Case Study · Dental practice

Dental Practice: From Failed DSPT Assertions to Cyber Essentials Certified

A two-site practice could not honestly complete its Data Security and Protection Toolkit assertions. A gap review found six blocking issues; eleven weeks later they were Cyber Essentials certified with the toolkit evidenced.

Client
Dental practice
Sector
Dental practice
Size
18 staff, two sites
Location
Leicestershire, UK
In short

How long does it take a small healthcare practice to get Cyber Essentials?

For this two-site dental practice, eleven weeks from first consultation to certificate — of which about seven weeks was remediation work, mostly replacing unsupported devices and rolling out multi-factor authentication, and the rest was assessment and questionnaire submission.

The challenge

The practice manager had been completing the Data Security and Protection Toolkit

for three years and had become increasingly uncomfortable with several of the assertions. The

questions asked for evidence of things nobody could point to: a documented leaver process, tested

backups, recorded staff training.

A commissioning conversation then raised Cyber Essentials, and the practice needed a defensible answer

rather than an optimistic one.

  • No record of who had access to the clinical system, or why
  • Two reception workstations running an operating system past vendor support
  • Multi-factor authentication not enabled on practice email
  • Backups running nightly, never once restored from
  • Locum access created ad hoc and never removed
  • No written breach procedure, despite holding special category health data

What we did

We started with an assessment rather than the questionnaire, because answering the

toolkit accurately requires knowing what is actually there.

Assessment

A vulnerability assessment across both sites covered the internal network, the workstations, the

practice email tenant and the internet-facing connection. It confirmed the six issues the practice

already suspected and found four more, including a network-attached device with default credentials

that nobody could identify.

Remediation, in priority order

  1. Multi-factor authentication enforced on practice email, with legacy authentication blocked
  2. The two unsupported workstations replaced — the only material hardware spend in the project
  3. Access to the clinical system reviewed line by line; eleven accounts removed, including four

locums who had not attended for over a year

  1. Backups reconfigured with an immutable off-site copy, then a full restore test performed and timed
  2. A written joiner, mover and leaver process adopted, with a single checklist the practice manager owns
  3. A breach procedure written, with the 72-hour ICO duty built into it

Evidence and certification

We assembled the toolkit evidence as the work completed rather than afterwards, then supported the

Cyber Essentials self-assessment questionnaire and coordinated with the certification body.

The outcome

The practice was certified to Cyber Essentials eleven weeks after the first

consultation, and completed its DSPT assertions with evidence behind each one for the first time.

  • Cyber Essentials certificate achieved at first submission
  • DSPT assertions completed with documented evidence rather than assumption
  • Eleven redundant clinical system accounts removed, including four dormant locum accounts
  • Backup restore tested and timed at 4 hours 20 minutes for the full clinical dataset
  • A leaver checklist now completed on the day, owned by a named person

The practice manager's summary was the part we found most useful: the toolkit had stopped being a

form to get through and started being a description of how the practice actually operates.

This case study is published anonymously. No patient data was accessed at any point during the

engagement, and the practice is not identified.

What we would tell a similar practice

Do the assessment before the questionnaire. Almost every practice we speak to has been answering

toolkit questions from memory, and the gap between what is believed and what is configured is

consistently wider than expected.

The expensive parts of this project were the two replacement workstations. Everything else was

configuration, process and about a day and a half of the practice manager's time.

Published anonymously. Identifying details have been removed or generalised, and no client is named without written consent. Outcomes described relate to this engagement and are not a guarantee of results elsewhere.