Very few cannabis operators need a full-time CISO. Almost all of them need the CISO function — one named person who owns security decisions, vendor risk, incident escalation, and the evidence a regulator or underwriter will ask for. Below roughly $50M in revenue that role is usually filled by a fractional or virtual CISO rather than a salaried executive.
The short version
- The question is not "do we need a CISO." It is "who signs off when security and operations disagree."
- An MSP manages your IT. It does not own your risk decisions, and it will not sit across from your regulator.
- A full-time hire starts to make sense at multi-state scale, a large internal IT team, or investor and audit pressure that runs continuously rather than annually.
What does a CISO actually do that an IT provider does not?
An MSP keeps systems running. A CISO decides what risk the business accepts, and documents why.
Those are different jobs, and the gap between them is where most operators get caught. Your MSP can tell you that MFA is enabled on 40 of 55 accounts. It cannot tell you whether the 15 without it are an acceptable risk given your license, your insurance policy language, and who those users are. It will not build the vendor register, run the tabletop, or decide the notification path when something goes wrong at 9pm on a Saturday.
The practical test: when your POS vendor emails to say they had a security incident, who reads it, decides what it means for you, and owns the response? If the honest answer is "we forward it to IT," you have an IT function and no security function.
At what size does a cannabis operator need dedicated security leadership?
There is no revenue threshold in any regulation. There are practical trigger points, and most operators hit several at once:
- You hold retail customer data — names, dates of birth, ID scans, purchase history — in a system you do not directly control.
- Your cyber insurance application started asking control-attestation questions you cannot answer from memory.
- You are approaching license renewal, an expansion application, or investor diligence.
- You run more than one location, or you have added a delivery, e-commerce, or loyalty platform.
- Someone in finance can move money based on an email.
Hit two of those and the informal arrangement is already failing. You just haven't been tested yet.
What is a virtual CISO (vCISO) and how is it different?
A vCISO is the same accountability, bought by the month instead of by the salary. The person owns your security program, runs on a defined cadence, produces the written artifacts, and is the named contact when a regulator, broker, or counsel asks who is responsible.
What you give up is availability. A fractional engagement is a set number of hours, so the work is prioritized rather than infinite. What you gain is a practitioner who has handled incidents, at a fraction of the cost of a senior security hire — and no recruiting cycle for a role you would struggle to interview for.
Can our compliance officer just take on security?
Partly, and it is often the right starting point — but understand the limits.
Your compliance officer already thinks in terms of evidence, retention, and regulator expectations. That is genuinely half the job, and it is the half most technical people are bad at. What they typically cannot do is evaluate whether a control works: whether the backup actually restores, whether the MFA method resists a real phishing kit, whether the vendor's SOC 2 covers the system you actually use.
The workable split is a compliance officer who owns the program internally, with outside technical judgment on call. What does not work is assigning the title and no time.
Does a cannabis regulator require us to name a security officer?
Not as a universal rule, and you should be suspicious of anyone who tells you otherwise.
Connecticut's cannabis rules concentrate on physical security, inventory control, record integrity, and incident reporting. DCP policies treat certain security incidents as reportable events with tight clocks — a qualifying security breach must be reported no later than the next business day, and related record-loss or alteration events can carry immediate and 24-hour requirements. None of that names a CISO.
What it does is create obligations that need an owner. A next-business-day reporting duty is not something you can improvise. Somebody has to know it exists, know what triggers it, and be reachable.
How does this affect cyber insurance?
Underwriters have gotten specific. Applications now ask whether MFA is enforced on email and remote access, whether endpoint detection is deployed, whether backups are tested and segregated, and whether there is a written incident response plan.
Those questions are warranties. An inaccurate answer can become a coverage argument at the worst possible moment — after a loss, when you need the policy to work. Someone has to be able to answer them accurately and produce the evidence behind each answer. That someone is functionally your CISO, whatever the business card says.
What does the CISO function cost at a small operator?
A full-time security leader is a senior executive hire, plus recruiting, plus the tooling budget they will immediately ask for. That is not a realistic first move for a single-site dispensary or a small cultivator.
Fractional engagements are priced by scope and cadence rather than headcount. CannaShield publishes its own rates — a GRC Foundations retainer at $1,800/month, a one-week Cannabis Cyber Starter Assessment at $750 for operators who want a written picture before committing to anything ongoing. Those are our numbers, not an industry benchmark; use them as one reference point when you compare providers.
What is the smallest useful first step?
Write down three things: who decides, what you would do in the first hour of an incident, and which vendors hold your data.
That is a single page. It will take an afternoon. It is also more security governance than most operators have, and it turns "we should look at security sometime" into a document someone can be handed. Everything else — framework alignment, control testing, evidence binders — builds on top of knowing who is accountable.
Where to go next
- License Protection: written security programs and audit-ready evidence
- What a GRC framework looks like for a cannabis company
- What a vCISO costs for a small cannabis business
