Fort Wayne & Northeast Indiana network security, Wi-Fi, optimization, and camera systems.
Systems Monitored: ACTIVE
Call: 260-408-5500
LiveWire Security Academy

The cybersecurity education your business actually needs.

Most small business owners discover they had a serious security problem the hard way. These lessons exist so you don't have to. Written by a network engineer with 15+ years in the field. No jargon. No upselling. Just the truth about what protects your business and what doesn't.

20+ Free Lessons 15+ Years Field Experience Plain English Only Fort Wayne & Beyond
How This Academy Works

Built for owners, not IT professionals.

Free Lessons

Every lesson on this page is completely free. Read at your own pace, share with your staff, print them out. No login required and no strings attached.

Real World Focus

These are not textbook definitions. Every lesson comes from real situations we have seen in Fort Wayne businesses — and the mistakes that made them vulnerable.

Premium Content Coming

Deeper dives, video walkthroughs, live Q&A, and certification are coming for members. Join the waitlist below to get early access and a discount.

Your Learning Journey

Where do you want to be?

Most small business owners start at Unaware — not through negligence but through lack of exposure. Here is where these lessons take you.

1
Unaware
You don't know what risks exist on your network. Most small businesses start here without realizing it.
Informed
You understand the core threats, recognize warning signs, and know what questions to ask your IT provider.
Protected
You have implemented the right controls, tested them, documented your network, and have a written response plan.
Confident
You can articulate your security posture with specifics, evaluate vendors, and lead your team with real authority.
These lessons take you from Unaware to Informed. Our paid program takes you the rest of the way.
Start Here

Foundation — What every business owner must know.

These six lessons cover the most critical concepts. If you read nothing else on this page, read these.

Beginner 5 min read
Lesson 01

What Is Phishing and How to Spot It

Phishing is the single most common entry point for cyberattacks against small businesses. An attacker crafts an email that appears to come from a trusted source — your bank, Microsoft, QuickBooks, a vendor, or even your own boss. The goal is always the same: get you to click a link, enter credentials, download a file, or wire money before you realize what is happening. These emails have become extraordinarily convincing — they use real logos, real names pulled from LinkedIn, and create artificial urgency so you act before you think. In 2024, over 91% of all cyberattacks began with a phishing email. Small businesses are targeted more than enterprises because attackers know they have fewer defenses.

▸ Real World Example

A Fort Wayne restaurant owner received an email appearing to be from their POS vendor saying their account would be suspended in 24 hours unless they verified their payment information. The email used the vendor's real logo and the owner's actual name. They clicked the link, entered their credentials, and within hours the attacker had accessed the POS system and exported three months of customer card data.

✓ Key Takeaway

Urgency is a weapon. Any email that demands immediate action, threatens consequences, or asks for credentials or payment is a red flag regardless of who it appears to come from.

→ Action Item

Forward one suspicious email per week to your staff and walk through why it is or is not legitimate. Ten minutes of practice builds better instincts than any policy document.

Beginner 6 min read
Lesson 02

Social Engineering — Humans Are the Vulnerability

Social engineering is the art of manipulating people into giving up access, information, or money without ever touching a computer. Attackers study their targets, build false trust, create urgency, and exploit natural human tendencies like helpfulness and fear of authority. It works on everyone — from front desk employees to CEOs. Kevin Mitnick, one of the most prolific hackers in history, built his entire career on social engineering rather than technical exploits. He said the human side of security is the easiest to breach and the hardest to patch. Common techniques include pretexting (inventing a scenario), vishing (voice phishing by phone), smishing (phishing by text message), and impersonation in person.

▸ Real World Example

An attacker called a small accounting firm in Indiana posing as their IT support company. They said there was an urgent security update needed and asked the receptionist to read them the temporary access code that appeared on her screen. She did. The attacker used that code to access the firm's remote desktop system and spent two weeks quietly exfiltrating client tax records before anyone noticed.

