— By Craig Lusher, Principal Solutions Architect at Continent 8 Technologies 

This blog looks at why security investment so often stalls, and how Continent 8 Technologies’ new Loyalty+ programme is designed to give eligible customers a clearer route to strengthening their cyber resilience. 

Craig Lusher

Most organisations already know their security could be better. Far fewer have an obvious route to getting there. 

That gap is rarely about awareness. In iGaming and online sports betting, security sits on board agendas, in supplier contracts and under regulatory scrutiny. The difficulty is more practical. Security work competes for budget against everything else a business needs to fund, and the case for spending money on a problem that has not happened yet is always harder to make than the case for spending it on one that has. 

The evidence has not made that argument any easier to win. Verizon’s 2026 Data Breach Investigations Report analysed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. It found third parties involved in 48% of breaches, a 60% rise year on year, and recorded exploitation of vulnerabilities overtaking stolen credentials as the most common way into an organisation for the first time in 19 years, accounting for 31% of breaches against 13% for credentials. Remediation is not keeping pace: only 26% of the vulnerabilities in CISA’s Known Exploited Vulnerabilities catalogue were fully patched during 2025, with a median remediation time of 43 days. 

The cost when something does go wrong has climbed as well. IBM’s 2026 Cost of a Data Breach Report puts the global average at $4.99 million, up 12% on the previous year. More than a quarter of organisations hit by a malicious attack said it was AI-driven, and those incidents added around $1 million each to the total. Downtime carries a separate bill. ITIC’s research into the hourly cost of downtime found that more than 90% of mid-size and large enterprises lose over $300,000 for every hour of outage, with 41% putting their exposure between $1 million and more than $5 million an hour. 

For a sector built on interconnected platforms, specialist suppliers and always-on services, the third-party and downtime figures tend to be the ones that land hardest. 

Why security investment stalls 

In practice, security spend is often triggered by something external. A regulator asks a question, a customer sends a security questionnaire, a penetration test result lands, or an incident forces the issue. Each of those produces a purchase, but not necessarily a plan. 

The result is familiar. Controls accumulate one at a time, chosen to answer whichever question was being asked at the time, and the joins between them are rarely revisited. Meanwhile the work that has no immediate trigger, such as testing an application nobody has looked at for two years, running a phishing simulation, or checking whether your brand is being spoofed somewhere, keeps sliding down the list because nothing is forcing it up. 

None of this reflects badly on the teams involved. It reflects how budgets work. Money that is already committed to infrastructure is easier to defend than money that has to be found for something optional. 

What Loyalty+ does 

Loyalty+ is Continent 8’s new security credits programme. Eligible contracts are automatically enrolled in the Loyalty+ programme, enabling customers to earn security credits worth 5% of the Total Contract Value (TCV) of invoiced Continent 8 spend. These credits can then be redeemed against our qualifying cybersecurity services. 

One credit is worth one US dollar when it is redeemed, so there is no conversion to work out and no ambiguity about what a balance is worth. There is nothing to buy and no sign-up process. If you have new invoiced spend with us, you earn credits automatically under the programme terms. 

For contracts of twelve months or longer, the credits for the whole term are granted when you sign, rather than trickling in month by month. A customer on $20,000 a month across cloud and colocation, signing a 24-month term, has 24,000 credits available from day one, worth $24,000 against security services. 

The practical effect is that the security work which normally waits for a trigger already has funding attached to it before the trigger arrives. 

Credits can only be redeemed against Continent 8 security services, within that, the choice is entirely yours. If you already have a supplier for penetration testing, direct your balance somewhere else. If you want to trial a service before committing budget to it, credits let you do that without a business case. 

What you can redeem against 

The catalogue covers two broad groups: one-time engagements, such as VAPTs and Audits and ongoing solutions, such as MSOC (Managed Security Operations Centre), EDR and MDR services, Threat Exchange, the SafeBait platform and dark web monitoring. 

You can pay part in credits and part in cash, so a balance that does not quite cover a piece of work is still useful. The minimum redemption is 250 credits. Subscriptions funded with credits carry a minimum twelve-month commitment, and continue at the standard rate afterwards unless you cancel. Your Account Manager holds the current credit price of each service and can arrange redemptions, though some engagements, penetration testing in particular, need scheduling and take a few weeks to organise. 

The rules worth knowing 

Credits expire twelve months after they are granted. When you redeem, the oldest credits in your balance are used first, so your more recent credits keep their full validity. We aim to remind you around 60 days and again around 30 days before anything is due to expire. 

When you renew a contract, you receive a fresh allocation for the new term, any unused credits carry over, and the expiry clock resets from the renewal date. If you end all of your Continent 8 services, you have 90 days from your final service ending to redeem what remains. 

Credits have no cash value. They cannot be exchanged for money or account credit, transferred to another customer, applied to non-security services, or refunded. The programme is offered at our discretion and the full terms are available from your Account Manager. 

We should also say what Loyalty+ is not. It does not make an organisation secure, and no programme of this kind could. It funds work that we think is worth doing, and the value of that work depends entirely on what you choose to do with the findings. 

Where this goes next 

The version launching now is deliberately simple. Every customer earns at the same 5% rate, and the mechanics are kept easy to explain. 

Continent 8 has been protecting the iGaming and online sports betting industry for decades. In a sector where one organisation’s exposure can reach across connected platforms, suppliers and players, we have a direct interest in the security maturity of the businesses we work with, not only our own. Loyalty+ is one attempt to act on that. 

For eligible Continent 8 customers, it turns spend you have already committed into security work you might otherwise have deferred. To find out what your balance could be, speak to your Account Manager or visit https://www.continent8.com/loyalty. T&Cs apply https://www.continent8.com/loyalty-tc/. 

In the iGaming industry, cybersecurity is not just about protection – it’s about uptime, regulatory compliance, and player trust.

Vulnerability Assessment and Penetration Testing (VAPT) plays a critical role in achieving those outcomes. Yet too often, the service operators and suppliers receive fails to deliver meaningful value.

Across the iGaming industry, we consistently hear the same frustrations. These aren’t minor issues – they represent gaps that can directly impact resilience, compliance, and revenue.

Here are the eight most common complaints – and what iGaming organisations should really expect instead.

  1. “The reports don’t translate into business risk”

This is one of the biggest challenges. Many VAPT reports focus heavily on technical scoring systems without explaining what the findings actually mean in an operational context.

The reality is that iGaming organisations need to understand how vulnerabilities affect player data, wallet integrity, and platform availability – not just their severity rating.

At Continent 8, we frame every finding in terms of real-world impact, linking vulnerabilities directly to risks such as player account compromise, payment exposure, or downtime during peak events – ensuring both technical and non-technical stakeholders can take action.

  1. “We get a list of vulnerabilities – but no clear next steps”

A long list of issues without clear direction often creates more confusion than clarity – particularly in complex, high-availability environments.

The reality is that operators need practical, prioritised guidance that can be implemented without introducing risk or disrupting services.

That’s why our approach focuses on:

  1. “It feels like a compliance checkbox exercise”

Too many VAPT engagements are carried out purely to tick a regulatory box, resulting in limited depth and minimal real-world value.

The reality is that attackers don’t work to compliance frameworks – they exploit weaknesses in real time.

That’s why we take a threat-led approach, focusing on:

We help customers move beyond compliance towards genuine resilience.

  1. “There’s no alignment with uptime-critical environments”

In iGaming, downtime isn’t just inconvenient – it directly impacts revenue and player trust, especially during major sporting events. We calculate that the average cost per minute for an operator during downing is $6K!

