Skip to content
Capability/Additional Industries

Gaming & Gambling

State gaming commissions and anti-fraud requirements

01 / Overview
24 hours
Nevada notification window after an incident response plan is activated

Nevada Gaming Commission Regulation 5.260(4)(a), Operation of Gaming Establishments, as amended January 2026.

Gaming and gambling operators face strict regulatory oversight from state gaming commissions with specific cybersecurity and anti-fraud requirements. Thalorin supports gaming industry compliance with multi-jurisdictional regulatory tracking, gaming system security, and fraud prevention controls.

Nevada tightened its clock. Regulation 5.260, adopted in December 2022 and amended in July 2024 and again in January 2026, requires a covered entity whose incident has produced a material loss of control, a compromise or an unauthorised disclosure of data to notify the Chair of the Gaming Control Board no later than 24 hours after activating its incident response procedures, submit an Initial Cybersecurity Incident Response report within five calendar days, and provide written updates every 30 days until the incident is resolved and documented. Failure to exercise proper due diligence is an unsuitable method of operation, which is a licensing matter rather than a fine.

The regulator here is a licensing authority, and there is one in every jurisdiction the operator entered. Nevada does not name a mandatory framework: 5.260 requires an initial risk assessment and whatever best practices the covered entity deems appropriate, offering CIS Version 8, COBIT 5, ISO/IEC 27001 and NIST SP 800-53 as examples, with full compliance within 90 days of being licensed. The standard is self-selected and the outcome is examined, and a licensee classified as Group I additionally needs an annual independent review with a written attestation.

The obligation operators consistently run as a separate programme is the Bank Secrecy Act. Casinos are financial institutions: 31 CFR 1021.210 requires a written compliance programme with internal controls, independent testing, training and a designated compliance officer; 1021.311 requires a report of currency transactions above $10,000; 1021.320 requires a suspicious activity report at a $5,000 aggregate, filed within 30 calendar days of initial detection. Financial crime and cybersecurity draw on the same identity, account and transaction records, and running them apart doubles the evidence without improving either.

Where an obligation comes from a specific licence, Thalorin keeps it attached to that licence. The same control state answers a Nevada examination, another state's technical standards and a Bank Secrecy Act independent test, notification clocks run as workflow against the event that started them, and the annual attestation a Group I licensee needs is assembled from evidence that already exists rather than reconstructed in the weeks before it is due.

02 / Challenges

Organizations face significant compliance challenges

A 24-hour clock you start yourself

The Nevada notification runs from activating the incident response procedures, so an internal decision starts the regulatory clock, and the Initial Cybersecurity Incident Response report falls due five calendar days later. Any waiver must be requested in writing before the deadline it concerns.

Self-selected standard, examined outcome

Regulation 5.260 lets a covered entity choose its own best practices from examples including CIS Version 8, ISO/IEC 27001 and NIST SP 800-53. What gets examined is whether the practices chosen are followed, which puts the burden on evidence rather than on selection.

Two programmes reading the same records

Bank Secrecy Act obligations and cybersecurity obligations both depend on patron identity, account and transaction data. Most operators maintain separate evidence for each, so a single record is collected twice, aged differently and reconciled by hand.

The regulator mandates the data attackers want

Before a wagering account can be created, Regulation 5.225 requires the licensee to record the patron's identity, date of birth, physical address and the last four digits of their social security number, and to check them against the excluded persons list. Retention is not optional.

03 / Capabilities

How Thalorin helps

State gaming regulationsGLI standards

Multi-state gaming compliance

Carry each jurisdiction's obligations against the licence that imposed them, so one incident runs as parallel clocks with different deadlines rather than as a single notification someone has to remember to repeat.

Gaming system security

Hold system builds against the GLI standards they were certified to — GLI-11 for gaming devices, GLI-13 for monitoring and control systems, GLI-19 for interactive gaming, GLI-33 for event wagering — and the environments actually running them.

Anti-fraud controls

Run Bank Secrecy Act obligations off the same evidence the security controls use: the 31 CFR 1021.210 programme, currency transaction reports above $10,000, and suspicious activity reports at the $5,000 aggregate.

Player data protection

Classify the account data Regulation 5.225 compels you to collect — identity, date of birth, address, the last four digits of a social security number — as the regulated record it is, with access recorded against it.

Responsible gaming integration

Evidence excluded person and self-exclusion checks at the point they are performed, against the list established under NRS 463.151 and Regulation 28 in Nevada and the equivalent list in each other jurisdiction.

Sports betting compliance

Track event wagering systems against GLI-33 and the account and location controls a jurisdiction conditions the licence on, with exceptions recorded per licence rather than per platform.

Questions

Gaming & Gambling: common questions

How fast must a Nevada licensee report a cyber incident?

Notify the Chair of the Gaming Control Board as soon as practicable and no later than 24 hours after activating the response procedures in your incident response plan. An Initial Cybersecurity Incident Response report is due within five calendar days on the Board's form, or you may request a meeting with the Chair inside that window and file the form within 30 days. Written updates follow every 30 days until the incident is resolved and documented, and an investigation report must be made available on request.

Which cybersecurity framework does Nevada require?

None specifically. Regulation 5.260 requires a covered entity to perform an initial risk assessment, develop the best practices it deems appropriate, and keep monitoring and revising them, listing CIS Version 8, COBIT 5, ISO/IEC 27001 and NIST SP 800-53 as examples rather than as requirements. Full compliance is due within 90 days of being licensed. Group I licensees must also designate a qualified individual, have an internal auditor verify the practices annually, and obtain an annual independent written attestation.

What makes an operator a Group I licensee?

Gross revenue. Regulation 6.010 defines a Group I licensee as a nonrestricted licensee with gross revenue at or above amounts the Board determines for each fiscal year and posts on its website by the preceding 15 December, adjusted annually against the Consumer Price Index. The designation is sticky: once an operator qualifies it remains Group I in later years unless the Chair cancels it in writing, even if revenue would otherwise drop it back to Group II.

Do casinos have anti-money laundering obligations?

Yes. Casinos and card clubs are financial institutions under the Bank Secrecy Act. 31 CFR 1021.210 requires a written compliance programme covering internal controls, independent testing, training, a day-to-day compliance officer and procedures for identifying reportable transactions. Currency transactions above $10,000 in cash in or cash out require a report under 1021.311, and suspicious activity involving at least $5,000 in funds or assets requires a SAR within 30 calendar days of initial detection, extendable to 60 where no suspect has been identified.

Does GLI certification cover our cybersecurity obligations?

No, and conflating them is a common error. GLI standards test the gaming system itself — GLI-11 for gaming devices, GLI-19 for interactive gaming systems, GLI-33 for event wagering systems — against technical requirements, and certification attaches to the tested build. A regulation like Nevada's 5.260 addresses the operator's enterprise: risk assessment, best practices, notification, retention and, for Group I licensees, an independent annual attestation. A certified build is evidence about a product, not about a programme.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Gaming & Gambling.

See how one evidence artifact satisfies Gaming & Gambling requirements alongside every other framework you carry.