SCCG · Licensing

Nevada Regulators Shorten Cybersecurity Incident Notification to 24 Hours

operatefreshnorth-america
Nevada Regulators Shorten Cybersecurity Incident Notification to 24 Hours

TL;DR — Nevada has cut the cybersecurity incident notification period to 24 hours from 72 and renamed “cyberattack” to “cybersecurity incident.” New rules require response plans, five-day initial reports (or in-person meetings), and 30-day updates. The changes follow major 2023-2025 breaches at Caesars, MGM, Wynn, and Station Casinos.

SCCG Take — This is a pragmatic structural shift that demands tighter incident playbooks from operators. Compliance teams should align protocols to the 24-hour trigger to minimize friction with regulators.

Nevada gaming regulators have tightened requirements for casinos facing cyber threats, reducing the mandatory notification window to regulators from 72 hours to 24 hours. The updates, approved this year by the Nevada Gaming Commission following recommendations from the Nevada Gaming Control Board, also rename “cyberattack” as “cybersecurity incident” and mandate formal response plans. Recent incidents underscore the stakes: Caesars Entertainment paid $15 million in ransom after a 2023 breach, MGM Resorts International reported $100 million-plus in losses from a similar attack that same year, Wynn Resorts paid $1.5 million in 2025, and Station Casinos was hit in March.

Updated Reporting Rules and Industry Input

The new regulations require operators to maintain a cybersecurity incident response plan covering preparation, protection, response, and recovery. Casinos must now provide written notification within 24 hours of a successful incident where systems are taken down or data is compromised. A cybersecurity response report is due within five days of activating response procedures, though operators may instead request an in-person meeting with the Board chair and submit the full report within 30 days. Written updates are required every 30 days until resolution.

Jeremy Eberwein, chief of the technology division for the Nevada Gaming Control Board, said, “We expect people to be under attack on a daily basis from cyber threats. We’re looking for cases where attacks are successful. If a system is taken down or data (is compromised or removed), that’s what we’re looking for.” Board Chair Mike Dreitzer emphasized the change addressed prior confusion: “Seventy-two hours in practice was just too long. We modified the reporting requirements for the licensees thereafter to comport with what we now understand is best practice.” Kristi Torgerson, chief of the enforcement division, noted that the 24-hour window ensures regulators are informed immediately without demanding extensive details upfront. As reported by CDC Gaming, the Board incorporated significant input from license holders and cybersecurity experts before finalizing the rules.

The Practical Balance for Operators

From a regulatory standpoint, these adjustments reflect a structural shift that prioritizes real-time awareness while giving operators breathing room to assess scope before full documentation. In my three decades advising gaming client-partners on compliance matters, I have seen how mismatched reporting timelines create unnecessary friction; the prior 72-hour rule often left licensees uncertain and noncompliant. The name change to “cybersecurity incident” was described as more palatable for operators, per Torgerson.

Crowd Strike has projected an 89% rise in AI-assisted threats this year, even as casinos deploy similar tools defensively. Hackers will continue targeting the sector given the potential for multimillion-dollar ransoms.

What This Means for Compliance Teams

Client-partners should treat this as an inflection point: update incident playbooks now to meet the 24-hour trigger and layered reporting cadence. Regulators have signaled they want visibility without premature speculation, which aligns the rules with actual crisis dynamics. Operators who build these protocols tightly will reduce both regulatory exposure and operational disruption going forward.

Reporting: CDC Gaming

Steve’s read · SCCG Intelligence

Nevada's 24-hour cyber notification rule is a structural tightening — compliance playbooks must now move at regulatory speed.

We've watched this play out across our 545 partners: Caesars, MGM, Wynn, Station — real losses, real ransom. Nevada just formalized what the last two years taught us: cyber resilience is now a compliance mandate, not an IT nice-to-have. Operators in every regulated market need incident protocols that match regulator expectations, or they'll be caught flat-footed.

SCCG angle: SCCG connects operators to vetted cybersecurity partners and compliance advisors who understand gaming-specific incident protocols. We've worked through breach response across regulated markets — we can help you build playbooks that meet Nevada's 24-hour standard and scale to other jurisdictions before the next incident hits.

Related

Tribal Nations Token — SCCG partnerGaming Regulators from Across the Americas Confirmed for SiGMA North America 2026 in Mexico CityLondon.Bet Named Official Betting Partner and Back-of-Shorts Sponsor of Charlton Athletic
Curated by SCCG · Powered by SCCG Technology