Two clocks start at once. Connecticut DCP policies can require a qualifying security breach to be reported by the next business day, while Conn. Gen. Stat. § 36a-701b drives notice to affected residents and the Attorney General on its own schedule. Meanwhile you are trying to keep selling. Operators who have not decided in advance who declares an incident and who calls counsel lose the first day to that question alone.
The short version
- The regulatory clock and the breach-notification clock are separate obligations with separate triggers.
- Call counsel before the forensic firm. Privilege is easier to establish at the start than to reconstruct later.
- MariMed disclosed a $646,000 loss from a single forged email with false banking instructions — no malware required.
What counts as a breach?
Two different definitions apply to you, and they do not overlap neatly.
For state cannabis purposes, DCP policies treat certain physical and cyber security incidents as reportable events — a category that can include things that never touched personal data at all, such as loss or alteration of licensee records.
For breach-notification purposes, § 36a-701b turns on unauthorized access to covered personal information about Connecticut residents, with encryption status factoring into the analysis.
An event can trigger one, both, or neither. Deciding which is a legal determination, which is why counsel gets involved early rather than after you have already filed something.
What should happen in the first hour?
Five things, and the order matters:
- Someone declares it. A named person with the authority to say "this is an incident" and start the process. Without this, everyone waits for someone else.
- Preserve, don't wipe. The instinct to reimage the machine destroys the evidence you will need to determine what was accessed — which is the fact that drives every notification decision.
- Contain what you can safely contain. Disable compromised accounts, revoke sessions, isolate affected devices from the network.
- Call counsel. Before the forensic firm, so that the investigation can be structured appropriately from the start.
- Start the log. Times, decisions, who was told what. You will be asked to reconstruct this later, under pressure, by people with subpoena power.
Do we have to tell the regulator before we know what happened?
Often, yes — and this is the part that catches operators off guard.
A next-business-day reporting duty does not wait for your forensic report. You may be reporting that an incident occurred while the investigation is still in its first day. That is normal, and it is why the initial report should be accurate about what you know and honest about what you do not.
The failure mode is speculation. Reporting a preliminary scope that later turns out to be wrong in either direction creates its own problems. "We are investigating unauthorized access to X system and will supplement" is a complete and defensible report.
When do customers have to be notified?
When the breach-notification analysis says so, on the statutory timeline in § 36a-701b, with notice also going to the Connecticut Attorney General. The Attorney General's office publishes reporting guidance and a submission process.
The practical bottleneck is almost never the drafting. It is determining who to notify — which requires knowing exactly which records were accessed, which requires forensics, which requires the evidence you preserved in hour one. Operators who reimaged the machine spend weeks trying to answer a question they made unanswerable.
What does business email compromise look like here?
It looks like an ordinary Tuesday, which is the problem.
MariMed disclosed in a quarterly filing that it lost $646,000 after receiving a forged email containing false banking instructions — a Chase account number supplied for what appeared to be a legitimate term-loan payment. The company described it as "a very sophisticated, global fraud that we believe took months of planning," said it initially caught the problem, and reported that the bank later confirmed the funds had reached the fraudulent recipient's account.
No ransomware. No breached server. One email, one wire, and a public company disclosure. This is the most likely six-figure cyber loss a cannabis operator will experience, and the control that stops it is a callback procedure to a known-good phone number for every banking-detail change — not a security product.
Can a breach cost us our license?
Be careful with this claim, including when you hear it from a vendor.
A data breach is not automatically a licensing violation. What creates licensing exposure is the surrounding conduct: failing to report a reportable incident inside the required window, being unable to produce required records, or an inability to demonstrate the controls your own policies say you maintain.
Framed correctly: the breach is a bad day. The unreported breach, or the breach you cannot explain because you have no records, is the license problem. That distinction should shape where you spend your preparation effort.
What does the year after look like?
Longer and more expensive than the incident itself.
Expect some combination of: forensic and legal costs, notification and credit monitoring for affected individuals, regulator follow-up, insurance claim administration, class action exposure, and remediation work that got deferred for years and now has a deadline. The STIIIZY incident produced consumer class litigation in federal court following its January 2025 notifications.
Underwriters will also want to know what changed. A renewal after an incident goes better when you can show a remediation plan with dates and owners rather than a promise to do better.
What should we have ready before any of this happens?
A one-page card, printed, in the manager's office and in your own wallet:
- Who declares an incident, and their mobile number
- Counsel's after-hours number
- Your cyber insurance carrier's incident hotline and the policy number — most policies require prompt notice and may require you to use panel vendors
- Your IT or MSP escalation path
- The DCP reporting contact and the next-business-day requirement, written out
- Your POS and seed-to-sale vendor support lines
Every item on that list is knowable today and unknowable at 11pm on a holiday weekend. CISA's ransomware guidance is a good structure for the fuller plan that sits behind the card.
Where to go next
- Connecticut cannabis cybersecurity requirements
- How cannabis businesses protect customer data
- Downtime Prevention: incident response retainers and BEC defense
