7 Essential Best Practices for Indiana Small Business Cyber Security

Protect your Indiana small business from costly data breaches with these 7 essential cybersecurity practices designed for professional service firms and owners.
I want to start with a number that should make every business owner in Indiana sit up a little straighter: $4.88 million. According to the IBM Cost of a Data Breach Report 2024, that is the average global cost of a data breach. Now, I know what you are thinking. You are thinking, "Kevin, I run a small professional service firm in Indianapolis, not a global conglomerate. That number doesn't apply to me." While you might not lose four million dollars in a single hit, the reality I have seen over the last 26 years is much grimmer for the little guy. For a firm with 20 or 30 employees, a breach costing even $150,000—which is a very realistic figure when you factor in legal fees, forensics, lost productivity, and the inevitable "trust tax" your clients will charge you—is often enough to turn the lights off for good. In fact, various industry studies over the years have suggested that up to 60% of small businesses that suffer a major cyber attack go out of business within six months.
I started Sentree Systems back in 1999. Back then, "cyber security" mostly meant making sure your dial-up connection didn't drop and keeping your Norton Antivirus subscription current. The world has changed radically since then, but the mindset of many small business owners hasn't caught up. I still hear the same refrain every week: "Why would a hacker in Eastern Europe care about my small accounting practice or my 10-person law firm?" The answer is simple: you are an easy target. You have sensitive data—Social Security numbers, tax records, legal strategies, and bank account info—but you likely don't have the $500,000-a-year security budget that a big bank has. To a cybercriminal, you aren't a small business; you are a low-hanging fruit with a high-value harvest.
In this guide, I am pulling back the curtain on what it actually takes to protect a small professional service firm in Indiana today. We aren't going to talk about "synergistic AI-driven threat landscapes" or other buzzwords designed to sell expensive software. We are going to talk about the practical, direct, and non-negotiable steps you need to take to ensure that the business you've spent years building doesn't disappear because of one wrong click on a Tuesday afternoon. This is about making smarter decisions so you can focus on your clients, not on whether your server is being held for ransom.
Key Takeaways:
- The Human Factor is Your Biggest Risk: According to the 2024 Verizon Data Breach Investigations Report (DBIR), roughly 68% of breaches involve a human element, including errors or falling for social engineering.
- MFA is Non-Negotiable: Implementing Multi-Factor Authentication (MFA) is the single most effective way to prevent unauthorized access, stopping upwards of 99% of bulk password-based attacks.
- Backup is Not Recovery: Having a copy of your files is not the same as having a "Business Continuity" plan. You need to know how fast you can be back in business after a total wipe.
- Phishing is Localized: Hackers are now using local Indiana references, specific vendor names, and even "spoofing" your own employees to make their scams look legitimate.
- Indiana Law Matters: If you lose client data, you are legally obligated under Indiana’s Disclosure of Security Breach law to notify affected individuals, which can be an expensive and reputation-destroying process.
- Cyber Insurance Requires Action: You can no longer just buy a policy and walk away. Most carriers now require proof of specific security controls before they will pay out a claim.
- Complexity is the Enemy: You don't need the most expensive tools; you need the right tools, configured correctly, and used consistently by your team.
The Growing Threat to Indiana’s Professional Service Firms
Since I opened our doors in 1999, the "threat actor" profile has shifted from bored teenagers looking for a thrill to sophisticated, state-sponsored criminal enterprises. These groups operate like legitimate businesses, with HR departments, help desks for their ransomware victims, and specialized "researchers" who spend all day finding vulnerabilities in small business software. Indiana firms are particularly attractive because we have a robust professional services sector—lawyers, accountants, engineers, and architects—who manage significant amounts of client capital and intellectual property.
Understanding the "Why Me?" Fallacy
Many owners I talk to in places like Carmel, Fishers, or downtown Indy feel a sense of security in their size. I've heard it a thousand times: "I only have 15 employees. Why would they bother?" The truth is that most attacks aren't personal. They are automated. Hackers use "bots" to scan the entire internet for open ports, unpatched software, and weak passwords. It's like a thief walking down a street and pulling on every car door handle. They don't care who owns the car; they just care that one of them is unlocked.
I remember a case a few years back with a local engineering firm. They thought they were too small to be a target. One morning, the office manager opened an email that looked like a routine invoice from a vendor they’d worked with for a decade. Within two hours, their entire file server was encrypted. The "ransom" was only $5,000, but the total cost of the downtime—three days of 12 engineers sitting idle—cost the company over $40,000. That’s the "small business" reality of cybercrime.
The Rise of Business Email Compromise (BEC)
While ransomware gets all the headlines, Business Email Compromise (BEC) is the silent killer for professional services. In a BEC attack, a hacker gains access to an executive's or office manager's email account. They don't lock the files; they just sit there and watch. They learn who your clients are, what your invoices look like, and when you expect payments.
