GLI launches GLI Secure to standardise gaming cybersecurity across vendors
New division provides a CIS/NIST-based vendor framework and third-party certification.

Key Takeaways
- GLI launched GLI Secure in June to provide a CIS and NIST‑based vendor cybersecurity framework and certification.
- The programme aims to replace lengthy operator questionnaires with a transferable GLI assessment for suppliers.
- High‑profile breaches in 2023 and a 2025 Tribal ISAC study show acute supply‑chain and tribal sector vulnerabilities.
- A Check Point report cited by GLI recorded an increase from 1,968 to 2,336 weekly cyberattacks between 2025 and July.
GLI launched GLI Secure in June to provide a dedicated cybersecurity and professional services division that assesses suppliers against a common standard for the gambling sector. The programme uses Center for Internet Security (CIS) and National Institute of Standards and Technology (NIST) best practices to offer operators independent assurance that third‑party vendors have been tested for vulnerabilities.
Why GLI Secure exists: vendor gaps and a notorious fish-tank hack
A widely cited industry anecdote illustrates the risk: hackers in Finland allegedly gained access to a Las Vegas casino’s IT estate through internet‑connected sensors on a lobby fish tank, ultimately downloading 10GB of data that included a high‑roller database. The episode underlines the way supplier devices and services can become entry points when operator and vendor security protocols are not aligned.
GLI created GLI Secure to address that exact problem by delivering a vendor security framework operators can trust and suppliers can be assessed against. The goal is to reduce the repeated cycle of operators issuing long cybersecurity questionnaires to every vendor and then having to review the returned answers.
GLI Secure: a CIS and NIST‑based vendor framework
The GLI Secure programme maps its controls to two established frameworks: the Center for Internet Security and NIST. GLI says the approach is deliberately calibrated to avoid blocking new technologies while maintaining cybersecurity integrity.
David Elmore, GLI’s Head of Casino Services North America, described the practical issue at G2E in Las Vegas:
“Right now, operators are sending out these massive questionnaires [to vendors] about their cybersecurity to make sure they don’t add a vulnerability.” — David Elmore, GLI
Elmore argued the questionnaires are burdensome for both operators and suppliers. Under GLI Secure, an operator can accept GLI’s assessment in place of their bespoke questionnaire, and a supplier gains a transferable certification they can present to multiple clients.
How GLI Secure fits operator and vendor workflows
GLI positions the service as a substitute for the time‑consuming questionnaire model. The division offers:
an assessment process mapped to CIS and NIST controls;
a certification or attestation vendors can present to operators;
access to GLI subject matter experts for advisory calls without charge.
Elmore said GLI Secure creates a “standard that’s almost like a stamp, like a golden ticket” operators can rely on when onboarding suppliers. He also emphasised GLI Secure avoids being so restrictive that it prevents vendors from deploying new technologies.
Sector context: recent breaches and exposed supply chains
High‑profile incidents have focused attention on cyber risk across the global gaming industry. In September 2023, MGM Resorts suffered a social‑engineering incident that forced shutdowns across parts of its systems; Caesars experienced a loyalty‑database breach from social engineering around the same period. Outside the US, Aristocrat Leisure reported a cyber incident linked to a third‑party file transfer application that resulted in staff personal data being stolen. Singapore’s Marina Bay Sands disclosed a data breach that affected over 665,000 lifestyle rewards members in October 2023.
The supply‑chain angle is clearest in cases where third‑party software or devices provided the attacker a foothold. GLI Secure is explicitly targeting that vector by assessing vendors before those suppliers are allowed into a casino operator’s environment.
Risk concentration for tribal casinos and rising attack frequency
GLI highlights a specific vulnerability in the tribal sector. A 2025 study by Tribal ISAC, State of Cybersecurity Within Tribal Nations, found 37% of tribal organisations had no dedicated cybersecurity personnel and another 30% had just one person responsible for cyber. Elmore noted the economic dependency some tribes have on casino revenues and warned that a major breach could imperil essential community services.
Industry telemetry also shows increasing attack volume. A Check Point report cited by GLI recorded an average of 1,968 cyberattacks per week against organisations in 2025, rising to 2,336 per week as of July — equivalent, the report said, to an attack roughly every four minutes.
What operators and suppliers should consider now
Operators that currently rely on bespoke vendor questionnaires face two choices: continue the manual programme or accept an accredited third‑party assessment. GLI pitches its service as a way to reduce duplicated effort across jurisdictions and brand portfolios.
Suppliers benefit by holding a certification they can present to multiple prospective operator clients, reducing repeated administration. GLI also positions its subject matter experts as an entry point for operators and vendors to discuss cybersecurity options informally; Elmore said those advisory calls do not carry a fee.
Implications for compliance, procurement and platform vendors
Procurement teams will need to decide whether GLI Secure attestation meets their internal risk tolerance and regulator expectations. For platform and systems vendors, a GLI assessment could become a commercial differentiator, especially in multi‑jurisdictional sales where the alternative is completing dozens of different questionnaires.
Regulators and licence holders remain the ultimate arbiters of acceptable controls but adopting a recognised baseline mapped to CIS and NIST may streamline both audits and procurement cycles. GLI’s proposition is to move that baseline out of bespoke paperwork and into a certification operators can rely on.
“At the very least, we have subject matter experts you can lean on, people who will hop on the phone and talk to anybody,” Elmore said, adding that those conversations do not cost anything.
For operators, suppliers and advisers, GLI Secure reframes a long‑running operational headache as a standardisation exercise. Whether licensing authorities and operators accept a third‑party stamp in place of internal compliance workflows will determine how widely the service is adopted.
Frequently Asked Questions
What is GLI Secure and when did it launch?
GLI Secure is a dedicated cybersecurity and professional services division of Gaming Laboratories International that launched in June. It provides a vendor assessment and certification framework mapped to Center for Internet Security and NIST controls to help operators verify supplier security.
How does GLI Secure change the vendor questionnaire process?
GLI Secure replaces the need for operators to send bespoke, lengthy cybersecurity questionnaires to each supplier by offering a standard assessment operators can accept instead. David Elmore said this avoids suppliers filling multiple questionnaires across jurisdictions and reduces the time operators spend reviewing responses.
Which incidents underline the need for a vendor security framework?
Incidents include September 2023 social‑engineering breaches at MGM Resorts and Caesars, an Aristocrat Leisure incident tied to a third‑party file transfer application, and the October 2023 Marina Bay Sands breach affecting over 665,000 members. These cases highlight third‑party vectors and supply‑chain risk.
What specific vulnerability does the tribal sector face?
A 2025 Tribal ISAC study found 37% of tribal organisations had no dedicated cybersecurity personnel and 30% had only one person responsible for cyber. GLI warns that many tribal casinos are economically essential to their communities, increasing the potential impact of a major breach.
Tags
About the author

Oliver Grant
Industry Technology Correspondent
Oliver Grant covers the technology and business machinery of iGaming — platform and data deals, AI and compliance tooling, affiliate and marketing shifts, and the quarterly numbers behind them. The reports lead with the announcement, name the vendors and figures exactly as published, and separate genuine capability from press-release promise. When a supplier ships a new engine or a regulator tightens ad rules, Oliver Grant explains what actually changes for the companies involved.
More from Oliver Grant








