ABOUT
Who's actually doing the work
CannaShield is a practice, not a rebranded IT shop. One person's name is on it, and that's deliberate: the work is judgment work. Deciding what a finding means for your license, your renewal, and your Tuesday morning isn't something you can put in a ticket queue.
Alex Castrillo, Founder
I do incident response for a living. In-house, for a national identity and security company in New York City, on a team that gets the alert before anyone outside the building knows there was one. Since 2023 that's been the job: figure out what happened, find out what evidence exists, decide who needs to be told, and do it while the clock is running.
Then I come home to Connecticut, where the operators I work with have the same exposure and almost none of the same resources.
That gap is the whole reason CannaShield exists. Nearly every licensed operator in this state has an MSP, and most of them are fine at what they're hired to do. What's missing is someone who owns the layer above it — what controls are expected, which ones are actually running, where the proof lives, which vendor owns each gap, and what leadership can truthfully say to DCP, an underwriter, or counsel when they ask.
Credentials
Certifications
- SSCP — ISC2 Systems Security Certified Practitioner
- Tines Expert Builder — security automation and response workflow design
- AWS Security Specialty — in progress
Practice areas
- SIEM and detection engineering — writing, tuning, and triaging the rules that decide what gets escalated
- Vulnerability management — finding, prioritizing, and tracking exposure to closure rather than to a report
- Incident response — live investigation, evidence handling, and the reporting decision that follows
- Cloud security — posture, identity, and workload exposure in AWS environments
- NIST CSF 2.0 program design — the framework behind every program CannaShield builds and maps evidence to
Working practitioner since 2023. That's why CannaShield findings name the control and the system rather than stopping at "improve your security posture."
What I don't claim
This section exists because the cannabis security market is full of people who will tell you anything. Here's the boundary:
- I wasn't inside the STIIIZY breach. I read the attorney general notices, the same as anyone can. What I bring is knowing how to read them.
- I can't guarantee your license, your coverage, or your premium. Nobody can. What I can build is the evidence that makes those conversations go better.
- I'm not your lawyer, your broker, or your regulator. When a question belongs to one of them, I'll say so and help you frame it.
- I'm not replacing your MSP. They own systems, uptime, and support. I own the program, the evidence, and the decisions.
- No framework is required to hold a cannabis license in Connecticut. Anyone telling you NIST or SOC 2 is mandated for licensure is selling you something. The obligations that do exist are narrower, and worth knowing exactly.
Why a practitioner instead of a firm
Enterprise vCISO firms are real, and for a 400-person MSO they may be the right call. For a single-site or growing multi-site operator, they tend to arrive with a maturity model, leave a document set, and bill for the meetings in between.
What a working analyst brings is different. I've watched enough real incidents to know which findings actually change an outcome and which ones just fill a report. That shows up as shorter deliverables, fewer recommendations, and a roadmap you can finish.
It also means direct access. You get me, not a delivery pod.
Where CannaShield works
Connecticut, primarily. The state's Department of Consumer Protection lists cyber events — including security and information breaches — among reportable events for licensed establishments, and CT-specific delivery is where the work is validated.
Operators in other states can still get value from an assessment, but out-of-state regulatory content is orientation, not a legal mapping, and I'll flag where local counsel needs to weigh in.
Start somewhere small
The Cannabis Cyber Starter Assessment ($750) is a written exposure snapshot and a prioritized next step. Not a certification, not a retainer commitment — a clear picture of what's exposed and what to do first.