According to the FBI’s Internet Crime Complaint Center (IC3), BEC scams accounted for over $2.9 billion in adjusted losses in 2023. I once saw a law firm in the Bloomington area nearly lose $150,000 because a hacker intercepted a real estate closing email. The hacker sent a "correction" to the wiring instructions from the lawyer's actual email account. Luckily, the paralegal thought the phrasing of the email sounded "off"—not like the boss at all—and picked up the phone to verify. That one phone call saved the firm. Most people aren't that lucky.
The Real Cost of a Data Breach
To help you understand why we focus so much on prevention, let's look at the actual math of a breach for a typical 25-person firm in Indiana. These numbers are based on the trends we see in the market and the costs associated with recovery and compliance.
| Expense Category | Estimated Cost (Low End) | Estimated Cost (High End) |
|---|---|---|
| IT Forensics & Recovery | $15,000 | $50,000+ |
| Legal Counsel & Compliance | $10,000 | $30,000 |
| Client Notification & Credit Monitoring | $5,000 | $20,000 |
| Lost Productivity (Staff Idle Time) | $20,000 | $60,000 |
| Reputation Management/PR | $5,000 | $15,000 |
| Total Potential Impact | $55,000 | $175,000+ |
For many small firms, $175,000 isn't just a "bad quarter"—it's a year's worth of profit or the entire cash reserve meant for expansion. This is why cyber security isn't an IT problem; it's a fundamental business risk management problem.
7 Essential Best Practices for Indiana Small Businesses
Over the last quarter-century, I’ve refined what actually works for small firms. You don't need a 50-person IT department, but you do need these seven pillars in place. If you are missing even one, you are leaving your back door wide open.
1. Implement Multi-Factor Authentication (MFA) Everywhere
If you take nothing else away from this article, let it be this: MFA is the single most important security control you can implement. Microsoft has stated that MFA can prevent 99.9% of attacks on your accounts.
In the old days (back in the early 2000s), a strong password was enough. Today, passwords are stolen in bulk and sold on the dark web. If your employee uses the same password for their LinkedIn account as they do for their firm email, and LinkedIn gets breached, the hacker now has the keys to your firm. MFA stops this by requiring a second form of verification—usually a code on a mobile app or a physical security key.
I’ve had business owners tell me their staff will find it "too annoying." My response is always the same: "Is it more annoying than explaining to your biggest client why their sensitive data is on the dark web?" We typically recommend using authenticator apps like Microsoft Authenticator or Duo rather than SMS (text) codes, as hackers can now "swap" SIM cards to intercept texts.
2. Culture-First Security Training
You can have the best firewall in the world, but if your receptionist clicks on a link titled "Urgent: Unpaid Invoice" that downloads a malicious file, the firewall won't save you. Cybersecurity training shouldn't be a boring, once-a-year video that everyone ignores. It needs to be a continuous part of your company culture.
According to KnowBe4, firms that conduct regular phishing simulations see their "Phish-prone" percentage drop from an average of 32.4% down to just 5% within a year. I’ve seen this work firsthand. We started a program for a local CPA firm where we sent out "fake" phishing emails once a month. The first month, nearly half the staff clicked. After six months of short, 2-minute "teachable moment" videos for those who fell for it, the click rate dropped to zero. Your team wants to do the right thing; you just have to show them what the "wrong thing" looks like.
3. Modern Endpoint Protection (Not Just Antivirus)
Traditional antivirus is dead. It works by looking for a "signature" of a known virus. The problem is that hackers create thousands of new variations of malware every single hour. By the time your antivirus has the signature, the damage is done.
Today, we use what’s called Endpoint Detection and Response (EDR). Instead of looking for a specific file name, EDR looks for suspicious behavior. If a program on your computer suddenly starts trying to encrypt all your files or "talk" to a server in a foreign country, EDR identifies that as abnormal behavior and kills the process immediately. It’s the difference between a security guard who only stops people on a "wanted" list and a guard who stops anyone trying to break a window.
4. The 3-2-1-1 Backup Strategy
Backups are your last line of defense. If all else fails, your backups allow you to tell the hackers where they can stick their ransom demand. However, I’ve seen too many Indiana businesses realize too late that their backups weren't working or, worse, that the hackers encrypted the backups too.
I advocate for the 3-2-1-1 rule:
- 3 copies of your data: The original and two backups.
- 2 different media types: For example, one on a local server/drive and one in the cloud.
- 1 offsite: Crucial for protecting against physical disasters like fire or the tornadoes we get here in Indiana.
- 1 immutable/air-gapped copy: This is a backup that cannot be changed or deleted for a set period, even by someone with administrator credentials. This is your "nuclear option" against ransomware.
5. Disciplined Patch Management
Every piece of software you use—Windows, Adobe, Chrome, even your office printer’s software—has bugs. When a developer finds a bug that a hacker could use, they release a "patch." If you don't install that patch immediately, you are essentially leaving your front door unlocked after being told there’s a burglar in the neighborhood.
The 2017 Equifax breach, which exposed the data of 147 million people, happened because they failed to patch a known vulnerability for two months. For a small firm, keeping up with updates on 20 different computers is a nightmare. This is why you need a centralized system that pushes these updates automatically, ensuring no one clicks "Remind me tomorrow" for three weeks straight.