The reality is that security testing must work around operational priorities, not against them.

That’s why our engagements are designed to:

Security should strengthen availability – not risk it.

  1. “Communication is limited during testing”

A lack of communication during VAPT engagements often leaves organisations uncertain about progress, findings, and potential risks. The reality is that testing should be a collaborative process, particularly in regulated environments where transparency matters.

Our approach ensures:

This gives customers greater visibility – and faster resolution of critical issues.

  1. “There’s no retesting or validation”

Fixing vulnerabilities is only part of the process. Without validation, organisations can’t be confident the risk has been fully addressed – or demonstrate that to regulators.

The reality is that verification is essential for both security assurance and compliance.

That’s why we include:

  1. “The provider doesn’t understand iGaming architecture”

iGaming environments are highly specialised, with complex integrations across platforms, wallets, APIs, and multi-jurisdiction infrastructure.

The reality is that generic testing approaches often miss the most critical risks.

At Continent 8, our deep experience (28+ years) in the sector means we understand:

This allows us to deliver relevant, targeted testing aligned to real-world environments.

  1. “It’s a one-off test in a constantly evolving environment”

Many organisations still rely on periodic testing, despite operating in a landscape where platforms and threats evolve continuously.

The reality is that a once-a-year test cannot provide meaningful assurance in a dynamic iGaming ecosystem. You need a long-term partner, not a one-off vendor.

That’s why we position VAPT as part of a continuous security lifecycle, including:

Final thoughts

In iGaming, the stakes are uniquely high. Security failures don’t just create risk – they can impact revenue, compliance, and player trust in real time.

VAPT should not be treated as a standalone exercise, but as a strategic capability that evolves alongside your platform.

At Continent 8, we’ve built our approach around what iGaming organisations actually need:

Because in iGaming, it’s not just about identifying vulnerabilities – it’s about ensuring your platform remains secure, resilient, and always available.

And we’re proud to be trusted by some of the biggest names in the industry, including: TheScore, NeoGames, Hard Rock, ODDSworks and more.

Thinking of switching providers? Experience a better standard of VAPT – without the switching risk.

If you’re considering replacing your current provider, we offer 25% off your first VAPT engagement* (based on our standard pricing), so you can properly evaluate a more effective approach. Learn more here

*T&Cs apply

Our Chief Transformation Officer, Anthony Abou-Jaoude, comments on how AI signals a shift towards faster, more autonomous cyber capability – and why iGaming companies must respond with greater resilience and visibility.

Artificial Intelligence (AI) is evolving at an unprecedented pace, transforming both how cyber criminals operate and how organisations defend themselves. As AI models become more capable, the speed of vulnerability discovery, reconnaissance, phishing and attack preparation is increasing, changing the economics of cyber attacks and reducing the time defenders have to respond.

Recent developments such as Anthropic’s Claude Mythos, alongside a wider wave of AI-driven cybersecurity initiatives, have highlighted just how quickly these capabilities are progressing. But while individual models may dominate the headlines, they are part of a much broader trend: AI is moving beyond content generation and into increasingly sophisticated security research and automation.

For iGaming operators, this shift is particularly important. The industry relies on always-on platforms, complex third-party ecosystems and high levels of customer trust. As AI accelerates the ability to identify and exploit weaknesses, operators face greater pressure to reduce exposure, improve visibility and strengthen resilience across their environments.

From our perspective working with the iGaming sector, the key change is not just the technology itself, but how quickly it is compressing the time between identifying weaknesses and exploiting them in live environments.

Recent analysis from Bain and the UK AI Security Institute points in the same direction: AI-enabled cyber capability is accelerating, requiring organisations to adopt more proactive, continuously monitored and resilient security models.

Industry data reinforces the urgency. Verizon’s 2025 Data Breach Investigations Report found that credential abuse remained the leading initial access vector in breaches at 22%, while vulnerability exploitation rose to 20%. Human involvement remained present in 60% of breaches and third-party involvement doubled to 30%. For operators managing high-value platforms and multiple suppliers, these risks are already business-critical.

Recent incidents in the iGaming supply chain have also shown how weaknesses at third-party providers can translate directly into financial and operational impact, including cases where compromised systems enabled exploitation of game mechanics and payouts.

The message is clear: as AI continues to reshape the threat landscape, organisations can no longer rely on traditional security approaches alone.

Here are eight priorities every iGaming organisation should focus on today.

  1. Reduce the time to patch vulnerabilities

The window between a vulnerability being disclosed and exploited is shrinking rapidly.

Continuous vulnerability assessments, penetration testing and efficient patch management are critical to identifying and remediating weaknesses before attackers can take advantage of them. In reality, we are already seeing shorter windows between vulnerability disclosure and exploitation, particularly across cloud infrastructure and third-party integrations. This is where the Claude Mythos story becomes relevant in practical terms: as AI improves vulnerability discovery, the time organisations have to assess exposure and remediate weaknesses will continue to shrink.

External commentary has gone as far as describing an approaching flood of machine-speed findings and a collapse in the window between discovery and weaponisation. Verizon’s 2025 DBIR also reported that exploitation of vulnerabilities as an initial access step grew by 34% year over year, while only around 54% of perimeter device vulnerabilities were fully remediated, with a median remediation time of 32 days. Organisations that can reduce that exposure window will be significantly better positioned to defend against AI-enhanced attacks.

  1. Eliminate single points of failure and find weaknesses early

Cyber resilience starts with understanding where your biggest risks lie.

Infrastructure assessments, architecture reviews and security consulting help organisations identify hidden dependencies, misconfigurations and operational weaknesses before they become business-critical incidents. In an industry where availability is essential, resilient design is just as important as strong perimeter security. This is also where zero trust principles, segmentation and the elimination of avoidable single points of failure become increasingly important as AI compresses the time attackers need to probe and exploit weaknesses.

  1. Continuously monitor your security environment

Threat actors don’t work to business hours, and neither should your security operations.

Continuous monitoring through a modern managed Security Operations Centre (SOC), supported by SIEM, EDR and MDR capabilities, enables organisations to detect suspicious activity quickly, investigate incidents efficiently and respond before they become major business disruptions. This matters even more during high-pressure periods we’re seeing, such as major sporting events, promotional campaigns and holiday traffic peaks, when availability is business-critical and attackers know disruption has greater leverage.

Our data reports have repeatedly shown that DDoS activity intensifies around high-profile events and high-demand periods such as Christmas, especially in sectors where uptime directly affects revenue and customer trust. In this sense, the future of iGaming security depends not only on prevention, but on maintaining continuous visibility when attack conditions are most favourable.

The earlier threats are identified, the more options defenders have to contain them.

  1. Strengthen identity security

As AI makes phishing attacks more convincing, stolen credentials remain one of the simplest ways for attackers to gain access to critical systems.

Multi-factor authentication (MFA), privileged access management and least-privilege policies continue to be among the most effective controls iGaming operators can implement. In today’s threat landscape, identity has become the new security perimeter. That is particularly relevant in iGaming, where account takeover, credential stuffing and promotional abuse are well-recognised attack paths. Recent cyber incidents at large casino and betting operators have also stemmed from compromised employee accounts, reinforcing how credential-based attacks remain a critical risk even in mature environments and why stronger authentication and tighter access controls are essential.

Across the environments we manage, credential-based attacks remain one of the most consistent and effective entry points for attackers.

  1. Improve visibility across your entire environment

Modern gaming environments span cloud infrastructure, private networks, edge locations and multiple third-party providers.

