We’ll start with a disclaimer: we are not cybersecurity experts.
But after working exclusively with dentists for years, we have learned a thing or two about what happens when cybersecurity problems become business problems. We have seen cyber incidents disrupt practices, create expensive headaches and leave owners trying to sort through the financial fallout.
One thing we have learned? Having antivirus on every computer does not necessarily mean your practice is protected from today’s biggest cyber threats.
Modern attacks can come through stolen passwords, phishing emails, compromised accounts, ransomware and even trusted vendors. Some never look like a traditional computer virus at all.
So instead of asking whether your practice has antivirus, here are three better questions to ask.
- Are We Just Protecting Devices, or Monitoring Them Too?
Traditional antivirus is designed to identify and block malicious software.
Modern endpoint protection can go further by watching for unusual activity on a device and alerting someone when something looks wrong.
CISA recommends endpoint detection and response tools as part of ransomware protection because they can help identify suspicious behavior before an attack spreads.
For a dental practice, the better question is not simply:
“Do our computers have antivirus?”
It’s:
“If something unusual starts happening on one of our computers, will someone know?”
Ask your IT provider what type of endpoint protection your practice uses and, just as importantly, who is responsible for responding to alerts.
- What Happens Five Minutes After Something Goes Wrong?
Prevention matters, but no security system is perfect.
Imagine someone at the front desk clicks a convincing email, enters their Microsoft password and then realizes the message may have been fake.
What happens next?
Does that employee know who to call? Does your IT provider need to be contacted first? Who handles the business side of the response?
NIST’s Cybersecurity Framework puts emphasis not only on protecting systems, but also on detecting, responding to and recovering from incidents.
A small dental practice probably does not need a giant cybersecurity manual. But it should have a simple incident response plan that tells the team what to do and who to contact.
The ADA also recommends that dental practices have an emergency action plan for cybersecurity incidents.
Ask:
“If someone on our team thinks they clicked something malicious, does everyone know what to do next?”
- How Easy Would It Be to Fool Someone on Your Team?
Some of the biggest cybersecurity risks do not start with technology.
They start with an email.
A phishing message today might look like a dental supplier invoice, a DocuSign request, a Microsoft password notice, a payroll message or even an email that appears to come from the dentist.
NIST warns that phishing attempts are becoming more convincing, especially as artificial intelligence makes fake messages easier to create.
The ADA also recommends training dental teams to recognize suspicious emails, links and attachments.
But training should go beyond telling employees to “be careful.”
Phishing simulations can test whether your team actually recognizes a suspicious message before a real one shows up.
Ask:
“Do we test our team with phishing simulations, or do we just tell them what phishing looks like?”
Antivirus Isn’t the Problem. Relying on It Is.
Antivirus still has an important role in cybersecurity.
It just should not be the entire plan.
A stronger approach combines technology that helps stop attacks, monitoring that helps detect suspicious activity, employees who know what to look for and a plan for what happens if something gets through.
And while cybersecurity is not our area of expertise at Engage Advisors, dental practices are.
After years of working exclusively with dentists, we have built relationships with professionals who specialize in areas like cybersecurity, IT and other parts of practice management that fall outside our lane.
If you are not sure whether your current cybersecurity setup is enough, talk with your IT provider. And if you need help finding someone who understands the unique needs of a dental practice, talk to an Engage Advisor. We would be happy to point you toward a trusted resource.