Under Constant Resource Constraints, CISOs Narrow Security To The First Step To Breach
Britton Burton, CISO at D4C Dental Brands, secured 180 pediatric dental and orthodontic practices across 10 states. His method: narrow security to the handful of controls, and get non-technical leaders to fund them.

Security leadership across a scattered footprint runs into a hard limit, fast. There's never enough staff, never enough presence in every location, and never a clean, standardized environment to defend. Growth by acquisition keeps adding sites that arrive with their own systems and their own years of accumulated habits. The job becomes an exercise in choosing what actually has to be locked down first, and in convincing the people who hold the budget why those few things matter more than everything else.
Britton Burton is Chief Information Security Officer at D4C Dental Brands, where he runs security across roughly 180 pediatric dental and orthodontic practices spread over 10 states. He came to the role after nearly a decade at HCA Healthcare, the largest health system in the United States, holding risk-management and information-security leadership posts, and later ran third-party risk and product strategy at CORL Technologies. That mix of enterprise-scale risk work and smaller, sprawling operations shapes how he decides what to defend.
"Ransomware is the thing we should care about the most. Nobody wants a data breach either, but at the end of the day, staying operational and being able to treat our kids is what keeps this company alive," Burton said. The reframing does real work with executives. It pulls the security conversation off abstract compliance and onto the one outcome a pediatric dental group can't afford to lose, which is the ability to see patients tomorrow morning.
The distributed constraint: Across scattered sites, the first real change is dependence. The threat model stays familiar; what shifts is who can act on it. Configuration gets specified centrally but executed by people who report elsewhere, and in low-density geographies there's nobody on payroll close enough to touch the hardware. "A lot of what you have to do in security, even from a technical configuration standpoint, isn't done by people who report to you. You're reliant on an admin in IT, or on someone who has to be physically on the ground, and you outsource to vendors for desktop support. They do that fine, but they may not do the things you need done locally that go a little beyond it," Burton said. A ten-employee, single-doctor office doesn't have the footprint to justify a local IT presence, so tasks a consolidated campus takes for granted turn into logistics problems.
Standardize the core, flex at the margins: Standardization sounds easy until you inherit hundreds of exceptions, where an edge case at one practice is the default at another. Burton draws the line at a set of core platforms that don't get renegotiated. "We're going to have standardized core platforms. Your practice management system or EHR, your patient communication system, your network gear, whether you're cloud or on-prem, that's going to be standard. We can't just be glomming on whatever someone happens to have because they're used to it." Below that line, there's room for local business workflows, how a given market schedules patients or blocks a doctor's calendar, to bend to real conditions. The standard holds when the message that it's non-negotiable is carried by operations and clinical leaders rather than delivered as an edict from the technology team.
First step to breach: Healthcare has trailed more advanced industries on security for years, and the smaller the practice, the wider the gap. Recent threat intelligence shows attackers increasingly aimed at smaller practices, the under-resourced targets that hospitals long overshadowed. That gap is exactly why Burton refuses to chase a full control framework at once. "I use 'first step to breach' controls. What are the five to ten things that, if you don't have them in place, you just know it's a ticking time bomb? We focus there, with no real wiggle room, and we make progress on everything else in the background," he said. The rest of the register still gets worked, but the order comes from what keeps the business running, not from the shape of any published standard.
Prioritization under constraint is one half of the job. The other is communication, and AI has sharpened that on two fronts at once. It's arming attackers faster than before, and it's the productivity lever an understaffed organization can least afford to ignore. The same instinct that weighs risk by impact shapes how Burton brings both to the people who sign off, turning something technical into something a non-technical executive can actually weigh.
Translating the AI risk: "No C-suite person wants to hear that a model is good at finding exploitable vulnerabilities in code, they've already fallen asleep. But if you say AI is really good at finding problems, and that Microsoft usually releases about five security patches in their monthly round and just released 470 or so, that's tangible," Burton said. A year and a half ago he was skeptical that AI meaningfully helped attackers, beyond a few better-crafted phishing emails. He isn't skeptical now. He does it in the governance meetings and routine check-ins he already has, pointing at one concrete data point, explaining what it means, and stopping there before the technical detail loses the room.
Adopting AI safely: The same resource math that forces ruthless prioritization also pushes Burton and his clinical counterpart to push adoption without blocking it. "We have to create efficiency in this organization, because we're dealing with non-standard systems and we don't have people to do all the things we need to do. How can we make that happen, and how can we do it safely?" His starting move is to run AI vendors through the same checklist any patient-care software would face, being on the right plan so a major AI provider will sign a business associate agreement, then ask what's different about AI that the standard checklist misses. Whether an employee gets computer-use and browser-use access, or whether someone in IT should have an unlimited coding-assistant subscription, comes down to a case-by-case read of real capabilities against real risk.
Designing out the noise: The people side is where transformation efforts either stick or become slogans on a wall. Burton's frame is to eliminate noise, because there will never be enough staff to answer every stakeholder need across the technology organization, security included. "What are the most common support requests causing an issue because of a poor implementation or a lack of user understanding? Can you change something so they stop causing that problem, or put self-service password reset in place, or use AI for first-level triage so your people focus on the Level 2 and Level 3 issues that actually need a human?" The lesson from the retail support chatbots everyone learned to hate is that a narrow, well-scoped path to a fix is the part AI can now handle well, which frees staff for the outages and edge cases a bot can't touch and lets IT move beyond reactive ticket work.
None of this reads to Burton as a break from the discipline he already practiced. The business has always wanted some new tool that promises to make it faster or more profitable, and the security leader's job has always been to weigh that want against the risk and explain the tradeoff in terms a non-technical audience can hold.
"It's really no different from what security has always been. There's always some new shiny thing the business wants. Can you talk to them about it succinctly and accurately? It's just that AI has the moment right now," Burton said.
If this caught your attention, that’s not accidental.
The best editorial systems don’t happen by accident. Outlever builds them.









