Join our Newsletter — 33% off our NHI Course

What breaks when cannabis security teams rely on intermittent surveillance?

Intermittent surveillance creates blind spots exactly where cannabis theft and diversion are most likely to occur. Missed coverage can hide entry, exit, and transfer activity, making it harder to spot insider-enabled incidents or prove what happened after a loss. It also weakens compliance readiness because regulators and law enforcement may expect continuous, retrievable footage during incidents or inspections.

How intermittent coverage creates the evidence gap

Intermittent surveillance does more than miss a few frames. It breaks the continuity that investigators rely on to reconstruct a timeline, confirm who entered or exited, and connect movement with a specific handoff or removal event. In practice, the absence of footage at the wrong moment is often indistinguishable from a successful concealment attempt.

For cannabis operations, that gap matters because theft and diversion are usually event based, not constant. A short blind spot at a loading bay, vault door, disposal area, or transfer point can erase the exact sequence that shows whether a loss was accidental, procedural, or deliberate.

Why intermittent surveillance weakens operational control

Coverage that comes and goes also weakens deterrence. Staff and contractors quickly learn when recording is least reliable, and that predictability changes behaviour around high-value product, waste handling, inventory movement, and restricted areas. The control may still look present on paper, but its practical value drops when it cannot be trusted during the moments that matter.

Intermittent recording can also undermine exception handling. If alarms, access logs, and video do not overlap, teams lose the ability to correlate events. That makes it harder to separate ordinary process noise from suspicious activity and slows down decisions about inventory reconciliation, incident escalation, and chain-of-custody review.

Why regulators and investigators care about continuity

Compliance expectations usually focus on whether the organisation can produce usable evidence, not whether a camera was installed. When footage is missing around an incident, teams may be unable to demonstrate that controls were operating as intended, which creates exposure during inspections, license reviews, or law-enforcement follow-up.

That is why continuous, retrievable footage is more than a technical preference. It supports a defensible record of activity, helps verify procedures, and reduces disputes after a loss. A surveillance system that cannot consistently record the full event window leaves the organisation reliant on partial logs and memory instead of objective evidence.

Risk and Threat Considerations

Intermittent surveillance creates a predictable weakness: the exact period when inventory is moved, transferred, or handled can become the least visible period in the facility. That raises the chance of undetected theft, insider-enabled diversion, and post-incident ambiguity about what actually happened.

Failure mechanism: Gaps in coverage interrupt the evidentiary chain, allowing entry, exit, transfer, or disposal activity to occur outside the recorded window or to be partially captured in a way that cannot support reconstruction.

Impact: Organisations may lose the ability to prove custody, identify the responsible party, or satisfy regulators and law enforcement that controls were effective at the time of the incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-8 — Audit Log Management Continuous footage functions as incident evidence and event correlation.
Recommendation — Validate video retention and retrieval so incident timelines can be reconstructed.
NIST SP 800-53 Rev 5 AU-12 — Audit Record Generation Reliable recording is needed to capture entry, exit, and transfer events.
AU-11 — Audit Record Retention Missing footage breaks post-incident evidence retention and review.
Recommendation — Ensure surveillance records are generated continuously for critical activity windows. Retain recordings long enough to support investigations and inspections.
NIST CSF 2.0 DE.CM-01 — The network is monitored to detect potential cybersecurity events Monitoring must be continuous to detect suspicious facility activity.
Recommendation — Maintain continuous monitoring for access and transfer events.

Practitioner Guidance

What to verify: Do not trust a camera estate based on installation alone. Verify that retention, time synchronisation, storage capacity, failover behaviour, and retrieval testing all support the full incident window, including peak business periods and after-hours activity.

What practitioners underestimate: The most damaging failure is often not total outage, but partial coverage that leaves just enough uncertainty to defeat a clean investigation. If the surveillance record cannot cover the moments of transfer, access, and exit in one continuous sequence, the control is not operationally complete.

Practitioner takeaway: For cannabis security, the question is not whether video exists, but whether it can reliably close the evidentiary gap at the exact moments theft and diversion are most likely to occur.