Treat the POS as license-critical infrastructure, not as a cash register. That means MFA on every account that can reach it, a dedicated network segment, no general web browsing on POS hardware, disciplined patching of the terminals and the tablets, and a written manual-sales procedure for the day it is unavailable. Most POS compromises in this industry arrive through the vendor or through stolen credentials, not through the terminal itself.
The short version
- The POS holds customer identity data, drives your state reporting, and gates lawful sales. Few systems in any industry carry all three.
- A tracking-system outage in Pennsylvania forced dispensaries to turn away patients and close early — no attacker required.
- Segmentation and MFA do more for POS security than any product you can buy this quarter.
Why is a dispensary POS a bigger deal than a normal retail POS?
Because it sits on three fault lines at once.
It holds identity data — the ID scan, the date of birth, sometimes the medical card. It feeds the state tracking system that makes each sale lawful and reportable. And it is the only way product legally moves out the door. A grocery store with a POS outage runs a manual line and reconciles later. A dispensary with a tracking outage may not be able to sell at all.
How do these systems actually get compromised?
Rarely by someone attacking the terminal directly. The realistic paths, roughly in order:
- The vendor. The STIIIZY notice describes a compromise involving a vendor that provided point-of-sale processing for certain retail locations — accounts at that organization were compromised by an organized cybercrime group. Roughly 380,000 people were notified.
- Stolen or shared credentials. A manager login that three people know, no MFA, reused elsewhere and already in a credential dump.
- The back-office computer. Same network, general web and email use, one malicious download away from being a foothold.
- Remote access left open. Support tooling installed during onboarding, never removed, never monitored.
What does network segmentation mean for a dispensary?
Keeping the machines that matter away from the machines that browse the internet.
Practically: POS terminals and payment devices on their own network segment. Guest and customer Wi-Fi completely separate, with no route to anything operational. Cameras, badge readers, and environmental controls on a third segment, because those devices are frequently unpatched and rarely monitored. The back-office computer that handles email and vendor invoices should not be able to reach a POS terminal at all.
This is a configuration change on equipment you already own. It costs an afternoon of your MSP's time and it is the highest-value thing on this page.
Does MFA on POS actually matter?
Yes, and specifically on the accounts that can do damage — administrative logins, reporting access, anything that can modify inventory or export customer records.
Requiring a second factor on every budtender's shift login is friction with limited payoff. Requiring it on the manager account that can pull a customer list is where the value is. If your POS platform does not support MFA on administrative accounts, that is a real finding, and it belongs in your vendor review and your next contract conversation.
How do we handle patching on POS hardware and tablets?
Deliberately, on a schedule, with an owner.
Dispensary floors run on tablets — and tablets are the devices most likely to be quietly running an OS version that stopped receiving security updates eighteen months ago. Inventory every device by model, OS version, and owner. Confirm which ones are still supported. Set a patch window that does not collide with your busiest hours, and get written confirmation from your POS vendor about which OS versions they support, because that constraint often drives the whole plan.
What is the plan when the POS or tracking system goes down?
Written, printed, and rehearsed — because this happens without any attacker involved.
When MJ Freeway's Leaf Data Systems failed during a software update in Pennsylvania, dispensary staff could not enter received shipments, one retailer turned away hundreds of patients, cultivators could not create manifests, and stores closed early with significant lost sales. The company put the outage at about an hour and a half of sporadic downtime; the Philadelphia Inquirer reported dispensaries unable to sell for hours.
Your plan should answer: who declares the outage, what is the manual sales procedure and is it lawful in your state, who contacts the regulator and when, how transactions get reconciled into the tracking system afterward, and who tells customers. Print it. A plan stored only in the system that is down is not a plan.
How much of this can our POS vendor answer for us?
Some of it, if you ask precisely.
Useful questions to send in writing: Does your platform support MFA on administrative accounts? Where is our data stored and who at your company can access it? What is your notification commitment to us after a security incident, in hours? What current security assurance can you provide, and what does its scope actually cover? Can we export our data if we leave?
File the answers. Vague replies are themselves an answer, and they belong in your vendor register with a review date.
What should we fix first?
Segment the network, then turn on MFA for every administrative account, then write the outage procedure.
Those three take days rather than months, need no new budget in most cases, and address the paths that incidents actually take. Everything more sophisticated — monitoring, detection tuning, threat hunting — assumes these are already done.
Where to go next
- Does PCI compliance apply to your dispensary?
- What happens when a cannabis company gets breached
- Downtime Prevention: ransomware resilience and IR retainers
