Skip to main content

Cannabis cybersecurity isn't an IT problem. It's a license problem.

STIIIZY: 420,000 customer records leaked. MariMed: $650,000 wired to attackers. Trulieve's customer data is on a dark web leak site right now. CannaShield is the vCISO and GRC partner cannabis operators call when their MSP isn't enough.

STIIIZY — 420,000 records · MariMed — $650K wired · Trulieve — dark web · MJ Freeway — 14-state outage · Aurora Cannabis — breach disclosed · Ontario Cannabis Store — customer data leaked ·

Built for the systems that keep cannabis businesses licensed and open.

CannaShield is a Connecticut-based cybersecurity and GRC partner for cannabis operators. We help translate cyber risk into license protection, insurance readiness, downtime prevention, and practical control evidence that executives, brokers, regulators, and investors can understand.

Who we serve

Dispensaries, cultivators, processors, manufacturers, MSOs, and ancillary cannabis operators.

What we protect

Licenses, customer data, patient data, POS systems, email domains, vendor payments, recovery plans, and audit evidence.

How we help

Virtual CISO, GRC programs, cyber insurance readiness, incident response retainers, BEC defense, and ransomware resilience audits.

Three reasons cannabis operators call us.

License Protection

Your MSP handles IT. Nobody owns the written ISP, vendor risk, or audit-ready evidence your regulator wants at renewal.

We deliver NIST CSF 2.0-mapped security programs built for cannabis operators — designed to hold up when your regulator, investor, or acquirer asks for proof.

Explore License Protection →

Insurance Qualification

Premiums went up 40%. Your carrier wants MFA attestation, an IR plan, and EDR proof — or they're non-renewing you.

We prepare the documentation, close the gaps, and sit on the call with your broker so you pass underwriting and stop overpaying.

Explore Insurance Qualification →

Downtime Prevention

POS goes down and you lose $30,000 a day. STIIIZY scared your board. Someone almost wired $200K to a fake vendor.

Incident response retainers, ransomware resilience audits, and BEC defense sprints — so when it hits the industry, it doesn't shut you down.

Explore Downtime Prevention →

Named. Dated. Documented.

These aren't hypotheticals. These are your peers.

STIIIZY

January 2025

420,000 customer records leaked

Root cause

Third-party POS vendor breach

Patient data, purchase history, ID scans — all exposed.

MariMed

2024

$650,000 wired to attackers

Root cause

Business Email Compromise (BEC)

A spoofed vendor email. One wire transfer. Gone.

Trulieve

2025

Customer data on dark web leak site

Root cause

Ransomware — data exfiltrated before encryption

Active leak site. Customer PII available for purchase.

MJ Freeway

2018 (industry reference)

14-state operational outage

Root cause

Ransomware destroyed seed-to-sale tracking

Dispensaries couldn't legally sell for days.

Aurora Cannabis

2024

Breach disclosed to regulators

Root cause

Undisclosed network intrusion

Public company. Mandatory disclosure. Brand damage.

Ontario Cannabis Store

2024

Customer data leaked

Root cause

Third-party vendor compromise

Government-run. Still got hit.

Your MSP isn't watching for this. We are.

Find out what's exposed before attackers do.

LIVE

Email Security Scorecard

Enter your domain. Get a report on your DMARC, SPF, and DKIM configuration — and whether attackers can impersonate your brand in 60 seconds.

Free · 90 seconds · No account needed

Check your domain →
COMING SOON

Attack Surface Snapshot

See what Shodan, Censys, and breach databases know about your business right now.

COMING SOON

Cannabis Compliance Quick-Check

State-by-state gap analysis against your current cyber posture — CT, NY, MA, IL, CA.

Eight services. Priced to move.

LP-1

GRC Foundations Retainer

$1,800/mo

Ongoing

You need a real security program, not a policy folder.

LP-2

State Cannabis Cyber Compliance Audit

$2,500–$4,500

3 weeks

Renewal, expansion, or investor diligence is coming.

LP-3

Schedule III Readiness Assessment

$3,500

2 weeks

Schedule III change creates new control expectations.

IQ-1

Cyber Insurance Readiness Package

$2,500

3 weeks

Your carrier is asking harder questions.

IQ-2

Renewal Defense Pack

$1,800/yr

2 weeks pre-renewal

Renewal is close and the paperwork is stale.

DP-1

Incident Response Retainer

$1,200/mo

Ongoing

You want IR muscle before the weekend call.

DP-2

BEC/Phishing Defense Sprint

$3,000

2 weeks

Finance is one spoofed email from a bad wire.

DP-3

Ransomware Resilience Audit

$4,000

3 weeks

Your POS, backups, and recovery plan need proof.

View full catalog →

Founder

Alex Castro

Cyber incident response analyst · vCISO for cannabis operators

  • Working cyber incident response analyst, NYC
  • NIST CSF 2.0 mapped programs
  • Cannabis-specific GRC & vCISO delivery
  • Connecticut-based, remote-friendly

Built by someone who's been inside the breach.

Alex Castro is a working cyber incident response analyst in New York City. He's spent years inside breaches like the ones that hit STIIIZY and Trulieve — watching how attackers move, what defenders miss, and why most cannabis operators don't realize they're targets until it's too late.

CannaShield is built around one premise: cannabis operators deserve the same caliber of security leadership that Fortune 500s have, at a price point an SMB can afford.

· NIST CSF 2.0 Mapped· Connecticut-Based

For the professionals who serve cannabis operators.

FOR MSPs

You handle IT. We handle GRC. No competition, no overlap — just stickier clients and 10% recurring revenue share on referrals.

Become a partner →

FOR INSURANCE BROKERS

Your insureds pass underwriting. Fewer claims. CannaShield listed as your preferred remediation vendor.

Become a partner →

FOR LAW FIRMS

Pre-incident hygiene and a technical partner who can work under privilege when something goes wrong.

Become a partner →

WHO WE SERVE

· Cannabis
· Hemp & CBD
· Cannabis-Adjacent SaaS
· Regulated Healthcare-Adjacent

Cannabis cyber intel, decoded.

THREAT INTEL

The supply chain doesn’t end at your loading dock. It stretches into every line of code powering your dispensary and grow operation. When trusted digital infrastructure turns toxic, your entire business is on the line.

The recent Axios supply chain attack is a direct threat to your cannabis license. Axios is the invisible courier connecting your Point of Sale to state...

Read →

THREAT INTEL

The highest walls still have shadows. When news broke that state-sponsored hackers breached the FBI, it sent a shockwave through the cybersecurity world.

If the absolute peak of federal security can be compromised, your 24/7 grow operation is not flying under the radar. The real lesson here isn't about...

Read →

THREAT INTEL

The modern cannabis empire isn’t run from a boardroom. It’s run from an iPhone at 2 AM.

But the glowing screen illuminating the dark can quickly become the biggest threat to your operating license.

Read →

Questions cannabis operators ask first.

What does CannaShield do?

CannaShield provides cannabis-specific cybersecurity, virtual CISO, GRC, cyber insurance readiness, incident response, ransomware resilience, and email security support.

Who does CannaShield serve?

CannaShield serves licensed cannabis dispensaries, cultivators, processors, manufacturers, MSOs, and ancillary cannabis operators.

Does CannaShield replace an MSP?

No. CannaShield works alongside MSPs by owning the cyber risk, compliance evidence, vendor risk, incident response, and board/regulator-facing security program work that many MSPs do not cover.

What is the free Email Security Scorecard?

The Email Security Scorecard checks DMARC, SPF, DKIM, MX, and domain spoofing signals so cannabis operators can see whether attackers can impersonate their business domain.

Find out what's exposed in 90 seconds.

Free. No account. Just your domain.

· NIST CSF 2.0 Mapped · No account required · Results in 90 seconds