Skip to main content

After a breach, regulators audit your compliance program — not your firewall.

CannaShield gives Connecticut cannabis dispensaries, cultivators, processors, and MSOs the vCISO services, GRC frameworks, and cybersecurity assessments to protect operations, strengthen insurance readiness, and produce defensible control evidence.

STIIIZY — 380,000 people notified · MariMed — $646K wired to attackers · MJ Freeway — 14-state outage · Aurora Cannabis — breach disclosed to regulators · Ontario Cannabis Store — customer data leaked ·

Built for the systems that keep cannabis businesses licensed and open.

CannaShield is a Connecticut-based cybersecurity and GRC partner for cannabis operators. We help translate cyber risk into license protection, insurance readiness, downtime prevention, and practical control evidence that executives, brokers, regulators, and investors can understand.

Who we serve

Dispensaries, cultivators, processors, manufacturers, MSOs, and ancillary cannabis operators.

What we protect

Licenses, customer data, patient data, POS systems, email domains, vendor payments, recovery plans, and audit evidence.

How we help

Virtual CISO, GRC programs, cyber insurance readiness, incident response retainers, BEC defense, and ransomware resilience audits.

Three reasons cannabis operators call us.

License Protection

Your MSP handles IT. Nobody owns the written ISP, vendor risk, or audit-ready evidence your regulator wants at renewal.

We deliver NIST CSF 2.0-mapped security programs built for cannabis operators — designed to hold up when your regulator, investor, or acquirer asks for proof.

From $1,800/mo

Explore License Protection →

Insurance Qualification

Premiums went up 40%. Your carrier wants MFA attestation, an IR plan, and EDR proof — or they're non-renewing you.

We prepare the documentation, close the gaps, and sit on the call with your broker so you walk into underwriting with the evidence your carrier is asking for.

From $1,800/yr

Explore Insurance Qualification →

Downtime Prevention

POS goes down and you lose $30,000 a day. STIIIZY scared your board. Someone almost wired $200K to a fake vendor.

Incident response retainers, ransomware resilience audits, and BEC defense sprints — so when it hits the industry, it doesn't shut you down.

From $1,200/mo

Explore Downtime Prevention →

Named. Dated. Documented.

These aren't hypotheticals. These are your peers.

STIIIZY

January 2025

380,000 people notified

Root cause

Third-party POS vendor breach

Patient data, purchase history, ID scans — all exposed.

MariMed

2024

$646,000 wired to attackers

Root cause

Business Email Compromise (BEC)

A spoofed vendor email. One wire transfer. Gone.

MJ Freeway

2018 (industry reference)

14-state operational outage

Root cause

Ransomware destroyed seed-to-sale tracking

Dispensaries couldn't legally sell for days.

Aurora Cannabis

2024

Breach disclosed to regulators

Root cause

Undisclosed network intrusion

Public company. Mandatory disclosure. Brand damage.

Ontario Cannabis Store

2024

Customer data leaked

Root cause

Third-party vendor compromise

Government-run. Still got hit.

Your MSP isn't watching for this. We are.

Find out what's exposed before attackers do.

LIVE

Email Security Scorecard

Enter your domain. Get a report on your DMARC, SPF, and DKIM configuration — and whether attackers can impersonate your brand in 60 seconds.

Free · 90 seconds · No account needed

Check your domain →
LIVE

Attack Surface Snapshot

See what Shodan, certificate logs, and breach databases already know about your business — open ports, exposed subdomains, breach history, and spoofing risk.

Free · 60 seconds · Passive recon only

Run the snapshot →
LIVE

Cannabis Compliance Quick-Check

A Connecticut-focused security-readiness check for cannabis operators. See where your controls need work before renewal, insurance underwriting, or counsel review.

Free · 60 seconds · No account needed

Check your compliance →

Nine services. Priced to move.

LP-1

GRC Foundations Retainer

$1,800/mo

Ongoing

You need a real security program, not a policy folder.

LP-2

State Cannabis Cyber Compliance Audit

$2,500–$4,500

3 weeks

Renewal, expansion, or investor diligence is coming.

LP-3

Schedule III Readiness Assessment

$3,500

2 weeks

Schedule III change creates new control expectations.

