{"id":60708,"date":"2026-02-04T00:10:01","date_gmt":"2026-02-04T05:10:01","guid":{"rendered":"https:\/\/centricconsulting.com\/?p=60708"},"modified":"2026-02-04T03:10:26","modified_gmt":"2026-02-04T08:10:26","slug":"compliance-doesnt-equal-security-but-what-if-it-does","status":"publish","type":"post","link":"https:\/\/centricconsulting.com\/blog\/compliance-doesnt-equal-security-but-what-if-it-does\/","title":{"rendered":"Compliance Doesn&#8217;t Equal Security, But What If It Does?"},"content":{"rendered":"<h2 style=\"text-align: center;\">In this segment of Shane O\u2019Donnell\u2019s Forbes Technology Council column, Shane talks about how compliance mandates are important for establishing cybersecurity within industries that underinvest in critical protections.<\/h2>\n<p>&#8220;Compliance doesn&#8217;t equal security&#8221; has become something of a rallying cry in cybersecurity circles.<\/p>\n<p>Security professionals have long argued that checking regulatory boxes doesn&#8217;t guarantee actual protection against threats. It&#8217;s a valid concern. Organizations can be fully compliant and still vulnerable to sophisticated attacks.<\/p>\n<p>But I&#8217;ve been questioning this conventional wisdom, particularly as I&#8217;ve watched industries struggle with persistent underinvestment in cybersecurity. The topic came into focus when I served as a panelist discussing cyber resiliency at the International Gaming Standards Association&#8217;s Technical Summit in Phoenix.<\/p>\n<p>What if, for industries that have historically underinvested in cybersecurity, compliance mandates are the forcing function they need? Regulation, despite its limitations, is better than nothing at all.<\/p>\n<p>Across multiple sectors, from gaming and hospitality to manufacturing and supply chain operations, cybersecurity has often taken a back seat to other business priorities. These industries operate complex digital ecosystems but lack the regulatory pressure that has driven security improvements in healthcare, financial services and critical infrastructure.<\/p>\n<p>The gaming industry offers a particularly compelling case study in what happens when an unregulated sector faces mandatory cybersecurity requirements.<\/p>\n<h2 class=\"subhead-embed\">Gaming&#8217;s Cybersecurity Gap<\/h2>\n<p>For years, casinos and gaming operations have focused heavily on physical security, while digital protections have lagged behind.<\/p>\n<p>Then came the high-profile attacks: MGM Resorts <a href=\"https:\/\/edition.cnn.com\/2023\/10\/05\/business\/mgm-100-million-hit-data-breach\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/edition.cnn.com\/2023\/10\/05\/business\/mgm-100-million-hit-data-breach\" aria-label=\"suffered an estimated $100 million in losses\">suffered an estimated $100 million in losses<\/a> from a September 2023 ransomware attack, while Caesars Entertainment reportedly <a href=\"https:\/\/www.cnbc.com\/2023\/09\/14\/caesars-paid-millions-in-ransom-to-cybercrime-group-prior-to-mgm-hack.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cnbc.com\/2023\/09\/14\/caesars-paid-millions-in-ransom-to-cybercrime-group-prior-to-mgm-hack.html\" aria-label=\"paid $15 million to hackers\">paid $15 million to hackers<\/a>. International Game Technology, a major <a href=\"https:\/\/www.cybersecuritydive.com\/news\/international-game-technology-cyberattack\/733899\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cybersecuritydive.com\/news\/international-game-technology-cyberattack\/733899\/\" aria-label=\"gambling technology vendor\">gambling technology vendor<\/a>, was hit in November 2024.<\/p>\n<p>These incidents indicated that the industry wasn&#8217;t prioritizing modern cyber threats.<\/p>\n<p>The gaming sector&#8217;s vulnerability stems from its unique characteristics. Casinos operate sprawling networks of interconnected systems spanning gaming floors, hotels, payment terminals and entertainment venues. Each connection point represents a potential entry for attackers, and legacy systems built on antiquated technology compound the problem.<\/p>\n<p>According to <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ransomware-targets-casinos-fbi\/699313\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cybersecuritydive.com\/news\/ransomware-targets-casinos-fbi\/699313\/\" aria-label=\"FBI warnings\">FBI warnings<\/a>, ransomware groups target the gaming industry by exploiting vendor-controlled remote access systems. The attacks disrupt gambling payouts and hotel check-ins and compromise customer data.<\/p>\n<p>With the American Gaming Association reporting that casino gaming <a href=\"https:\/\/www.americangaming.org\/gaming-industry-delivers-329-billion-annual-economic-impact-to-u-s-economy-new-aga-study-finds\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.americangaming.org\/gaming-industry-delivers-329-billion-annual-economic-impact-to-u-s-economy-new-aga-study-finds\/\" aria-label=\"contributes nearly $329 billion annually\">contributes nearly $329 billion annually<\/a> to the U.S. economy, the financial stakes for protecting this industry are enormous.<\/p>\n<h2 class=\"subhead-embed\">The Compliance Paradox<\/h2>\n<p>This is where the compliance paradox becomes clear. Compliance alone doesn&#8217;t guarantee security, but for industries where cybersecurity has been consistently underfunded and deprioritized, regulatory mandates create accountability and force minimum standards.<\/p>\n<p>Gaming companies that might have continued operating with insufficient protections now face regulatory requirements they cannot ignore. Compliance demands drive budget allocation, executive attention and operational changes that might never have occurred otherwise.<\/p>\n<p>Gaming organizations must implement monitoring systems, patch management processes and incident response plans. They must designate responsible parties and demonstrate ongoing vigilance.<\/p>\n<p>The alternative, no regulation, has proven inadequate. Despite the 2023 attacks making headlines, cybersecurity experts noted at the Global Gaming Expo in October 2024 that the industry still isn&#8217;t investing sufficiently in IT and security. Voluntary best practices failed to create widespread change. Mandatory compliance, while imperfect, establishes a baseline that moves the entire industry forward.<\/p>\n<h2 class=\"subhead-embed\">A Pattern Across Industries<\/h2>\n<p>The pattern extends beyond gaming. Consider manufacturing operations that depend on interconnected industrial control systems or supply chain networks managing sensitive data across dozens of partners.<\/p>\n<p>These sectors lack comprehensive cybersecurity regulations and face similar challenges, including budget constraints, competing priorities and vulnerability to cyberattacks. Like gaming before recent regulatory developments, they&#8217;re operating in a gap where market forces alone haven&#8217;t driven adequate security investment.<\/p>\n<p>Healthcare adopted structured security practices and breach notification requirements after HIPAA established mandatory protections for patient data. Financial services strengthened controls to meet PCI DSS requirements for payment card information. Critical infrastructure operators are enhancing defenses to comply with new <a href=\"https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/information-sharing\/cyber-incident-reporting-critical-infrastructure-act-2022-circia\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/information-sharing\/cyber-incident-reporting-critical-infrastructure-act-2022-circia\" aria-label=\"incident reporting mandates\">incident reporting mandates<\/a>. In each case, regulation provided the impetus that voluntary measures failed to achieve.<\/p>\n<p>Each regulatory framework has limitations, and compliance can become a checkbox exercise where organizations meet technical requirements while missing the spirit of protection. But industries without regulatory pressure often fail to self-regulate on cybersecurity, particularly when security investments compete with other business priorities.<\/p>\n<h2 class=\"subhead-embed\">New Regulations Forcing Change<\/h2>\n<p>Now, new cybersecurity regulations are emerging that will fundamentally change how gaming companies approach digital security. The EU&#8217;s <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/nis2-directive\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/nis2-directive\" aria-label=\"NIS2 Directive\">NIS2 Directive<\/a> and <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\" aria-label=\"Cyber Resilience Act\">Cyber Resilience Act<\/a> both potentially bring gaming operations within the scope of mandatory cybersecurity requirements. These regulations mandate secure-by-design principles, vulnerability management, incident reporting and ongoing security updates throughout product life cycles.<\/p>\n<p>The industry is also developing its own standards to fill the cybersecurity gap. Gaming Laboratories International recently released its Gaming Security Framework (<a href=\"https:\/\/gaminglabs.com\/press-releases\/gaming-laboratories-international-gli-releases-three-new-modules-and-one-updated-module-of-its-gaming-security-framework\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/gaminglabs.com\/press-releases\/gaming-laboratories-international-gli-releases-three-new-modules-and-one-updated-module-of-its-gaming-security-framework\/\" aria-label=\"GLI-GSF\">GLI-GSF<\/a>), the first and only gaming information security standard to date.<\/p>\n<p>This framework addresses the cybersecurity gap in the gaming industry. Created through collaboration with thousands of gaming industry stakeholders, GLI-GSF provides baseline security guidelines that regulators can adopt and gaming organizations can use to enhance security across all operations.<\/p>\n<h2 class=\"subhead-embed\">Making Compliance Work<\/h2>\n<p>The key is recognizing compliance for what it is: a starting point, not a destination. Organizations that treat regulatory requirements as minimum thresholds while building mature security programs beyond compliance can achieve the best outcomes. They use compliance as the business justification to secure resources, then apply those resources strategically.<\/p>\n<p>This approach requires leadership commitment beyond rule-following. It means investing in security expertise, implementing defense-in-depth strategies and fostering a culture where security is everyone&#8217;s responsibility. Compliance provides the framework and accountability, but organizations must build the substance.<\/p>\n<p>Compliance does not inherently equal security, but in industries where security investments have been insufficient, compliance creates the forcing function that drives improvement. It establishes accountability, mandates minimum standards and ensures that cybersecurity receives the attention and resources it deserves.<\/p>\n<p>The gaming industry&#8217;s experience demonstrates this reality. New regulations won&#8217;t solve every security challenge, but they will compel organizations to implement protections they should have deployed years ago.<\/p>\n<p><em><a href=\"https:\/\/www.forbes.com\/councils\/forbestechcouncil\/2026\/01\/20\/compliance-doesnt-equal-security-but-what-if-it-does\/\" target=\"_blank\" rel=\"noopener\">This article was originally published on Forbes.com<\/a><\/em>.<\/p>\n\n        <div class=\"inline-cta blue\">\n            <div class=\"inline-cta--content\">\n                Build a resilient cyber team with the right mix of internal talent and external expertise \u2014 without the burnout or blown-out budget.\n            <\/div>\n            <div class=\"inline-cta--button\">\n                <a\n                    class=\"button\"\n                    href=\"https:\/\/centricconsulting.com\/resources\/cyber-expertise-at-scale-your-playbook-for-scoring-an-all-star-team_cyber\/\"\n                    target=\"_blank\"\n                    >\n\n                    Download the Playbook\n                <\/a>\n            <\/div>\n        <\/div>\n<p style=\"text-align: center;\"><em>You know you need to protect your brand and financial stability by prioritizing cybersecurity. But do you know where to start? Our <a href=\"https:\/\/centricconsulting.com\/technology-solutions\/cybersecurity-consulting-services\/\">Cybersecurity team<\/a> is ready to help you focus on everything from strategy development to penetration testing.<\/em><\/p>\n<p style=\"text-align: center;\"><a class=\"button-text\" href=\"https:\/\/centricconsulting.com\/contact-webless\/\">Let\u2019s talk<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this segment of Shane O\u2019Donnell\u2019s Forbes Technology Council column, learn how compliance mandates help establish security.<\/p>\n","protected":false},"author":456,"featured_media":60710,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","footnotes":""},"categories":[1],"tags":[23785],"coauthors":[23762],"class_list":["post-60708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cybersecurity","resource-categories-perspectives","orbitmedia_post_topic-cybersecurity"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-04-14 07:30:42","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/posts\/60708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/users\/456"}],"replies":[{"embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/comments?post=60708"}],"version-history":[{"count":2,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/posts\/60708\/revisions"}],"predecessor-version":[{"id":60712,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/posts\/60708\/revisions\/60712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/media\/60710"}],"wp:attachment":[{"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/media?parent=60708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/categories?post=60708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/tags?post=60708"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/centricconsulting.com\/wp-json\/wp\/v2\/coauthors?post=60708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}