Skip to main content
← Back to blog

How Do You Protect a Cannabis POS System From Attackers?

Your point-of-sale system is the one machine that can stop lawful sales, expose customer records, and break your state reporting at the same time. Here is how to defend it.

By Alex Castrillo8 min readFact-checked September 6, 2026
CannaShield answer page: protecting cannabis point-of-sale systems from hackers

Treat the POS as license-critical infrastructure, not as a cash register. That means MFA on every account that can reach it, a dedicated network segment, no general web browsing on POS hardware, disciplined patching of the terminals and the tablets, and a written manual-sales procedure for the day it is unavailable. Most POS compromises in this industry arrive through the vendor or through stolen credentials, not through the terminal itself.

The short version

  • The POS holds customer identity data, drives your state reporting, and gates lawful sales. Few systems in any industry carry all three.
  • A tracking-system outage in Pennsylvania forced dispensaries to turn away patients and close early — no attacker required.
  • Segmentation and MFA do more for POS security than any product you can buy this quarter.

Why is a dispensary POS a bigger deal than a normal retail POS?

Because it sits on three fault lines at once.

It holds identity data — the ID scan, the date of birth, sometimes the medical card. It feeds the state tracking system that makes each sale lawful and reportable. And it is the only way product legally moves out the door. A grocery store with a POS outage runs a manual line and reconciles later. A dispensary with a tracking outage may not be able to sell at all.

How do these systems actually get compromised?

Rarely by someone attacking the terminal directly. The realistic paths, roughly in order:

  • The vendor. The STIIIZY notice describes a compromise involving a vendor that provided point-of-sale processing for certain retail locations — accounts at that organization were compromised by an organized cybercrime group. Roughly 380,000 people were notified.
  • Stolen or shared credentials. A manager login that three people know, no MFA, reused elsewhere and already in a credential dump.
  • The back-office computer. Same network, general web and email use, one malicious download away from being a foothold.
  • Remote access left open. Support tooling installed during onboarding, never removed, never monitored.

What does network segmentation mean for a dispensary?

Keeping the machines that matter away from the machines that browse the internet.

Practically: POS terminals and payment devices on their own network segment. Guest and customer Wi-Fi completely separate, with no route to anything operational. Cameras, badge readers, and environmental controls on a third segment, because those devices are frequently unpatched and rarely monitored. The back-office computer that handles email and vendor invoices should not be able to reach a POS terminal at all.

This is a configuration change on equipment you already own. It costs an afternoon of your MSP's time and it is the highest-value thing on this page.

Does MFA on POS actually matter?

Yes, and specifically on the accounts that can do damage — administrative logins, reporting access, anything that can modify inventory or export customer records.

Requiring a second factor on every budtender's shift login is friction with limited payoff. Requiring it on the manager account that can pull a customer list is where the value is. If your POS platform does not support MFA on administrative accounts, that is a real finding, and it belongs in your vendor review and your next contract conversation.

How do we handle patching on POS hardware and tablets?

Deliberately, on a schedule, with an owner.

Dispensary floors run on tablets — and tablets are the devices most likely to be quietly running an OS version that stopped receiving security updates eighteen months ago. Inventory every device by model, OS version, and owner. Confirm which ones are still supported. Set a patch window that does not collide with your busiest hours, and get written confirmation from your POS vendor about which OS versions they support, because that constraint often drives the whole plan.

What is the plan when the POS or tracking system goes down?

Written, printed, and rehearsed — because this happens without any attacker involved.

When MJ Freeway's Leaf Data Systems failed during a software update in Pennsylvania, dispensary staff could not enter received shipments, one retailer turned away hundreds of patients, cultivators could not create manifests, and stores closed early with significant lost sales. The company put the outage at about an hour and a half of sporadic downtime; the Philadelphia Inquirer reported dispensaries unable to sell for hours.

Your plan should answer: who declares the outage, what is the manual sales procedure and is it lawful in your state, who contacts the regulator and when, how transactions get reconciled into the tracking system afterward, and who tells customers. Print it. A plan stored only in the system that is down is not a plan.

How much of this can our POS vendor answer for us?

Some of it, if you ask precisely.

Useful questions to send in writing: Does your platform support MFA on administrative accounts? Where is our data stored and who at your company can access it? What is your notification commitment to us after a security incident, in hours? What current security assurance can you provide, and what does its scope actually cover? Can we export our data if we leave?

File the answers. Vague replies are themselves an answer, and they belong in your vendor register with a review date.

What should we fix first?

Segment the network, then turn on MFA for every administrative account, then write the outage procedure.

Those three take days rather than months, need no new budget in most cases, and address the paths that incidents actually take. Everything more sophisticated — monitoring, detection tuning, threat hunting — assumes these are already done.

Where to go next

Scope note: This page is practical cybersecurity and GRC guidance for licensed cannabis operators. It is not legal advice, and it does not claim that every recommended control is expressly required by a cannabis regulator. Confirm how each obligation applies to your business with counsel.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.

GRC & Frameworks

Cannabis Cybersecurity Checklist for 2026

Twelve controls, ordered by what actually prevents loss, with the evidence each one should produce. Built for operators who have limited hours and need to spend them well.

Compliance & Licensing

Cannabis Data Privacy Requirements by State

A method for reading any state’s obligations, plus what applies in Connecticut, New York, Massachusetts, New Jersey, and Illinois. Verify the details with counsel before you rely on them.

Security Leadership

Do Cannabis Companies Need a CISO?

Most licensed operators do not need a full-time CISO. They do need someone accountable for security decisions. Here is how to tell which one you are.