MGM, Caesars Face Regulatory, Legal Maze After Cyber Incidents
MGM and Caesars are putting new SEC incident disclosure regulations to a real-world test in the aftermath of twin cyberattacks on the casinos, as class-action lawsuits loom.
4 Min Read
Alamy
This article originally appeared on Dark Reading.
In the wake of the new Securities and Exchange Commission (SEC) regulatory requirements to disclose "material" cyber incidents within four days of discovery, the dual cyber breaches of MGM Resorts and Caesars Entertainment have demonstrated how differently those rules can be interpreted.
Both breaches resulted from abuse of an Okta Agent, and both were reportedly carried out by the same ransomware threat actor. Both occurred within days of one another. But how each organization handled the new SEC disclosure rules