6. Zero Trust and the Principle of Least Privilege
In many small offices, everyone is an "administrator" on their computer. This is a massive security hole. If an employee with admin rights accidentally runs a malicious file, that file has the power to change anything on the entire system.
We practice the "Principle of Least Privilege." This means employees only have the access they absolutely need to do their jobs. Does your marketing person need access to the payroll folders? No. Does your intern need the ability to install new software? Probably not. By limiting what each person can touch, you limit how far a hacker can travel if they get into one person's account. This is part of a "Zero Trust" model: never trust, always verify.
7. Vendor Risk Management
As a small professional service firm, you rely on other companies—your cloud-based CRM, your payroll provider, your IT company (like us). Your security is only as strong as your weakest link. If your payroll provider gets breached, your employees' data is gone.
I recommend that my clients do a quick "security audit" of their major vendors once a year. Ask them for their SOC2 report or a summary of their security practices. If they can’t give you a straight answer, it might be time to find a vendor that takes your data as seriously as you do. In my 26 years, I’ve seen more than one firm get compromised not through their own office, but through a "trusted" partner who had sloppy security.
Implementation: How to Start Today
Knowing what to do is half the battle; actually doing it is where most owners get stuck. You have a business to run. You can't spend 40 hours a week playing IT director. Here is a practical, step-by-step roadmap to getting these practices in place over the next 90 days.
- Week 1-2: Audit and MFA. Make a list of every single app your firm uses (Email, OneDrive, QuickBooks, etc.). Turn on MFA for every one of them. No exceptions for the "old school" partners who hate it.
- Week 3-4: Inventory and Access. Identify who has access to what. Move your files into folders with restricted permissions. Remove local "Admin" rights from staff computers.
- Week 5-8: Update Your Tech Stack. Replace "free" antivirus with a managed EDR solution. Ensure your backup system includes an offsite, immutable copy. Set up automated patching for Windows and third-party apps.
- Week 9-12: Training and Policy. Hold a 30-minute "All Hands" meeting to discuss the new security culture. Start your monthly phishing simulations. Create a simple "Incident Response" one-pager: If you think something is wrong, call [IT person] immediately. Do not restart your computer. Do not try to fix it yourself.
Frequently Asked Questions
Is Mac more secure than Windows for a small firm?
This is a common myth. While there used to be more viruses for Windows because it was a larger target, hackers have caught up. Macs are just as vulnerable to phishing, BEC, and modern malware. No matter what hardware you use, the security practices (MFA, EDR, Training) remain exactly the same.
We use the "Cloud" (like Microsoft 365 or Google Workspace). Aren't we already protected?
No. Microsoft and Google provide a secure infrastructure, but you are responsible for how you use it. This is called the "Shared Responsibility Model." If you don't turn on MFA, or if you grant a malicious app permission to read your emails, Microsoft won't stop it. The cloud is a tool, not a shield.
What about Cyber Insurance? Is it worth it?
Absolutely, but with a caveat. Cyber insurance is vital for covering the costs of a breach (forensics, legal, etc.), but it is not a replacement for security. Most insurance carriers now require a checklist of security measures (like MFA and backups) before they will issue a policy. If you claim to have MFA and you don't, they will deny your claim after a breach.
How much should a firm with 15 people spend on cybersecurity?
While every firm is different, a good rule of thumb for professional services is that IT and security combined should account for about 4% to 7% of your total revenue. Think of it as an "existence tax"—the cost of doing business safely in the digital age.
I’m just a small shop. Can’t I just use a free antivirus?
In my 26 years, I have never seen a "free" security tool provide adequate protection for a business environment. Free tools lack the centralized management, behavioral analysis, and support needed when things go wrong. If you are protecting client data, you need professional-grade tools.
What is the biggest mistake you see Indiana business owners making?
Assuming that "it won't happen to me" or that their "IT guy" has it all covered without ever asking for proof. I’ve seen many "IT guys" who are great at fixing printers but have no idea how to defend against a modern ransomware attack. You need to be an active participant in your firm's security.
Conclusion
I’ve been doing this since 1999, and if there is one thing I’ve learned, it’s that security is not about being "unhackable." Nothing is unhackable. Security is about making yourself a difficult target. It’s about building layers of defense so that when one thing fails—and eventually, something will—the whole house doesn't come crashing down.
For small professional service firms in Indiana, your reputation is your most valuable asset. Your clients trust you with their most sensitive information. Failing to protect that data isn't just an IT failure; it’s a breach of that trust. The steps I’ve outlined here aren't just "best practices"; they are the foundation of a resilient, professional business.
Don't let the technical details overwhelm you. Start with MFA. Start with training your team. The return on investment for these steps isn't just "not losing money"—it's the peace of mind that comes with knowing you’ve done everything in your power to protect your employees, your clients, and your legacy. If you have questions or aren't sure where your firm stands, I'm here to help. We've been doing this for over a quarter-century, and we're just getting started.
Watch: How to Stop Escrow Wire Fraud Scams in a Small Title Company
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment