Cannabis operators depend on cloud services for email, file sharing, inventory, payments, marketing, and vendor coordination. An incident at one provider can create downstream exposure even when the operator did not cause the original compromise.
What the evidence supports
CISA supply-chain guidance recommends identifying critical suppliers, understanding which systems and data they can access, setting security expectations, and monitoring supplier assurance over time. CISA also provides a vendor-assessment template designed for small and midsize businesses.
Why it matters to a Connecticut operator
The useful question is not whether a vendor claims to be secure. It is whether the operator knows what the vendor touches, what evidence supports the claim, and how the business will continue if that service is unavailable.
Operator checklist
- Maintain a vendor register with service owner, data handled, access level, renewal date, and recovery dependency.
- Prioritize vendors connected to identity, POS, seed-to-sale, payments, and backups.
- Request current assurance evidence and document exceptions instead of relying on sales language.
- Record an alternate process for every vendor whose outage would stop sales or required reporting.
