Protect Indiana.org East Central Region

Protect Indiana · small business security

The part of securityyour IT guy was neverhired to do.

We work the layer where small businesses actually lose money — the invoice that isn’t real, the vendor who “changed banks,” the voice on the phone that sounds exactly like the owner. Nothing to install. Nobody touching your computers. A named agent in your region who picks up.

See what we find on your domain

Free. No card, no call required.

$233,016,771

reported lost by Indiana people and businesses in a single year. Indiana files the 15th-most complaints of any state.

FBI Internet Crime Complaint Center, 2025

Two different jobs

You probably already have someone for the computers.

Good. That is not this. An IT company is measured on whether things work. We are measured on whether things get taken. Those are different questions, and almost nobody is being asked the second one.

Someone else’s job

What the IT company is for

  • The computers turn on and stay on
  • The email accounts exist and sync
  • The Wi-Fi reaches the back office
  • Something is running that says “backup”
  • The printer, always the printer

Ours

What we are for

  • Who is allowed to move a payment, and how they check first
  • Who can log in to the bank, the payroll, the website — and who still can after they quit
  • Who answers when a caller claims to be you, in your voice
  • Whether that backup has ever actually been restored
  • What you can prove when an insurer or a big customer asks

We do not sell software. We do not take a commission on anything. We never hold the keys to your systems. If those things ever change, we have stopped being useful to you.

Where the money actually goes

Almost none of it is the movie version.

This is every dollar American victims reported losing in 2025, sorted by how it was taken. Look at what sits near the top. Nobody broke in. Somebody was convinced — by an email, by a phone call, by a screen that looked official.

Investment & crypto scams$8.65B
Fake invoices & payment redirectsthe one that hits small business hardest$3.05B
Fake tech supportthe pop-up and the “Microsoft” phone call$2.13B
Personal data stolen$1.31B
Romance & confidence scams$929M
Someone posing as a government office$798M
Company data breaches$435M
Ransomwarefar understated — excludes lost business, wages and equipment$32M

FBI Internet Crime Complaint Center, 2025 Internet Crime Report. $20.9 billion reported lost in total, up 26% in one year.

And now the voice on the phone is free to fake.

In 2025 the FBI logged 22,364 complaints that specifically named AI, totalling $893 million. Cloned voices are now used to call a bookkeeper and authorise a wire in the owner’s own voice. Over $30 million of invoice-fraud losses last year involved AI directly. There is no app that reliably detects a cloned voice — not ours, not anybody’s. What works is a rule you agree on in advance, which is the first thing we write with you.

22,364

complaints naming AI in 2025

$893M

lost in those complaints

$0

cost of the rule that stops it

What is true on your street

We checked, and we did not ask permission first.

Anyone on the internet can read the settings that decide whether a stranger is allowed to send email in your company’s name. We read them for every independent business we could find across four counties. Nothing here required access to anyone’s systems, and none of it is a break-in — it is public, which is exactly the problem.

74%

404 of the 544 businesses of the businesses we checked can be impersonated by a stranger today

By county

Delaware274 of 371
Henry89 of 118
Wayne26 of 33
Madison15 of 22

By trade

Other local business56%
Restaurants, retail & hospitality81%
Healthcare & dental68%
Construction & trades62%
Churches & nonprofits62%
Clubs, sport & recreation76%
Home & property services63%

Share of each trade whose email can currently be forged. A business is counted as exposed when its domain publishes no enforced policy telling the world’s mail servers to reject forgeries.

We do not publish which businesses. Ever. If yours is one of them we will tell you privately, show you the exact settings, and fix it for nothing.

What we actually do

Eight things, and only two of them are about email.

Take all of it or take one piece. Most businesses start with the free check and add the rest when something makes them want to.

Someone is pretending to be you

The most common attack on a small company is not against the company at all — it is against the people who trust it. Your customers, your suppliers, your bank. We watch the places your name shows up that you do not control.

  • Stop strangers sending email in your company’s name
  • One line a week telling you whether anybody tried
  • Watch for web addresses registered to look like yours
  • Watch your online listing, your reviews, and job ads posted in your name
  • If it happens: the customer notice, the front-desk script, and the reports filed the same morning

Nobody moves money on an email alone

The rules that decide whether a convincing request actually becomes a payment. Written on one page, posted where the money is handled.

