Security failures rarely come from a single missing device. More often, they appear where responsibilities, procedures, people, physical controls, technology, intelligence, and response plans fail to reinforce one another.
That is why modern cannabis security should be built as a layered program. Each layer has a different job. Together, they help deter preventable incidents, identify problems earlier, limit consequences, support an organized response, and restore operations with better information.
Oregon cannabis rules establish important requirements for security plans, alarms, access, surveillance, records, and incident reporting. Those requirements are foundational, but operators still have to decide how the controls will function as one system in a changing business.
The urgency is practical. In a March 2025 bulletin, the Oregon Liquor and Cannabis Commission reported increased burglaries and armed robberies affecting licensees and emphasized staff discussion, opening and closing awareness, panic-button familiarity, and testing of alarms and cameras. The message was clear: the presence of controls matters, and so does how people use them.
The VSG seven-layer model organizes that work:
1. Leadership
Security begins with ownership. Leadership sets risk tolerance, assigns authority, funds corrective action, and decides whether security is part of operations or something reviewed only after a loss. Without visible ownership, the remaining layers become inconsistent.
2. Policies and standard operating procedures
Policies turn leadership intent into repeatable expectations. Facility-specific SOPs should address access, visitors, contractors, opening and closing, alarm response, incident escalation, evidence preservation, and continuity. A procedure is useful only when it matches the actual facility and names the people responsible.
3. Training and awareness
Employees are the first people to notice many changes: an unfamiliar person, a propped door, unusual questions, a damaged control, or a procedure that no longer works. Training should be role-based, repeated, and supported by a reporting culture that treats concerns seriously without encouraging profiling or panic.
4. Physical security
The physical layer uses the site itself to deter, delay, and control access. Doors, locks, windows, barriers, lighting, secure storage, public-to-restricted transitions, and key or credential management should work together. The objective is not a fortress appearance; it is deliberate control of movement and time.
5. Technology
Cameras, alarms, access systems, communications, and monitoring tools multiply visibility and speed when they are configured correctly. They also introduce dependencies: power, networks, software, permissions, maintenance, and user behavior. Technology should be tested as part of the operating process, not assumed reliable because it is installed.
6. Intelligence
Intelligence gives context to the other layers. It includes incident trends, recurring exceptions, access patterns, local conditions, regulatory changes, employee reports, and lessons from other locations. Its purpose is to help leadership decide what matters now, not to collect information without a defined use.
7. Emergency response
Plans must translate into action. Employees need to know how to report an emergency, protect themselves, account for people, request help, preserve essential information, and transition into recovery. Training and exercises reveal gaps that a written plan cannot.
This layered approach is compatible with broader resilience models. The NIST Cybersecurity Framework 2.0 organizes cyber risk around Govern, Identify, Protect, Detect, Respond, and Recover. CISA physical-security guidance uses a similar lifecycle. The VSG seven layers are not a government standard, but they apply the same useful idea to cannabis operations: risk must be governed across the full cycle, not handled by a single product.
A weakness in one layer does not automatically cause failure. It increases the load on every other layer.
Operational standard
Review each layer with one direct question:
Leadership: Who owns security performance and unresolved risk?
Policies: Do procedures match the real site, shifts, and responsibilities?
Training: Can employees explain what to do without searching for a binder?
Physical security: Where can an unauthorized person gain time, access, concealment, or leverage?
Technology: What happens when a system, connection, credential, or power source fails?
Intelligence: Which changes and repeated exceptions reach decision-makers?
Emergency response: When was the plan last exercised, evaluated, and corrected?
A weakness in one layer does not automatically cause failure. It increases the load on every other layer. That is why reviews should examine the connections between layers, not score each in isolation.
Nexus insight
The intelligence layer can connect the program by organizing events, control status, procedures, review dates, and corrective actions into a leadership view. Nexus should help operators see where one weak layer is creating pressure elsewhere: a recurring access exception, an overdue camera repair, a procedure that no longer matches the site, or training that has not followed a staffing change.
The technology does not own the risk. Leadership does. The value of the intelligence layer is making that ownership more informed and timely.
Work with VSG
VSG can assess a cannabis operation across all seven layers and build a prioritized improvement plan that strengthens the system without losing sight of compliance, people, or business continuity.
