Skip to content

Nevada to tighten cyberattack rules after MGM, Caesars breaches

Ansh Pandey
Written by Ansh Pandey

​Nevada gambling regulators are moving to tighten cybersecurity reporting rules following a series of cyberattacks that exposed weaknesses in how casinos alert authorities.

The proposed changes stem from ransomware attacks in September 2023 on MGM Resorts International and Caesars Entertainment. The incidents disrupted casino operations across Las Vegas, affected customer services, and highlighted gaps in how quickly regulators were informed.

In response, the Nevada Gaming Control Board (NGCB) held a public workshop on 4 December 2025 to review potential reforms. The session was led by NGCB Chair Mike Dreitzer, signalling that cybersecurity is now a growing priority for the state’s gaming regulator.

24-hour incident reporting rule

At the heart of the discussion is Regulation 5.260, which sets out how licence holders must report cybersecurity incidents. Currently, casinos are required to notify regulators within 72 hours of confirming an attack. Under the proposed amendments, that window would be reduced to just 24 hours.

Regulators say earlier notification would reduce the risk of learning about serious breaches from media reports or outside sources. Officials argued that faster reporting would allow the NGCB to assess operational and regulatory risks more quickly, while maintaining confidence in Nevada’s gaming sector.

Source: Nevada Gaming Control Board & Commission

If adopted, the revised rules would require operators to alert regulators by phone or email within 24 hours of confirming a cyber incident. A more detailed “Initial Cyber Incident Response” report would then need to be submitted within five days. Casinos would also be expected to provide regular updates every 30 days until the issue is fully resolved.

The reporting requirements would apply to incidents that compromise gaming systems, customer data, daily operations or regulatory compliance. However, regulators stopped short of defining a rigid threshold for what qualifies as a reportable incident, noting large differences in the size and complexity of casino operations.

Reduced reliance on third-party verification

Industry representatives have raised concerns about the practicality of the tighter timeline. The Nevada Resort Association told regulators that many cyber incidents are initially detected by third-party security firms, which may take more than 24 hours to confirm an attack.

In response, the NGCB clarified that the reporting clock would begin only once a casino operator confirms the incident internally, not when an external vendor first flags suspicious activity.

Casino security teams also pointed out the risk of false alarms, with many alerts investigated daily never resulting in confirmed breaches. Regulators acknowledged the issue but said operators should have clear internal processes for escalation and assessment. The NGCB stressed that the proposal does not mandate specific cybersecurity technologies. Instead, the focus remains on governance, decision-making and communication between casinos and regulators.

Research presented during the workshop showed that Nevada casinos have experienced dozens of cyber incidents over the past 15 years, reflecting the industry’s exposure due to large financial flows and sensitive customer data. The proposed changes will be reviewed by the Nevada Gaming Commission on 18 December 2025. If approved, they would mark a significant shift in how cybersecurity risks are monitored in the state’s casino industry.

The fuse is lit in Mexico CitySiGMA North America hits Mexico City, 01–03 Sept 2026. 4,000 delegates. Three days of deals, insight, and startup sparks. The most serious stage of the Spanish-speaking sector. Lead from the front and book your spot.