Without comprehensive visibility, security teams risk missing early indicators of compromise.

Centralised monitoring, security analytics and unified visibility enable organisations to identify risks faster, prioritise investigations more effectively and maintain stronger operational resilience across increasingly complex environments. As organisations adopt more AI tools internally, visibility also needs to extend to how those tools are being used, what data they can access and where governance controls may be lacking.

  1. Prepare for AI-enhanced phishing attacks through user education

As AI enhances phishing sophistication and enables more convincing impersonation attempts, stolen credentials remain one of the simplest ways for attackers to gain access to critical systems. We are seeing phishing campaigns that are increasingly difficult for users to distinguish from legitimate communications, even in well-trained organisations, further increasing the importance of continuous awareness.

According to ENISA’s 2025 Threat Landscape report, phishing accounts for around 60% of all initial intrusion attempts, and over 80% of social engineering campaigns now use AI-generated content. In response, multi-factor authentication (MFA), privileged access management, and least-privilege policies continue to be among the most effective controls iGaming companies can implement. Regular phishing simulations and security awareness training help reinforce these controls. In today’s threat landscape, identity has become the new security perimeter.

  1. Build incident response readiness before an attack happens

No organisation can expect to prevent every cyber attack.

What separates resilient organisations is how effectively they respond when an incident occurs.

Well-defined incident response plans, regular tabletop exercises, threat intelligence sharing and clearly established communication processes help minimise disruption, accelerate recovery and protect customer trust when every minute counts. In an AI-driven threat landscape, resilience depends on being able to make faster decisions under pressure, contain attacks earlier and recover services without prolonged operational impact.

  1. Leverage AI to strengthen your security operations

While AI is helping attackers become more sophisticated, it is also transforming cyber defence.

AI-powered security operations can analyse vast volumes of telemetry, identify behavioural anomalies, prioritise alerts and accelerate investigations faster than traditional manual processes alone. That is the constructive side of the Claude Mythos conversation. The headline may be about what advanced models could enable, but the real opportunity for operators lies in applying AI carefully and defensibly within security operations to improve visibility, triage and response. In the years ahead, cybersecurity will increasingly become an AI-vs-AI challenge, with organisations needing trusted human oversight, strong governance and resilient operating models alongside automation.

By combining AI with experienced security professionals, organisations can improve detection, reduce response times and strengthen their overall security posture in an increasingly complex threat landscape.

Looking beyond today’s headlines

Claude Mythos may be one of the latest headlines, but it is only one example of a much broader shift. AI is changing the speed, scale and sophistication of cyber activity across the board, creating both new opportunities for defenders and new advantages for attackers. For the iGaming industry, the question is not whether AI will reshape the threat landscape, but whether organisations are prepared to adapt as quickly as it evolves.

The companies best placed to succeed will be those that translate this shift into practical action: shorter patch cycles, stronger identity controls, better visibility across hybrid environments, continuous monitoring, more mature incident response and ongoing workforce awareness. In other words, the same eight priorities outlined here become even more important as AI raises the pace of attack and defence alike.

The future of iGaming security will not be defined by a single tool or model. It will belong to organisations that continuously adapt by reducing vulnerabilities, strengthening infrastructure, improving visibility, investing in their people and embracing AI as part of a proactive cybersecurity strategy grounded in real operational risk.

At Continent 8, we believe cybersecurity is no longer just about protecting technology. It is about protecting business continuity, player trust and long-term growth across the iGaming industry. That is why operators are increasingly looking for joined-up support across areas such as vulnerability assessment and penetration testing, managed SOC and SIEM, EDR and MDR, phishing simulation, identity security and MFA, rather than relying on isolated point solutions.

As AI continues to redefine the threat landscape, companies that invest in resilience today will be better positioned to stay ahead of tomorrow’s threats. For the iGaming sector, that means combining strong cyber fundamentals with continuous monitoring, informed governance and practical use of AI in cyber defence. To learn how Continent 8 supports always-on environments with layered cybersecurity services, speak to our team at sales@continent8.com.

In an exclusive Q&A with NEXT.io, Continent 8 Technologies CEO Mike Small discusses his transition into the role, succeeding founder Michael Tobin, the impact of AI on the technology sector, and the strategic priorities shaping the company’s next phase of growth.


NEXT: After serving as a strategic board advisor over the last year, what ultimately convinced you to take on the CEO role at Continent 8 Technologies?

Mike Small: Having worked alongside the leadership team over the past year, I gained a real appreciation for what makes Continent 8 special. The company has built an outstanding reputation as a trusted technology partner to many of the world’s leading iGaming operators and platform providers, and that reputation has been earned through a relentless focus on customer success, innovation and operational excellence. Our Net Promoter Score of 71 is a great reflection of the trust our customers place in us and the commitment of our teams to delivering exceptional outcomes.

What ultimately convinced me was the combination of a strong foundation and the opportunity ahead. The business has exceptional people, deep customer relationships and market-leading technology, but I also see tremendous potential for growth as the industry continues to evolve and embrace new technologies, including AI.

Joining as CEO was an opportunity to help shape the next chapter of an already successful story.

NEXT: Looking back on your first months engaging with the business, what stands out most about Continent 8’s culture, people and customer relationships?

MS: The first thing that stood out to me was the calibre of the people. Across every part of the organisation and every location, I encountered teams that are passionate about what they do and genuinely committed to delivering for customers.

A key part of my work as strategic board advisor was helping shape the future operating model of the business, drawing on my experience building and scaling global delivery organisations. One of the achievements I’m particularly proud of is strengthening our Global Capability Centre strategy across India, the Philippines and Bulgaria. These centres play an important role in supporting our customers around the world, while enhancing our ability to scale, innovate and access exceptional talent.

I was also impressed by the strength of the relationships Continent 8 has built across the industry, not only with customers but also with strategic partners (the likes of AWS and Nutanix). Technology is obviously at the heart of our business, but it’s the trust we’ve established over many years that truly differentiates us.

Attending my first Continent 8 Customer Advisory Board meeting brought that to life. Hearing directly from customers about the value they place on our partnership, and seeing the openness of those conversations, reinforced just how strong those relationships are.

NEXT: Michael Tobin founded the business nearly three decades ago and has become one of the most recognisable figures in gaming technology. What conversations did you have with him ahead of taking the role, and how do you balance preserving what has made Continent 8 successful while bringing your own leadership approach?

MS: Michael has built an incredible business over the past 28 years, and one of the things that struck me most during our conversations was his passion for the company, our people and our customers. His leadership has shaped not only Continent 8’s success, but also the culture and values that define the business today. The respect he has earned across the industry reflects that legacy.

The transition has been carefully planned and there is a shared understanding that success comes from building on the foundations that have already been established. My focus is not on changing what has made Continent 8 successful. It’s about helping the company evolve, identifying new opportunities and ensuring we’re positioned for long-term growth.

Michael remains closely involved as chairman, which provides valuable continuity, while I bring my own experience from leading global technology organisations and scaling businesses through periods of transformation and growth. Together, that creates a strong platform for the future.

NEXT: You bring experience from organisations including Akkodis, Adecco, IBM, Hewlett Packard and Capgemini. Which lessons from those roles will be most valuable in this next chapter?

MS: I’ve been fortunate to work across a variety of global technology and services businesses, and while every organisation is different, some lessons are universal.

