← Back to Newsroom

Focus on GLI: Vendor security program maximizes proactive approach to cybersecurity for gaming industry

Tuesday, September 15, 2026 8:00 AM

    After several cybersecurity incidents involving gaming companies in recent years, GLI Secure’s David Elmore says the vast majority of casinos aren’t equipped to handle a major threat. Cyber criminals are like sharks swimming in the ocean looking for prey – and most companies are easy pickings.

    Relationships with third-party providers are a major part of the problem. No matter what measures are in place, if suppliers with access to a company’s systems aren’t safe (and the companies that also service those vendors), the entire security apparatus can fall like a house of cards.

    GLI Secure’s Vendor Security Program is a massive leap forward at providing the safest technological ecosystem possible. The program is geared specifically for the gaming industry and helps plug any security leaks by taking proactive measures.

    “We were trying to find a consistent way to independently evaluate what the cybersecurity posture was of all these vendors,” Elmore says. “Because operators are depending on these increasingly interconnected third parties’ networks, the goal was to provide a way to ensure the vendors that had access to these networks or systems, or sensitive information had some base level of appropriate security controls in place.”

    The Vendor Security Program involves seven critical steps:

    1. Classifying the vendor by risk tier
    2. Requesting and reviewing current security certifications
    3. Sending a risk-tiered security questionnaire
    4. Validating answers and not accepting responses at face value
    5. Embedding security requirements into a contract
    6. Defining and enforcing the minimum-security baseline
    7. Adding the vendor to a company’s ongoing monitoring system

    “The security of your operation doesn’t just stop at the four walls,” Elmore says. “It extends out to all these vendors and third parties you trust and you’re working with. When you think about a casino environment, they have point-of-sale systems, hotel systems, gaming manufacturers, loyalty programs, displays, elevators, HVAC, and others.

    “About six years ago a casino in Vegas got hacked through their fish tank. Essentially, the fish tank was being temperature controlled on the network, and somebody actually hacked the fish tank to get on the network, and then exfiltrated about 10 gigs of data of their high roller program to a server in Finland.”

    Everything that sits on a network can be vulnerable, he says. An analysis of 22,000 incidents in 2025 found that 48% of those breaches involved a third party, up 30% in the prior report. This means third-party involvement increased by 60% in a single year.

    “So while you can be fully contained and secure on your casino property, whether you’re a regulator or an operator, you’re really at the mercy of this cyber posture or how mature that is for every single third-party vendor you’re using, whether that’s dozens or hundreds,” Elmore says.

    The goal with the Vendor Security Program was to create an overall best practices system based on two major sets of standards, the National Institute of Standards and Technology (NIST) and Center for Internet Security (CIS). GLI initially launched a Gaming Security Framework which operates as a best practice to help govern controls at gaming properties.

    However, more was needed because of the proliferation of vendors used in the industry. There had previously been no baseline system tailored specifically for the gaming industry. The Vendor Security Program changes that and streamlines the entire process of verifying vendors, while putting in place a coherent and consistent set of standards to help prevent security breaches.

    “We create the standards for the industry on all-new technology,” Elmore says. “They saw us as being the one to go to pull various elements together and establish a framework for testing third-party vendors against industry best practices to prevent what we know as being the specific threats the gaming industry faces. We did that by pulling the controls from CIS and NIST, and then gathered input from the gaming industry as whole.”

    The process included input from CISOs on the operator side, manufacturer side, and tribal side to make sure what GLI was crafting could become a well-rounded, ironclad set of controls. The goal was not to be so restrictive as to hinder new technologies, but not so loose to let in more sophisticated threats.

    “It was basically, who do we trust? What do they have access to and how confident are we in their security?” Elmore says.

    The program is in the process of being rolled out now and will be highlighted at the upcoming G2E conference. As Elmore notes, cybercrime brings in billions of dollars and casino operations not taking appropriate measures can literally risk a company’s solvency. The Vendor Security Program could be key in preventing that.

    “It’s not going to slow down, it’s only going to get worse,” Elmore says of the threats gaming companies face. He adds: “The GLI Secure Vendor Security Program is going to be a game changer because the majority of threats the casino industry is facing right now are from third-party exploitation. Because GLI and GLI Secure are seen as the tip of the spear with new regulations and new technologies, this is another way for us to show that we have created a framework that people can use to ensure they’re as protected as they can be.”