia/subscribe.aspx">[Want more information like this? Subscribe to our newsletter and get it delivered right to your inbox.]</a></strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NAB Debuts Cybersecurity Certificate Program for Broadcasters ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/nab-debuts-cybersecurity-certificate-program-for-broadcasters</link>
                                                                            <description>
                            <![CDATA[ Courses will help participants to protect their stations in “the current threat environment.” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sJrhYiTDNZLG3Skqby9CGy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Nov 2018 19:05:37 +0000</pubDate>                                                                                                                                <updated>Mon, 13 Apr 2020 13:12:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emily Reigart ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the world gets increasing connected, broadcasters have become hyperaware of the need for good security practices off- and online. Because of this, the National Association of Broadcasters is introducing a new, online <a href="https://www.pathlms.com/nab/courses/9683">Broadcast Cybersecurity Certificate Program</a> intended for engineering and IT staff.</p><p>“The current threat environment frames the need for enhanced cybersecurity education at all levels,” NAB Senior Director of Technology Education and Outreach Brian Savoie said in an announcement.</p><p>The program was designed by DCT Associates Senior Analyst and President Cynthia Brumfield in order to reflect the <a href="http://templatelab.com/cybersecurity-framework/" target="_blank">National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity</a> released in May.</p><p>The four courses will cover: cybersecurity risk planning and management; user and network Infrastructure planning and management; tools and techniques for detecting a cyberattack; and how to develop a continuity of operations plan.</p><p>The courses are available to both NAB members ($500) and nonmembers ($1,100), according to the NAB website. Courses can also be taken individually, but it’s more economical to sign up for the whole program, according to the association.</p><p>Those interested can also check out the companion guides to the two standalone courses (Cyber Awareness for Broadcasters and Broadcast Executive Guide to Cybersecurity). </p><p><a href="https://metacurity.com/essential-reports/">The guides can be found here</a>, and others will be available soon, NAB says.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Next Gen TV Offering Television Industry a Chance to Impede Piracy and Compete in OTT Era ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/next-gen-tv-offering-television-industry-a-chance-to-impede-piracy-and-compete-in-ott-era</link>
                                                                            <description>
                            <![CDATA[ Today’s broadcasters and content providers should follow the same lead as movie studios when it comes to content protection. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vkGSvppYBEdfCRRYQTs8qM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Nov 2018 15:25:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Streaming]]></category>
                                                    <category><![CDATA[Platform]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mitch Singer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Samsung, LG and Sony – the biggest TV manufacturers – have recently joined Fox, NBC and Telemundo Owned Stations Group and a growing list of leading broadcasters in <a href="https://www.tvtechnology.com/atsc3/station-groups-endorse-atsc-3-0-for-2020-market-debut">voicing their commitment to ATSC 3.0</a>, which powers Next Gen TV.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FsuznVVTBLWwr9NKPnrBVY" name="" alt="Mitch Singer" src="https://cdn.mos.cms.futurecdn.net/FsuznVVTBLWwr9NKPnrBVY.jpg" mos="https://cdn.mos.cms.futurecdn.net/FsuznVVTBLWwr9NKPnrBVY.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Mitch Singer </span></figcaption></figure><p>With ATSC 3.0’s large-scale introduction now looking assured for 2020, broadcasters will be able to introduce a variety of cool, new internet-enabled business and consumer features with the standard’s advanced transmission technologies.</p><p>These features will let broadcasters offer more channels along with better picture and sound quality, while improving broadcast reception for both TV and mobile viewers. In short, broadcasters will have the opportunity to redefine themselves by offering lots of new viewing experiences including those comparable to OTT subscription and ad-supported internet providers.</p><p>And why not? People love OTT services like Netflix, Amazon and Hulu for their phenomenal original content and, at an even more basic level, how they make TV fun with appealing user interfaces and tailored content recommendations. For broadcasters and content providers looking to compete in this dynamic new world, creating seamless viewer experiences between broadcast channels and their growing subscription OTT services could help close the gap.</p><p>Yet these promising new premium content profit centers will be doomed, even before they begin, if broadcasters miss the opportunity to incorporate necessary technological safeguards and defend themselves against competing pirate services bent on destroying what could become a boon for the industry.</p><p>The Next Gen TV standard has the usual assortment of Digital Rights Management (DRM) tools, but neither DRM nor the standard, itself, include anti-piracy measures. Ultimately, the revenue from this new market will depend on broadcasters’ willingness to target pirate streaming services by protecting their high-value content and services against theft. Without the additional layer of anti-piracy protection, these new broadcast services will suffer the same fate as the music industry.</p><p>The movie studios sought to prevent what happened to their music brethren by encrypting DVDs with DRM at the outset of that industry, letting DVD player manufacturers know they would be excluded from this profitable new market if they failed to agree to their content protection rules.</p><p>What they did not see coming, however, was the loss of billions of dollars with the emergence of DRM-only DVD as a format for piracy growth. Pirates embraced the convenient discs over the original VHS format, because they could be perfectly replicated and easily transported all over the world.</p><p>Not for long, though. Realizing the financial hit they were taking, and that DRM alone was not enough to protect their DVD business, content providers required manufacturers to install playback control watermarking for their Next Gen Blu-ray format, effectively shutting down the pirated optical disc market. (<em>Full Disclosure: I represent Verance, the company behind the Cinavia anti-piracy technology utilized by major movie studios, as well as Aspect, a foundational element of the Next Gen TV standard.</em>)</p><p>Today’s broadcasters and content providers should follow the same lead as movie studios when it comes to content protection in the era of Next Gen TV, but first they will have to overcome manufacturers’ resistance to Next Gen TV anti-piracy measures.</p><p>I believe this can be done. The consumer electronics industry operates on the theory of “perceived obsolescence,’” which means that to stay in business it must convince consumers of the constant need to upgrade. So even though your iPhone or Galaxy may work perfectly well, the perception is you need to get the next shiny new phone.</p><p>As multiple recent consumer surveys have made clear, when it comes to selling the next generation of TVs starting in 2020, Next Gen TV is the motivator. Potential customers say they are drawn to a variety of its new personalized audio and video features including access to multiple languages, hometown announcers for national broadcast games and selecting multiple camera angles, as well as interactive capabilities such as catch-up TV and start over.</p><p>Without the support of broadcasters or streaming services, the adoption of Next Gen TVs will be challenging at best and TV sales will lag. New business models that make broadcast competitive with SVOD and OTT will be at risk. Now is the time for the content side of the business to encourage TV manufacturers to promote legitimate broadcast services.</p><p>Bill Gates knows this. In his now-famous <a href="https://www.silkstream.net/blog/2014/07/content-is-king-bill-gates-1996.html">1996 essay, <em>Content is King</em></a>, the Microsoft founder looked at long-term winners in the television revolution and predicted the next big upheaval would come with internet-delivered content. More broadly, Gates knew that new distribution channels and supporting hardware cannot exist without compelling content.</p><p>For Next Gen TV and its new revenue-generating broadcast OTT services to thrive, broadcasters and studios must start thinking like Gates and realize Kodi and other black boxes for what they are – direct competitors offering reliable, high-quality offerings at prices far lower than legitimate OTT services. A report released by Sandvine indicated 6.5% of U.S. households are stealing live TV service at a cost to service providers of $4 billion in annual revenue.</p><p>Next Gen TV empowers content providers and broadcasters like never before, handing them the cards to stay competitive. In order for that to happen, however, they must remember what the studios learned in their earlier successful quest to end DVD/Blu-ray disc piracy: content is king, and these assets must be protected with more than DRM.</p><p><em>Mitch Singer, formerly Chief Digital Strategy Officer of Sony Pictures Entertainment, is an industry media and technology consultant.</em></p><p><em>For a comprehensive list of TV Technology’s ATSC 3.0 coverage, see our <a href="https://www.tvtechnology.com/atsc3" data-original-url="http://www.tvtechnology.com/atsc3">ATSC3 silo</a>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Next Gen TV Dominates IEEE-BTS Gathering ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/atsc3/next-gen-tv-dominates-ieee-bts-gathering</link>
                                                                            <description>
                            <![CDATA[ Annual symposium probes broadcast technologies, practices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">resGUqY9zKFqa6N2nUyZYE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HFHxwYwPD2Bz9Q3EDjkhoh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Oct 2018 14:03:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Standards]]></category>