The most important is staying close to your customers. Technology evolves rapidly, but organisations that truly understand their customers’ challenges are best positioned to create value. Throughout my career, the most successful businesses I’ve seen are those that listen carefully, anticipate change and remain focused on solving real customer problems.

Additionally, I’ve seen firsthand the importance of balancing innovation with execution. It’s one thing to have a vision for where the market is headed; it’s another to consistently deliver for customers every day. The most successful organisations are those that can do both.

Those principles will continue to guide my approach at Continent 8 as we focus on supporting our customers, developing our people and driving the next phase of growth.

NEXT: Continent 8 has grown from a single data centre business into a global technology provider operating more than 100 connected locations worldwide. What do you believe has been the key to that success, and what opportunities excite you most about the next stage of growth?

MS: The company’s success has been built on consistently listening to customers and evolving alongside their needs. As the industry has grown and become increasingly global, regulated and technology-driven, Continent 8 has continued to invest in the infrastructure, expertise and services required to support that evolution.

A key part of that success has been our global network of 100+ locations, which today is recognised as one of the top 20 most connected networks in the world. It is the bedrock of our business and the foundation on which we have built our broader portfolio of infrastructure, cloud, cybersecurity and managed technology services. Our customers operate in environments where performance, resilience and connectivity are critical, and that network gives them the platform they need to scale with confidence.

What excites me most is that we’re still at the beginning of some very significant opportunities. New regulated markets continue to emerge, customer environments are becoming more complex, and organisations are increasingly looking to modernise their technology estates through cloud adoption, data-driven decision making and AI-enabled innovation. At the same time, demand for secure, resilient and high-performance technology solutions continues to increase.

As these trends accelerate, customers need partners that can help them navigate change with confidence. With 28 years of experience in the highly regulated iGaming industry, Continent 8 combines deep sector expertise with a global technology platform spanning infrastructure, cloud, cybersecurity and managed services.

That puts us in a unique position to help customers modernise their environments, leverage emerging technologies such as AI, and expand into new markets, all while maintaining the security, performance and compliance that are critical to their success.

NEXT: Artificial intelligence is becoming a major focus across every industry. Having helped shape AI strategy in previous leadership roles, where do you see the biggest opportunities for AI within Continent 8 and across the wider gaming ecosystem?

MS: AI has enormous potential, but I believe the iGaming industry is still in the early stages of understanding how transformative it can be. During my time at Akkodis, I saw firsthand how AI can move beyond theory and deliver real business value, helping organisations accelerate innovation, improve productivity, optimise operations and make smarter decisions at scale.

Across the gaming ecosystem, AI will help operators become more efficient, make better use of data and improve decision-making. It also has significant potential to strengthen cybersecurity capabilities, automate repetitive processes, enhance operational performance and improve the overall customer experience.

Within Continent 8, we’re focused on how AI can help us deliver even greater value to customers. That includes improving operational efficiency, enhancing service delivery and creating smarter, more resilient technology environments. We also see significant opportunities to leverage AI across our global infrastructure and cybersecurity capabilities, helping customers identify risks faster, respond more effectively to player queries and optimise their operations.

NEXT: Finally, when you reflect on your tenure several years from now, what would success look like to you?

MS: Success starts with our customers. If we continue helping customers achieve their goals and strengthen our position as a trusted long-term partner, that will be a significant measure of success.

Equally important is creating an environment where our people can thrive and develop. Great organisations are built by great teams, and I’m committed to ensuring Continent 8 remains a place where talent, innovation and collaboration flourish.

Ultimately, I would like to look back and see a business that has continued to grow, continued to innovate and continued to build on the remarkable legacy that Michael and the team have created, while positioning itself for even greater success in the years ahead.

We have an exceptional foundation, a world-class team and a tremendous opportunity ahead of us. I’m incredibly excited about the future of Continent 8.

For iGaming and online sports betting operators, growth rarely happens in a straight line. A major sporting event, a new market launch, a jackpot promotion, or a live betting surge can place sudden pressure on platforms that need to be fast, resilient, compliant, and always available.

That is why scaling modern iGaming platforms is no longer just an infrastructure challenge. It is an operational challenge. Operators need to keep innovating while managing more environments, more technologies, more regulatory requirements, and more demand from players who expect a seamless experience every time they log in.

The pressure behind modern iGaming platforms

Today’s operators and providers run highly distributed environments that span multiple virtualisation platforms, database engines, and deployment models – including co-location, on-premises, private cloud, public cloud, edge, and hybrid setups. At the same time, technologies such as Kubernetes, micro segmentation, automation, and distributed databases are becoming part of the standard architecture.

In practice, that means platform teams are often supporting legacy services alongside cloud-native workloads, virtual machines alongside containerised applications, and stateful databases alongside stateless services. They must also balance low-latency player journeys with unpredictable traffic patterns driven by betting events, casino promotions, and regulatory market launches.

Each layer adds capability, but each layer also adds operational responsibility. Teams need to provision infrastructure, manage upgrades, maintain security policies, monitor performance, plan capacity, validate backups, and ensure availability around the clock. As complexity grows, the skills required to manage these environments become harder to maintain and more expensive to scale.

Where operational complexity slows down momentum

Kubernetes is a strong example. It gives operators a flexible way to deploy and scale modern applications, but running Kubernetes across co-location, on-premises, cloud, and hybrid environments requires more than cluster deployment. It requires decisions around cluster and distribution design, infrastructure integration, networking, storage, control plane security, node lifecycle management, upgrades, and capacity planning.

On a scale, those responsibilities become more visible during the moments that matter most. A live betting operator may need to support sharp traffic spikes while odds are updating in real time. A casino operator may need infrastructure that can absorb a sudden surge during a promotion. A sportsbook may need to prepare for a major final where downtime is not an option. An operator entering a regulated market may need clear evidence of data residency, access controls, segmentation, and audit readiness.

In each case, the challenge is not simply whether the platform can scale. It is whether the platform can scale predictably, securely, and without pulling engineering teams away from the work that differentiates the business.

From infrastructure ownership to operational confidence

Many iGaming operators are now looking for a different model: one that reduces ownership of foundational infrastructure layers while preserving control over applications, player experience, product strategy, and data decisions.

This shift is about more than outsourcing tasks. It is about creating a consistent operating model across environments, with predictable cost models aligned to platform usage, built-in resilience and disaster recovery, standardised security and compliance controls, and clearly defined accountability between the operator and its managed services partner.

The diagram below helps illustrate this change. Instead of treating cloud, Kubernetes, databases, security, observability, backup, and day-to-day operations as disconnected workstreams, the model brings them together into a managed operating layer. That layer supports the application teams above it, helping them move faster while reducing the operational burden beneath them.

For iGaming businesses, that matters because demand is event-driven by nature. The platform may be stable on a quiet weekday, then face a sharp spike during a football final, an e-sports tournament, or a high-profile jackpot campaign. A managed operating model helps ensure capacity, resilience, monitoring, and response processes are ready before those moments arrive.

For example, our teams supported customers during the Super Bowl, helping them prepare for exceptional event-driven demand with managed services designed to maintain performance, resilience, and operational confidence when traffic and transaction volumes were at their highest.

How Continent 8 simplifies scale

Continent 8 cloud and managed services are designed for the realities of regulated iGaming and online sports betting. The aim is to help operators scale across private, multi-tenant, Kubernetes, virtual machine, AWS Outposts, hybrid, and multi-cloud environments without asking internal teams to absorb every infrastructure, networking, database, security, compliance, and operations task themselves.

In this model, Continent 8 can support the operational foundations that sit beneath the application layer, including infrastructure lifecycle management, security and network segmentation, backup and disaster recovery, observability, integration with hyperscale cloud services, and 24/7 operations.

Managed Kubernetes service

Managed Kubernetes can reduce the day-to-day effort involved in cluster provisioning, configuration, control plane and node lifecycle management, Kubernetes and operating system upgrades, availability, and scaling integration.

Managed database service

Managed database services can reduce recurring operational work around patching, version upgrades, backup validation, recovery testing, replication, failover management, and audit readiness.

The result is a more practical path to modernisation. Operators can retain control over their applications and business logic while foundational services are operated using consistent, repeatable practices designed for regulated, high-demand environments.

What this means in real iGaming scenarios

For a live betting operator, operational confidence means being ready for sudden spikes while odds, transactions, and customer interactions are moving in real time. The infrastructure must be scaled, but it must also remain observable, secure, and resilient throughout the event.

For an operator launching in a new regulated market, the pressure is different. Data residency, segmentation, logging, access controls, and audit evidence need to be considered from the start. A consistent managed model helps create repeatable foundations, so market expansion does not require a complete operational rebuild each time.

For a casino or sportsbook preparing for a major campaign, the priority is readiness. Compute capacity, database resilience, backup validation, monitoring, and incident response must all be in place before player activity peaks. Reducing the operational heavy lifting gives engineering teams more time to focus on product performance and player experience.

The value: faster, safer, and easier to operate

When infrastructure modernisation is paired with an operating model designed for scale, the value becomes more concrete. Features can move faster because teams are not waiting for every foundational task. Platforms become more resilient because lifecycle management, observability, and recovery processes are handled consistently. Compliance becomes easier to demonstrate because controls are designed into the operating model rather than added after the fact.

Costs also become easier to manage because capacity, services, and responsibilities are aligned to platform usage and business growth. Most importantly, teams gain clarity. They know what they own, what their partner operates, and how both sides work together to protect uptime, performance, compliance, and customer experience.

This focus on service quality is reflected in customer outcomes too, with a 2026 NPS score of 71 reinforcing the value of Continent 8’s managed services model that supports reliability, responsiveness, and trust.

Modern iGaming platforms do not just require modern technology. They require a smarter way to operate it – one that helps operators simplify complexity before it slows innovation, growth, or the player experience.

If you are evaluating how to scale your platform more efficiently, reduce operational overhead, or prepare for growth across regulated markets, Continent 8 can help you explore the right approach. Speak to our team at sales@continent8.com to build a more resilient, scalable, and manageable foundation for your next phase of growth.

Why iGaming operators and sportsbooks should treat networking infrastructure as a revenue engine (not just infrastructure). 

After a long four-year wait, the FIFA World Cup is back – and this one is a monster. FIFA World Cup 2026 will be the largest tournament ever, featuring 48 teams and 104 fixtures, running from 11 June to 19 July 

For sportsbooks and iGaming operators, that schedule isn’t just exciting – it’s a traffic forecast. World Cup season compresses peaks into tight windows: match starts, halftime surges, late goals, VAR drama, stoppage time, and knockouts. These moments produce short, intense betting spikes where latency, availability, and security directly affect conversion, player trust, and margins. 

As a managed IT service provider focused on networking, specialising in the iGaming sector, here’s the core truth we see every time a global event hits: 

Your platform doesn’t “run on the cloud.” It runs on the network path between the player and your service. 

In 2026, “Networking” means more than bandwidth 

Over the last four years, networking has evolved from “pipes and ports” to a performance and security fabric spanning edge, cloud, and identity. 

What’s changed since 2022? (A quick networking evolution) 

Why it matters for iGaming: these advances shift the goal from “keep the WAN up” to “optimise experience under load, under attack, and under regulatory constraints.” 

Sports betting platforms have changed since 2022 (and Networking had to keep up) 

From 2022 onward, the product playbook moved aggressively toward real-time, high-frequency engagement: 

1) Live betting became the center of gravity 

Operators doubled down on in-play experiences where odds update constantly, and settlement must be fast. That model demands low jitterfast market datapredictable latency, and a trusted, secure iGaming infrastructure partner. 

2) Microbetting and “fast markets” pushed latency requirements into the sub-second zone 

Trade coverage of microbetting repeatedly highlights low latency as a foundational requirement – a small delay can misalign markets with real-world events and break trust.

3) A more complex ecosystem: more vendors, more APIs, more paths to fail 

Modern sportsbooks are assembled from components (streaming/CDNs, risk engines, KYC/AML, payments, fraud, personalisation and sports data feeds). Each added dependency increases the need for network segmentation, resilient routing, and end-to-end observability. 

Bottom line: Since 2022, sportsbooks have increasingly become real-time transaction platforms. And real-time platforms live or die on networking. 

Fun fact: Will 2026 produce an “Animal Oracle” to beat Paul the octopus? 🐙 

Remember Paul the Octopus, the 2010 World Cup “oracle” who predicted match outcomes by choosing between flag-labeled boxes? CNN documented how the method worked and how Paul became a phenomenon. Paul’s overall record is often summarised as 12 correct predictions out of 14 (~85.7%).

Will 2026 bring a new animal oracle? Maybe. But the only “oracle” sportsbooks should rely on is better: network telemetry (latency, loss, jitter, and availability) – because those predictions are actionable. 

Why network downtime is still one of the biggest revenue risks in sports betting 

This is the uncomfortable part: the betting window is time-bound. If a user can’t place a bet when the moment happens, they don’t “come back later.” The moment is gone – and so is the revenue opportunity. 

To ground that in real numbers, here’s a look at US sports betting performance over the last four years: 

Real-world US sports betting stats (AGA) 

 

Now translate that into downtime risk: 

In other words: downtime isn’t just an IT incident – it’s a commercial event. 

What “World Cup-ready networking” looks like 

If we had to summarise a World Cup networking plan in one sentence: Build for peak, defend for attack, and operate for recovery. 

The 5 pillars we design around 

  1. Lowlatency cloud networking for iGaming
    Use edge routing, optimised cloud interconnects, and protocol modernisation (e.g., HTTP/3 where appropriate) to reduce handshake cost and improve loss tolerance.  
  2. iGaming infrastructure resilience
    Redundant circuits, active-active routing, tested failover, managed peering, and segmented blast-radius boundaries so one failure doesn’t flatten the whole platform. 
  3. DDoS protection for sportsbooks
    Traffic spikes attract attackers. Edge protection and rate controls are not “nice to have” during marquee events. 
  4. Zero Trust sports betting networks
    Modern access must follow user/device/app context, not physical location – consistent with SASE principles. 
  5. Network observability and response for iGaming 
    Latency, packet loss, jitter, DNS performance, API dependency maps – all tracked in a way that answers: “Is the player able to bet right now?” 

The World Cup is a network event (whether you like it or not) 

World Cup 2026 will deliver 104 matches worth of demand shocks, and the operators who win won’t just have better odds or better promos – they’ll have better uptime, better latency, and better recovery. 

The last four years prove why: US sports betting handle and revenue have climbed dramatically from 2022 through 2025.  

As the market grows, the cost of downtime grows with it – and the network becomes the invisible line between “player excitement” and “player churn.” Are you ready to handle the traffic? 

Continent 8 is a global iGaming network service provider, learn more about our trusted solutions here or contact the team via sales@continent8.com 

In a recent interview with G3 Magazine, Justin Cosnett, Chief Product Officer at Continent 8 Technologies, shared his insights on how major global sporting events are reshaping infrastructure demands across the betting industry.

The world’s biggest sporting events are no longer just moments-they are sustained digital stress tests for the global betting ecosystem. 

Traditionally, operators prepared for short bursts of activity. A spike. A surge. A single, intense window. 

But that model is rapidly becoming outdated. 

The 2026 Super Bowl- and the upcoming FIFA World Cup-are reshaping how we think about infrastructure entirely. These events are not just about scale; they are about duration, distribution and resilience under constant pressure. 

The shift: from spikes to sustained demand 

The Super Bowl has long been viewed as the ultimate peak event for sports betting. But even here, patterns are evolving. 

Traffic no longer simply builds towards kick-off-it extends before, during and after. The operational window has widened, and so too have expectations placed on infrastructure. 

And then comes the World Cup. 

Unlike the Super Bowl, the World Cup is: 

Rather than a single spike, it creates continuous, rolling demand across regions. 

This is where the true challenge begins. 

Why infrastructure needs a new playbook 

Scaling for a single peak is one thing. Designing for sustained, distributed engagement is quite another. 

Operators must now rethink: 

One critical takeaway is clear: 

Infrastructure strain is driven by user volume and concurrency-not by individual high-value bets. 

It’s not a handful of large wagers that push systems to their limits- it’s millions of users interacting simultaneously across markets. 

The hybrid reality: cloud alone isn’t enough 

Cloud adoption has transformed the industry- but it is not a cure-all. 

Simply relying on hyperscale cloud providers does not guarantee resilience. 

Instead, operators are increasingly adopting hybrid architectures, combining: 

The objective is straightforward: 

As Justin highlights, genuine resilience is achieved through careful design and planning-not technology alone. 

Preparing for what comes next 

As global sporting events grow in scale and complexity, infrastructure must evolve accordingly. 

This means: 

Because the next generation of betting moments will not just test systems over a few hours-they will test them continuously, worldwide and without pause. 

For a deeper dive into Justin Cosnett’s perspective and Continent 8’s approach to managing global event infrastructure, read the full article in G3 Magazine: Read here

From infrastructure to compliance, artificial intelligence is transforming gambling’s operational backbone. Continent 8 Technologies’ chief data, information and AI officer Cris Kuehl tells iGamingBusiness how the technology is unlocking major efficiency gains.

The influence and reach of artificial intelligence (AI) is growing rapidly in the gambling industry.

Until now, though, much of the attention has focused on player-facing tools that sharpen marketing campaigns and personalise experiences. After all, tangible, revenue-generating applications of the technology – from tailored promotions and recommendation engines to dynamic odds – are relatively straightforward to measure.

However, arguably the greatest impact is behind the scenes, with the technology becoming indispensable for improving efficiency and reducing costs. Indeed, this deployment of AI across this operational layer, which spans infrastructure, monitoring, compliance and internal services, is transforming how gambling businesses function at scale.

“The industry conversation gravitates towards the player-facing AI because the outcomes are visible and commercially intuitive,” says Continent 8 chief data, information and AI officer Cris Kuehl. “But the operational side is where AI delivers the most structurally significant efficiency gains, and it is considerably underinvested relative to its potential.”

Given the scale at which gambling platforms operate, AI is playing a vital role in analysing the data, logs, metrics, alerts and network telemetry underpinning each business. It would be impossible for a human to perform such tasks simultaneously.

“AI-driven operations help with initiating some automated remediations, and I think that’s key,” Kuehl says.

“The cost reduction there is very real, but it’s also more significant to gain resilience, catching degradation before it becomes an outage.

“Right now, we’re seeing a lot of AI use as a cost savings tool, but I like to look at it as a cost preventative measure. Outages are massive from a revenue loss perspective alone.”

Importance of compliance

As gambling businesses expand into new jurisdictions, regulatory requirements become increasingly complex.

AI is well suited to the challenges of ensuring compliance with regulations by automating structured, rule-based processes. This enables operators to scale more efficiently while maintaining consistency and accuracy.

“Compliance operations is a core component [of AI’s ability to improve infrastructure efficiency],” says Kuehl.

“The regulatory overhead of running a multi-jurisdiction iGaming business is massive. It’s substantial.

“The reporting, the audit trail management, monitoring, the data retention, enforcement – all of these are largely structured rule-based processes with high volume and load tolerance for error.

“This is not only well suited but designed to be AI assisted. Automation and the efficiency gains compound as the number of active jurisdictions continues to grow.”

Reimagining support and service

The impact of AI extends beyond infrastructure into customer support, with these traditionally resource-intensive functions undergoing substantial change.

The conventional model relies on large agent pools, high attrition and reactive ticket management. It also struggles to scale efficiently across time zones, making it both costly and inconsistent. As a result, every new jurisdiction adds different language requirements or regulatory context that compounds the headcount cost.

However, AI can handle a significant portion of enquiries such as account questions, payment status, bonus mechanics and general troubleshooting.

“AI can handle those without any human involvement at all,” says Kuehl. “The proportion varies obviously by implementation quality and query complexity, but the biggest thing is it can consistently reduce agent volume requirements materially.

“I’ve seen it first-hand for the last five years – the transformation effort since COVID – and I think it’s only getting more and more aggressive.”

Agent augmentation is another key feature of AI’s impact on the customer support aspect of operations. With AI now able to handle the more menial tasks, a significant proportion of internal IT incidents can be resolved without a ticket escalation, leaving humans to focus on making a difference in other areas.

“This is great because mean time to resolution basically drops to nothing,” Kuehl says. “Repeat incidents decrease as root cause analysis continues to improve, and then my favourite part is that time is protected for the work that actually requires it. And I think this is absolutely huge.”

Smarter monitoring, better decisions

One of AI’s most valuable contributions is how it can enhance monitoring and therefore efficiency.

Companies like Kuehl’s Continent 8 can amass tens of thousands of alerts, sometimes for minor incidents.

AI can distinguish genuine anomalies from normal variance, allowing for an operations team to focus its attention where it is actually needed.

Another area where AI plays a key role is in predictive failure identification due to its pattern recognition ability across historical incident data, telemetry and vendor signals.

All of these can identify degradation patterns and trajectories before they produce an actual outage, bringing a clear financial value.

For Kuehl, automated correlation and root cause acceleration is another core way that AI is changing the type of intelligence and insight that managed service providers can deliver to customers.

“The reporting, the audit trail management, monitoring, the data retention, enforcement – all of these are largely structured rule-based processes with high volume and load tolerance for error.

“This is not only well suited but designed to be AI assisted. Automation and the efficiency gains compound as the number of active jurisdictions continues to grow.”

“Complex incidents are in a distributed environment involving signals across multiple different layers,” he says.

“You have the application layer, the network layer, the infrastructure layer and the security layer. AI-driven correlation platforms can assemble that picture faster than a human analyst can and even somebody who’s been working in this industry for decades.

“It’s not a replacement. It’s allowing them to actually use their brainpower in the right way and letting AI augment that to compress the time and the detection to resolution. I think that that’s key.”

Balancing opportunity with responsibility

Despite its benefits, AI introduces inevitable challenges.

Hyper-personalisation, for example, can enhance user engagement, but equally raises concerns about encouraging excessive gambling and potentially breaching data privacy laws.

For this reason, having a human in the process to ensure adequate oversight is essential, with clear audit trails, escalation mechanisms and accountability frameworks all important when using AI.

“The governance consideration that matters here is how AI handles the customer interactions in iGaming,” Kuehl says. “They are going to be extremely important because they touch the regulated activities, including responsible gaming complaints, KYC queries and payment disputes, for example.

“This audit trail and escalation logic has to be built in, and whether you’re deploying a customer-facing AI agent or an IT system, doing so without the appropriate governance architecture is regulatory suicide.”

Knowledge gaps

While much of the conversation around AI focuses on technical capability, such as data science, prompt engineering and model development, a more limiting knowledge gap is business-side AI literacy.

Another knowledge gap that is holding back operators, according to Kuehl, is AI governance capability, meaning the ability to design and operate a model risk framework and maintain audit trails.

Furthermore, one of the most common mistakes when it comes to designing, implementing and managing IT infrastructure and security with AI is treating security as a compliance exercise rather than an operational priority.

“Designing a security posture around passing audits that produces a documented environment that may not be materially secure,” says Kuehl.

“Genuine security requires continuous operational investment, threat monitoring, vulnerability management and incident response rehearsal. I think that’s the biggest mistake iGaming businesses are making. After all, this industry is one of the most attacked!”

AI is transforming the gambling industry, but one of its biggest impacts is taking place under the surface.

While player-facing applications are scrutinised and noticed the most, it is the operational side of monitoring, infrastructure, compliance and support that is being remodelled.

As the industry continues to evolve, those who successfully integrate AI into their core operations will have a huge advantage over those who do not.

Learn more about it, in the iGaming Business report. Read the full report here.

Strengthening trust, resilience and recovery in a high‑risk digital industry

In the latest episode of Continent 8’s Ask the Expert podcast series, Craig Lusher, Principal Solutions Architect, sits down with Elizabeth Grima, Senior Executive Manager at New Dawn Risk, to unravel one of the most misunderstood – but increasingly critical – areas of iGaming resilience: cyber insurance.

Both experts have spent years helping operators navigate real-world incidents that strike without warning – from ransomware to payment fraud, account takeovers, and vendor outages. Their message is clear: cyber insurance is no longer optional – it’s a core component of operational continuity for any iGaming business.

If you haven’t had time to watch the podcast episode, below is a summary of the episode’s key takeaways.

The rising importance of cyber insurance in iGaming

The iGaming sector is one of the most attractive global targets for cybercriminals. High‑value financial transactions, player data, round‑the‑clock uptime requirements, and interconnected vendor ecosystems create a perfect storm of cyber risk.

Cyber insurance helps operators withstand these threats by providing a financial safety net – but also much more. Modern policies include:

This combination ensures operators can recover faster, smarter, and with less long‑term damage.

How cyber insurance acts as a financial shock absorber

When a breach or outage occurs, every minute matters – and every minute is costly. Cyber insurance helps operators rapidly mobilise the right resources by covering:

This dual support – financial and operational – means operators can focus on restoring service and protecting players, rather than scrambling to fund or coordinate a crisis response.

Cybersecurity + insurance: Why one cannot replace the other

A persistent misconception in the industry is that strong cybersecurity reduces the need for insurance – or vice versa.

In reality, the two work hand in hand:

Insurers increasingly expect baseline controls before offering coverage, including MFA, backups, monitoring, and social‑engineering safeguards.

Businesses that demonstrate strong cyber maturity often receive better pricing, fewer exclusions, and higher coverage limits.

What really determines whether a claim gets paid

Not all losses are automatically covered. Operators must pay close attention to key policy conditions:

  1. Coverage triggers
    Protection is activated only when specific events – such as a security failure – occur.
  2. Time deductible
    Most policies have a waiting period – this could be anywhere from the first 8–24 hours of downtime, and these aren’t covered.
  3. Period of restoration
    Business interruption stops when systems are restored and not when reputation fully rebounds.
  4. Limits and sublimits
    Business interruption may share the overall limit and can be sublimited; forensics, restoration, and legal costs can eat into the pot before revenue loss is paid.
  5. Compliance with the insurance contract
    Late notice, poor documentation, or not following policy conditions can jeopardise the claim.

Ensuring internal teams understand these requirements is essential for maximising protection.

Misconceptions still holding operators back

Craig and Elizabeth highlight several myths that continue to cloud decision‑making across the industry:

Real‑world scenarios: Why every operator needs coverage

Consider two of the most common (and costly) incidents:

1. DDoS attack during peak traffic

An operator suffers a sustained DDoS attack during a major sporting event. Impacts include:

With cyber insurance, expert teams rapidly intervene, reduce downtime, and help restore services – while the insurer covers response and recovery costs.

2. Player data breach

When sensitive player data is exposed, expenses skyrocket:

Cyber insurance helps manage the fallout and protects the operator’s reputation.

The Continent 8 + New Dawn Risk advantage

To address the growing needs of iGaming operators, Continent 8 and New Dawn Risk have partnered to deliver a unified, industry‑specific cyber defence and insurance solution.

The partnership offers:

By combining Continent 8’s multi‑layered cyber protection with New Dawn Risk’s specialist insurance expertise, operators gain a comprehensive solution designed specifically for their operational and regulatory environment.

A holistic approach to iGaming cyber resilience

In an industry where downtime directly translates into lost revenue – and lost trust – cyber insurance has become a fundamental layer of resilience.

By integrating:

… iGaming operators can withstand today’s evolving threats with confidence.

The Continent 8 and New Dawn Risk partnership ensures that operators are not only protected – but empowered – to operate securely across multiple jurisdictions.

Watch episode 7 of Continent 8’s Ask The Expert podcast featuring New Dawn Risk

Cybersecurity regulation in Europe is evolving rapidly, and iGaming businesses must prepare now for two major incoming frameworks: the NIS2 Directive and the EU cyber resilience act (CRA). These regulations introduce stricter security obligations, tighter reporting deadlines and heightened accountability across the iGaming ecosystem.

Oliver Crofton

In our recent webinar, “iGaming’s new cybersecurity rules”, Oliver Crofton (Regional Sales Director – Cybersecurity at Continent 8 Technologies) hosted an in‑depth discussion with Craig Lusher (Principal Solutions Architect EMEA at Continent 8 Technologies) and Jo Joyce (Partner and Head of Regulatory, IP & Digital at Taylor Wessing Ireland). Together, they provided clarity on the regulatory landscape and outlined what operators, suppliers and technology partners must do to stay ahead.

Here’s a breakdown of the key takeaways.

WHY NIS2 AND THE CRA MATTER FOR IGAMING

The iGaming industry operates in a high‑risk digital environment. Real-time financial transactions, complex technology stacks, and large volumes of sensitive personal data (including government-issued identity documents attached to financial information) make it a prime target for attackers. As cyber threats grow more sophisticated, regulators are raising the bar to ensure resilience.

NIS2 and the CRA aim to:

For iGaming, where uptime, trust and compliance underpin commercial success, these changes are significant.

NIS2: BROADER SCOPE AND HIGHER STANDARDS

NIS2 is fully live and enforcement has begun. This is no longer about preparation; the question is whether your organisation is compliant right now.

According to Craig and Jo, NIS2 represents a major overhaul of Europe’s cybersecurity framework. It replaces the original NIS Directive (2016), which was fragmented, voluntary in practice, and allowed each country to implement it differently.

Key updates include:

 

THE EU CYBER RESILIENCE ACT: SECURITY BY DESIGN

Whilst NIS2 focuses on how organisations manage security, the CRA concentrates on the digital products those organisations depend on and produce.

