Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

A Tale of Two Disclosures: SEC Cyber Filings from MGM and Caesars After Their Recent Hacks

Posted on September 20, 2023September 20, 2023 By Mark Sauter

We’ve written extensively about the SEC regulations requiring public companies to disclose material cyber events (see full regs and legal analysis of it here.) Analysis of the legal and business ramifications of the disclosure regime have raised a number of issues, including potential conflicts between the cyber and D&O or other policies of insureds hit by reportable hacks.

Another issue sure to arise is the level of detailed required in the 8K disclosures. Compare and contrast the disclosures of MGM Resorts and Caesars Entertainment, Inc., both gambling and hospitality companies hit around the same time by attacks attributed to the Okta penetration.

MGM’s disclosure is in essence a vague one-paragraph press release. Caesars’ is far more detailed, includes an apology and help-line for impacted customers and even alludes to an ransomware payment (see bold below).

We wonder if litigation and/or regulatory action around these hacks may include complaints of inadequate disclosure. We’re also interested in whether the companies issue additional 8Ks, or consider they’ve met the cyber disclosure requirement and communicate from here on via press releases and normal, scheduled regulatory filings.

MGM Resorts 8K disclosure on 9/13/23: The 8K simply links to a press release, which reads:

“Las Vegas, September 12, 2023 – MGM Resorts International (the “Company” or “MGM Resorts”) today issued the following statement: MGM Resorts recently identified a cybersecurity issue affecting certain of the Company’s systems. Promptly after detecting the issue, we began an investigation with assistance from leading external cybersecurity experts. We also notified law enforcement and are taking steps to protect our systems and data, including shutting down certain systems. Our investigation is ongoing, and we are working diligently to resolve the matter. The Company will continue to implement measures to secure its business operations and take additional steps as appropriate.”

See also  Falcon Risk Services Introduces FalconFlight: Cyber and Professional Liability Insurance

Caesar’s 8K disclosure on 9/14/23: “Caesars Entertainment, Inc. (the “Company,” “we,” or “our”) recently identified suspicious activity in its information technology network resulting from a social engineering attack on an outsourced IT support vendor used by the Company. Our customer-facing operations, including our physical properties and our online and mobile gaming applications, have not been impacted by this incident and continue without disruption.

After detecting the suspicious activity, we quickly activated our incident response protocols and implemented a series of containment and remediation measures to reinforce the security of our information technology network. We also launched an investigation, engaged leading cybersecurity firms to assist, and notified law enforcement and state gaming regulators. As a result of our investigation, on September 7, 2023, we determined that the unauthorized actor acquired a copy of, among other data, our loyalty program database, which includes driver’s license numbers and/or social security numbers for a significant number of members in the database. We are still investigating the extent of any additional personal or otherwise sensitive information contained in the files acquired by the unauthorized actor. We have no evidence to date that any member passwords/PINs, bank account information, or payment card information (PCI) were acquired by the unauthorized actor.

We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result (Cyber Insurance News bold highlighting.) We are monitoring the web and have not seen any evidence that the data has been further shared, published, or otherwise misused. Nonetheless, out of an abundance of caution, we are offering credit monitoring and identity theft protection services to all members of our loyalty program. To sign up for these services, members may call (888) 652-1580 from 9:00 a.m. to 9:00 p.m. Eastern Time, Monday through Friday other than holidays.

See also  Ramping Cyber Insurance Premiums Help Hiscox Hit Profitability in H1 2021 

Additionally, we will be notifying individuals affected by this incident consistent with our legal obligations. These notifications will be made on a rolling basis in the coming weeks. In the meantime, individuals with questions may contact the dedicated incident response line we have established to address questions about this incident, which can be reached at (888) 652-1580 from 9:00 a.m. to 9:00 p.m. Eastern Time, Monday through Friday other than holidays.

While no company can ever eliminate the risk of a cyberattack, we believe we have taken appropriate steps, working with industry-leading third-party IT advisors, to harden our systems to protect against future incidents. These efforts are ongoing. We have also taken steps to ensure that the specific outsourced IT support vendor involved in this matter has implemented corrective measures to protect against future attacks that could pose a threat to our systems.

We have incurred, and may continue to incur, certain expenses related to this attack, including expenses to respond to, remediate and investigate this matter. The full scope of the costs and related impacts of this incident, including the extent to which these costs will be offset by our cybersecurity insurance or potential indemnification claims against third parties, has not been determined. Although we are unable to predict the full impact of this incident on guest behavior in the future, including whether a change in our guests’ behavior could negatively impact our financial condition and results of operations on an ongoing basis, we currently do not expect that it will have a material effect on the Company’s financial condition and results of operations.

The trust of our valued guests and members is deeply important to us, and we regret any concern or inconvenience this may cause.

See also  What Companies Need to Know About the SEC's New Cybersecurity Rules: Reports & Analysis

For additional information, please visit https://response.idx.us/caesars. Information set forth on that website is not incorporated herein by reference.”

