Seven Years in Cybersecurity at Resorts Casino with security dashboards, network monitoring, and the Atlantic City casino skyline

Seven Years in Cybersecurity at Resorts Casino

How Cybersecurity at Resorts Casino Changed My Career

I came to Resorts Hotel and Casino in Atlantic City in December 2015 as a contractor. At the time, I was working through DSI, and one of my original assignments was helping migrate Resorts from its on-premises Exchange environment to Office 365. I wasn’t hired as the Senior Security Analyst. I wasn’t even technically hired by Resorts yet.

What changed things was that I kept finding myself involved with the security side of the operation. I started talking with the CISO, sitting in on vendor calls, sharing ideas, and getting involved with projects that were much closer to security engineering than traditional systems administration. Eventually Resorts released me from my contract with DSI and brought me aboard full-time.

That began a seven-year run that would probably become the most substantial period of my cybersecurity career.

Building the Security Environment

In the beginning, I was much more of a security engineer than a security analyst. I was given technologies to deploy, configure, troubleshoot, and somehow make work in a large casino environment.

Some of those systems included Quest KACE, formerly Dell KACE; Blue Coat ProxySG; Tenable Security Center and Nessus; three AlienVault USM appliances; and Carbon Black, which at the time was still closely associated with Bit9. One of the AlienVault systems was dedicated to the online gaming environment, which was maintained separately from much of the traditional casino network.

I liked this part of the job. I was building things, testing things, breaking things, fixing things, and learning constantly. There was usually some new technology sitting in front of me that I had to figure out.

Then we had an incident that made some of those security projects much less theoretical.

The Game That Shouldn’t Have Been Downloaded

As I remember it, one of our server administrators downloaded a game from the Internet. I think it was some kind of Mario clone. Whatever it was, it wasn’t harmless.

The software eventually made its way far enough into the environment that we discovered communication with a malicious IP address in Russia. More importantly, it had reached systems associated with the Point of Sale environment.

Fortunately, the malicious address was blocked before what we believed could become a larger command-and-control operation really took hold. During the response, I created a read-only forensic image of a suspected system using dd, and the New Jersey State Police ultimately took possession of the server administrator’s laptop.

Carbon Black also became an important part of isolating the malicious software and understanding what had happened.

We recovered, but the incident exposed something that needed to be addressed beyond simply removing malware.

Segmentation.

Our network engineer went to work creating separate network segments for different areas of the business: HR, administration, marketing, sales, gaming systems, table games, and other operational areas. Online gaming was maintained as its own separate environment.

It was one of those incidents where the lesson afterward was almost as important as the incident itself. Security tools matter, but you don’t want malware on one workstation to have an easy path across an entire organization.

The Blue Coat Adventure

Blue Coat was another project that taught me a lot, although “adventure” may be a nicer word than I would have used while deploying it.

We were implementing a corporate proxy and SSL inspection system in an environment where there wasn’t really a mature browser policy beforehand. People were using Chrome, Firefox, Internet Explorer, Edge, and whatever else they preferred.

That became a problem very quickly.

Firefox was particularly difficult for us because it didn’t integrate with the Windows and Group Policy environment as cleanly as the Microsoft browsers did. Eventually we standardized things and removed Firefox from the environment.

The first months were rough. Sites would break. Certificates caused problems. Something that worked yesterday suddenly needed to be whitelisted today. There were always exceptions.

After about a year, though, the environment settled down. The exceptions became manageable, users mostly stopped noticing the proxy, and Blue Coat quietly did what it was supposed to do.

That’s usually how you know an infrastructure project is finally working: people stop talking about it.

Finding Things Before Someone Else Did

One of the advantages of working in security at Resorts was having the opportunity to experiment.

At one point, using Kali Linux, I discovered a flaw in the VPN network configuration that allowed access farther into the environment than it should have, including access toward highly regulated cash-counting systems.

That’s the kind of discovery you want your own security people making.

I also used Kali against older or vulnerable systems to test whether compensating controls were actually working the way we said they were. There is a big difference between having a document that says a control protects something and actually testing it.

I eventually had an ESXi server essentially available as my own security laboratory. I built vulnerable machines, installed Kali, created proof-of-concept environments, and experimented with whatever I happened to be interested in.

In that sense, it wasn’t that different from what I do today. Give me some hardware and enough time, and I’ll probably build something on it.

Becoming the Senior Security Analyst

Over time, the organization changed.

The CIO left, leadership changed, and my role gradually moved away from engineering. Some of my administrative rights were removed, although after enough complaining I was eventually given an administrative account again.

My responsibilities became much more analyst-oriented: vulnerability management, scanning, reporting, SIEM monitoring, investigating anomalies, and identifying issues that needed to be escalated to operations or management.

I reported high-risk vulnerabilities to executive leadership and worked with operational teams on remediation. I investigated SIEM alerts, used Carbon Black’s forensic capabilities when something didn’t look right, participated in policies and security procedures, and worked with phishing-awareness programs.

Eventually I received a raise and the title Senior Security Analyst.

Which sounds impressive until you realize I was basically the only security analyst.

It’s a little like being an IT Director today when I don’t have anyone to direct. Maybe IT Manager would technically make more sense because I manage IT, but titles are funny things.

For a while I had managed a junior analyst, but after he left we decided another wasn’t really necessary. Mostly it was me, the systems, the alerts, the vulnerability reports, and my lab.

And honestly, I was pretty happy with that arrangement.

When the Environment Changed

Eventually my boss left too.

His replacement came from operations and, as far as I could tell, had essentially no cybersecurity background. He had previously worked with the Director of IT at Borgata, which explained the connection, although from where I was sitting it was frustrating.

Here I was with years of IT and security experience, a degree, certifications, and probably twenty six years of technical experience by that point, now reporting to someone who couldn’t have explained the contents of an IP packet or probably told me what services commonly ran on basic network ports.

Before I even knew what was happening, he took me to lunch and asked how I would feel about him becoming my boss.

What was I supposed to say?

“You don’t know anything about cybersecurity, so absolutely not”?

Instead, I gave the professional answer.

“Man, that’s great. No problem at all.”

But the job had changed. I wasn’t doing as much engineering anymore, and the part of the job I enjoyed most had slowly been disappearing.

Then my phone rang.

It was someone I had previously mentored. He had moved on to a company called GigaOm, and he wanted to know whether I would be interested in coming to work with him.

The salary would be more than $100,000.

After seven years at Resorts, I decided to take the chance.

My next job looked like the beginning of something bigger. Instead, it started one of the strangest periods of my career.

Next: Two Lost Jobs, a Ruptured Appendix, and Starting Over

Similar Posts