NewsTradingSentimentCalendarCommunityBriefing
Tech

Gaming Industry Adopts New Vendor Security Standards

By Tech Desk · 2026-09-15 · 2 min read
A stylized digital shield protecting a network of interconnected nodes
Illustration: Tradingbird

Casinos are increasingly vulnerable to hackers who exploit third-party systems. A new industry program aims to fix this by enforcing strict security baselines for all suppliers.

Cybercriminals often target the weakest links in a company's digital infrastructure, and for the gaming industry, that link is frequently a third-party vendor. According to recent data, nearly half of all cyber breaches involve external suppliers, a figure that has risen sharply in the past year. This trend highlights a critical gap in how casinos and operators manage their security perimeters, which extend far beyond their physical walls.

To address this growing risk, GLI Secure has introduced a specialized vendor security program. The initiative is designed to create a consistent, industry-wide standard for evaluating the cybersecurity posture of suppliers. By moving from reactive defense to proactive verification, the program aims to ensure that every entity with access to sensitive gaming networks meets a minimum baseline of security controls.

Third-party risks dominate breach statistics

The reliance on external vendors for everything from point-of-sale systems to climate control creates a vast attack surface. David Elmore, from GLI Secure, notes that operators often find themselves at the mercy of their suppliers' security maturity. If a vendor is compromised, the entire ecosystem is at risk, regardless of how secure the casino's own internal systems may be.

A notable example of this vulnerability occurred six years ago when a Las Vegas casino was hacked through its fish tank. The aquarium’s temperature control system was connected to the main network, allowing attackers to exfiltrate gigabytes of high-roller data. This incident underscores that any device on a network, no matter how mundane, can serve as an entry point for malicious actors.

Program enforces strict security baselines

The new program outlines seven critical steps to vet suppliers. These include classifying vendors by risk tier, reviewing existing certifications, and sending detailed security questionnaires. Crucially, the process does not accept responses at face value; it involves validating answers and embedding specific security requirements directly into contracts. This ensures that security is a contractual obligation rather than a suggestion.

Once approved, vendors are added to an ongoing monitoring system. This continuous oversight helps detect changes in security posture over time. The approach transforms vendor management from a one-time checkbox exercise into a dynamic, ongoing process that adapts to evolving threats.

Standards based on national frameworks

The program is built upon established national standards, specifically those from the National Institute of Standards and Technology and the Center for Internet Security. By aligning with these recognized frameworks, the initiative provides a coherent set of best practices tailored specifically for the gaming sector. This fills a previous void where no industry-specific baseline for vendor security existed.

As reported by GN technics/gaming (en-US), this shift toward standardized vendor security is a significant step for the industry. It reduces the fragmentation of security practices and provides operators with a reliable method to verify their suppliers. While no system is perfect, this structured approach significantly raises the bar for entry and reduces the likelihood of catastrophic breaches through third-party channels.

Based on reporting by cdcgaming.com, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories