The Problem
Ask a board what a ransomware attack costs, and the answer that comes back first is almost always the ransom figure, as if the whole event were a single negotiation with a single price tag at the end. That framing is understandable, since the ransom demand is the one number a criminal group actually puts in front of the organisation, and it lands with the kind of drama that concentrates minds in a crisis meeting. But it is also the least useful number for planning purposes, because for a casino, a sportsbook, or an online operator, the ransom is frequently the smallest line item in the eventual bill, given how much of a gambling business’s revenue depends on systems staying live minute by minute, whether that is a slot floor that cannot pay out, a cage that cannot process a marker, or a player account system that locks out real money balances. Once a board treats the ransom as the headline cost, it under-budgets for everything that happens afterwards, and that gap gets worse for an operator holding licences in more than one jurisdiction, because the notification duty that follows a breach is not one rule but several, running on different clocks, to different regulators, with different penalties attached.
How It Actually Works
The two clearest illustrations sit next to each other on the calendar, because MGM Resorts and Caesars Entertainment were both hit by the same crew, ALPHV/Scattered Spider, within days of one another in September 2023, and made opposite decisions on the ransom, which is why the pair is so useful for a cost breakdown. Caesars reportedly paid around $ 15 million against an initial $ 30 million demand, according to CNBC reporting, citing people familiar with the matter, which disclosed the incident as a material event in an SEC filing. MGM refused to pay, and the operational consequences showed up immediately, as slot machines, digital room keys, and loyalty programme tools went down across its Las Vegas properties for more than a week, with September occupancy on the Strip falling to 88 per cent against 93 per cent the year before. MGM later disclosed, in an SEC filing reported by CDC Gaming Reports among others, that it expected a 100 million dollar hit to adjusted property EBITDAR for the third quarter of 2023, alongside under 10 million dollars in one-time costs for technology consulting, legal fees, and third-party advisors. That is already three cost categories: downtime, forensic and legal cleanup, and insurance interaction, and none of them is the ransom. The bill kept growing well past the quarter of the attack, and in January 2025 MGM agreed to a 45 million dollar settlement covering more than 37 million affected customers across its 2019 and 2023 breaches combined, as reported by TechCrunch and confirmed in court filings, with roughly 13.5 million dollars of that settlement going to attorney fees alone.
What that US case does not show, because MGM’s exposure ran through American state law rather than a single national regime, is what the same attack would cost in notification terms for an operator licensed in the UK or the EU. In the US there is no single federal data breach law, so every state, plus DC and several territories, sets its own notification rule, and while all require telling affected residents without unreasonable delay, the concrete deadlines where they exist range across 30, 45, or 60 days, with some states also requiring separate notice to the state attorney general and others triggering only above a minimum number of affected residents, according to a summary of the patchwork from the law firm Jackson Lewis. A UK- or EU-licensed operator faces a tighter, more unified clock but two regulators to satisfy at once, rather than dozens. Under UK GDPR, a breach likely to risk people’s rights and freedoms must be reported to the Information Commissioner’s Office within 72 hours of the operator becoming aware of it, and affected individuals must be told directly and without undue delay if the risk to them is high, according to the ICO’s own guidance, which sets a fine of up to 8.7 million pounds or 2 percent of global annual turnover for failing to notify within that window, a separate offence from the underlying breach itself. On top of that, a UK Gambling Commission licensee carries its own, independent duty under LCCP condition 15.2.1 to report any security breach that affects the confidentiality of customer data or that locks customers or staff out of their accounts for more than 12 hours, as a Key Event submitted as soon as reasonably practicable and within five working days. A UK operator hit by the same crew as MGM would be running the ICO’s 72-hour clock and the Commission’s five working-day clock at once, against two regulators who can each act independently on the same facts, a genuinely different exposure from a US operator working through a state-by-state disclosure list with no gambling-specific breach duty attached to most of those states at all.
A Practical Way In
A board’s incident response budget, and its cyber insurance conversation, should name these categories explicitly rather than lumping everything under one “cyber incident” reserve, because each has a different owner, timeline, and trigger.
– Operational continuity: the revenue lost per hour or per day that core systems (payments, slot floors, sportsbook settlement, player accounts) are down, modelled against your actual peak trading hours rather than an average day.
– Forensics, legal, and technical remediation: the outside counsel, incident response firm, and system rebuild costs that start on day one, regardless of whether a ransom is ever discussed.
– Jurisdiction-mapped notification: a pre-built table of every licence you hold against its own regulator, clock, and recipient, so a UK operator is not discovering the 72-hour ICO deadline and the five-working-day LCCP deadline mid-incident, and a US operator is not assuming one disclosure letter satisfies every state on its list.
– Litigation and regulatory exposure: a reserve for class action settlement and defence costs, and separately for any penalty a gaming or data protection regulator might impose for inadequate controls, since these can land years later and from more than one regulator on the same breach.
– The ransom decision itself, pre-agreed: who has authority to approve a payment, on what evidence, and how that interacts with the insurance policy, because deciding this mid-crisis is slower than deciding it in advance, and paying a criminal group removes no notification duty owed to customers or regulators.
That list is deliberately not exhaustive, but it moves the conversation past “would we pay” and into “what does the full 12 months after the attack actually cost us, in every jurisdiction we are licensed in.”
Where This Goes Deeper
Mapping those five categories against your own systems, your own peak trading hours, and your own regulatory footprint across every licence you hold, not just the one your head office sits under, is where this stops being a general explainer and starts being a working budget, and that is the kind of detail our members work through with us directly.
Sources
1. CDC Gaming Reports, ‘SEC filing by MGM: Cyberattack will cost $100 million in adjusted earnings’, 5 October 2023, https://cdcgaming.com/sec-filing-by-mgm-cyberattack-will-cost-100-million-in-adjusted-earnings/
2. CNBC, ‘Caesars paid millions in ransom to cybercrime group prior to MGM hack’, 14 September 2023, https://www.cnbc.com/2023/09/14/caesars-paid-millions-in-ransom-to-cybercrime-group-prior-to-mgm-hack.html
3. TechCrunch, ‘MGM Resorts settles lawsuits after millions of customer records stolen in data breaches’, 29 January 2025, https://techcrunch.com/2025/01/29/mgm-resorts-settles-lawsuits-after-millions-of-customer-records-stolen-in-data-breaches/
4. Information Commissioner’s Office, ‘Personal data breaches: a guide’, https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
5. UK Gambling Commission, ‘Notification of information security breaches’, https://www.gamblingcommission.gov.uk/licensees-and-businesses/guide/notification-of-information-security-breaches
6. UK Gambling Commission, ‘LCCP Condition 15.2.1: Reporting key events’, https://www.gamblingcommission.gov.uk/licensees-and-businesses/lccp/condition/15-2-1-reporting-key-events
7. Jackson Lewis, ‘State Data Breach Notification Laws: Overview of the Patchwork’, https://www.jacksonlewis.com/insights/state-data-breach-notification-laws-overview-patchwork