
GLI Secure launched a Vendor Security Program using NIST and CIS standards to evaluate third-party vendors for gaming operators. 48% of 22,000 breaches in 2025 involved third parties, a 60% increase year-over-year. The seven-step process includes questionnaires, contract clauses, and continuous monitoring to limit exposure.
SCCG Take — Operators must treat vendor networks as extensions of their own security perimeter. This framework offers a practical route to reduce third-party breach probability before threats further erode solvency.
GLI Secure is advancing a proactive cybersecurity stance for the gaming industry with its new Vendor Security Program. David Elmore of GLI Secure stated that the vast majority of casinos lack readiness for major threats, as cyber criminals seek easy targets in interconnected systems. Third-party vendors represent a central vulnerability, where compromise at any supplier level can undermine an entire operation.
One documented breach occurred six years ago when a Las Vegas casino was hacked through an internet-connected fish tank monitoring system. That intrusion allowed exfiltration of about 10 gigabytes of high-roller program data to a server in Finland. An analysis of 22,000 incidents in 2025 found that 48% of breaches involved a third party, up 30% in the prior report and reflecting a 60% increase in third-party involvement in a single year.
The Vendor Security Program creates consistent, independent evaluation of vendor cybersecurity posture, tailored to gaming. It draws controls from National Institute of Standards and Technology (NIST) and Center for Internet Security (CIS) frameworks, following GLI’s earlier Gaming Security Framework for property-level controls. Input came from chief information security officers on the operator, manufacturer, and tribal sides to balance protection against new technology adoption with defense against specific gaming threats.
As reported by CDC Gaming, the program encompasses requesting and reviewing current security certifications, sending risk-tiered security questionnaires, validating answers, embedding security requirements into contracts, defining and enforcing minimum-security baselines, and adding vendors to ongoing monitoring. “The security of your operation doesn’t just stop at the four walls,” Elmore says. The initiative is now rolling out and will be highlighted at the upcoming G2E conference. Elmore described the program as a game changer against the majority of threats arising from third-party exploitation, noting that unchecked cybercrime risks company solvency as threats continue to escalate.
Reporting: CDC Gaming
Generated by SCCG’s automated editorial system from published source reporting. SCCG Management holds editorial responsibility.
Gaming, betting and prediction markets — the desk’s read, every weekday.
Subscribe →