CRA reporting obligations begin on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products, following the same 24-hour early warning, 72-hour notification structure. For vulnerabilities, the final report must be submitted within 14 days of a corrective measure becoming available. Full product standards, including CE-marking requirements for software and connected devices, come into force in December 2027.

Jo Joyce

Jo highlighted that the CRA requires manufacturers and developers of digital tools – including gaming software, APIs, hardware and integrated systems – to

Given the heavy reliance on third‑party tech in iGaming, this places strong emphasis on vendor due diligence and supply‑chain oversight.

ARE YOU IN SCOPE? MOST LIKELY.

Jo: “I think one of the things that I’ve spotted is quite a lot of operators and firms within the iGaming ecosystem haven’t really necessarily accepted that they’re in scope.”

If your organisation provides or supports any of the following, NIS2 likely applies:

There are two additional points worth flagging. First, white-label and B2B providers are often managed service providers (MSPs) without realising it. If you run a player account management (PAM) system for 20 other brands, you are managing their core services, which, by definition, makes you an MSP. Under NIS2, MSPs are designated as essential entities, meaning they face ex ante supervision (proactive inspections and audits at any time), the same regulatory tier as a data centre or cloud provider.

Second, there is no “group privilege” under NIS2. If an internal IT arm provides services to the wider corporate group, it may be classified independently as an essential entity in its own right. Being part of a larger group does not shield individual subsidiaries or divisions from independent classification.

A readiness assessment is the essential first step.

THE THREAT LANDSCAPE: GROWING IN COMPLEXITY

Craig emphasised how the threat landscape facing iGaming businesses has intensified – including a 400% surge in cyber attacks targeting the gambling industry. This is not a gradual trend; attackers have industrialised their approach.

Craig Lusher
Craig Lusher

Operators and suppliers now face:

The interconnected nature of the sector amplifies the impact of any single vulnerability.

The cost of downtime in the industry now exceeds $6,000 per minute, and attacks are more visible in the news than ever, and recent breaches have seen hundreds of thousands of user profiles and identity documents exposed through relatively basic misconfigurations.

ARE ALL EU COUNTRIES FOLLOWING THE SAME RULES?

Craig highlighted several country‑specific differences in how NIS2 is being implemented, here are a few examples:

Malta

Malta moved faster than most EU member states, issuing Legal Notice 71 of 2025, with the CIPD as the ‘competent authority’. Self‑registration was due September 2025, so organisations that missed the deadline are now operating in a regulatory grey area. Governance and risk‑management controls must be live by March 2026, which at the time of the webinar was just weeks away.

Malta also goes further than EU baseline requirements by mandating a 24/7 security operations centre for digital infrastructure providers. Properly staffing a round-the-clock SOC requires at least 12 people to maintain a true rotation, which is a substantial operational investment for mid-sized operators.

The ultimate sanction isn’t just a fine; Malta can suspended MGA licences. For Malta-licensed gaming companies, this is an existential threat. If you lose your MGA licence, you are effectively locked out of dozens of global markets overnight.

Germany

Germany passed its implementation late, in November 2025. Registration deadlines for German‑based entities land in April 2026, leaving limited time for compliance.

Other member states are at various stages of transposition, and several missed the original October 2024 deadline. For operators with a presence in multiple EU countries, the practical challenge is managing compliance against several different national timelines and requirements simultaneously.

IMPLEMENTATION IN OTHER EU MEMBER STATES

NIS2 is an EU directive, which means each member state must transpose it into national law. The result is that implementation timelines and specific requirements vary from country to country, and organisations operating across multiple jurisdictions need to track each one independently.

LEADERSHIP MUST BE ACTIVELY INVOLVED

Both speakers stressed that NIS2 and the CRA require visible, ongoing engagement from senior management. Leading organisations will:

Under NIS2, leadership accountability is explicit. Executive training is not optional; it is a legal requirement under the directive.

Jo: “Just because something bad has happened doesn’t mean that you’re necessarily at fault… but you are going to have to produce reasonable reporting in layman’s terms… and explain that we’re operating in different risk parameters.”

Craig added the importance of training: “It’s mandatory for board‑level staff… you’ve got to keep training and constant training.”

REPORTING REQUIREMENTS

Craig and Jo discussed the importance of reporting – especially when something goes wrong.

Jo: “The kind of reporting that one has to do under NIS2 is not a million miles away from the pre‑existing reporting… but there’s a real shift when you are experiencing a very serious incident.”

The 24‑hour reporting window is the operational flashpoint. Many companies are not ready for this. Under NIS2, the clock starts as soon as you become aware of a significant incident. You then have 24 hours to submit an early warning to the relevant CSIRT, 72 hours for a more detailed incident notification, and one month for the final report. A single incident can also trigger reporting obligations under the CRA and DORA simultaneously, each with different data requirements, formats, timelines and regulators.

Businesses need to prepare now by having supplier lists to hand, knowing exactly where to submit reports for each applicable regulation, and understanding that multi-jurisdictional reporting may be required.

Top tip from Jo:
Please print out a copy of your breach response plan… print out your incident response team list with phone numbers, ideally personal ones. If you can’t access your systems, it will take you an astonishing amount of time to pull this together.

ENFORCEMENT: WHAT BUSINESSES SHOULD EXPECT

Jo highlighted that enforcement activity under the CRA and NIS2 will be phased but increasingly serious.

From September 2026, the CRA introduces mandatory reporting of actively exploited vulnerabilities and severe incidents affecting product security. Full product‑related obligations take effect in December 2027, including the requirement for CE‑marking digital products, software included.

According to Jo, failure to report will likely be the first area where regulators take action, and penalties will be treated seriously.

Many NIS2 requirements are already enforceable. For essential entities that breach Articles 21 or 23, fines can reach up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum is EUR 7 million or 1.4% of worldwide turnover (Article 34 of NIS2). Regulators also have the power to issue binding instructions, order security audits, and, for essential entities, temporarily suspend or prohibit individuals from exercising managerial functions (Article 32(5)).

Jo: “They will factor in whether it’s going to bankrupt you… but they want these fines to hurt.”

This means businesses must act now to ensure reporting pathways, governance structures, supplier oversight and security controls are ready.

HOW TO PREPARE: PRACTICAL STEPS HIGHLIGHTED IN THE WEBINAR

Craig and Jo recommended several clear actions for organisations:

ADDRESS OPEN-SOURCE SOFTWARE OBLIGATIONS

There is a growing issue around the use of open‑source software (OSS) under the CRA. Although many OSS developers lobbied for exemption, OSS is widely used in commercial products. The CRA makes clear that organisations relying on OSS within regulated products remain fully responsible for meeting all cybersecurity and update obligations, including providing security updates for the minimum five-year support period.

Managing updates is difficult when you did not write the code – but the responsibility remains. The Software Bill of Materials (SBOM) requirement compounds this: manufacturers must maintain a machine-readable inventory of every library, open-source component and module in their products, kept as a living record.

Top tip from Jo:
If your business relies heavily on OSS, pay close attention to how it’s managed, seek specialist guidance and plan how you will meet long‑term update and security requirements.

FINAL THOUGHTS

The introduction of NIS2 and the EU cyber resilience act marks a significant shift for cybersecurity in iGaming. While the regulations bring real compliance challenges, they also create an opportunity for the industry to strengthen its defences, reduce operational risk and future‑proof operations.

Early preparation will help businesses stay compliant, competitive and trusted.

👉 Watch the full webinar here:

Let's work together.

GET IN TOUCH

Asia +65 3165 4649
Europe +44 1624 694625
Latin America +54 11 5168 5637
North America +1 514 461 5120