                                                                                                                    <dc:creator><![CDATA[ James E. O&#039;Neal ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HFHxwYwPD2Bz9Q3EDjkhoh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Attendees packed the presentation room at the 2018 BTS Symposium.]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HFHxwYwPD2Bz9Q3EDjkhoh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>ARLINGTON, VA.--</strong>Broadcast engineers from around the globe converged here for three days last week to exchange information about the industry and broadcast technology developments at the annual IEEE Broadcast Technology Society Fall Symposium.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HFHxwYwPD2Bz9Q3EDjkhoh" name="" alt="Attendees packed the presentation room at the 2018 BTS Symposium." src="https://cdn.mos.cms.futurecdn.net/HFHxwYwPD2Bz9Q3EDjkhoh.jpg" mos="https://cdn.mos.cms.futurecdn.net/HFHxwYwPD2Bz9Q3EDjkhoh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Attendees packed the presentation room at the 2018 BTS Symposium. </span></figcaption></figure><p>In spite of the demands of the ongoing television spectrum repack, some 160 engineering consultants, equipment manufacturers, and broadcast group personnel took time away from their duties to join academics and others from as far away as Russia, Brazil and South Korea at the Oct. 9-11 tech con.</p><p>Next-Gen TV was the hot topic this year, with nearly half of the presentations falling into this category and nine directly focused on ATSC 3.0’s potential, field testing, deployment, business models, and evaluation metrics. Presentations even included some “one step beyond” views into the future television experiences. One described methodology for transmitting information to provide sensory stimulation beyond sight and sound, and a lunchtime keynote presenter described taking virtual reality out to the ball game.</p><p><strong>BRINGING BACK THE ACTION WITH VR</strong></p><p>In her presentation, Uma Jayaram, engineering director for Intel Sports True VR division, described why her company decided to launch a virtual reality TV sports production element, and discussed some of the technical issues that had to be resolved to make it possible.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pCrY6N2xynQVxsovEHmdvE" name="" alt="Uma Jayaram " src="https://cdn.mos.cms.futurecdn.net/pCrY6N2xynQVxsovEHmdvE.jpg" mos="https://cdn.mos.cms.futurecdn.net/pCrY6N2xynQVxsovEHmdvE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Uma Jayaram  </span></figcaption></figure><p>“The timeline for [introduction and acceptance] of new use cases is dramatically shortening,” Jayaram said. “The telephone took 75 years to reach the 50 million user mark; ‘Angry Birds’ took just over a month to reach this mark.</p><p>“Companies such as Intel realize that you cannot afford to join the party after it’s well underway and things are moving really fast," she continued. "So, you place some bets, you get into the ecosystem, you play with it, you try to move it, and essentially see what’s going on in a more involved manner.</p><p>“When you think of Intel, you ordinarily think of the more traditional segments—CPUs, graphics and so on, but some of the big bets we are making have to do with artificial intelligence, VR, hygiene, and automated driving” observing that all of these emerging technologies involved moving and processing massive amounts of data, an Intel specialty.</p><p>“These areas are moving so fast that you want to be in that ecosystem,” said Jayram in explaining Intel’s decision to launch the sports business unit two years ago.</p><p>“On ‘game day’ we show up with our cameras, we set up alongside the networks and stream VR experiences in near real time,” she said. “We provide [feeds] to about 10 right’s-holding broadcasters.”</p><p>In her presentation, Jayaram did flag some VR limitations, noting that perhaps the biggest centers on the cumbersome headgear that consumers must don.</p><p>“I can’t watch with a headset for more than a few hours,” she said.</p><p>As one solution, her unit is creating shorter duration or “snackable content” sports highlights packages. “We’re also working to provide a better user interface…something that would allow a person to do VR viewing while still interacting with friends,” she said.</p><p>She also described some technical considerations in VR that don’t really exist in ordinary television coverage.</p><p>“Time synchronization is very important when you have six separate cameras that all have to be synched together along with the audio," she said. "Seamless ‘stitching’ of the multiple views is also very important.”</p><p>Branding of the viewing apps for consumers is also something of a challenge as Intel's Sports unit is dealing with multiple broadcast entities operating in several countries. “In the U.S., NBC has the rights, so we have to have an NBC app with the 'NBC look and feel' and colors. We now have to put out about 33 of these apps [to accommodate the various broadcast entities and viewing devices].”</p><p>Jayaram also noted that a business model has to be established before widespread deployment of VR sports coverage can take place.</p><p>“We’re looking at subscription models,” she said. “In the end you have to make money. This is still being worked out.”</p><p><strong>WHAT’S HAPPENING OUT IN THE [3.0] FIELD?</strong></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7J2n3jxNVBH9wajArhTXw7" name="" alt="Matt Brandes" src="https://cdn.mos.cms.futurecdn.net/7J2n3jxNVBH9wajArhTXw7.jpg" mos="https://cdn.mos.cms.futurecdn.net/7J2n3jxNVBH9wajArhTXw7.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Matt Brandes </span></figcaption></figure><p>Status reports on ATSC 3.0 rollouts in three U.S. markets were part of the conference program, with WRAL-TV’s Transmitter Supervisor Matt Brandes describing activities at his company’s Raleigh-Durham, N.C. test facility. Fred Baumgartner, director of Next Gen TV implementation for Sinclair Broadcast Group, provided an update on the station group's Dallas-Ft. Worth ATSC 3.0 single-frequency network initiative, and Pearl TV’s Dave Folsom described goings-on in connection with the "Phoenix Model Market project.</p><p>All offered some lessons learned and dos and don’ts takeaways.</p><p>“If you’re a person blessed with the privilege of setting up a brand new ATSC 3.0, please download and read the ATSC recommended practices on the <a href="https://www.tvtechnology.com/opinions/the-atsc-30-physical-layerbootstrap-basics" data-original-url="https://www.tvtechnology.com/expertise/the-atsc-30-physical-layerbootstrap-basics">Physical Layer,</a> go play with your toys, and then come back and read the recommended practices again,” said Brandes. “Also, buying a new encoder might do more for your coverage than putting in two transmitters. If you can get three dB improvement [in encoding], this is equivalent to doubling your power.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ngzgcaDcwBdzwA528rN3tY" name="" alt="Dave Folsom" src="https://cdn.mos.cms.futurecdn.net/ngzgcaDcwBdzwA528rN3tY.jpg" mos="https://cdn.mos.cms.futurecdn.net/ngzgcaDcwBdzwA528rN3tY.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Dave Folsom </span></figcaption></figure><p>Speaking for Pearl TV, Folsom noted that early equipment implementations are still not complete and software versioning is a big issue</p><p>“Anytime someone makes a software upgrade, everything downstream quits working, including the receivers," he said. </p><p>Folsom added that the ability to interchange encoding, packaging and encapsulation units isn’t fully developed yet. “You should be able to connect up the unit and it should work, but it doesn’t," he said. "The standards are clear, [but] there’s a lot of misunderstanding among manufacturers about what needs to be there.”</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XRPHbkTdptdWSj9pkCDrzE" name="" alt="Fred Baumgartner" src="https://cdn.mos.cms.futurecdn.net/XRPHbkTdptdWSj9pkCDrzE.jpg" mos="https://cdn.mos.cms.futurecdn.net/XRPHbkTdptdWSj9pkCDrzE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fred Baumgartner </span></figcaption></figure><p>Baumgartner observed that monitoring and control in connection with SFN transmitter sites is a potentially big issue. “We’re just starting to put our toes in that water and we can run [the Dallas-Ft. Worth installations] from our handheld devices, but at some point, it’s going to start to look like <a href="https://www.tvtechnology.com/news/qualcomm-shuts-down-flo-tv">MediaFLO</a> and then you’re got 300 transmitters out there and you have to start thinking about trucks, spare parts, and support infrastructure," he said. "You have to figure out how to make it all run economically.”</p><p><strong>‘HACKING’ NEXT-GENERATION TELEVISION</strong></p><p>Although the ATSC 3.0 racehorse is barely out of the stable, due to its hybrid broadcast/internet delivery, concerns are already surfacing about vulnerability of signals to manipulation by pranksters or others with darker agendas. Broadcast cybersecurity expert Wayne Pecena examined this in his presentation, “Hacking ATSC 3.0.”</p><p>He noted that the broadcast community was not exactly a stranger to nefarious intercepts of program streams, citing the 1986 takeover of HBO’s satellite transponder by “Captain Midnight,” and the “Max Headroom” incident the following year in which the studio-to-transmitter feeds of Chicago stations WGN-TV and WTTW were breached and third-party content aired.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="T5A8r4HVWicVhcQvgAV6CP" name="" alt="Wayne Pecena" src="https://cdn.mos.cms.futurecdn.net/T5A8r4HVWicVhcQvgAV6CP.jpg" mos="https://cdn.mos.cms.futurecdn.net/T5A8r4HVWicVhcQvgAV6CP.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Wayne Pecena </span></figcaption></figure><p>Pecena observed that those incidents had required a lot of technical savvy and large equipment costing many thousands of dollars. “Now someone with a tablet computer sitting in a coffee shop can wreak a lot more havoc,” he said.</p><p>He cited the potential risks to broadcasters of ATSC 3.0 stream hijacking, including dead air, loss of revenue, public embarrassment, data breaches, potential legal liability, loss of public trust, and impact on station resources.</p><p>Pecena urged station operators to gain a thorough understanding of their IP systems and think about ways in which they might be compromised, observing that “the Internet of Things really provides only minimal, if any, safeguards against hacks, with security often being an afterthought or a ‘neverthought.’”</p><p>He said that even with the security components inherent in ATSC 3.0 and a tightening of security at broadcast facilities, there still could be breaches occurring within the home environment.</p><p>“The consumer industry must adopt stronger IoT security features,” he said. “The weakest link determines the overall security of any system.”</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ppzUAqr6MqamuwMLxJpXSE" name="" alt="Merrill Weiss (photo credit: IEEE-BTS)" src="https://cdn.mos.cms.futurecdn.net/ppzUAqr6MqamuwMLxJpXSE.jpg" mos="https://cdn.mos.cms.futurecdn.net/ppzUAqr6MqamuwMLxJpXSE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Merrill Weiss (photo credit: IEEE-BTS) </span></figcaption></figure><p>During the gathering the society also recognized Merrill Weiss with its highest honor, the Jules Cohen award for excellence in broadcast engineering. </p><p>The BTS Symposium moves to Hartford, Conn. in 2019. Conference dates are Oct. 1-3.</p><p><em>For a comprehensive list of TV Technology’s ATSC 3.0 coverage, see our <a href="https://www.tvtechnology.com/atsc3" data-original-url="http://www.tvtechnology.com/atsc3">ATSC3 silo</a>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity: What Execs Should Know ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/cybersecurity-what-execs-should-know</link>
                                                                            <description>
                            <![CDATA[ Broadcasters aren’t exempt from hacking activity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sdpidKkkok7NjiiRgzzSxi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Sep 2018 21:16:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Cynthia Brumfeld ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZxRnbvL8ekXScAgUFPjYHo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZxRnbvL8ekXScAgUFPjYHo.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZxRnbvL8ekXScAgUFPjYHo.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>On April 5, 2015, Yves Bigot, the director-general of TV5Monde, was in the midst of a dinner with a fellow broadcaster, celebrating the launch of his company’s latest channel, when he received an unexpected volley of messages. All twelve TV5Monde channels were knocked off-air. A massive cyberattack was underway, infecting the stations’ equipment in rapid succession. If top technical staff had not been on site working to handle the new channel launch, and had they not acted quickly to unplug the source of the infection, TV5Monde might have lost all of its satellite distribution contracts due to the outage, placing the entire company in jeopardy.</p><p>Although few broadcasters have experienced a TV5Monde-level of attack, a host of entertainment companies, including Sony, Netflix and HBO, have also suffered at the hands of hackers. Odds are that an equally if not more devastating attack will hit another broadcast organization.</p><p>Broadcasters are just as vulnerable to cyberattacks and malware infections as any other business, government, or non-profit organization in the world. Virtually no aspect of radio, TV station, network operations is truly isolated from the internet. Every broadcaster has a host of digital connections with suppliers, customers, and audiences.</p><p>That’s why I’m gratified to have worked with the National Association of Broadcasters and a team of subject matter experts in the broadcasting industry over the past two years to create eight online courses that seek to equip broadcasters with the tools they need to create more secure workplaces. NAB will soon launch this series of vital courses on cybersecurity for broadcasters, starting with the first two, one of which walks broadcast managers and executives through the essential cybersecurity knowledge and skills they need. (The other course is designed to help the overall workforce adopt better cybersecurity habits.)</p><p>As nice as it would be to have a checklist of cybersecurity items to tick off and then be “one and done,” cybersecurity is an ongoing, ever-challenging fact of everyone’s life. There are no easy solutions, magic bullets, or single technology to keep your organization safe.</p><p>There are, however, sensible steps you can take as an executive to help guide your organization to practices that better protect your business and employees. here are just a few rules of the road covered in one of the two NAB courses launching this week that should help your organization find a better security posture.</p><p><strong>1. Know Your Threat Landscape</strong></p><p>It’s important for you to understand the current biggest cybersecurity threats to your organization, known in security circles as the threat landscape. Although your circumstances may differ, here are three top threats most broadcasters face:</p><p><strong>Malware:</strong> All kinds of malware can infiltrate a broadcast organization’s assets. Ransomware is currently a constant battle for most broadcasters, but there are all kinds viruses, trojans, worms, backdoors, and spyware that can infiltrate your systems. It’s important to understand the different kinds of malware threats you face. According to research by AT&T, around 90% of all organizations in the U.S. experience a malware-related incident every year. The vast majority of malware finds its way into an organization from the actions of insiders. Most of these insiders were unaware that they brought malware in-house, having innocently clicked on maliciously crafted emails, or downloaded bad programs from the internet, or inserted a contaminated USB stick.</p><p><strong>Advanced Persistent Threats:</strong> APTs or Advanced persistent threats are sophisticated threats from nation-states or organized cybercrime rings and typically take place silently and undetected for extended periods of time, sometimes even years.</p><p>The TV5Monde attackers, Russia’s APT28 group (the same group that hacked the Democrats during the 2016 election), had mapped out the computer networks and digital production systems that ran TV5Monde’s operations well in advance of the stations’ blackout. Experts speculate that the data obtained from this mapping required teams of telecommunications engineers, skilled coders, and expert tacticians to interpret the information and carry out the attack.</p><p><strong>DDoS Attacks:</strong> DDoS attacks or distributed denial of service attacks are not terribly sophisticated threats but can shut down operations if not dealt with properly. According to AT&T 2016 research, 73% of organizations around the world have reported at least one DDoS attack.</p><p><strong>2. Steer Your Organization to Risk-Based Management Approaches to Cybersecurity</strong></p><p>Risk-based management involves understanding, analyzing, addressing, and communicating risks to ensure that your organization achieves its desired objectives. It is the practice of looking at what could go wrong and coming up with plans to minimize potential problems. Managing risks is a difficult, ongoing, and multivariable process that often requires the input of virtually every part of an organization’s operations. It is not easy to do but when it comes to cybersecurity, experts agree it is essential.</p><p>The most important guidepost when it comes to risk-based management of cybersecurity is the <em>Framework for Improving Critical Infrastructure Cybersecurity</em>, produced by the National Institute of Standards and Technology (NIST). The NIST Framework delves extensively into many different aspects of cyber risk management.</p><p>While most non-technical broadcast managers and executives don’t need to dive into the Framework on a practical or comprehensive basis, it is very useful to understand the high points of the Framework to better guide your organization’s cybersecurity strategy. It is also a handy tool in understanding emerging cybersecurity insurance policies, negotiating with outside vendors, and communicating with outside stakeholders – the press, government and citizen groups – when cybersecurity incidents do occur.</p><p><strong>3. Protect and Secure Personal Data</strong></p><p>Although many broadcasters don’t fully see themselves as being in the personal data collection game, all broadcasters maintain some personal data within their organizations, even if only employee and contractor personal data. But as broadcasters increasingly push into expanded digital platforms such as mobile apps, streaming audio, streaming video, and dedicated websites, more and more personal data become part of the broadcast business world.</p><p>Moreover, the new ATSC 3.0 standard supports the ability to collect private data with the dedicated return channel from other backchannels, such as the Internet. Finally, the growing delivery of broadcaster content over smart TVs means that broadcasters will have to manage even more personal data.</p><p>Senior organization executives are increasingly held responsible for protecting the privacy of the personal information retained by organizations. The steps managers, executives, and other leaders take to ensure privacy protection can be greatly aided by how data privacy and security practices are treated within the organization’s risk-based cybersecurity practices, as exemplified by the NIST Cybersecurity Framework and another important NIST framework, the Risk Management Framework.</p><p>Furthermore, regulatory requirements to protect personal data are ramping up across the globe, with the changes likely affecting your organization. Chief among these regulatory shifts is the European Union’s General Data Privacy Regulation (GDPR). The GDPR not only applies to organizations in the EU but also to organizations outside of the EU if they offer goods or services to, or monitor the behavior of, EU data subjects.</p><p><strong>4. Foster a Culture of Cybersecurity</strong></p><p>Perhaps the single most important role a manager or executive can fill when it comes to cybersecurity is fostering a culture that favors secure operations, making the integrity and ongoing reliability of operations a priority on par with financial targets. Although the technical difficulties and costs of implementing security can seem less important than achieving near-term business goals, bear in mind how quickly a severe cyberattack can threaten revenues, spike expenses, and expose broadcasters to long-term liabilities.</p><p>According to the Ponemon Institute, the average price for small businesses to clean up after a cyberattack stands at $690,000. For medium-sized companies, that cost rises to over $1 million. For large organizations, the cost of a severe cyberattack can even reach tens of millions.</p><p>Fostering a culture of cybersecurity covers a wide canvas of management support techniques and activities, including</p><ul><li>Prioritize cybersecurity outside of IT roles by bringing IT and cybersecurity experts into business conversations from the outset.</li><li>Establish a culture of personal integrity and reliability by establishing acceptable use policies and guidelines, creating a safe environment for employees to self-report security incidents free from negative ramifications, communicating consistently across the organization about the need for security integrity, and rewarding and empowering employees for identifying security issues.</li><li>Support awareness and training programs because poorly educated employees can be one of the biggest threats. Therefore, enhancing cyber awareness among employees can be one of the best defenses any organization has.</li><li>Establish the right metrics to track effectiveness of cybersecurity efforts because if you don’t, you might end up continually make the same mistakes.</li></ul><p><strong>5. Evaluate New Technologies for Cybersecurity When Building Budgets</strong></p><p>As threats rise, evolve, mutate, expand and recede, a good cybersecurity culture accommodates flexibility in drawing up new technology and purchasing contingency plans in shorter windows than most managers and executives have experienced in the past.</p><p><strong>6. Support Investment in Necessary Cybersecurity Tools</strong></p><p>If it isn’t already, cybersecurity spending should be part of any broadcaster’s yearly cost management process. When drawing up budgets, it’s most helpful to prioritize investments in the tools that ensure greater information security even though the expenditures may not enhance the bottom line in the short-term.</p><p><strong>7. Prepare for the Threats Ahead</strong></p><p>The greatest unknown - and the biggest threat to security - is the introduction of new technology. For broadcasters, the biggest technology shifts also radically increase the “attack surface” or areas where hackers can infiltrate your systems and assets. It’s important to build in cybersecurity protections as your organization embraces the Internet of things, cloud migration, and the integration of multiple screens for content and services.</p><p>TV5Monde had a lot of clean-up to do after its devastating cyberattack. Weeks went by before the company was able to transmit anything other than pre-recorded programming due to the massive damage caused by the attack. TV5Monde incurred 10 million euros (or nearly $11 million) in immediate unanticipated costs and likely lost even more in unrealized revenue. Hindsight is of course 20/20, but it’s possible had TV5Monde followed these and other crucial cybersecurity steps, they might have dodged some of the more catastrophic aspects of this unprecedented attack.</p><p>To learn more about these and other ideas and practices that broadcast executives can put into place for better cybersecurity management, check out NAB’s course “Broadcast Executive Guide to Cybersecurity” <a href="https://www.pathlms.com/nab/categories/2109/courses">here.</a></p><p><em>For those interested in a written companion to this course, please visit <a href="https://metacurity.com/essential-reports/">https://metacurity.com/essential-reports/</a>.</em></p><p><em>Cynthia Brumfield, president of DCT Associates, is a veteran media, communications and technology analyst who is now focused almost exclusively on the emerging field of information security, writing extensively about the topic for publications, clients and on her own cybersecurity news aggregation site <a href="file://localhost/about/blank">Metacurity.com.</a></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pai Calls Out Former CIO for “Inaccurate Information” About ECFS ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/pai-calls-out-former-cio-for-inaccurate-information-about-ecfs</link>
                                                                            <description>
                            <![CDATA[ He also announced plans to revamp comment system, change commission’s IT culture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4XpJrK8rpkXeT4urXvVY9u</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Usb6t9DuDNVwdDNpEZMhEL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Aug 2018 15:21:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[FCC]]></category>
                                                    <category><![CDATA[Regulatory &amp; Legal]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emily Reigart ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Usb6t9DuDNVwdDNpEZMhEL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[FCC Chairman Ajit Pai]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Usb6t9DuDNVwdDNpEZMhEL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON--</strong><a href="https://www.fcc.gov/" data-original-url="http://www.fcc.gov/">Federal Communications Commission</a> Chairman Ajit Pai threw some serious shade at former FCC Chief Information Officer David Bray in a Monday statement about the Office of Inspector General’s investigation into the May 2017 “incident involving the FCC’s Electronic Comment Filing System.”</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Usb6t9DuDNVwdDNpEZMhEL" name="" alt="FCC Chairman Ajit Pai" src="https://cdn.mos.cms.futurecdn.net/Usb6t9DuDNVwdDNpEZMhEL.jpg" mos="https://cdn.mos.cms.futurecdn.net/Usb6t9DuDNVwdDNpEZMhEL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">FCC Chairman Ajit Pai </span></figcaption></figure><p>Although he did not refer to Bray by name — only as “the FCC’s former Chief Information Officer (CIO), who was hired by the prior Administration and is no longer with the Commission,” “the former CIO” or “then-CIO” — in the statement, Pai made clear that he laid the blame for the rumors and conspiracy theories at his feet.</p><p>Pai said he is “deeply disappointed” that Bray “provided inaccurate information about this incident to me, my office, Congress, and the American people,” referring to a statement released by Bray’s office that said the <a href="https://www.tvtechnology.com/news/fcc-comment-filing-system-flooded">disruption to the comment system</a> was a result of “multiple distributed denial-of-service attacks (i.e. DDoS). These were deliberate attempts by external actors to bombard the FCC’s comment system with a high amount of traffic to our commercial cloud host.”</p><p>Although he called Bray’s actions “completely unacceptable,” Pai said he is “pleased that this report debunks the conspiracy theory that my office or I had any knowledge that the information provided by the former CIO was inaccurate.”</p><p>In addition to castigating Bray for telling him “we’re 99.9% confident this was external folks deliberately trying to tie-up the server to prevent others from commenting and/or create a spectacle,” Pai said it’s “abundantly clear that ECFS needs to be updated.” And he said the good news is that Congress last week authorized funding to revamp the FCC comment system.</p><p>Pai also addressed cultural issues that he said contributed to the misleading statements. “I’m also disappointed that some working under the former CIO apparently either disagreed with the information that he was presenting or had questions about it, yet didn’t feel comfortable communicating their concerns to me or my office.”</p><p>Because of this report, Pai said his office plans to “make it clear” that FCC IT employees “are encouraged to speak up if they believe that inaccurate information is being provided to the commission’s leadership.”</p><p>Bray now works as executive director of the <a href="https://peoplecentered.net/">People-Centered Internet Coalition</a>.</p><p>A representative shared a prepared statement: “Dr. Bray has not been contacted by the FCC IG and has not seen their reported findings. There has not been any outreach to ask what he had seen, observed, or concluded during the events more than a year ago in May 2017.” After emphasizing that Bray is no longer with the commission, the statement added that “Swift response ensured the commenting system was up more than 99.4% of the time for the total commenting period” (presumably referring to the Title II debate). </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Need to Know: Protecting the Broadcast Plant ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/need-to-know-protecting-the-broadcast-plant</link>
                                                                            <description>
                            <![CDATA[ Practically every piece of gear in the facility now has an Ethernet port ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mNkP9Aj5RWae5AvHcq7xPA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zj5KZWPwaMCjd9HC2CXRYJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jul 2018 14:25:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ James E. O&#039;Neal ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Zj5KZWPwaMCjd9HC2CXRYJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zj5KZWPwaMCjd9HC2CXRYJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>ALEXANDRIA, VA.—</strong>When our world was a little younger and a lot more innocent, a broadcast operation had little to worry about in terms of security. Perhaps the only safeguard was a hired guard brought in during evening hours to ensure only personnel and expected guests came and went (and no equipment walked out).</p><p>That was then; this is now.</p><p>Thanks to our highly connected world, it now takes a lot more than a Pinkerton guard to protect broadcast operations. This has given rise to a whole new enterprise—cybersecurity, a term that surfaces almost daily, along with reports of email hackings, data breaches, credit card skimmers—even electronic intrusion at the Pentagon.</p><p><strong>RISK TOLERANCE</strong></p><p>With almost every piece of gear having an Ethernet port, one might think broadcasters would be especially vigilant. However, this is not always the case.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VK2rb6PsdtCMypJyQxR5rg" name="" alt="Kelly Williams" src="https://cdn.mos.cms.futurecdn.net/VK2rb6PsdtCMypJyQxR5rg.jpg" mos="https://cdn.mos.cms.futurecdn.net/VK2rb6PsdtCMypJyQxR5rg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Kelly Williams </span></figcaption></figure><p>“Some broadcasters are; some aren’t,” says Kelly Williams, senior director of engineering and technology policy for NAB. “Human behavior is still an issue,” noting that this boils down to risk tolerance—just how serious the threat is perceived to be by businesses and individuals running them.”</p><p>While networks and larger station groups have implemented “special ops” groups for safeguarding technical infrastructures, cybersecurity for others is merely installation of antivirus software and implementation of “off-the-shelf” firewalls.</p><p>“The banking business has been all over this for a long time and the government has also been very concerned about cybersecurity,” said Williams. “However, some companies haven’t given it much thought at all,” adding that the problem is greater now than ever.</p><p>“We’re much more reliant on products that are essentially computer-based,” he continued. “Encoders, playout servers—these are really just computers running Linux or Windows, with software that makes them do what they need to do. Also, the control for devices now is all IP, with access to machines often through a web-based GUI, as not all have keyboards and monitors. Control is via an IP network. Your broadcast plant is really an IP network and is susceptible to ‘shenanigans’ on someone’s part, be it an employee, an outsider, or even a nation state. Operations are much more vulnerable to some sort of a cyber mishap than a few years ago,”</p><p>(As an example. Williams related an incident in which France’s Canal Plus was electronically hijacked, with programming on its 11 channels ceasing and normal content on its website replaced by messages presumably supporting the Islamic State. The cyberattack was so devastating it took hours to restart even basic operations, and weeks passed before everything was fully normalized. The attack cost the broadcaster nearly $11 million, not including lost advertising revenue.)</p><p><strong>A LONG WAY SINCE ‘CAPTAIN MIDNIGHT’</strong></p><p>Wayne Pecena, director of engineering at KAMU public radio and television, and the Texas A&M University System’s wide area data and distance learning network, and a frequent lecturer on cybersecurity at broadcast engineering conferences, echoed Williams’s remarks.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yJc4rEm4uX7Q6oGfTqEAmY" name="" alt="Wayne Pecena" src="https://cdn.mos.cms.futurecdn.net/yJc4rEm4uX7Q6oGfTqEAmY.jpg" mos="https://cdn.mos.cms.futurecdn.net/yJc4rEm4uX7Q6oGfTqEAmY.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Wayne Pecena </span></figcaption></figure><p>“Cybersecurity in any organization often takes less priority because it is not the core business,” he said. “It is certainly not the core business of a broadcast entity.”</p><p>And he agreed that the threat is worse than ever, recalling that two 1980s “hacking” incidents (the “Captain Midnight” and “Max Headroom” transmission disruptions) required specialized hardware (a satellite uplink and microwave transmitter). It’s much different now.</p><p>“Today, havoc can be implemented with a notebook computer from a Starbucks,” Pecena said/</p><p>So, is there anything broadcasters can do, other than bringing in specialized cybersecurity companies?</p><p>“It’s all about ‘cyber hygiene,’” said Williams, explaining that much of this is just common sense.</p><p>He suggests immediately changing any manufacturer-supplied passwords when installing new equipment, and implementing policies forbidding such things as connection of employee devices to station networks, as something as innocent as the insertion of a “foreign” thumbdrive into a computer USB port can place malware on a network.</p><p>“You need to make the entire staff aware of cybersecurity,” he said.</p><p>Williams added another very important (but often overlooked) “cyber hygiene” practice to the list.</p><p>“When an employee leaves, immediately kill off all of their passwords,” noting that neglecting this places a station’s infrastructure at high risk, especially in the case of terminated staffers.</p><p>He added that firewall implementation is not something that can be done once and forgotten about.</p><p>Pecena added his own suggestions for safeguarding broadcast infrastructures, which include:</p><p>· Use a “best practice” approach to network architecture design.</p><p>· Segment the network into functional domains—keep broadcast content and control networks separate.</p><p>· Allow access on a “need-to-access” basis.</p><p>· Use a proxy device to transfer external files with enterprise grade antivirus.</p><p>“A firewall takes regular care and feeding to be an effective cybersecurity measure,” Pecena said. “‘Care’ [in analyzing] the log files to see what is being filtered [denied or permitted] and ‘feeding’ to maintain security signature updates.”</p><p>Whether it’s a major television network or LPTV, all broadcast operations are vulnerable to cyberattacks. It behooves players to learn as much about cybersecurity as possible and to practice it on a daily basis.</p><p><em>Gary Arlen is president of Arlen Communications LLC, a research and consulting firm. He can be reached at</em><a href="mailto:info@arlencommunications.com">info@arlencommunications.com</a>.</p><p><strong>Need to Know More?</strong><br/>Do you have a burning question about cybersecurity? Or maybe there's a particular topic you'd like to see us tackle in future installments of Need to Know. Email us at <a href="mailto:needtoknow@futurenet.com">needtoknow@futurenet.com</a> and we’ll put our top minds on it!</p><p><strong>To learn more about cybersecurity's influence on other technology channels, check out these articles from Future sister titles:</strong></p><p>· <a href="https://www.residentialsystems.com/needtoknow/cybersecurity/resi-need-to-know-cybersecurity"><strong>Cybersecurity and Residential Integration [Residential Systems]</strong></a></p><p>· <a href="https://www.avnetwork.com/needtoknow/need-to-know-cybersecurity-and-av"><strong>Cybersecurity and AV [AV Network]</strong></a></p><p>· <strong><a href="https://www.prosoundnetwork.com/needtoknow/need-to-know-cybersecurity-and-pro-audio" data-original-url="http://www.prosoundnetwork.com/needtoknow/need-to-know-cybersecurity-and-pro-audio">Cybersecurity and Pro Audio [Pro Sound Network]</a></strong></p><p>· <a href="https://www.radioworld.com/needtoknow/cybersecurity-its-not-just-a-problem-for-it"><strong>Cybersecurity and Radio [Radio World]</strong></a></p><p>· <a href="https://www.multichannel.com/needtoknow/need-to-know-iot-poses-new-cybersecurity-threats-cable"><strong>Cybersecurity and TV [Multichannel News]</strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Need to Know: Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/need-to-know-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ Every enterprise is at risk as attacks diversify and adversaries get smarter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nmi972wneq2PrC8xMTNtHG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q4FK39zerrqZGVv2H7GooZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jul 2018 13:51:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Paul McLane ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q4FK39zerrqZGVv2H7GooZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q4FK39zerrqZGVv2H7GooZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Editor’s Note: Welcome to Future’s third edition of Need to Know, a series exploring complex topics like blockchain, 5G and artificial intelligence — and how they apply to each industry served by our websites and magazines.</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="C2WQkK5w3E8yYDBiSHZq4N" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/C2WQkK5w3E8yYDBiSHZq4N.jpg" mos="https://cdn.mos.cms.futurecdn.net/C2WQkK5w3E8yYDBiSHZq4N.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>“We keep building new things on old infrastructure that never seems to get fixed.”</p><p>Chris Wysopal is a hacker who was quoted in a Washington Post column about the state of internet security (or perhaps we should call it insecurity). In May Wysopal — also known by his hacker name Weld Pond — joined several others in a return visit to Capitol Hill, where 20 years earlier they’d testified in a congressional hearing about the insecurities of software and networks.</p><p>Their 1998 appearance helped put the issue of cybersecurity on the national stage. A central part of their 2018 message is that digital security isn’t much better today.</p><p><strong>COSTLY AND DANGEROUS</strong></p><p>Malicious cyber activity cost the U.S. economy between $57 billion and $109 billion in 2016, according to the White House Council of Economic Advisors. Cyber threats are ever-evolving, and the sophistication of adversaries keeps growing. But, according to the White House report, the private sector may, for any number of reasons, be tempted to underinvest in cybersecurity.</p><p>National security officials echo the concern.</p><p>“Our daily life, economic vitality and national security depend on a stable, safe and resilient cyberspace,” says the U.S. Department of Homeland Security in explaining why it devotes a large web resource to the topic.</p><p>The department this spring released a strategy hoping to help reduce vulnerabilities, build resilience, counter malicious actors and make the ecosystem more secure. It identifies 16 “critical infrastructure” sectors where a loss of networks would have a debilitating effect on the country. But even trying to define the sectors demonstrates how broadly the subject touches every corner of American life; they range from commercial facilities and manufacturing to the communications sector and health care.</p><p>Homeland Security took particular note of a growing concern about the threat of “wide-scale or high-consequence events” that could cause harm or disrupt services on which the economy and millions of people depend. “Sophisticated cyber actors and nation-states exploit vulnerabilities to steal information and money and are developing capabilities to disrupt, destroy or threaten the delivery of essential services.”</p><p>How might your own business be whacked? A threat can come via denial of service attacks; destruction of data and property; disruption of business, perhaps for ransom; and the theft of your proprietary data, intellectual property and financial and strategic information. Reports of data breaches and cyber attacks are everyday news. Lewis Morgan on the IT Governance Blog curated more than 60 such stories in the month of May and counted the total of breached records that month at more than 17 million — “actually quite low when compared with previous months.”</p><p>In 2018, virtually every major and minor business or organization relies on the global, interdependent IT ecosystem. The degree to which leaders take the subject seriously could, in the long term, determine the survival of those enterprises.</p><p>To learn what trends businesses should be watching, we turned to several sources approaching the topic from various angles.</p><p><strong>THREATS IN BURSTS</strong></p><p>In its 2018 Annual Cybersecurity Report, Cisco said malware is definitely becoming more vicious and harder to combat. “We now face everything from network-based ransomware worms to devastating wiper malware,” the company stated. “At the same time, adversaries are getting more adept at creating malware that can evade traditional sandboxing.”</p><p>While encryption can enhance security and is used by roughly half of global web traffic, Cisco continued, encryption provides bad actors with a powerful tool to hide command-and-control activity. “Those actors then have more time to inflict damage.”</p><p>Artificial intelligence may help. “Encryption also reduces visibility. More enterprises are therefore turning to machine learning and artificial intelligence. With these capabilities, they can spot unusual patterns in large volumes of encrypted web traffic. Security teams can then investigate further.”</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FEqSSa5iBmb8XjNDhrmf9S" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/FEqSSa5iBmb8XjNDhrmf9S.jpg" mos="https://cdn.mos.cms.futurecdn.net/FEqSSa5iBmb8XjNDhrmf9S.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Cisco made note of several other trends and findings:</p><ul><li>Short, pernicious “burst attacks” are growing in complexity, frequency and duration. “In one study, 42% of the organizations experienced this type of DDoS [distributed denial of service] attack in 2017. In most cases, the recurring bursts lasted only a few minutes.”</li><li>Many new domains are tied to spam campaigns. “Most of the malicious domains we analyzed, about 60%, were associated with spam campaigns,” Cisco reported.</li><li>Security is seen as a key benefit of hosting networks in the cloud. “The use of on-premises and public cloud infrastructure is growing. Security is the most common benefit of hosting networks in the cloud, the security personnel respondents say.”</li><li>One bad insider can be a big threat, and a few rogue users can have a huge impact. “Just 0.5% of users were flagged for suspicious downloads. On average, those suspicious users were each responsible for 5,200 document downloads.”</li><li>It’s not just your IT assets that are at risk. Expect more attacks on operational technology as well as the internet of things. “Thirty-one percent of security professionals said their organizations have already experienced cyber attacks on OT infrastructure.”</li><li>The multivendor environment affects risk. “Nearly half of the security risk that organizations face stems from having multiple security vendors and products.”</li></ul><p><strong>IOT RANSOMWARE</strong></p><p>Another observer taking stock is Aidan Simister, the global SVP for Lepide Software. Writing in a post on the CSO website, he too predicts artificial intelligence will take a bigger role. But while AI may help the good guys, he notes, hackers too can use it to launch more sophisticated cyber-attacks. Further, new strains of malware can work around “sandbox” defensive techniques, waiting until they are outside the sandbox before executing their malicious code.</p><p>Meanwhile, Simister agrees that the “internet of things” could become more of a target for ransomware, with hackers targeting power grids, factory lines, smart cars or home appliances to demand payment. Many businesses, Simister predicted, will not comply with the European Union’s new General Data Protection Regulation on data protection and privacy (the thing you’ve been getting all those emails about). He predicts some companies will choose to ignore it, accepting the risk.</p><p>We’re also likely to see a growing number of companies adopt multi-factor authentication in response to data breaches involving weak, stolen or default passwords.</p><p>He expects that more sophisticated security strategies may find wider adoption. These may include the use of “remote browsers”; deception technologies that imitate a company’s critical assets; systems to spot and identify suspicious behavior; better network traffic analysis; and “real-time change auditing solutions” that do things like detect abuses of user privileges or suspicious activity in files and folders.</p><p>But Simister too sees the risk of more attacks backed by hostile governments; in response he predicts more efforts to train staff and to develop international sharing of information.</p><p><strong>PRIVACY PARADOX</strong></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ErcFP9Cdmwcc3yXB77TxiA" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ErcFP9Cdmwcc3yXB77TxiA.jpg" mos="https://cdn.mos.cms.futurecdn.net/ErcFP9Cdmwcc3yXB77TxiA.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>One change in mindset visible in the market is a deemphasis on the idea of “perimeter security.” “You are not safe behind the perimeter, because the perimeter itself no longer exists,” Akamai argues on its website. “Today’s world is cloud- and mobile-driven, and the traditional moat-and-castle approach to enterprise security is no longer applicable for modern business practices.”</p><p>With applications hosted in various places and a workforce on the move, the company argues, there is no longer a delineation between inside and outside the network. “As a result, seemingly every week there are new reports about high-profile data breaches and cyberattacks.”</p><p>Akamai Chief Technology Officer Charlie Gero argues in favor of what he calls zero trust security architecture. “Companies must evolve to a ‘never trust, always verify’ zero trust model to secure against the wide variety of threats that exist and are constantly evolving,” Akamai states.</p><p>Looking at the consumer economy more broadly, cybersecurity is only likely to become more crucial thanks to ongoing developments in areas as diverse as cryptocurrency, interactive smart speakers and mobile payments.</p><p>For example, a major trend toward platform personalization — whether it be on Facebook or Spotify, Wave or NextDoor — raises the privacy stakes. Venture capitalist Mary Meeker of Kleiner Perkins notes the massive amount of personalized data that people have put into such platforms.</p><p>That data, she said in remarks at the Code 2018 conference, improves engagement and leads to better experiences for consumers — but it also helps creates what she calls a privacy paradox: “Internet companies are making low-price services better in part from user data. Internet users are increasing their time on internet services based on perceived value. Regulators want to ensure data is not used improperly, and not all regulators think about this in the same way.”</p><p>Regulatory considerations are thus a big, uncertain element in this picture.</p><p><strong>THE WEAK HUMAN LINK</strong></p><p>IT expert Wayne Pecena, who works in the broadcast and education sectors, says security should be an ongoing process. Yet that at many business, unfortunately, it tends to be treated as a one-time, set-it-up-and-forget-it event.</p><p>Pecena is assistant director information technology of educational broadcast services at Texas A&M University and director of engineering for KAMU Public Radio and Television; he says cybersecurity never has an end.</p><p>“It is a continuous process of monitoring, evaluation, analysis and prevention as the threat landscape is always in a state of change and evolution,” he said. “I would also not lose sight of the past, as ransomware, phishing [and] distributed denial of service will likely continue at an accelerated pace. As cloud services and applications continue to expand, I would also keep the cloud cybercrime landscape or Cybersecurity-as-a-Service on my radar.”</p><p>In Pecena’s experience, most organizations do spend plenty of time and money in protecting their IT environment, but often the simplest areas can be overlooked while the focus is on higher-tech matters. “Social engineering remains one of the largest threats to an organization, and the human factor remains a weak link. The internet of things movement brings challenges, as most of these types of devices lack any real internal security capability and instead rely on external protection means.”</p><p>He also finds “crypto-mining” a fascinating area of concern as computing resources are hijacked for someone’s bitcoin mining applications. “Not necessarily destructive — like DDoS or ransomware — to an organization, [but] host computing resources can be [affected] such that legitimate application use is impacted. Malicious mining scripts can easily be picked up from a casual website visit, and this opens a new area for antivirus protection software.”</p><p>Pecena said for him this recalls the days of desktop computers being unknowingly hijacked to serve music or distribute porn. Those well-meaning hackers who returned to Washington recently hoped to draw attention once again to the issue of digital security. At least one pushed for government to play a larger role. But another said companies also need to take advantage of the tools and knowledge that are already available.</p><p>It was Robert Mueller — yes, that one — who is credited with saying back in 2012 that there are only two types of companies: those that have been hacked and those that will be hacked. Today that wisdom is often updated to read: “There are two types of companies: Those that know they’ve been hacked, and those that don’t know that they’ve been hacked.”</p><p>Manage accordingly.</p><p><strong>SOURCES AND MORE READING</strong></p><p><a href="https://www.washingtonpost.com/news/powerpost/paloma/the-cybersecurity-202/2018/05/23/the-cybersecurity-202-these-hackers-warned-congress-the-internet-was-not-secure-20-years-later-their-message-is-the-same/5b045df31b326b492dd07e30/">Derek Hawkins, The Washington Post, “Hackers: Internet Security Threats From 20 Years Ago Persist”</a></p><p><a href="https://www.dhs.gov/news/2018/05/15/department-homeland-security-unveils-strategy-guide-cybersecurity-efforts">Department of Homeland Security, “Cybersecurity Strategy”</a></p><p><a href="https://www.csoonline.com/article/3250086/data-protection/7-cybersecurity-trends-to-watch-out-for-in-2018.html">Adam Simister, “7 Cybersecurity Trends to Watch Out for in 2018”</a></p><p><a href="https://www.cisco.com/c/en/us/products/security/security-reports.html">Cisco “2018 Annual Cybersecurity Report”</a></p><p><a href="https://www.kpcb.com/internet-trends" data-original-url="http://www.kpcb.com/internet-trends">Mary Meeker, Kleiner Perkins, “Internet Trends 2018</a></p><p><a href="https://www.whitehouse.gov/wp-content/uploads/2018/03/The-Cost-of-Malicious-Cyber-Activity-to-the-U.S.-Economy.pdf">White House Council of Economic Advisors, “The Cost of Malicious Cyber Activity to the U.S. Economy”</a></p><p><a href="https://content.akamai.com/us-en-PG10736-zero-trust-moving-beyond-perimeter-security.html">Charlie Gero, Akamai, “Moving Beyond Perimeter Security”</a></p><p><strong>MORE RESOURCES</strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Cybersecurity Tips for Broadcasting ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/show-news/5-cybersecurity-tips-for-broadcasting</link>
                                                                            <description>
                            <![CDATA[ 5 Cybersecurity Tips for Broadcasting ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3t9f4cjRgbKsGSr7cq1dR1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Mar 2018 21:07:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Leslie Ellis ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Here’s another example of the blurring boundaries between “enterprise IT” functions and broadcast engineering: Security. Not so long ago, the IT side of the typical TV broadcaster handled Internet-facing security necessities, like email and firewalls, while the engineering side shored up distribution-related security, usually over dedicated links. Those links were plumbed in Internet Protocol (IP) but didn’t traverse the “big Internet,” so they were, in essence, cordoned off.</p><p>These days, securing the attack surfaces of broadcast and media providers is necessarily a collaboration between IT and engineering, increasingly buttressed by top-down mandates to do whatever it takes to keep the bad guys off the digital premises. Just ask TV5Monde, in France, which suffered a massive hack in April of 2015 that took down 12 of its 12 channels overnight. Like so many hacks, the bad guys had gained entry a few months earlier, maneuvering in the background to find the weak spots.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TV6AfRB8ANP7pzno3mwZf8" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/TV6AfRB8ANP7pzno3mwZf8.jpg" mos="https://cdn.mos.cms.futurecdn.net/TV6AfRB8ANP7pzno3mwZf8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>“The real-time nature of broadcast television doesn’t lend itself well to today’s time-to-detect metrics,” which can average 100 days, said Michael Korten, cyber security practice leader for Cisco. “Everyone knows the stresses that come from ads not airing, regardless of the reason.” To use a worst-case example, Super Bowl ads cost around $170,000 per second.</p><p>Korten’s group, and in particular Cisco’s Talos division –a team of nearly 300 cyber security experts– live for this stuff. They are scheduled to deliver a full readout of the latest trends during the 2018 NAB Show in Las Vegas. This will happen in the Connected Media IP Theater (which is in the South Hall, Upper Level of LVCC) on Monday, April 9, from noon to 1 p.m. They deliberately won’t compile their report until much closer to the date, so as to capture what happens between now and then. But here’s a short list of best practices and general observations they’ll likely cover:</p><p><strong><strong>1.</strong> You can’t protect what you can’t see –visibility is job No. 1.</strong></p><p> The prevailing wisdom over the last two or so decades was to buy hardware to secure different types of “perimeters” –the so-called “see a problem, buy a box” solution. Each hole gets plugged with a new thumb, which is fine, until you run out of thumbs. Plus, broadcast and media companies typically average 40 to 50 individual security products. But if the firewall can’t “see” the web security product –and so on down the chain– the entirety of the threat surface can’t easily be visualized, let alone pre-emptively protected.</p><p><strong><strong>2.</strong> Add “time-to-detect” to your vital metrics.</strong></p><p> According to the Talos folks, the average time-to-detect for enterprise companies (meaning beyond the media/broadcast sector) is 100 days. That’s a little over three months! How to get that vital metric down from months to hours is one of the things they’ll explain during the NAB keynote.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SS4pWCxmPziVv4qVHL7397" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/SS4pWCxmPziVv4qVHL7397.png" mos="https://cdn.mos.cms.futurecdn.net/SS4pWCxmPziVv4qVHL7397.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><strong><strong>3.</strong> Know your attack entrances (which are anywhere there are end points).</strong></p><p> E-mail is a threat surface for its potential to disseminate malicious links. Web searches can be a threat surface because of rogue DNS addresses that redirect to unsafe places. Memory sticks, remote and unsecured (non-VPN) network access, cloud handoff points, connected devices, orphaned or neglected websites –all need to be sussed out, continuously.</p><p><strong>4. Attacks increase with each new innovation.</strong></p><p> Whether it’s a new cloud platform, mobile offering or device, if it’s new, digital and “on-net” from production to distribution, it’s probably already being deconstructed somewhere for undesired access. Innovation cuts both ways –the intended uses and the unintended consequences. (This is why security people constantly talk about how security needs to be considered from the get-go of any new product or service and not bolted on at the end.)</p><p><strong><strong>5.</strong> Have a “before, during and after” plan, and check it frequently. </strong></p><p>Improved visibility across all potential threat surfaces is step one; gaining control after a breach is step two. “The first thing people want to know, after a breach, is scope –can we contain it?” said Cisco’s Korten. “The second thing they want to know is: how bad is it? How much damage, what does remediation look like?” That’s why it’s a good idea to know what levers to pull once the alarms have sounded. (Sometimes, it’s a matter of even having levers to pull.) That means a security blueprint with perimeter detection and a “cloud firewall” designed for real-time threat management and automation. Overall mission: Stay ahead of the hack.</p><p>The grim reality about broadcast TV and security is this: Attackers have unlimited opportunities to get where they want to go. They’ll keep trying and trying and trying. We’re likely see more evidence of this, even in the short run-up to the 2018 NAB Show. If this is a topic near and dear to your day-to-day, it might make sense to check out the Talos presentation and the rest of its security portfolio while you’re in Vegas.</p><p><em>This is the third in a six-part blog series preceding the 2018 NAB Show. <a href="https://www.tvtechnology.com/the-nab-2018-agenda-series" data-original-url="https://www.tvtechnology.com/show-news/the-nab-2018-agenda-series">Click here to read more</a> about what broadcasters will be talking about at this year's show. </em></p><p><em>About the Author:</em> Leslie Ellis is a respected “technology translator,” known in cable and telecom circles for her award-winning, 20+ year “Translation Please” column in Multichannel News. She took on this Cisco-sponsored pre-NAB series to point out common and frustrating obstacles, for anyone on the sliding transition toward “being more Internet-like.” It is less of a comprehensive representation of available options and more a glimpse into what’s worrisome, on a day-to-day basis for engineers and IT people who work in media and entertainment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybercrime: A Looming Global Threat ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/opinions/cybercrime-a-looming-global-threat</link>
                                                                            <description>
                            <![CDATA[ In today’s hyper-digital world, vulnerabilities are everywhere—buried in web applications, concealed in networks, hidden in servers, embedded in endpoints. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iJgYv6DGwUxBXVps4sZCaj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jan 2018 09:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Opinion]]></category>
                                                    <category><![CDATA[Insights]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ramki Sankaranarayanan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/xvmxhr2L3efW4mFdFEfehL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nAhWpwioKe2EMacr5C2A7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In today’s hyper-digital world, vulnerabilities are everywhere—buried in web applications, concealed in networks, hidden in servers, embedded in endpoints. Across literally every industry vertical, fear of a data security breach is keeping business leaders awake at night, because as technology has developed exponentially, so has cybercrime. Gone are the days when physical frisking, increased security personnel and surveillance cameras were enough to deter crime. Today, a lot more is needed as corporations, government agencies and individuals grapple with new realities like ransomware, system hacks, identity theft, phishing, Distributed Denial of Service (DDOS) attacks, zero-day attacks and online piracy; not to mention—in addition to what continues to be every organization’s worst nightmare—trusted insiders committing a security breaches.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GbFnHanbsmZgwuz4QU67Ve" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/GbFnHanbsmZgwuz4QU67Ve.jpg" mos="https://cdn.mos.cms.futurecdn.net/GbFnHanbsmZgwuz4QU67Ve.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A quick look at figures published by Gemalto’s Breach Level Index is enough to make anyone cringe. In 2016 alone, 1,792 data breach incidents <a href="https://globenewswire.com/news-release/2017/03/28/945626/0/en/Gemalto-releases-findings-of-2016-Breach-Level-Index.html">took place</a> across the globe. <a href="https://solutions.teamavalon.com/blog/data-breaches-a-year-at-a-glance" data-original-url="http://solutions.teamavalon.com/blog/data-breaches-a-year-at-a-glance">According to</a> cybersecurity specialists Avalon, the average total cost of each breach was a whopping $7.01 million. This of course does not even begin to cover the associated damage to brand and reputation, which is often unrecoverable.</p><p><strong>M&E: A MAGNET FOR CYBERCRIME</strong></p><p>While cybercrime can hurt organizations in almost any industry, recent incidents have demonstrated that M&E companies are particularly vulnerable targets. Their susceptibility is centered on the fact that they have a sprawling supply chain with large volumes of digital content moving through at all times. The M&E industry is still reeling from the 2014 hack at Sony Pictures Entertainment, when hackers released confidential data which included personal information about employees and their families, data on executive salaries and copies of then unreleased Sony films. Sony <a href="https://www.eweek.com/security/sony-pegs-initial-cyber-attack-losses-at-35-million" data-original-url="http://www.eweek.com/security/sony-pegs-initial-cyber-attack-losses-at-35-million">pegged</a> the damage caused by the massive cyber-attack at $35 million. Also etched in broadcasters’ memory is another watershed moment from 2015, when cyber terrorists succeeded in taking French TV network TV5Monde off air, almost completely destroying the network.</p><p>Since then, cyber storm clouds have continued to gather over M&E players. Their woes reached historic proportions in July 2017, when hackers gained control of 1.5 TB of data from HBO, including confidential scripts and other content from the network’s marquee shows. Even before the team had a chance to catch their breath, they found their social media handles infringed as well. The incident came close on the heels of 10 new episodes of Netflix’s popular show “Orange is the New Black” getting leaked as a result of an attack on their post-production company, Larson Studios. Hackers also succeeded in stealing a copy of “Pirates of the Caribbean: Dead Men Tell No Tales” from Disney 10 days before the official release date, threatening to release it to torrent sites if they weren’t paid. ABC Studios also joined the bandwagon of beleaguered cybercrime victims, when hacker group, “The Dark Overlord” leaked unaired episodes of their upcoming game show.</p><p><strong>IMPLEMENTING BEST-IN-CLASS SECURITY PRACTICES</strong></p><p>Is there any foolproof formula to avoid such security breaches? Not yet. But M&E enterprises can certainly learn from these incidents and take precautionary measures so that in future, cybercriminals cannot find a single hole to burrow through. Whether this means hiring external security advisory firms, bolstering approval procedures, isolating environments, establishing content type-led operating procedures, automating IT security processes like system patching, increasing the use of URL encryption, content encryption (including for “at rest” and downloaded content), conducting unannounced penetration testing, strengthening identity management or building applications that are coded for security, no effort is too big and no detail is too small. Technology partners must also be chosen carefully. Ideally, the organization selected should meet widely recognized, internationally accepted security standards like ISO 270001 and SOC2 certification.</p><p><strong>SECURING OPERATIONS ACROSS THE CONTENT SUPPLY CHAIN</strong></p><p>In today’s “TV Everywhere” universe, there are several use cases where sending content to external stakeholders becomes necessary to fulfil international syndication requirements. One such case is localization, since delivering content worldwide in multiple languages is key to boosting monetization. Studios have to send copies of their content to third party vendors for subtitling, dubbing etc., which increases the risk of piracy. While measures like encryption, secure transport, forensic watermarking etc. can help protect content from being illicitly distributed, a holistic MAM solution, like a Media ERP software, can help manage end-to-end content workflows securely across the supply chain. Such solutions allow users to perform tasks like localization within the same, secure environment, eliminating the need to send coveted assets outside the system.</p><p><strong>MANAGING THE HUMAN FACTOR</strong></p><p>Any organization is only as good as its people, and every employee has the potential to make or break a business. Even a single illicit act can bring a billion-dollar company to its knees. Companies therefore need to pull out all the stops to create an environment where commitment to content security comes from everyone, not just the leadership. Educating employees is extremely important, as often they have little understanding of the consequences that can result from sharing data unwisely. Since human intervention is mandatory at various stages of the content lifecycle, increasing electronic management control to make piracy harder is a constant endeavor. More specifically, deploying work order management to assign manual tasks to particular individuals is key. So is providing “just in time” access to content, wherein the said person is given access only for a watertight duration with access ceasing the moment his/her task is completed successfully.</p><p><strong>JOINING FORCES TO TIGHTEN THE SECURITY BELT</strong></p><p>In a bid to curb cybercrime, a group of 30 content enterprises, including major digital media players, networks and Hollywood outfits, have recently joined forces to create a group called the Alliance for Creativity and Entertainment (ACE). The group conducts research and works closely with law enforcement agencies to identify and stop pirates from stealing movies and TV shows.</p><p>M&E enterprises are hardly alone in their battle against cybercrime—healthcare, retail, finance, social media, education and even government have been hit hard in recent times. Industry leaders like J.P. Morgan Chase, eBay, Adobe and Target are just a few among many who have faced major cyber-attacks that have impacted millions of users. Technology giants like Yahoo and LinkedIn have not been spared either. High profile individuals like Mark Zuckerberg and Sundar Pichai have woken up to find their social media handles compromised. The battle is clearly on, and cybercriminals are leveraging new technical innovations to launch more complex, intelligent and targeted attacks across the globe. Predicting their next target is close to impossible, as their motives vary from financial gain, political ideology, espionage and revenge to sheer fun and fame.