  • One page: what can be paid on an email, what needs a phone call first, what nobody may ever do
  • The vendor rule: no bank-detail change without a callback to a number you already had
  • A code word so a cloned voice cannot authorise anything
  • Sit down with your banker and switch on the free protections they never mentioned
  • Lock the payroll portal so nobody can quietly redirect a paycheque

Who can log in — and who still can

The unglamorous one. It is also the first thing an insurance form asks about, and the first thing that goes wrong when someone leaves badly.

  • Get shared passwords out of the group text and the sticky notes
  • Turn on the second step where it actually matters
  • Tell you when your addresses show up in somebody else’s data breach
  • A written list of every account that can change something important
  • The checklist you run the day somebody quits

The people who actually stop it

Every one of these attacks ends with a human being deciding to believe something. The advice to “look for typos” is dead — the scams are written by the same tools we all use now.

  • Training on what is hitting businesses in your county this month
  • A harmless practice scam, so you learn who clicks before a real one does
  • One page on what staff may and may not paste into an AI chatbot
  • A card at the bookkeeper’s desk with the four questions to ask
  • A short orientation you can run yourself for every new hire

The doors you forgot were open

What a stranger can see, reach, or walk into without being invited. Most of what we find is something switched on years ago by someone who has since moved on.

  • Look at your business the way the internet sees it
  • Ask your web host the questions the FTC says you should have asked before hiring them
  • Make sure nobody can steal the web address your whole business runs on
  • Check the guest Wi-Fi is genuinely separate from the one you work on
  • A walk through the building: the unlocked screen, the unshredded bin, the old laptop

The morning everything is locked

Not preventing the bad day — surviving it. The FBI’s number one recommendation is a backup somebody has actually restored from. Nearly every business believes it has one. Very few have ever tried.

  • We do not run your backups. We make somebody prove one restores, and write down the date
  • Three pages: the first hour, how you keep serving customers, how you get back
  • Decide in daylight what you would do if you were locked out — not at 2am
  • Work out in advance who you would have to tell, and how fast
  • If money has already gone: we work the recall clock with you while it still counts

When somebody asks you to prove it

A growing amount of small-business pain is paperwork with a deadline attached, arriving from someone else. This is the department nobody around here sells.

  • The cyber-insurance form, answered honestly — wrong answers can void the cover you are paying for
  • The forty-question security form a big customer just sent you
  • A four-page security policy a twelve-person company can actually follow
  • One document listing what you own and who can reach it
  • Plain-English security terms for the vendors who touch your systems

“Is this real?” Ask us.

This is the part people actually pay for. Everything above is the reason you trust the answer. Forward anything that smells wrong — an invoice, a text, a login warning, a caller who knew too much — and get a straight answer the same business day from a person who already knows your business.

  • Same business day, from your named agent, not a ticket queue
  • Most of what gets forwarded to us turns out to be fine, and we say so plainly — we are not paid to keep you frightened
  • A note when something is actually working on businesses in your county
  • Forty-five minutes a quarter with the owner: what changed, what we caught, what is next

How it starts

Nothing you have to decide today.

We built this backwards from how people actually buy something like this, which is slowly, after watching it work.

First

We check, and we tell you

We read the public settings on your web address and show you exactly what a stranger could do with them. Plain English, with the technical proof underneath for whoever handles your IT. It costs nothing and there is no call attached to it.

Then

We fix it, still for nothing

If you are exposed, you get the exact settings to paste in — or we walk your IT person through it. We do not hold this hostage. A business that can be impersonated is bad for the whole county, ours included.

Weekly

One line, free, forever

Once it is fixed we keep watching, and once a week you get a single line from your agent: nothing happened, or here is what did. No card. No expiry. If you never speak to us again, that keeps running.

Later

You already know who to call

Most people come to us the first time they need judgement instead of data — a form they cannot answer, a message they cannot read, a payment that already went out. That is when the retainer starts making sense, and not before.

Plans

What it costs when you want it always there.

Month to month. No setup fee, no minimum term, no equipment. Cancel by saying so.

The Watch

$0

always

We already watch your front door.

Anyone in the region who took the free check.

  • The exposure check and the exact fix
  • One line a week on your domain
  • A note when something is going around your county

No card, no expiry, no catch.

