In February, a Mississippi medical center closed every one of its clinics statewide after a ransomware attack. Outpatient surgeries and imaging appointments were canceled. Their electronic records system went dark. When reporters asked how long it would last, leadership said they didn't know.
Almost none of these start dramatically. They start with one person opening one file.
Microsoft published a case study in August that's worth your time. An employee opened a malicious attachment. It launched a legitimate, signed Windows utility the attacker had borrowed, and reached out to pull down the next stage of the attack. That's normally where the clock starts: hours of quiet spreading before anything gets encrypted.
Instead, Defender caught it and cut that machine off the network on its own. 128 seconds from the first detection. Nobody on the security team had to lift a finger, and the attack never got off that one laptop.
That's the part I'd want a practice owner to understand. The question was never whether someone on your staff will eventually click something — they will. The question is whether what's watching your endpoints can act in two minutes or two hours, and whether a human is actually reading the alerts it sends.
Worth asking your IT provider before your next renewal: what happens on my network at 2am on a Saturday?
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email