This is a scenario walkthrough of a four-quarter security program shape, not a client engagement summary. The narrative below is a composite drawn from M&A cyber-diligence and DSO consolidation work Obsidian Ridge has seen across the dental service-organization market; no single group is described. The architecture pattern — multiple M365 tenants accumulated through acquisition, a mixed practice-management estate, fragmented MSP relationships — is common in DSO deal flow and is described in ADA Practice Transitions coverage, the 2024–2025 Coveware ransomware quarterlies, and HHS OCR multi-facility breach disclosures.
Why DSO security programs fail — and it is rarely a bad decision
Most DSO security programs do not fail because somebody made a bad decision. They fail because nobody made any decision at all. Acquisitions stack up faster than the security program can absorb them, and one day the CFO realizes the group is running on five identity stacks and three IT firms with no single pane to look at any of it. This walkthrough describes the shape of the program that brings a group of that description back to a single defensible posture over roughly four quarters, and the specific decisions inside each quarter that determine whether the plan holds.
The starting condition
Assume a multi-location dental service organization in the Southeast, formed through a stack of acquisitions over a few years. Practice mix that spans general dentistry, orthodontics, and a surgical center. Each acquired practice retained its IT firm, its practice-management system, and, critically, its Microsoft 365 tenant. The group grew faster than its security program.
The engagement is typically triggered by an event — the CFO watching a second near-miss inside eighteen months, one location's phish-driven session theft exposing how little visibility the central team had below the HQ tenant, or a cyber-insurance renewal that came back with a coverage restriction the board did not want to accept. The board wants a defensible answer, not another intentions spreadsheet.
The audit that opens the program
The first thirty days is discovery, and the findings in scenarios of this shape are typical for DSOs growing through acquisition:
- Multiple separate M365 tenants still active — the parent group's original tenant plus several acquired tenants never consolidated.
- Endpoint detection coverage well under 100%, with a substantial fraction of endpoints running only built-in Windows Defender, often with policy gaps.
- MFA coverage concentrated at the HQ tenant, with at least one acquired tenant that has MFA disabled entirely.
- Several MSPs servicing the locations, with overlapping admin credentials and no documented separation of duty.
- Multiple practice-management systems in production across the locations — Dentrix on-prem, Eaglesoft on-prem, Denticon cloud, and occasionally an outlier that came in through a single acquisition.
- Two or more near-miss incidents in the last eighteen months — commonly a BEC attempt at a satellite location and a credential-stuffing burst against an acquired tenant — both reaching the "attacker has valid credentials" stage before being noticed by location staff, not by tooling.
- A HIPAA risk analysis on file, dated well before the acquisitions, never updated.
The pattern is documented at length in Multi-Location Dental & DSO Cybersecurity: The Consolidation Problem. This walkthrough describes the version that gets caught before it makes the news.
Q1 — Discovery and identity-consolidation start
Full inventory across every location: every endpoint, every M365 tenant, every practice-management-system instance, every MSP admin account. An identity-consolidation plan is agreed with the executive team. MFA is enforced group-wide as the first non-negotiable, including the tenant that had it disabled. Nothing is migrated in Q1; the point of the quarter is to know the shape of the estate and to close the single biggest identity gap in the shortest possible time.
Q2 — Endpoint and identity coverage to full
Managed EDR is deployed to every endpoint and every practice-management server. Managed ITDR is connected to every M365 tenant in parallel, so the SOC has identity visibility even into tenants slated for retirement during the migration window. Most acquired tenants are migrated into the HQ tenant by the end of Q2. When a location's brand or an operating separation makes a full merge undesirable, that tenant is retained deliberately, documented, and monitored under the same ITDR umbrella.
Q3 — Process and training
Managed Security Awareness Training rolls out to every staff member. Quarterly phishing simulations are tuned to dental-specific themes: insurance-verification scams, lab payment redirects, ADA-membership impersonations. A documented incident-response runbook is published, with named contacts for each location and a defined escalation to the group's executive team.
Q4 — Compliance and evidence packaging
HIPAA risk analyses are completed for each covered-entity location. A group-level WISP is authored. The cyber-insurance renewal proceeds with the consolidated program documentation in the carrier's file — the specifics of premium and coverage vary, but the underwriter conversation shifts from restrictive to routine because the group can produce evidence rather than intentions. The year closes with a tabletop exercise run with the executive team.
The controls that make the program actually work
- Identity-first sequencing. Getting MFA and ITDR coverage to full in Q1–Q2 pays off when low-grade credential-stuffing attempts in Q3 are caught and neutralized before any human at the locations sees them.
- A single tenant view for the SOC. The SOC and the Obsidian Ridge analyst see every location in one pane, not a dozen fragmented dashboards. That single view is what cuts alert-to-acknowledged time from hours to minutes.
- Intentional exceptions, documented. A separately-branded satellite may have legitimate business reasons to stay on its own tenant. The program documents and accepts the residual risk instead of forcing a consolidation that does not make sense.
- Quarterly executive briefings. The CFO and COO know at every quarter boundary what has changed, what has not, and what is next. No surprise budget asks.
- A visible program, not a heroic effort. The four-quarter sequence is visible to leadership from Q1 — predictable cadence, predictable costs, no scope creep.
What the program deliberately does not do
- The program does not force consolidation of the practice-management estate. The cost-benefit almost never justifies a multi-million-dollar migration during the security work; PMS consolidation is revisited when the group crosses a location threshold that makes it economical on its own terms.
- The program does not replace the location IT firms. Each location keeps its existing IT relationship; the security operation sits alongside the IT function, not on top of it — that is what makes the program politically survivable inside the acquired practices.
- The program does not deploy Managed SIEM at every location out of the gate. SIEM is deployed at HQ for centralized log retention; per-location SIEM is deferred until the compliance footprint justifies it.
Where to go from here
If you run or advise a multi-location dental group and want to know what a four-quarter consolidation program looks like on the ground, start at the dental industry page or the enterprise page, and read The Briefing for the weekly write-ups of patterns that show up in DSO audits before they reach a board packet. The shape of the program is the durable part; the specific number of acquired tenants and the exact PMS mix are the parts that vary from group to group.
Last updated
August 22, 2026. We refresh this content as the threat landscape and tools evolve.