IQ-1

Cyber Insurance Readiness Package

$2,500

3 weeks

Your carrier is asking harder questions.

IQ-2

Renewal Defense Pack

$1,800/yr

2 weeks pre-renewal

Renewal is close and the paperwork is stale.

DP-1

Incident Response Retainer

$1,200/mo + $275/hr

Ongoing

You want IR muscle before the weekend call.

DP-2

BEC/Phishing Defense Sprint

$3,000

2 weeks

Finance is one spoofed email from a bad wire.

DP-3

Ransomware Resilience Audit

$4,000

3 weeks

Your POS, backups, and recovery plan need proof.

TOF-1

Cannabis Cyber Starter Assessment

$750

1 week

You need a written snapshot of your exposure before committing to a program.

Not sure which fits? Book a call →

Founder

Alex Castrillo

Cyber incident response analyst · vCISO for cannabis operators

  • Working cyber incident response analyst, NYC
  • NIST CSF 2.0 mapped programs
  • Cannabis-specific GRC & vCISO delivery
  • Connecticut-based, remote-friendly

Built by someone who's been inside the breach.

Alex Castrillo is a working cyber incident response analyst in New York City. He's spent years inside breaches like the one that hit STIIIZY — watching how attackers move, what defenders miss, and why most cannabis operators don't realize they're targets until it's too late.

CannaShield is built around one premise: cannabis operators deserve the same caliber of security leadership that Fortune 500s have, at a price point an SMB can afford.

· NIST CSF 2.0 Mapped· Connecticut-Based

For the professionals who serve cannabis operators.

FOR MSPs

You handle IT. We handle GRC. No competition, no overlap — just stickier clients and 10% of first-year recurring revenue on referred retainers, plus $500 per fixed-fee project.

Become a partner →

FOR INSURANCE BROKERS

Your insureds present stronger, clearer evidence for underwriting — we don't promise coverage or premium outcomes. CannaShield is listed as your preferred remediation vendor.

Become a partner →

FOR LAW FIRMS

Pre-incident hygiene and technical incident-response preparation that outside counsel can structure under privilege.

Become a partner →

WHO WE SERVE

· Cannabis
· Hemp & CBD
· Cannabis-Adjacent SaaS
· Regulated Healthcare-Adjacent

Reviewed guidance for Connecticut operators.

Practical cybersecurity briefings, grounded in primary sources and written for Connecticut cannabis businesses.

Explore the Blog →

Start here / 2026 operator guide

Connecticut cannabis cybersecurity requirements, without the legal fog.

The DCP reporting clocks, tracking-system controls, privacy rules, and evidence your team should have ready before an incident or inspection.

Read the CT guide →

Identity & Fraud

MFA Is Essential, but the Method Matters

Why passkeys and security keys resist phishing better than codes and approval prompts.

Read →

Identity & Fraud

A Familiar Voice Is Not Payment Authorization

How to design payment controls that survive executive impersonation, compromised email, and synthetic audio.

Read →

Vendor & Supply Chain

Manage Outlook Add-Ins Like Connected Applications

Why Microsoft 365 add-ins need an owner, a business purpose, permission review, and centralized deployment.

Read →

Questions cannabis operators ask first.

What does CannaShield do?

CannaShield provides cannabis-specific cybersecurity, virtual CISO, GRC, cyber insurance readiness, incident response, ransomware resilience, and email security support.

Who does CannaShield serve?

CannaShield serves licensed Connecticut cannabis dispensaries, cultivators, processors, manufacturers, MSOs, and ancillary operators.

Does CannaShield replace an MSP?

No. CannaShield works alongside MSPs by owning the cyber risk, compliance evidence, vendor risk, incident response, and board/regulator-facing security program work that many MSPs do not cover.

What is the free Email Security Scorecard?

The Email Security Scorecard checks DMARC, SPF, DKIM, MX, and domain spoofing signals so cannabis operators can see whether attackers can impersonate their business domain.

Find out what's exposed in 90 seconds.

Free. No account. Just your domain.

· NIST CSF 2.0 Mapped · No account required · Results in 90 seconds