Tag Archives: theft

Processes, Protocols and Layers of Protection: Essential Security Measures for the Medical Cannabis and Hemp Industries

By Joshua Wall
No Comments

As legalization of cannabis products from hemp to medical cannabis takes root across the U.S., there’s a growing need to understand and build good security practices. While many think of security as safeguarding assets like facilities and product, effective security does much more. It protects a business’ workers, providing them secure workplaces and incomes. Ideally, it reaches from supply chain to customers by ensuring consistently safe products.

To truly understand the value of this for a brand or for the industry as a whole, consider the opposite: the destructive effect – on a brand and on the industry at large – of unsafe or tampered product reaching customers, or of crimes occurring, just as the industry seeks to demonstrate its validity and benefits. Security is vital not only to individual farmers, processors or customers but to all who value what the industry brings to those who rely on CBD or medical cannabis products for their wellbeing.

Know the Threats.

Part of the learning process involves understanding the value of the product.Security is all about anticipating and reducing risks. These can include physical threats from natural sources – think flood, fire, tornado or crop fail – or from human threats. Human threats can arise from organized criminals, hackers, amateur thieves, vandals – or insiders.

As regulated industries, hemp and cannabis businesses also face risk of losses, which can be significant, from penalties ranging from fines to being shut down for non-compliance. While rules vary from state to state and continue to change, a disciplined approach to security is foundational to reducing risk at many levels. Rigorous operational processes must incorporate security that addresses risks at multiple points of access, transport and sale of products.

Learn the Rules.

In a rapidly evolving industry, one of the most important things producers can do is to learn. Security requirements vary by region and providers need to be aware of what is available. Get to know your state, local and federal resources for your operating area. California law, for example, specifies use of high-resolution video surveillance in dispensaries, while others do not.

Joshua Wall, Chief Operating Officer at Harvest Connect LLC

Part of the learning process involves understanding the value of the product. With medicinal cannabis, it’s helpful to grasp both its commodity value and the street value that could make it attractive to thieves. In “Why Marijuana Plant Value is So Important for Adjusters,” Canadian Underwriter Magazine gave examples that indicate the size of losses that may occur in growing and processing operations:

“In the medical marijuana space, ClaimsPro has already seen losses primarily between $150,000 and $750,000. These losses, mostly on Vancouver Island, were for fire and water damage, as well as boiler machinery issues, physical damage to buildings and specialized greenhouse equipment, as well as extra expense and business interruption.”

The same article notes a claim over $20 million at another single flower greenhouse. Security needs to reflect what’s present on our premises.

Educating the community can reduce risk as well. Producers of industrial hemp may need to inform would-be thieves that what they are looking at is not street-valued product. To protect the crops, which are generally grown outdoors and do not require a full security detail, a best practice is simply posting signs on the property that say explicitly “No THC.” 

Begin with a Risk Assessment.

Security begins with a professional evaluation of site vulnerabilities, examining key weaknesses that could be exploited by attackers. These include:

  • Monitoring access to the site is a foundational principle of security.
  • Design limited access points into the facility as well as prepare for possible facility breaches with perimeter access control, technological redundancies and ballistic glass for defensive architecture measures.
  • Look at route vulnerabilities as well.
  • Hedge site risk by not limiting your operation to a single site where one incident could wipe out an entire year’s crop.

The nature of threats is always changing. A 2018 Newsweek article described the struggles of legal cannabis farmers against illegal and potentially cartel-backed and violent operations in California. While a 2020 Business Insider report described indications that legalization was prompting some cartels to leave cannabis alone and move on to fentanyl and meth. “While Mexican drug cartels made their money predominantly from marijuana in past decades, the market has somewhat dissipated with the state-level legalization of cannabis in dozens of states across the US.”

Define Levels of Risk and Access.

The best security matches spending to risk in a commonsense way. Are you more at risk from the occasional smash and grab incident or is there reason to anticipate an organized assault? As in many industries, the greatest risk often comes from employee fraud or theft. Hiring carefully, paying fairly and training staff well are important to long term security.

Iron Protection Group in a training session
Image credit: Tampa Bay Times

How will the product be moved around within the facility and beyond it – and what staff are responsible for each part of the journey? Who can enter the cultivation areas and what protocols must they follow? On site staff should be trained on what to look for if they observe a security breach. Consider biometrics such as retinal scans, fingerprint scans or similar.

In cases where valuable product or cash is present, guards can play an important role. Harvest Connect uses only high-level former military or police officers in these roles, an approach recognized by many. Hunter Garth of Iron Protection Group notes they have “the ability to de-escalate a potentially harmful situation and the fortitude to see a mission through to completion, no matter what external circumstances may arise.”

Inventory and Transaction Controls

Inside threats from sloppy processes can be just as insidious as attacks. Poor tracking of inventory by Oregon’s legal cannabis producers made headlines in 2018 as The Oregonian reported, “U.S. Attorney Billy Williams told a large gathering that included Gov. Kate Brown, law enforcement officials and representatives of the cannabis industry that Oregon has an ‘identifiable and formidable overproduction and diversion problem.’’ Discipline, applied by state pressure but carried out by producers themselves, has begun to reduce the diversion of untracked product into the black market a year later.

Cannabis businesses need a professional approach to monitoring all product and money that moves through its systems. These operational processes can include time, date and attendance stamps on all inventory. Similarly, accounting systems and software must follow the highest professional standards. Lastly, when breaches occur, it is essential that fraud and theft are caught, eliminated and prosecuted as appropriate.

Nurturing an Emerging Industry

Security resources are an integral part of maintaining the integrity of a business’ supply chain. As the product moves from the fields to processing centers to consumers, purity assurance becomes an operational objective. Ultimately, protecting the product through secure and professional practices is the optimal way to serve customers, build a brand, and sustain the industry.

Transporting Cannabis Can Be a Costly Business Risk

By Susan Preston, T.J. Frost
1 Comment

Did you know that the use of personal vehicles for transporting cannabis products is one of the most frequent claims in the cannabis industry? It surpasses property, product liability and even theft. Businesses are either unaware of the risks involved in using personal vehicles for transporting cannabis, or they aren’t taking them seriously enough.

Considering the strict statutes many states have placed on transporting cannabis should be reason alone to be more diligent. For example, the California Bureau of Cannabis Control’s proposed regulations require cannabis business owners to ensure their drivers have designated permits to transport the product. The state’s current legislation mandates inspections at any licensed premises, and requires employers to provide detailed tracking and schedules on the transport of product. Further, the state prohibits using minors to transport cannabis, and considers it a felony to do so.

Regulatory concerns, combined with the potential liabilities that could come from driver behavior, are keeping insurers from offering auto coverage to the cannabis industry. In fact, just four insurers currently offer the industry auto coverage, with premiums running as high as $17,000 per auto on average. It is important to note that personal auto insurance falls short because it doesn’t cover cargo loss.

Alternatively, because the stakes are so high, many companies are using courier services to transport cannabis product. But cargo insurance is still an issue. Without it, the care, custody and control of someone else’s products, and insurance limits are lacking. Even when the courier has cargo coverage, because they are delivering for multiple companies, the claims payout would have to be split amongst all the customers – likely below the value of your loss.

Consider the following best practices when transporting cannabis:

  • Conduct background checks/review DMV records. Uncovering any potential driver issues prior to hiring is critical. Look for previous DUIs or drug related history. Employees who might use product before getting behind the wheel are a significant danger to other drivers and a major liability to the employer. Even after hiring, be on alert for signs that indicate poor driving performance. Use check-in/check-out processes for all drivers, and conduct regular vehicle walk-arounds to look for scratches, dents or other damage that otherwise might be unreported to the employer.First, and most importantly, assess your risk mitigation options. Then, put processes in place as soon as possible to eliminate risk. 
  • Implement quarterly driver training. Educate employees on proper procedures. While minor fender benders and sideswipe accidents are most common, even these can be costly if not handled properly. Once law enforcement get involved in an accident the car’s transportation of cannabis could become a secondary issue. Teach drivers how to handle accidents while on the scene, including informing law enforcement about the cargo and the employer.
  • Use unmarked vehicles. Drivers carrying a significant amount of product and/or cash are tempting targets for thieves. Company cars used for transporting product should be newer, and have no fleet serial numbers or anything identifying the company.
  • Require increased personal liability limits. If an employee is using their own personal vehicle for business purposes, the business owner should require that person carry more than minimum limits of personal liability.  Ideally, they should have $300,000 or more, at an absolute minimum $100,000.

Get started now

First, and most importantly, assess your risk mitigation options. Then, put processes in place as soon as possible to eliminate risk. Secure the right insurance coverage, and ask your broker/underwriter to provide any additional recommendations to best mitigate your transportation, delivery, and cargo exposures.

To learn more, please visit our website.

Matt Engle
Soapbox

Insurers Must Play Catch-Up to Meet Cannabis Industry Needs

By Matt Engle
No Comments
Matt Engle

As the cannabis industry continues to grow, demand for insurance products is also increasing. While insurers have been cautious about entering a market that carries the stigma of a Schedule I drug, the cannabis industry is clamoring for insurance coverage options tailored to meet the needs of key players— distributors, growers, processors and retail dispensaries.

The escalating need for insurance products tailored to these cannabis business sectors has not expedited an increase in coverage offerings. The slow entry of insurance carriers into the cannabis sector can be tied to a reluctance to insure an industry with emerging and often unknown risks. This will begin to change as more information becomes available on what loss ratio trends look like in the cannabis industry.

For now, there is a wait-and-see stance held by insurance carriers. This presents a major concern for cannabis-related businesses that are subject to risk at every stage of the supply chain, with particular exposure for theft, general liability, crop loss, and product liability.some degree of crime and theft coverage is needed for these enterprises to help manage the risks associated with a cash-based business

Theft

For cannabis companies, the use of paper currency is a huge part of their risk exposure. Federal banking regulations have limited these businesses to dealing mostly in cash, which makes them a prime target for crime and fraud. Currently, only one carrier will insure coverage for cash and theft risk, and the policy is limited to $1 million for most risks. This is inadequate coverage since many operators have more than that amount on-site.

In states with legislation legalizing cannabis, the cannabis sector will be able to move away from operating in cash if Congress passes the Secure and Fair Enforcement (SAFE) Banking Act, which would protect financial institutions from liability for federal prosecution that could arise from servicing cannabis-related businesses authorized under state law. Until banking regulations give the cannabis industry the ability to operate as legitimate businesses with the stability and safety that would deter criminal activity, some degree of crime and theft coverage is needed for these enterprises to help manage the risks associated with a cash-based business.

General Liability

Cannabis-related businesses need the same general liability coverage as other businesses to protect their premises and operations from lawsuits involving public contact. However, standard general liability policies—which exclude Schedule I substances from coverage—were not created with cannabis businesses in mind. It is still difficult for these businesses to obtain adequate general liability as a result of the legal uncertainty associated with the industry.

Product Liability

Product liability exposures for cannabis businesses encompass a wide range of areas, including edibles, vaporizers, pesticides, mold/fungus, misrepresentation, label claims, breach of warranty, deceptive practices, and failure to warn.

A major area of exposure concerns accidents resulting from impairment. A cannabis cultivator, processor, distributor, or retailer potentially may be considered liable in the event a product defect results in injury after reasonable use or when label defects fail to warn users that a product may have psychoactive effects.

Another area of risk exposure involves products that contain THC, the psychoactive compound that gives cannabis users a high. As the number of THC-containing products such as edibles and tinctures increases, so does the potential exposure to product liability claims for manufacturers and retailers.

The California Cannabis Track-and-Trace (CCTT) system also has implications for product liability. The CCTT is a statewide system used to record the inventory and movement of cannabis and related products through the commercial supply chain. All state cannabis licensees, including those with licenses for cultivation, manufacturing, retail, distribution, testing labs and microbusinesses, are required to use this system. The product liability impact lies in its capacity to determine responsibility along the supply chain from seed to sale.

For example, if a plastic vape pen explodes, a product liability lawsuit could have repercussions for many touch points across the supply chain beyond the manufacturer of the pen–all of which can be identified through CCTT. Entities that touch cannabis products such as soil suppliers or delivery persons also have product liability risk exposure. Personal injury attorneys can find incident-related parties easily and determine liability. This makes it particularly important to add these parties to the policy as additional insureds to help reduce claims exposure.

Crop Loss

Another area of concern for risk exposure is crop loss. Crop insurance is generally hard to obtain due to the significantly different nature of cannabis crops compared to traditional crops like corn or soybeans.

Fires in Sonoma County devastated cannabis crops in Northern California back in 2017.

An indoor crop insurance policy covers cultivators when there is loss resulting from threats such as fire, theft, and sprinkler leakage. However, crop insurance policies generally do not cover losses resulting from mold, rot, disease, changes in climate, or fertilization issues. Many growers forgo this coverage and instead elect to absorb losses and regrow their crops.

Outdoor crop coverage is generally unavailable, or the cost is prohibitive. Any potential for writing outdoor crop insurance for the cannabis industry essentially disappeared as a result of the recent wildfires in California. These devastating fires highlighted the pressing need for property damage and business interruption coverage for growers and dispensaries and other downstream businesses whose supply was disrupted. This lack of available outdoor crop insurance is one of the more notable gaps in available cannabis business insurance coverage.

While cannabis businesses operating in states that have legalized medical and/or recreational cannabis use have challenges getting adequate insurance coverage, there is some good news on the insurance front for those in California. Last year, California’s insurance commissioner announced approval for carriers to offer insurance coverage specifically to cannabis businesses. The state also approved a cannabis business-owners policy (CannaBOP) program that provides a package policy containing both property and liability coverage for qualifying dispensaries, distributors, manufacturers, processors and storage facilities. Colorado is on the verge of being the second state to approve its version of a CannaBOP program.

While more insurance carriers are beginning to write cannabis coverage, the limited insurance options and policies with restrictive plans currently offered todaydo not meet the needs of the cannabis industry. Insurers must catch up to the coverage requirements of this sector by offering more options tailored to growers, retail dispensaries, processors and distributors with better terms and better pricing.

MJ Freeway’s Source Code Stolen & Published Online

By Aaron G. Biros
9 Comments

Portions of MJ Freeway’s source code were reportedly stolen and posted in Reddit threads as well as on Gitlab.com, a source code hosting website. On June 15th, the account “MJFreeway Open Source” was made on Gitlab.com, and portions of the source code were posted, but have since been taken down. Source code is essentially a list of commands of a program, the basis for making improvements and modifications to a software system. Source code can sometimes contain sensitive information. To be clear, MJ Freeway does not use an open source model; their source code is the basis of their traceability software. Open source is a tool that fosters public collaboration on software development, helping identify weaknesses or areas for improvement.

When asked to comment on the matter, MJ Freeway issued the following statement:

“Last week we discovered that someone had obtained an outdated portion of MJ Freeway’s source code. This incident has absolutely no impact on our systems or MJ Freeway services, and client and patient data is not at risk. While this theft poses no risk to our clients, patients, or business operations, we take any incident involving unauthorized access very seriously and have reported it to the Colorado Bureau of Investigation.

Unfortunately, it has come to our attention that our competitors are spreading inaccurate information about the incident, including baseless claims about SSL info and the potential for client data being compromised – neither of which is true. We encourage our customers to contact us directly with any questions they may have.

We follow or exceed all relevant industry security standards and are confident that we have the most robust security measures in our industry. None of our peers come close. However, we live in a world of determined cyber-criminals and we operate in a competitive environment. Success and size makes a company a bigger target for malicious actors, as other large companies also know. We will continue to investigate and take follow-up action as we learn more about this incident.”

On Sunday, June 18th, a user by the name of ‘techdudes420’ posted in the subreddit, r/weedbiz, a thread titled “MJFreeway goes open source.” The link for that post was the Gitlab.com page where MJ Freeway’s source code was published briefly. The same user then published a second reddit post the following day with the same link to the stolen code, but this time in the r/COents, a subreddit for the Colorado cannabis community. MJ Freeway is based in Denver. That post claimed the user found the stolen source code with a quick search and that the user was banned because of that. The moderator of the thread chimed in, saying they banned the user for posting the stolen code. “We received a takedown request from the software owner stating the code had been stolen and released without permission,” says the moderator. “After investigating the matter I reached the same conclusion and removed the thread.” The moderator then updated the comment shortly after: “Edit: As for OP [original poster] ‘finding’ the code, if that were true I don’t know why he or she would have created a new Reddit account just to post the link.”

In addition to their own cybersecurity analysis, a spokeswoman for MJ Freeway says they will be performing a third party audit and analysis this week as well. When that information becomes available, we will update this article.


Update: Multiple sources have reported that portions of MJ Freeway’s source code are still available online on torrent sites like PirateBay.