MGM Resorts International

Building Scalable Security: A Framework for Stability, Innovation, and Growth

Viraf Machhi is the Director of Cyber Engineering at MGM Resorts International, specializing in security engineering, data engineering, and product innovation. With a background in software architecture, cybersecurity, and high-frequency trading, he has a proven track record of developing automated vulnerability management tools, penetration testing strategies, and data-driven business solutions. Before MGM Resorts, he worked at PayPal as a Technical Product Manager, focusing on Zero Trust Identity Access Management and security posture improvements.

Through this article, Machhi highlights the critical role of scalable, secure IT architecture in balancing security, stability, and innovation to protect businesses from cyber threats.

Growing up, my dad often played “Destroyer” by The Kinks and little did I realize its chorus, “Paranoia the Destroyer,” would inspire my career path. Cybersecurity has long been a battleground where a single vulnerability could threaten an organization. Shows like Mr. Robot dramatized this through fictional hacks that destabilized global economies, showing how cybersecurity failures affect individuals and enterprises alike. In the real world, scalable, secure architecture is not about paranoia but Good IT.

Good IT is about establishing standards and controls, enabling technologies to grow stable and scalable while adhering to consistent principles. Organizations rely on diverse systems, making it critical to define “foundational criteria,” allowing each product to retain its unique characteristics while maintaining reliability and security. When these foundations are weak, businesses suffer – outages, cyberattacks, and operational failures disrupting operations, with some companies coming to a complete standstill. Even when technology isn’t the core business, it is the backbone of keeping everything running. We saw this firsthand during the MGM cyberattack, where the inability to check guests in, process transactions, and manage customer service left critical functions paralyzed.

To prevent disruptions, organizations must work closely with cross-functional teams to identify business needs and the technologies enabling their operations. Different business units require different solutions, and establishing clear standards ensures that technologies like third-party applications or internally developed tools are evaluated appropriately. Some areas demand stricter policies, while others require flexibility to foster innovation. By collaborating with technology teams, companies can strike the right balance, enforcing security where necessary without hindering the agility needed for growth.

Automation and adaptability are key to scalability. Standards shouldn’t be static, they should grow with the business. Regular stress testing of our applications for security flaws and performance issues helps identify risks that aren’t always captured in standard frameworks.

Penetration testing is critical to this process, exposing vulnerabilities that may only emerge under certain conditions. Additionally, we collaborate with teams to analyze issues identified through incident response, gaining insights into our environment's active threats and ongoing incidents. These findings feed back into our baseline standards, allowing us to refine and expand them, making every iteration stronger and more secure.

“To prevent disruptions, organizations must work closely with cross-functional teams to identify business needs and the technologies enabling their operations”

Integrating security into the change management process has been one of our most impactful steps, allowing us to track and monitor every change across our environment. This keeps systems aligned with evolving standards and streamlines development, reduces tech debt, and strengthens overall security. It provides clear visibility into modifications, helping teams quickly identify and remediate unintended security gaps before they become larger issues. A well-structured change management process fosters accountability, ensuring every update is reviewed, tested, and documented to maintain system integrity and compliance. A substantial change management process doesn’t just enhance security; it directly contributes to system stability and availability.

Stability and availability go hand in hand with security. We know things will break, and while perfection isn’t attainable, the expectation of near-100% uptime is nonnegotiable. If a single server fails, a customer can’t enter their room, or someone misses a critical moment of their day. These aren’t just minor inconveniences; they’re business-impacting failures. Our responsibility is to build resilient systems to minimize those moments, ensuring we deliver secure, scalable, and supportable services when our customers need them most.

This isn’t always an easy conversation with leadership. Business priorities are often misaligned with what it takes to build secure, scalable systems. Leaders may push for faster timelines and more features, while engineers advocate for stability and thorough testing. Bridging this gap requires open communication and framing the conversation in business terms. Instead of listing risks, we help leadership understand how stability supports innovation. Sometimes, it’s about showing what’s feasible with the given resources and finding the right balance between speed and security.

Ultimately, scalable security is not about layering on complex technologies for their own sake; it’s about simplifying and creating frameworks that allow systems to evolve confidently. When done right, security becomes an enabler, not a barrier. It provides the foundation for innovation thrives, ensuring the business can move forward while protecting what matters most: our customers, services, and reputation.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.