Cyber Insurance, Cyber Insurance Best Practices, Cyber Insurance Laws & Regulations Tags:Caesars, cyber disclosure 8K, MGM, SEC Cyber Regulations

Post navigation

Previous Post: Potential Insurance Conflicts Exposed by New SEC Cybersecurity Reporting Rules
Next Post: New SEC Rules: Impact on Cyber Insurance Industry

Related Posts

  • New York State Mulls Groundbreaking Cybersecurity Regulations for Hospitals Cyber Insurance Laws & Regulations
  • Must Read: Skeptical Analysis of a Potential Federal Cyber Insurance Backstop, From Lawfare Cyber Insurance Best Practices
  • Onda Launches Onda X Cyber Insurance for Mid-Market Companies in the UK and France Cyber Insurance
  • Time for a “Parametric Approach” to Cyber Insurance?  Cyber Insurance Best Practices
  • Zurich’s Defeat in Court is Win for Companies Seeking to Cover Cyber Insurance Deductibles with 3rd Party Payments  Cyber Insurance Carriers & Brokers
  • Cyber Insurance Sunday – Upload Cyber Insurance

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In this clip from Episode #EP-6 of Cyber Insurance News Podcast, host Martin Hinton is joined by guest Dan Candee, CEO of Cork Protection, to break down the often-confusing acronyms MSP (Managed Service Provider) and MSSP (Managed Security Service Provider).

🔍 Dan explains how these service providers play a crucial role in modern business — supporting IT infrastructure, cybersecurity, cloud services, and more — in a clear, relatable way.

👨‍💻 Whether you're a small business owner, entrepreneur, or just trying to make sense of cybersecurity, this clip offers valuable insights into how to secure your business with the right tech partners.

✅ Topics Covered:

What MSPs and MSSPs really do

Cybersecurity made simple with real-world analogies

Why modern businesses rely on managed service providers

Protecting your data, brand, and reputation

🎧 Subscribe for more expert insights into cybersecurity, tech, and cyber insurance trends.

#CyberSecurity #MSP #MSSP #SmallBusinessTech #CyberInsurance #CyberRisk #ManagedServiceProvider #BusinessSecurity #CorkProtection #DanCandee #CyberProtection #TechSimplified
Cybersecurity for Small Business - MSP vs MSSP Explained | Dan Candee Simplifies A Jargon-Rich Space
In this clip from our latest podcast, Dan Candee, CEO of Cork Protection, discusses a critical component of SMB cyber resilience—the evolving role of cybersecurity insurance. Dan highlights the need for nimbleness in cyber coverage, especially for small businesses that often bear the brunt of devastating attacks.

💬 Quote Highlight:
"At the end of the day, my business is to serve the SMB market... who is providing the most value fastest." – Dan Candee, CEO Cork Protection.

#CyberResilience, #CyberSecurity, #SmallBusinessSecurity, #SMBProtection, #DigitalSafety, #CyberInsurance, #InsurTech, #MSPCommunity, #TechForSMBs, #CyberThreats, #DanCandee, #CorkProtection, #PodcastClip, #CybersecurityPodcast, #FastResponseInsurance, #BusinessTips, #EntrepreneurAdvice, #TechTalks, #DataProtection, #InsuranceTrends
Cyber Insurance for SMBs – What Needs to Change? | Dan Candee Interview
In this clip from our latest podcast episode, Dan Candee, CEO of Cork Protection, dives into a critical topic that hits close to home: Cybersecurity for Main Street businesses.

🛡️ With a background in enterprise-level cybersecurity on Wall Street and a personal connection to small business through his family, Dan shares why Cork focuses on protecting small and mid-sized businesses from rising cyber threats.

🚨 "The threat actors are getting better, and they're coming after Main Street more and more."

👉 Discover why Main Street is being underserved in today's digital threat landscape and how Cork is filling that gap with a unique value proposition.

🔗 Learn more about Cork: corkinc.com
🎧 Full Podcast Episode: www.youtube.com/@CyberInsuranceNews/podcasts

📣 Don't forget to LIKE, SUBSCRIBE, and hit the 🔔 notification bell so you never miss a powerful conversation.

#Cybersecurity #SmallBusiness #MainStreet #DanCandee #CorkProtection #TechForGood #SMBs #PodcastClip #CyberThreats #BusinessSecurity
Cybersecurity for Main Street: Dan Candee on Protecting Small Businesses | CEO of Cork Protection
Load More... Subscribe

Categories

  • 8-K
  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • Cybersecurity Law
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI AI in Cybersecurity Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime CyberCube cyber insurace cyber insurance cyberinsurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyberliabilityinsurance cyber liability insurance Cyber Resilience Cyber Risk Cyber Risk Management Cybersecurity cyber security cybersecurity insurance Cyber threats Data Breach Data Breaches Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • CatX and CyberCube Partner to Enhance Cyber Risk Analytics Cyber Insurance Carriers & Brokers
    • Cyberattacks on Schools: Why Educational Institutions Are Prime Targets – KnowBe4 Report Cyber Insurance
    • Ransomware Claims Jump in Q1 2023: Marsh  Cyber Insurance Carriers & Brokers
    • Blumira & Beltex: Strengthening MSPs’ Cyber Insurance Offerings & Client Security Cyber Insurance for SMEs/SMBs
    • Cybersecurity Made Easy: Affordable Insurance Solutions for SMEs Under $50 Million Cyber Insurance for SMEs/SMBs
    • Cyber Insurer Envelop Launches Strategic SPA 1925 in Lloyd’s Collaboration with Apollo Cyber Insurance
    • Chubb and SentinelOne Join Forces Cyber Insurance Carriers & Brokers
    • AI to Increase Cyber Attacks Until Countermeasures Catch Up Over Next 2 Years: Lloyd’s Report Cyber Insurance

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme