Case Study: Securing Growth in the Cannabis Retail Sector 

Tags: Cyber Security, it solutions toronto, managed it, managed it services Toronto

KEY TAKEAWAYS

  • An AGCO-licensed store in Ontario is a compliance environment before it is a shop: 30 days of video retention, 3 years of records, monthly inventory counts, a certified point-of-sale system.
  • Fusion Computing built one validated store template and reused it at every new location, so compliance evidence fell out of normal operations.
  • The hard part of a multi-store rollout is repeatability. No single product solves it.

Mike Pearlstein is CEO of Fusion Computing and holds the CISSP. He has led Fusion’s CISSP-led managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.

IT security for cannabis retail means protecting the point-of-sale and the age-verification data an ID check creates, while satisfying an Ontario regulator that can inspect any of it. Whatever you install has to survive being copied into the next store, and the one after that.

Introduction

I took this engagement when the client had one signed lease and a licence application in progress. They wanted a chain across the Toronto market, and they had worked out that every shortcut taken in store one would be inherited by store six. That is the right instinct, and it is rarer than you would think in a market moving this fast.

Retail cannabis product being weighed and organized into jars behind the counter of an Ontario cannabis store

Overview

My client was a new entrant in Ontario’s cannabis retail market, opening connected stores across the Greater Toronto Area. Customer experience mattered to them, but so did surviving an inspection. I needed to hand them infrastructure that a regulator and a store manager could both read the same way, at every address.

Cannabis retail back-office desk in Ontario with a printed multi-location rollout overview beside a coffee mug
Every cannabis-retail engagement I run starts on a back-office desk, not in a server room.

A single store is a manageable problem. Six Ontario stores on six slightly different setups is an audit exposure, because what you can produce on request is only as good as the least consistent site. That is the problem I was hired to prevent, and it is why I start these engagements with a written standard rather than a purchase order.

Challenges: what AGCO requires and the criteria we build to

Ontario stores answer to the AGCO. According to the Registrar’s Standards for Cannabis Retail Stores (2025), a licensee must run continuous surveillance, keep detailed records for years, count inventory monthly, and operate a certified point-of-sale system. Those four obligations set the criteria for every technical decision below.

What AGCO Requires of an Ontario Cannabis Store. Standard 2.1 requires 24 hour camera coverage of entrances, ID checks, pick-up areas, point-of-sale areas, receiving areas, the sales floor and cannabis storage. Recordings must be retained a minimum of 30 days and made available to the AGCO on request. Standard 8.1 requires employee, transaction, destruction, recall and purchaser records to be kept a minimum of 3 years. Standard 8.2 requires a full physical inventory count of all cannabis at least monthly. Standards 8.4 and 8.5 require a certified point-of-sale system. It must log all system access and changes, and be able to participate in the national cannabis tracking system. What AGCO Requires of an Ontario Cannabis Store. Four obligations that set the criteria. Standard 2.1. Surveillance. 24-hour camera coverage. Entrances, POS, receiving, storage. Recordings kept 30 days minimum. Standard 8.1. Records. Staff, transactions, destruction. Traceable to the employee level. Retained 3 years minimum. Standard 8.2. Inventory. Full physical count of all cannabis. Monthly at minimum. Reconciled against the POS. Standards 8.4, 8.5. Systems. POS certified, PCI or ISO. Access and change logging. Federal tracking system ready.
Source: AGCO Registrar’s Standards for Cannabis Retail Stores, standards 2.1, 8.1, 8.2, 8.4 and 8.5.

Read those together and the shape of the problem appears. Under Standard 2.1 surveillance is a data-retention system. Under Standards 8.1 to 8.5 the point-of-sale is a regulated record. Both feed the tracking system created by section 81 of the Cannabis Act, so an outage is a compliance event.

Risk register on a cannabis retail whiteboard with sticky notes covering point-of-sale, inventory and privacy exposures
A wall of sticky notes is what a cannabis-retail risk register honestly looks like on day one.

Age verification adds a second regulator. ID checks create personal information, and the Office of the Privacy Commissioner requires organizations to report breaches posing a real risk of significant harm (2018) and to keep breach records for 2 years under PIPEDA.

Fusion Computing’s Approach

Fusion Computing delivered the work in four phased layers, each one chosen because it had to be copied into the next store without redesign. I told the client we were writing a template, not installing equipment. The Toronto IT support team then ran that template at every subsequent address.

Printed cannabis retail IT runbook open on a Toronto conference table with tabs for point-of-sale, network and compliance
The runbook is the deliverable. Everything else is a copy of it.
The Four-Layer Store Template. Layer one, network. A next-generation firewall at every store, encrypted links back to head office, and point-of-sale traffic separated from back-office and guest Wi-Fi. Layer two, endpoint. Managed detection and response with 24 by 7 monitoring on registers and back-office machines. Layer three, access. Surveillance and door access installed to the Registrar’s Standards, with named staff accounts rather than shared logins. Layer four, evidence. A control-by-control documentation pack kept current for AGCO review and for the annual insurance questionnaire. The Four-Layer Store Template. Built once. Copied at every address. 1. Network. Next-generation firewall per store. POS separated from office and guest. 2. Endpoint. Managed detection on registers and back-office machines, monitored 24 by 7. 3. Access. Surveillance and door access to standard. Named staff accounts, no sharing. 4. Evidence. Control-by-control pack kept current for AGCO and insurer review.

Layer four is the one most operators skip. Assembling compliance paperwork the week before a renewal is expensive and it reads badly. Fusion Computing keeps the pack current as a by-product of running the estate, which turns an Ontario inspection into a retrieval exercise. If that is where your gap sits, talk to our team.

The control set behind the template is not exotic. The Canadian Centre for Cyber Security’s Baseline Cyber Security Controls (2022) list 13 control areas for organizations under 500 staff, on an explicit 80/20 premise. I map each store against that list, then add what the Registrar’s Standards demand on top.

Cost discipline mattered too, because a startup pays for every duplicated tool. I consolidated licensing and dropped the overlapping products. SD-WAN over business broadband replaced premium leased circuits. That kept the per-store bill sane across the Toronto estate as it grew. If your second store is already quoted differently from your first, get a second opinion before you sign.

Results

According to Statistics Canada (2024), 16% of Canadian businesses were impacted by a cyber security incident in 2023, and recovery spending doubled to $1.2 billion CAD. Large businesses were the most likely to be hit, at 30%. Smaller operators are not spared, they simply absorb it with fewer people.

Printed before-and-after comparison sheet for a multi-store cannabis retail IT rollout on an owner desk in Toronto
The before-and-after sheet is the only artefact an owner actually keeps.
Before the engagement. After the rollout.
Each store scoped and cabled from scratch. One validated template reused at every address.
Point-of-sale, surveillance and guest traffic on one flat network. Separated segments with a firewall at each store.
Compliance evidence assembled by hand before a renewal. Evidence pack maintained continuously against the standards.
IT escalations handled ad hoc during store hours. Monitored endpoints with a 1-hour priority response.

The client opened multiple downtown Toronto locations on that single standard, with monitoring and endpoint protection running from the first day of trade at each one. Store openings stopped being technology projects. They became a checklist, run by the same people, in the same order.

“Fusion Computing has been the best IT Services provider we’ve ever had. Their managed IT services offering covers all 4 of our JP Motors locations bumper to bumper.”

Ryan Pattinson, JP Motors. A different Fusion Computing client, also multi-site retail, on the same standardized model described here.

Conclusion

Growing in a regulated Ontario market punishes improvisation. The client got a foundation they could copy, a paper trail they could hand to the AGCO or an insurer, and a support model that did not need rebuilding at every opening. That is the whole return on a build like this, and it compounds with each new address.

Plan a multi-site rollout

Security outcomes: what is a compliant cannabis retail build, explained

A compliant build is one where the regulator’s questions already have answers on file. Surveillance retained the full 30 days. Records kept the full 3 years. A certified point-of-sale that logs its own access. Named accounts and separated networks. Monitored endpoints. One documented standard behind every store rather than six variations of one. See our client case study library for comparable rebuilds.

Cannabis retail IT security FAQ: how much it costs, how long it takes

What unique IT challenges does the cannabis retail sector face?

Cannabis retailers carry two regulators at once. The AGCO sets physical and record-keeping standards, including 24-hour surveillance retained a minimum of 30 days and transaction records kept 3 years. PIPEDA breach rules govern the personal information created by age verification. The point-of-sale is a till, a regulated record, and a feed into the federal tracking system at the same time, so an outage is never only an outage.

What does AGCO require from a cannabis retail point-of-sale and record-keeping system?

Standards 8.4 and 8.5 require a point-of-sale system certified by a recognized industry body such as PCI or ISO, with logging that monitors all system access and changes. It must also support the national cannabis tracking system created under section 81 of the Cannabis Act. Standard 8.2 adds a full physical inventory count at least monthly, so the numbers have to reconcile.

How much does managed IT and cybersecurity cost for a cannabis retailer?

Fusion Computing prices managed IT from CA$180 per user per month. Lighter scopes start at a CA$160 floor, and roughly CA$230 applies where after-hours coverage and heavier compliance work are bundled. Managed cybersecurity is priced separately at CA$180 to CA$250+ per user per month. Store count, surveillance retention obligations, and whether 24 by 7 monitoring is included are what move a retailer inside that band.

How long does a multi-store cannabis IT rollout take?

The first store is the slow one, because it produces the template. I scope a design and installation phase of 6 to 10 weeks once the premises are ready, plus lead time on cabling, cameras and circuits. Subsequent stores run against the finished runbook and land in a fraction of that. The gating item is almost never technology. It is landlord access and electrical work, plus how early the licence timeline reaches my team.

Talk to Fusion Computing

Fusion Computing runs managed IT services and cybersecurity services for regulated Canadian operators, with vCIO and vCISO support where a board or an insurer wants a named owner.

For comparable engagements, see our GTHA dealership overhaul, the marketing agency crisis recovery, the design studio that scaled from 35 to 205 users, and the Prolift Crane startup build. You can also read verified Google reviews or book a consultation with my CISSP-led team.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 10 to 150 employees across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611