AUDIENCE
For Cultivators
What cybersecurity risks do cannabis cultivators face?
Cultivators carry six recurring exposure points: vendor risk in the climate-control, irrigation, and camera systems that keep a canopy running; operational continuity when one of those systems — or seed-to-sale tracking — goes down mid crop-cycle; seed-to-sale platform dependency on METRC or BioTrack; payment fraud against equipment and nutrient vendors; access control and evidence for badge and camera systems; and a state reporting duty that treats cyber events as a compliance matter, not just an operations one. None of this is an argument for treating grow-facility technology as a specialized OT security problem — it is vendor risk and continuity planning applied to the systems a cultivation license depends on.
Not sure where you stand? Start with the Cannabis Cyber Starter Assessment — a written exposure snapshot and a prioritized next step, not a certification.
Cannabis Cyber Starter Assessment · $750 →THE SIX EXPOSURE POINTS
Where cultivator risk actually sits.
Each one below follows the same shape: what breaks, who owns it today, and what the evidence trail should show if a regulator, an insurer, or your own leadership asks.
Environmental and facility-system vendor risk
Climate control, irrigation, and camera platforms at a grow facility are almost never systems your team built — they belong to a vendor who holds remote access to keep them running. That access is part of your security program whether you manage it or not.
What breaks
A vendor's remote-management portal is compromised, and whoever holds that credential can reach the same climate, irrigation, or camera systems your team relies on every day.
Who owns it today
Usually whichever vendor sold the system, with no one on your side tracking who else can reach it or when access was last reviewed.
What the evidence trail should show
A current list of every vendor with remote access to an environmental or facility system, who owns that relationship, and what you would ask them the day after their name showed up in a breach notice.
On the record
STIIIZY's 2024 breach is the clearest illustration of this pattern, even though it started at a point-of-sale vendor rather than an environmental one: a vendor was compromised, and the incident affected 380,000 people.
The lesson carries over directly — a vendor holding remote access to any system in your building is part of your security program whether you manage its systems or not.
Crop-cycle operational continuity
A dispensary can usually work around a short outage. A cultivator running a live crop cycle has less room — climate control, irrigation, or seed-to-sale tracking going dark for even a few days creates a different kind of exposure.
What breaks
Climate control, the irrigation controller, or seed-to-sale tracking becomes unavailable for 72 hours, and there is no written manual fallback — just whoever happens to be on shift improvising.
Who owns it today
Often nobody in writing. Cultivation staff know the manual workaround exists in someone's head; it is rarely documented as a procedure the whole team can follow.
What the evidence trail should show
A written continuity procedure for each system a crop cycle depends on, when it was last tested, and who is authorized to invoke the manual fallback.
If recovery and continuity planning is the open question, the Ransomware Resilience Audit reviews backups, recovery, and critical-vendor continuity for the systems your crop cycle depends on.
Ransomware Resilience Audit · $4,000 →Seed-to-sale platform dependency
METRC or BioTrack integrations are how the state tracks your plants in real time. They are also an API connection, a set of credentials, and a vendor relationship most cultivation teams never revisit after go-live.
What breaks
An expired API key or a vendor-side outage breaks the seed-to-sale sync — which is not just an inconvenience, it is a compliance-tracking gap the moment it happens.
Who owns it today
Frequently unclear. Compliance staff know the reporting requirement; whoever set up the integration holds the credentials; nobody has mapped who does what when the connection drops.
What the evidence trail should show
Who holds the API keys and how often they rotate, what the fallback process is during an outage, and who is authorized to re-establish the connection.
Equipment and nutrient vendor payment fraud
Lighting, HVAC, nutrient, and equipment vendors get paid by wire or ACH on a recurring basis — which makes every one of those payment threads a target for a forged invoice or a spoofed approval email.
What breaks
A forged payment email — one that looks like it came from your equipment or nutrient vendor, or from your own finance lead — routes a wire transfer to the wrong account before anyone checks.
Who owns it today
Usually IT, but the verification step before a wire or ACH goes out is a governance decision, not just a technical setting.
What the evidence trail should show
MFA enforcement across every account that touches vendor payments, and a documented verification step — a callback to a known number, not a reply to the same email thread — before funds move.
On the record
MariMed's 2023 incident is the anchor here: a forged loan-payment email moved $646,000 to a fraudulent account before anyone caught it. The FBI got involved; MariMed filed a cyber-insurance claim.
The mechanism is identical for a nutrient or equipment vendor payment — a single unverified email is what it costs.
If payment verification and MFA gaps are the open question, the BEC/Phishing Defense Sprint closes that loop — email, identity, and payment-verification controls in one scoped engagement.