On Call

$99

per month

A security person who picks up.

Roughly 5–15 people, and somebody pays invoices out of an inbox.

  • Everything in The Watch
  • Forward anything, get an answer the same business day
  • Your money rules and the vendor callback rule written and posted
  • A code word so a cloned voice cannot authorise a payment
  • Passwords and second-step sorted; we watch for your addresses in breaches
  • We check what the internet can see of you, and lock your web address
  • We make somebody prove your backup restores
  • The insurance form, when renewal comes round
  • If money goes out the door: we work the recall clock with you

Priced like a phone bill, not an IT contract.

Trained Crew

$199

per month

It is rarely the owner who stops it. It is whoever opens the invoice.

Roughly 10–40 people, where several hands touch the inbox and the money.

  • Everything in On Call
  • Training in person, on this month’s real scams
  • A harmless practice scam each quarter, results to you only
  • Joiner and leaver checklists; a list of who can change what
  • Your banker meeting, and the payroll portal locked
  • Website, host, Wi-Fi and remote access all checked
  • The bad-day plan, on paper
  • Your listing, reviews and name watched
  • Forty-five minutes with you every quarter

Most businesses land here after their first practice scam comes back.

Locked Down

$349

per month

Your name is worth stealing. We watch that too.

Law, accounting and title offices, and anyone moving large sums or holding client money.

  • Everything in Trained Crew
  • Your own and your partners’ personal details pulled off the broker sites, quarterly
  • A walk through the building
  • Notification readiness worked out in advance
  • First call on the recall clock
  • All project work included at cost

Sold on the principal’s exposure, because that is what is actually at risk.

One-off jobs

per job

quoted first

Someone else set the deadline. We can just do the thing.

Anyone, including businesses on the free tier.

  • The big customer’s security questionnaire
  • A written security policy
  • A list of what you own and who can reach it
  • Security terms for your vendors
  • A review of how card payments move through your shop

Quoted before we start. No subscription required.

Straight answers

The questions people actually ask.

Aren’t we too small for anyone to bother with?

It is the opposite, and this is the single most expensive belief in small business. You are targeted because you have no security staff, and because you move real money with a small number of people who all trust each other. The attacks that took $3 billion last year were not aimed at banks. They were aimed at somebody’s bookkeeper.

Isn’t this our IT company’s job?

Some of it overlaps, and where it does we will tell you and stay out of the way — we are not trying to replace them and we will never ask you to. But an IT company is hired to keep things working. Almost none of them are hired to write your payment rules, train your front desk, answer your insurance form, or tell you that a caller sounded wrong. If yours does all that, you are in good shape and you do not need us.

Do you need access to our computers?

No. Not the computers, not the servers, not the network, not the passwords. We never hold your keys. Everything we do is either public information, something we hand you to paste in yourself, or a rule written on paper. That is a deliberate limit — it means a break-in at our end cannot become a break-in at yours.

Are you with the state, or the police?

No. Protect Indiana is a private Indiana company. Nothing we send you is a legal notice, nothing we find is a violation of anything, and you are under no obligation to reply to us or to hire us. If we ever sound official, we have written it badly — tell us.

What if it already happened to us?

Then the clock matters more than anything else on this page. The FBI’s recovery team managed to freeze 58% of the money it went after last year, but that depends on the bank recall and the federal report going in immediately, with the full transaction detail. We will work that checklist with you on the phone. We will not promise you get the money back, we never handle the money, and anybody who does promise that is lying to you.

Do we have to sign something long?

No. Month to month, no setup fee, no minimum term, no equipment to buy back. If it stops being worth $99 to you, say so and it stops.

How do you make money if the check is free?

Some people who take the free check eventually want somebody on retainer, and a few of them pick us because they have watched us be useful for months first. The rest get a fixed domain and a weekly email forever and we are genuinely fine with that. It is a cheap way to be known in a region where nobody else is doing this.

Find out what a stranger can already do with your name.

Send us your web address. We will read what is public, tell you plainly what it means, and if there is a hole we will give you the exact fix. There is no invoice at the end of it and no one will call you unless you ask.

Send us your web address

or call 1-888-985-6187 — ask for the East Central Region

Protect Indiana is a private company. We are not a government office and this is not a legal notice.