</p><p>While the list of cybercrime victims grows longer, organizations of all shapes and sizes are rethinking their security investments. Gartner <a href="https://www.gartner.com/newsroom/id/3784965">predicts</a> information security spending to reach $93 billion in 2018, and Microsoft has already <a href="https://www.reuters.com/article/us-tech-cyber-microsoft/microsoft-to-continue-to-invest-over-1-billion-a-year-on-cyber-security-idUSKBN15A1GA">announced</a> its decision to invest over $1 billion a year on cyber security R&D. Needless to say, the cost of doing business is only going up on the back of these investments, and the burden is sure to percolate down to end customers sooner rather than later.</p><p>Is it time to go bring back fax machines and tapes, some may ask. Not quite. After all, crime has existed since time immemorial, and in all probability, it will continue to exist till the end of time. But lessons have to be gleaned from past events, as prevention remains the best line of defense against cyber criminals. Corporations need to get into the minds of hackers and identify every potential security loophole without a moment’s delay. A Cyber Defense Control roadmap needs to be put in place, with effective strategies for every level, starting right at the grass roots and going up to the top brass. Security best practices need to be exercised at an individual and organizational level, as a holistic, cross-country, cross-industry risk-based approach alone can help stay a step ahead in the war against cybercrime.</p><p><em>Ramki Sankaranarayanan is founder & CEO of Prime Focus Technologies (PFT).</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Preparing for the Coming Hacks ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/preparing-for-the-coming-hacks</link>
                                                                            <description>
                            <![CDATA[ In July, HBO’s media content library was hacked when 1.5 TB of data was illegally accessed and downloaded, including unaired episodes of “Ballers,” “Barry,” “Insecure,” and “Room 104,” plus a script for an unaired episode of “Game of Thrones.” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2DUksqfqdm7bAPEhgScM4E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Dec 2017 15:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Careless ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/bn83ZVLW852QhJFSyXeFs7.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>OTTAWA—</strong>In July, HBO’s media content library was hacked when 1.5 TB of data was illegally accessed and downloaded, including unaired episodes of “Ballers,” “Barry,” “Insecure,” and “Room 104,” plus a script for an unaired episode of “Game of Thrones.” These were later made available on the apparently hacker-run website Winter-leak.com, (the site is currently inaccessible but media coverage is available at winter-leak.ml). The result: HBO’s expensively-produced premium content was online for anyone to see for free.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SH2boBxLLYMwP79hFtcFjc" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc.png" mos="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>An Akamai Security Operations Center</em></p><p>HBO is just the latest victim of unauthorized entry into its video operations. In April of 2015, hackers claiming allegiance to the Islamic State, (and now potentially believed to be Russian), knocked French-language broadcaster Canal Plus off the air for the better part of a day; in March, 2013, North Korea posed a series of cyber-attacks on South Korea inflicting damage on three major banks and two broadcasters. “The broadcasters were not affected on-air; however, their business IT infrastructure was paralyzed,” according to the white paper “Cyber Security Services for Broadcasters,” by Obor Digital, an Orlando, Fla.-based provider of cyber security solutions for broadcasters.</p><p>These kinds of attacks are becoming more common and more serious, said Rob Caldwell founder and CEO for Obor Digital, which, along with TV Technology, conducted a series of Cyber “boot camps” for broadcasters this fall. “In the case of content producers, the threat is to their bottom line,” he said. “Who will pay to see premium video content if hackers are making it available for free?”</p><p>Making matters worse is that “broadcasters haven’t yet begun to seriously address the threat of ‘content replacement’ where a hacker or disgruntled employee could potentially replace a commercial spot with media intended to create panic, confusion and chaos,” Caldwell added. Not all threats come from hackers breaking directly into servers either. “All it takes is an employee to bring in a USB flash drive that’s infected with hacker malware—say with some ‘free music’ they downloaded to listen to at work—then plugging the flash drive into the broadcaster’s internal network. All of a sudden, the ‘bad guys’ can get in and steal what they want—and they will.”</p><p>There are several caveats broadcasters should be aware of when protecting their valuable media content from online theft and illegal distribution. Here are three of them:</p><p><strong>WORK WITH A SECURE CONTENT DISTRIBUTOR</strong></p><p>As broadcasters and content creators distribute more of their premium content online, they will invariably come under hacker attacks more often.</p><p>So says Dave Lewis, global security advocate the Boston-based streaming provider Akamai. His remedy is for broadcasters and content providers to hook up with a secure content delivery network (like Akamai), which has sophisticated cyber security tools such as web application firewalls (WAF) already in place.</p><p>Case in point: A distributed denial of service (DDoS) attack occurs when a hacker floods a web site with so many requests that the site ceases to function, knocking it offline. Unfortunately, such attacks are extremely common these days, and they can result in content distributors being unable to serve paying clients.</p><p>To prevent this from happening, “Akamai can provide a line of defense to ensure your web site stays online, so that your customers can be assured that they will have access to your programming during DDoS attacks,” said Lewis. “As well, our platform is extremely secure; making your content far less vulnerable to piracy.</p><p><strong>HIRE A PROFESSIONAL </strong></p><p>Originally, the U.S. military decided to use Obor Digital’s Zeus software to track military communications equipment, configurations, failures and repair issues in Afghanistan and Iraq, according to Caldwell. Subsequently, Obor decided to partner with those military cyber specialists and bring this expertise directly to broadcasters.</p><p>Cyber security services offered by Obor Digital to broadcasters include “Vulnerability Assessments” to determine a content provider’s operational/IT system weaknesses and remedies for them; ongoing Monitoring (three available levels) to detect and address security threats/attempted intrusions; Security Device Management to ensure that the broadcaster’s security devices are running properly; and Incident Response to step in when an attack succeeds, minimize it, and determine what happened after the fact to keep it from happening again.</p><p><strong>GO FULL OUT ON END TO END SECURITY</strong></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HPNQEMxJU2GUic2ehrXnEc" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/HPNQEMxJU2GUic2ehrXnEc.png" mos="https://cdn.mos.cms.futurecdn.net/HPNQEMxJU2GUic2ehrXnEc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The Entertainment Security Operations Center in Los Angeles</em></p><p>Los Angeles’ new Entertainment Security Operations Center (ESOC) is an end-to-end response to hacker threats. Built by security solutions provider Secure Channels Inc., ESOC combines a “tier 3” (99.98 percent availability) data center infrastructure with dark fiber tethering (connecting over so-called dark fiber networks that are not otherwise in use), to provide content creators with a totally secure, membership-only production process.</p><p>“We only connect your company to other ESOC-checked members, meaning that everyone in your production chain is secure and verified,” said Richard Blech, CEO of the Irvine, Calif.-based company. “Too many times, a major content provider with reasonable security will contract a third-party firm that isn’t secure, putting the entire production/distribution chain at risk. The ESOC model eliminates this risk, because everyone you work with is as secure as you are.” ESOC’s protection extends to member documents and emails, as well as video content.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DraftKings and McAfee Execs Leading NAB Show New York Opener ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/show-news/draftkings-and-mcafee-execs-leading-nab-show-new-york-opener</link>
                                                                            <description>
                            <![CDATA[ The 2017 NAB Show New York is taking a special interest in cybersecurity, announcing that it will kick the event off this year with a special session focused on cybersecurity applications and implications for media and technology. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LpprknVqyevP74EYh3o8L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sfMAqVCkT7kTWCinH8dbSg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Aug 2017 09:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Events]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Balderston ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sfMAqVCkT7kTWCinH8dbSg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sfMAqVCkT7kTWCinH8dbSg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>WASHINGTON—</strong>The 2017 NAB Show New York is taking a special interest in cybersecurity, announcing that it will kick the event off this year with a special session focused on cybersecurity applications and implications for media and technology. Headlining the session will be Paul Liberman, chief operating officer and co-founder of DraftKings, and Gary Davis, chief consumer security evangelist at McAfee.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="irK7czWcZMfqaN4LDh62pm" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/irK7czWcZMfqaN4LDh62pm.jpg" mos="https://cdn.mos.cms.futurecdn.net/irK7czWcZMfqaN4LDh62pm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>“DraftKings, McAfee and the Future of Cybersecurity” will take a specific look at the trends in digital security, including evolving threats and best practices for protecting the safety and privacy of businesses and customers.</p><p>“These executives represent two companies that are leading the way by innovating and working with legal authorities to ensure that tech platforms are compliant,” said Chris Brown, NAB executive vice president of Conventions and Business Operations. “This session will provide critical insight on cybersecurity and how businesses can protect themselves from growing threats.”</p><p>The session is slated for Oct. 18 at 10:30 a.m.</p><p>The 2017 NAB Show New York will run from Oct. 18-19 at the Javits Convention Center in New York.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>