BEC/Phishing Defense Sprint · $3,000 →Access control and evidence
Badge systems at the facility entrance, camera retention on the canopy floor, and remote network access for staff and contractors all generate a paper trail — if anyone is keeping it.
What breaks
A regulator or insurer asks who could reach the facility network remotely last month, and the honest answer is that nobody has checked.
Who owns it today
Whoever administers the badge and camera systems, which is rarely the person accountable for producing that record on request.
What the evidence trail should show
A current access list tied to your cultivation license, camera retention settings, and a record of who reviewed remote-access permissions and when.
The reporting obligation
A cyber event at a cultivation facility is not only an operations problem the moment it happens — it is a compliance question, too.
What breaks
The first instinct after an incident is "get the environmental systems back online." That is necessary, but it is not the whole job.
Who owns it today
Often nobody, until the moment it is needed — which is the worst time to figure it out.
What the evidence trail should show
Who owns the incident decision, what gets escalated immediately, current regulator and insurer contacts, and a simple timeline of what happened and when.
Primary source
Connecticut's Department of Consumer Protection expressly includes cyber events, security breaches, and information breaches among the events licensed operators must report.
Backups restore your systems. They don't decide what happened, document the response, or tell you what the state expects next — that's a separate, ownable job.
CT DCP — Summary of updates to policies and procedures ↗THE OWNERSHIP GAP
This isn't about replacing your MSP — or building an OT security program.
None of this means replacing your MSP, and it doesn't mean standing up an industrial-control-systems security program. Your MSP keeps the systems running — that's its job, and it's a real one.
What most cultivators are missing isn't more technology. It's one accountable owner for the program: the vendor relationships behind facility systems, the evidence, and the decision-making when something breaks mid crop-cycle.
The GRC Foundations Retainer is that ownership layer — an ongoing program, a roadmap, and evidence you can hand to a regulator, an insurer, or your own leadership without scrambling to assemble it after the fact.
GRC Foundations Retainer · $1,800/mo →Not ready for an ongoing retainer? The Cannabis Cyber Starter Assessment ($750) is the lower-friction way to see where you actually stand first.
Start with the assessment →Heading into a cyber-insurance renewal? The Insurance Qualification package builds the MFA, EDR, and backup evidence underwriters ask cultivators for before they quote.
Insurance Qualification services →Want to see the full catalog, or talk through which of these fits your cultivation license first?
COMMON QUESTIONS
What cultivators ask first.
Do cannabis cultivators need a CISO?
Most cultivation operations do not need a full-time CISO — but they do need someone accountable for the security program: which vendors hold access to facility systems, where the evidence lives, and who owns each gap. A fractional or vCISO arrangement fills that role without the full-time cost, working alongside your existing MSP rather than replacing it.
Are climate control and irrigation systems a cybersecurity risk?
They are a vendor-risk exposure more than a technical one. Most cultivators do not manage these systems directly — a vendor does, with remote access to keep them running. The exposure is not the equipment itself; it is not knowing who else can reach it, how the vendor secures its own remote-access platform, or what happens to your crop cycle if that access is misused.
What happens to a crop cycle if seed-to-sale tracking or climate control goes down?
That depends entirely on whether a manual fallback exists and is written down. Without one, a 72-hour outage can create both an operational problem and a compliance-tracking gap. A documented continuity procedure — tested before it is needed, not during the outage — is what separates a manageable interruption from a scramble.
Ransomware Resilience Audit →What if a nutrient or equipment vendor's payment email is compromised?
The exposure lands on your business even though the vendor's email account failed, not yours. MariMed lost $646,000 to a forged loan-payment email in 2023. The fix is not avoiding vendor payments — it is enforcing MFA on every account that touches payments and requiring a callback verification, not a reply to the same email thread, before a wire or ACH moves.
BEC/Phishing Defense Sprint →Does a cyber incident at a cultivation facility have to be reported to Connecticut's DCP?
Cyber events, security breaches, and information breaches are explicitly listed among Connecticut's reportable events for licensed cannabis establishments, cultivators included. Whether a specific incident triggers that duty depends on its scope and impact, so this is not legal advice — but treating "was this reportable?" as a first-day question, not an afterthought, is the safer default.
Connecticut cannabis cybersecurity requirements →What's the difference between what an MSP covers and what CannaShield covers?
Your MSP owns infrastructure, support, and uptime — keeping systems running and issues contained technically. CannaShield owns the layer above that: vendor-risk ownership for the facility systems you depend on, control mapping, evidence, and the business decisions leadership needs to make when something breaks. The two roles work together.
This page is practical cybersecurity and GRC guidance for licensed operators. It is not legal advice, and it does not replace a license-specific review with Connecticut counsel or DCP.