How Maryland Cannabis Businesses Can Strengthen Cybersecurity in 2026 

Maryland’s cannabis market has moved fast. Adult-use sales went live on July 1, 2023, and the market has been building steadily ever since, with new dispensaries, new cultivation licenses, new processors coming online, more competition, more data, and more exposure. What hasn’t kept pace in a lot of operations is the security infrastructure sitting underneath all of it. 

That’s not a knock on operators. The regulatory load in this industry is genuinely heavy, and it’s easy to treat cybersecurity as something to get to once the build-out is done, the license is active, and the POS is running. The problem is that by the time most businesses think seriously about it, the exposure is already there. 

Why Is the Cannabis Industry Such a Consistent Target for Cyberattacks? 

Cannabis businesses hold an unusually concentrated mix of sensitive data. A single dispensary transaction can touch a customer’s government ID, date of birth, medical cannabis card, purchase history, and payment details, all in one interaction. Multiply that across thousands of customers and you have a data profile that cybercriminals find genuinely valuable, not just as an abstract target but as something they can monetize directly through identity theft, extortion, or sale on dark web markets. 

What makes it worse is that many operators are still running security programs built for compliance rather than for actual threat defense. The two are not the same thing. 

The STIIIZY breach in late 2024 made this gap very visible. STIIIZY, one of California’s largest cannabis brands, officially notified 380,000 customers that their personal data had been compromised. The attack was attributed to the Everest ransomware group, and the breach didn’t originate inside STIIIZY’s own systems. It came through a point-of-sale processing vendor. The company learned about it roughly a month after it started. 

That vendor-entry pattern was the defining characteristic of cannabis cyberattacks throughout 2025. In incident after incident, the breach began not with the cannabis operator but with a marketing platform, a third-party analytics tool, or an outsourced IT provider, often one that had been given access and then never had it revoked. Some operators found out from regulators. Others found out from customers. 

The financial damage from a breach is significant regardless of how it happens. The average cost of a ransomware incident now sits at $4.6 million, and for a cannabis business in Maryland, the consequences can definitely go beyond the financial. A serious incident can trigger license review by the Maryland Cannabis Administration. That turns a cybersecurity problem into an existential business problem. 

What Does Maryland Law Actually Require and Where Does It Leave Gaps? 

The MCA’s regulations under COMAR Title 14.17 cover physical security in real detail. Dispensaries must operate 24/7 motion-activated surveillance with high-definition cameras. Video must be retained for a minimum of 90 days and made available within 48 hours of a regulator request. Restricted zones like vaults, storage areas, and surveillance monitoring rooms, require access control systems with logged entry records. Intrusion detection systems with backup power are mandatory. And every licensee, without exception, must participate in METRC, Maryland’s seed-to-sale tracking platform, logging every cannabis movement from cultivation through final sale. 

That’s a meaningful compliance floor. What it doesn’t address is the digital infrastructure sitting on top of it. 

There are currently no MCA-mandated requirements for multi-factor authentication, network segmentation, data encryption standards, or written incident response plans. As legal observers have noted, many states require strict reporting for inventory tracking while leaving data security largely to operator discretion. Maryland is in that category. 

That gap has gotten more consequential in 2026, because two Maryland privacy laws now apply directly to cannabis operators, and most haven’t fully absorbed either of them. 

The first is Maryland’s Personal Information Protection Act (PIPA), which has required breach notification within 45 days of discovery for years. If a breach occurs, Maryland operators must notify affected residents and the Office of the Attorney General within that window, before sending notice to consumers. If the breach involves more than 1,000 individuals, the major consumer reporting agencies must also be notified. 

The second is the Maryland Online Data Privacy Act (MODPA), which took effect October 1, 2025, with active enforcement beginning April 1, 2026. MODPA imposes data minimization requirements. Businesses can only collect and retain personal data that is genuinely necessary for the transaction, and requires opt-in consent for sensitive data categories. Given that cannabis dispensaries routinely collect government IDs and medical cannabis card information, this law is directly relevant. Violations carry penalties of up to $10,000 for an initial offense and $25,000 for repeat violations, enforced by the Maryland Attorney General. 

A quick side-by-side of what’s required versus what good practice looks like: 

Area MCA Required Cybersecurity Best Practice 
Video surveillance 24/7 HD, 90-day retention Encrypted cloud storage, tamper-evident audit logs 
Access control Restricted zone entry logs Role-based access + MFA on all digital systems 
METRC tracking Full seed-to-sale participation Secured API keys, SSO, monitored audit logs 
Data collection Not specified by MCA MODPA data minimization — collect only what’s necessary 
Breach response 45-day notification under PIPA Written IR plan, tabletop drills, cyber insurance 
Vendor oversight Not specified SOC 2 reviews, access termination at contract end 
Employee screening Criminal background check via CJIS Least-privilege access, same-day offboarding protocol 

What Are the Actual Threats Maryland Operators Need to Plan For? 

Generic threat lists aren’t that useful. What’s more useful is understanding where attacks in this industry actually originate, based on what happened across the sector in 2024 and 2025. 

Ransomware via POS Systems 

Point-of-sale systems are among the most frequently exploited entry points in cannabis operations. Attackers in 2025 repeatedly targeted known vulnerabilities in POS software that operators had delayed patching, often because they were nervous about disrupting active operations mid-cycle. That hesitation is understandable and also dangerous.  

A locked POS during business hours doesn’t just create an IT ticket. It stops every transaction until it’s resolved, and a prolonged outage means both lost revenue and potential compliance issues with METRC reporting. 

Third-Party and Vendor Compromise 

Cannabis operations rely on an ecosystem of vendors covering POS providers, METRC integrators, loyalty platforms, e-commerce tools, and delivery apps, many of which weren’t built with cannabis-specific regulatory sensitivity in mind. In multiple documented 2025 incidents, the breach path ran through a vendor that still had active system access long after their contract had ended. Nobody had formally deprovisioned them. 

Phishing and Business Email Compromise 

Employees remain one of the most reliably exploited vectors across every industry, and cannabis is no different. A Business Email Compromise incident flagged by the Cannabis ISAO involved a cash management company that received fraudulent wire transfer requests following a phishing compromise. A similar attack later hit MariMed, resulting in losses of nearly $650,000. High employee turnover, a persistent reality in cannabis retail, compounds this risk because new staff haven’t been trained yet and departing staff may still have active credentials. 

METRC and Seed-to-Sale Exposure 

Because METRC participation is mandatory for all Maryland licensees, it represents a shared point of potential vulnerability across the industry. API keys and user credentials for METRC integrations are frequently poorly managed, either they are reused, shared informally, or left active after a staff change. Seed-to-sale systems contain sensitive operational data but are rarely monitored with the same scrutiny as financial platforms, which creates blind spots that aren’t obvious until after something goes wrong. 

How Do You Actually Build a Security Program That Works? 

The instinct to treat cybersecurity as a checklist is understandable. This industry runs on compliance checklists. But a checklist completed once isn’t a security program. Here’s a practical approach to building something that actually reduces risk. 

Step 1: Start with a Risk Assessment 

Before spending money on tools, understand what you have and where the exposure is. Map every system that touches sensitive data. This would include POS, METRC, surveillance, email, HR platforms, and loyalty programs. Review which third-party vendors have access and whether that access is current, scoped appropriately, and documented. Look at your network architecture: is the guest Wi-Fi isolated from operational systems? Identify software and firmware that hasn’t been updated recently, especially on POS and cultivation hardware. 

Step 2: Lock Down Identity and Access 

This is the highest-leverage intervention most operators can make. Implement multi-factor authentication on every system that holds sensitive data like POS, METRC, email, cameras, and HR platforms. Use single sign-on (SSO) where possible to create a consistent audit trail and reduce password sprawl. Review access privileges at least every 90 days, and build an offboarding protocol that immediately revokes credentials the same day an employee leaves. 

Step 3: Segment Your Networks 

A flat network, where the guest Wi-Fi, POS terminals, surveillance cameras, and back-office systems all share the same network, is one of the most common and most preventable vulnerabilities in cannabis operations. If an attacker gets onto the guest network, they shouldn’t be able to pivot to the POS or the METRC integration. Segmenting networks isn’t technically complex, but it does require intentional configuration and someone to verify it’s actually working. 

Step 4: Protect and Test Your Backups 

Configure immutable backups for POS databases, METRC logs, and surveillance data. Immutable means the backup can’t be modified or deleted by ransomware. It’s a write-once copy stored separately from production systems. Test restoration at least quarterly. A backup that’s never been tested is a backup you can’t rely on when you need it. 

Step 5: Apply MODPA-Aligned Data Minimization Now 

With MODPA enforcement now active, Maryland cannabis businesses should audit what personal data they’re actually collecting and retaining. The rule is straightforward: don’t keep what you don’t need. If you’re holding customer government IDs and medical card information, that’s sensitive data under MODPA, and collecting it without a clear operational necessity creates both legal and security exposure. Less data retained means less data at risk. 

Step 6: Take Vendor Risk Seriously 

Develop a vendor review process that goes beyond general questions about security policies. Ask specifically how access to your systems is provisioned and deprovisioned. Request their SOC 2 Type II report if one exists. Confirm their breach notification timeline and what they’re obligated to tell you if something goes wrong. When contracts end, don’t assume access has been revoked. Verify it. Review vendor access at least annually. 

Step 7: Train Staff in Short, Regular Doses 

Annual security awareness training is better than nothing, but it fades fast. Brief monthly touchpoints, like a quick email about a real phishing trend that hit another dispensary, or a five-minute standup noting a recent industry incident, build more durable awareness than a once-a-year module that people click through while watching something else. The goal is a team that feels comfortable flagging suspicious emails rather than embarrassed about almost clicking on one. 

Step 8: Write the Incident Response Plan Before You Need It 

A breach in Maryland triggers more than an IT cleanup. Under PIPA, operators have 45 days from discovery to notify affected residents and the Maryland Attorney General. If medical cannabis patient records are involved, HIPAA considerations may also apply. MODPA adds its own notification and documentation obligations. Assign clear roles before an incident happens. Run a tabletop exercise at least once a year where the team walks through a realistic scenario: who calls whom, what gets preserved, what gets communicated to the MCA. The best time to figure out your incident response is not the moment it’s actually needed. 

What Does a Layered Security Program Look Like in Practice? 

Defense in depth, using overlapping security controls so no single failure creates a total compromise, is the right mental model for cannabis operations. Think of it in three layers: 

Layer 1: Physical Security (MCA Mandated)  

24/7 HD surveillance, 90-day retention, controlled access zones, alarm systems with backup power, full METRC participation. This is the compliance floor, and it needs to be solid. 

Layer 2: Network and Endpoint Security  

MFA on all systems, network segmentation, endpoint protection across all devices, mobile device management, immutable cloud backups, patched and updated software with a defined patch schedule. 

Layer 3: Detection, Response, and Insurance  

Centralized audit log monitoring through a SIEM that alerts on anomalous admin activity. A documented, tested incident response plan. Cyber liability insurance sized to your data exposure. Participation in the Cannabis ISAO for shared threat intelligence across the industry. 

Is Cyber Insurance Worth It for Maryland Cannabis Operators? 

The math is not complicated. The average data breach costs $4.6 million. A meaningful cyber liability policy for a small-to-mid cannabis operator is a fraction of that annually. And given that Maryland dispensaries are collecting government IDs, purchase histories, and in many cases medical patient records, all of which carry legal exposure under PIPA, MODPA, and potentially HIPAA, the liability profile is real. 

There’s also a practical incentive: insurers increasingly require evidence of security controls before issuing or renewing coverage. They ask about MFA deployment, network segmentation, backup practices, and whether an incident response plan exists. Operators who can demonstrate those controls get better rates. The process of qualifying for coverage is itself a useful diagnostic. It surfaces gaps you might not have otherwise noticed. 

What Should Maryland Operators Be Watching Right Now? 

The regulatory picture is actively shifting. The MCA is currently reviewing proposed amendments to COMAR 14.17, with formal public comment expected to open later in 2026. Operators should monitor those amendments closely. Increased attention to data security practices is a reasonable expectation as the market matures, and the MCA sees more compliance data from the industry. 

MODPA enforcement is now live as of April 1, 2026. If your business processes personal data of 35,000 or more Maryland consumers annually, or derives more than 20% of gross revenue from selling personal data and processes data of at least 10,000 consumers, you’re covered by the law. For most active dispensaries, that first threshold isn’t hard to reach. 

The businesses that will be best positioned going forward from a licensing, reputational, and financial standpoint, are the ones treating cybersecurity as an ongoing operational discipline rather than a one-time project. That means knowing where your data lives, controlling who can access it, keeping current with regulatory changes, and having a tested plan ready when something goes wrong. 

Cure8 is a cannabis IT and security partner with a track record of helping Maryland dispensaries, growers, and distributors stay secure and compliant. If you’re not sure where your current program stands, a structured security assessment is the right place to start. For any questions about your current security posture, contact us today. 

Tags