
Nevada Casinos Now Have 24 Hours to Report Cyberattacks Under New Rules
The Nevada Gaming Control Board has tightened its cybersecurity reporting requirements, cutting the notification window from 72 hours to 24 hours following a string of high-profile attacks on Las Vegas properties.
A Tighter Clock After a Run of Costly Attacks
Nevada’s casino regulators are not waiting around anymore. The Nevada Gaming Commission, acting on recommendations from the Nevada Gaming Control Board, has adopted new cybersecurity regulations that cut the required notification window for a cyberattack in half, from 72 hours down to 24. The change is one of the more significant updates to come out of a broader rules overhaul and arrives after several bruising years for Las Vegas’s biggest operators.
The recent track record is grim enough to justify urgency. Caesars Entertainment and MGM Resorts International were both successfully attacked in 2023. According to CDC Gaming, Caesars reportedly paid $15 million in ransom to recover access to customer data, while MGM claimed losses of more than $100 million after hackers disrupted casino operations nationwide. Wynn Resorts was hit in 2025, reportedly paying $1.5 million in ransomware. Station Casinos was also attacked this past March. That is a lot of fire for one industry in a short span.
What the New Rules Actually Require
The regulations lay out a structured response timeline that tries to balance speed with practicality. Within 24 hours of a cybersecurity incident, a casino must notify the Board. Within five days of activating its incident response procedures, it must submit a cybersecurity response report. Operators who are not ready to commit details to paper that quickly can instead request an in-person meeting with the Board chair within those five days, but they are still required to produce a written report within 30 days of the incident. From that initial reporting date, casinos must then submit written updates every 30 days until the matter is fully resolved.
Board Chair Mike Dreitzer, as quoted by CDC Gaming, explained the thinking behind collapsing the early window while extending the written report deadline. “Seventy-two hours in practice was just too long,” Dreitzer said. “We modified the reporting requirements for the licensees thereafter to comport with what we now understand is best practice. Previously, the regulation didn’t comport with best practices and it caused a lot of confusion and consternation on the part of licensees. They would have to potentially provide a written response before they were ready or prepared to do so.”
Dreitzer added that input from both license holders and outside cybersecurity experts shaped the final framework. Requiring a full written report within five days, he said, was simply too soon given how long it can take to assess the scope of a breach.
AI Is Now Part of Both Sides of the Fight
The regulatory tightening is happening against a threat environment that keeps getting more complicated. American cybersecurity firm CrowdStrike reported this year that it expects an 89% increase in threat actors using artificial intelligence to conduct cyberattacks. At the same time, casinos and other companies are deploying the same technology defensively.
Jeremy Eberwein, chief of the technology division for the Nevada Gaming Control Board, described a baseline of near-constant pressure. “We expect people to be under attack on a daily basis from cyber threats,” Eberwein said, according to CDC Gaming. “We’re looking for cases where attacks are successful. If a system is taken down or data is compromised or removed, that’s what we’re looking for.”
With ransomware payments potentially running into the millions, experts say the incentive for hackers is not going away. The new regulations also include a terminology shift, renaming a “cyberattack” to a “cybersecurity incident” at the request of the gaming industry, along with a requirement that operators maintain a formal incident response plan covering preparation, protection, response, and recovery.
The 24-hour notification requirement gives the Board an early window to monitor the situation even before a casino has a complete picture of what happened. As Dreitzer put it, the idea is that licensees are still assessing the full scope when they first report in. Regulators, it seems, would rather know early and wait for the details than learn late once the damage is already tallied.
What is the new cyberattack reporting deadline for Nevada casinos?
Under newly adopted Nevada Gaming Commission regulations, casinos must notify the Nevada Gaming Control Board of a cybersecurity incident within 24 hours of it occurring, down from the previous 72-hour window.
What other reporting requirements do Nevada casinos now face after a cyberattack?
Casinos must submit a cybersecurity response report within five days of activating their incident response procedures, or request an in-person meeting with the Board chair within that same window. If they choose the meeting, they have 30 days to file the written report. Casinos must also provide written updates every 30 days until the incident is fully resolved.
Which Las Vegas casinos have been targeted by hackers in recent years?
Caesars Entertainment and MGM Resorts International were both attacked in 2023. Caesars reportedly paid $15 million in ransom, while MGM claimed losses exceeding $100 million. Wynn Resorts was attacked in 2025 and reportedly paid $1.5 million in ransomware. Station Casinos was also hit in March 2026.
Why did Nevada regulators reduce the notification window from 72 to 24 hours?
Nevada Gaming Control Board Chair Mike Dreitzer said 72 hours was too long in practice and did not align with cybersecurity best practices. The old timeline also caused confusion among licensees who felt pressured to submit written responses before they were ready.
