TL;DR: Delta Dental’s security programme is framed around business email compromise and invoice fraud, with controls designed to protect 80 million members across 39 independent companies operating in all 50 states, according to Abnormal AI. The case shows that at scale, identity and email governance have to be built around business workflows, not just perimeter controls.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How Delta Dental’s Cybersecurity Program Protects 80+ Million Smiles”.
Key questions
Q: How should security teams reduce vendor email compromise risk in finance workflows?
A: They should remove email as the sole trust signal for any payment or vendor-change action.
A: They remain effective because attackers exploit trust, not just technical vulnerabilities.
Practitioner guidance
- Harden vendor approval workflows Require secondary verification for payment changes, bank detail updates and invoice exceptions before any downstream action is taken.
- Separate communication trust from action trust Do not let a validated email sender automatically authorise business execution.
- Standardise fraud controls across member companies Set a minimum control baseline for all business units, then document where local workflow variation is allowed and how it is compensated.
Bottom line: Delta Dental’s threat model shows that vendor email compromise and invoice fraud succeed when business trust is granted too early in the workflow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email security alone does not solve identity abuse in business workflows: Delta Dental’s threat focus shows that fraud is succeeding where trusted communication meets operational approval. Business email compromise and invoice fraud are not just message-level problems; they are failures in the trust logic that sits behind payment and vendor workflows. The practitioner takeaway is that identity assurance has to extend into the business process itself, not stop at mailbox hygiene.
A question worth separating out:
Q: How should federated organisations govern email-based fraud risk across business units?
A: Set minimum control requirements for all units, especially around payment validation, vendor changes and exception handling. Then allow local variation only when it is paired with compensating verification steps that preserve the same risk reduction.
👉 Read our full editorial: Delta Dental’s identity controls show the limits of email fraud defense