✓ Key Takeaway

Create a verification rule: no passwords, no access codes, no wire transfers, and no sensitive information changes hands based on a phone call or email alone — always verify through a second channel using contact information you already have on file.

→ Action Item

Write a one-paragraph policy for your business today: "Any request for passwords, financial transfers, or system access must be verified by calling back on a known number." Post it near every phone in the office.

Beginner 4 min read
Lesson 03

Your ISP Router Is Not a Firewall

When your internet provider installed your service they left behind a device — usually a white or black plastic box with blinking lights. That device is a modem-router combo. It connects your business to the internet and handles basic traffic routing. What it does not do is inspect traffic for threats, enforce security rules, log suspicious activity, block malicious connections, or give you any visibility into what is happening on your network. A real business-grade firewall does all of those things and more. The gap between an ISP-provided router and a proper firewall is not a small gap — it is the difference between an open door and a staffed security checkpoint.

▸ Real World Example

A Fort Wayne retail shop was breached through their ISP router. The router had a known vulnerability that had been publicly disclosed for eight months. Because the ISP never pushed a firmware update and the owner did not know to check, the router was running vulnerable software that an automated scanner found and exploited in under three minutes. The attacker used it as a pivot point to access the point-of-sale system.

✓ Key Takeaway

If the only device between your business and the internet is the box your ISP gave you, you have no real network security. That box was designed to connect you to the internet, not to protect you from it.

→ Action Item

Look at the device your ISP installed. Find the model number and search for "[model name] vulnerabilities" online. If you find results from the last two years you have a problem worth addressing immediately.

Beginner 5 min read
Lesson 04

VLANs — Why Your Network Needs Walls

A VLAN is a Virtual Local Area Network — a way to logically divide one physical network into separate isolated segments that cannot communicate with each other without explicit permission. Think of your business network as a building. Without VLANs, every room is connected to every other room with no doors and no locks. Your point-of-sale system can see your cameras. Your cameras can see your file server. Your guest Wi-Fi can reach your accounting software. With VLANs, each segment is its own locked floor with controlled access between them. This is not a luxury for large enterprises — it is a basic necessity for any business that processes payments, stores customer data, or has security cameras.

▸ Real World Example

A small dental practice had their patient management system, X-ray workstations, guest Wi-Fi, and front desk computers all on the same flat network. A patient connected to the guest Wi-Fi and used a simple network scanning tool out of curiosity. They could see every device on the network including the patient management server. They reported it to the practice — but a malicious actor would not have.

✓ Key Takeaway

Every business should have at minimum four separate network segments: one for business computers, one for point-of-sale or payment systems, one for cameras and IoT devices, and one for guest Wi-Fi. These should not be able to reach each other without a firewall rule explicitly allowing it.

→ Action Item

Ask whoever manages your network one question: "Can you show me our network diagram and explain which VLANs we have?" If they cannot answer or you do not have a network diagram, you do not know what you have.

Beginner 4 min read
Lesson 05

Guest Wi-Fi Done Wrong — The Most Common Mistake

Offering guest Wi-Fi is good customer service. Offering it incorrectly is an open door into your business. The most common mistake is creating a separate Wi-Fi password on the same router without any network isolation. A customer connected to your guest network can still see and potentially reach devices on your main business network because they are on the same underlying subnet. Proper guest Wi-Fi requires a separate SSID, a dedicated VLAN, and firewall rules that allow the guest network to reach the internet only — nothing on the inside. This requires a business-grade access point and a proper firewall, not a consumer router with a guest password option.

▸ Real World Example

A coffee shop offered free guest Wi-Fi. Their network printer, point-of-sale iPad, and back-office computer were all reachable from the guest network. A regular customer who happened to be a network engineer pointed this out after being able to see the printer and connect to it from his laptop while ordering a latte. The owner had no idea.

✓ Key Takeaway

If your guest Wi-Fi and your business systems are managed by the same consumer router, they are not actually isolated — regardless of what the settings page says.

→ Action Item

Connect a personal device to your own guest Wi-Fi and open a network scanning app like Fing (free on iOS and Android). If you can see your business devices from the guest network, your isolation is not working.

Beginner 5 min read
Lesson 06

Password Security — What Actually Works

Most password advice is wrong. Requiring complex passwords with symbols and numbers that change every 90 days actually makes security worse because people write them down, reuse them across sites, or make predictable substitutions. What actually works according to NIST — the National Institute of Standards and Technology — is length over complexity, no forced rotation unless a breach is suspected, and checking passwords against lists of known compromised credentials. A 20-character passphrase like "coffee-fort-wayne-network" is stronger than "P@ssw0rd1!" and far easier to remember. The other thing that actually works is multi-factor authentication — requiring a second form of verification in addition to a password.

▸ Real World Example

A small logistics company in Indiana was breached through a reused password. An employee used the same password for their work email and a fitness app. The fitness app was breached in 2022 and the credentials were sold on the dark web. An attacker used those credentials to log into the company's email system nine months later and spent three weeks reading emails and forwarding financial communications to an external address before anyone noticed.

✓ Key Takeaway

Password length beats complexity. Multi-factor authentication beats both. Enable MFA on every business account that offers it — email, banking, accounting software, and remote access — today.

→ Action Item

Go to haveibeenpwned.com right now and enter your business email address. It will tell you if your credentials have appeared in any known data breaches. It is free and takes 10 seconds.

Go Deeper

Intermediate — Common attack scenarios and how they work.

You know the basics. Now learn how real attacks unfold — step by step — so you can recognize them before they reach your business.

Intermediate 7 min read
Lesson 07

Ransomware — A Step by Step Breakdown

Ransomware does not happen instantly. The visible moment — when your files are encrypted and the ransom note appears — is actually the end of a process that began days, weeks, or even months earlier. Phase one is initial access, typically through a phishing email, a vulnerability in an internet-facing service, or compromised credentials. Phase two is persistence — the attacker installs tools to maintain access even if the original entry point is closed. Phase three is reconnaissance — they map your network, identify valuable data, and locate your backups. Phase four is lateral movement — they spread through your network to reach high-value targets. Phase five is exfiltration — they copy your data before encrypting it, giving them leverage even if you restore from backup. Phase six is encryption — only then do they trigger the ransomware. By the time you see the note, your backups may already be compromised and your data may already be sold.

▸ Real World Example

A Midwest manufacturing company paid $340,000 in ransom in 2023 after attackers spent 23 days inside their network before triggering encryption. The initial entry point was a phishing email opened by an accounts payable employee. The attackers moved to the domain controller, disabled antivirus across the network, encrypted both primary storage and backup drives, and exfiltrated 40GB of financial data before triggering the payload.

✓ Key Takeaway

Ransomware defense is not about antivirus. It is about network segmentation that limits lateral movement, offline backups that cannot be reached from the network, and rapid detection of unusual internal traffic.

→ Action Item

Ask yourself: if your primary server was encrypted right now, where is your most recent backup and is it accessible from the network? If the answer is yes, your backup will be encrypted too.

Intermediate 5 min read
Lesson 08

Why IP Cameras Are a Security Risk

IP cameras are the most commonly overlooked security vulnerability in small business networks. Most are installed by low-bid security companies that connect them directly to the main business network, never change the default credentials, and never update the firmware. IP cameras run embedded Linux with a web server and often have remote access capabilities — which means they are internet-facing computers with known vulnerabilities running on your internal network. Mirai, one of the largest botnets in history, was built almost entirely from compromised IP cameras and DVRs. In 2021, a hacker accessed 150,000 cameras at Verkada — a major security company — through a single set of stolen credentials.

▸ Real World Example

A small Fort Wayne manufacturer installed eight IP cameras for facility security. The installer connected all cameras to the main business network and left the default admin password of "admin" on every camera. Eighteen months later a routine security scan found that two cameras had been compromised and were being used as part of a botnet — generating outbound traffic to command and control servers 24 hours a day. The business had been unknowingly participating in cyberattacks against other organizations.

✓ Key Takeaway

Cameras must be on their own isolated VLAN with no ability to reach business systems. Default credentials must be changed on every device. Firmware must be updated regularly. Remote viewing should go through a VPN, not a direct port forward.

→ Action Item

Find your camera system's DVR or NVR and try logging in with the username "admin" and password "admin" or "12345." If it works, your system has default credentials that need to be changed immediately.

Intermediate 6 min read
Lesson 09

Vendor Access — The Hidden Threat Inside Your Network

Third party vendor access is one of the most underestimated risks in small business security. Your HVAC technician needs building access. Your POS vendor needs remote access for updates. Your accountant needs access to financial files. Your cleaning crew works alone after hours and knows your Wi-Fi password. Each of these access points represents a potential entry vector — not because these people are malicious but because their own systems, credentials, and practices may be compromised. The 2013 Target breach that exposed 40 million credit cards started through a heating and air conditioning vendor who had network access for remote monitoring. The vendor was compromised and that access was used to reach Target's POS systems.

▸ Real World Example

A small law firm gave their IT vendor persistent VPN access for remote support. When that IT vendor was acquired by a larger company, the VPN credentials were transferred to a new team. A disgruntled employee at the acquiring company used those credentials to access the law firm's file server and exfiltrated client documents. The law firm did not know their vendor had changed ownership and had no process for reviewing or rotating third party credentials.

✓ Key Takeaway

Every vendor access credential should be documented, time-limited, and reviewed quarterly. Vendors should be on isolated network segments. When a vendor relationship ends, their access must be revoked immediately.

→ Action Item

Make a list right now of every person or company that has access to your network — physically or remotely. For each one, ask: do they still need this access, when did we last review it, and what can they actually reach?

Intermediate 6 min read
Lesson 10

How to Analyze a Suspicious Email

Display names in email mean nothing. An attacker can set the display name to "Microsoft Support" or "Your Bank" or even your CEO's name while sending from any address they control. What matters is the actual sending domain — the part after the @ symbol in the real address, not the display name. Beyond the sending address, look at the reply-to address which may differ from the from address, hover over all links to see the actual destination URL before clicking, check whether the email was authenticated using SPF, DKIM, and DMARC by viewing the full headers, and look for subtle domain spoofing like micros0ft.com with a zero instead of an o or paypa1.com with a one instead of an l. Legitimate organizations will never ask for your password, send unexpected attachments, or demand immediate action to avoid account termination.

▸ Real World Example

An office manager received an email appearing to be from the company's owner asking her to purchase $2,000 in Google Play gift cards for a client gift and email the codes immediately. The display name showed the owner's name. The actual sending address was from a Gmail account with a slight variation of the owner's name. The urgency and the owner's authority overrode her instincts. She purchased the cards and sent the codes before calling to verify.

✓ Key Takeaway

Any request involving money, gift cards, wire transfers, or credential changes that comes through email should be verified by calling the requester directly on a number you already have — never using contact information from the email itself.

→ Action Item

Open any email in your inbox and find how to view the full headers — in Gmail click the three dots and select "Show original." Look at the "From" field in the raw headers versus what displays in your inbox. Practice reading the actual sending domain.

Intermediate 6 min read
Lesson 11

Network Traffic — What Normal Looks Like and What Doesn't

Most small business networks have never been baselined — meaning no one has ever documented what normal traffic looks like so that abnormal traffic can be detected. On a healthy network, traffic patterns are predictable: business hours show activity to known cloud services, file servers, email, and the internet. After-hours traffic should drop to near zero except for scheduled backups and updates. Red flags include large outbound data transfers at unusual hours, connections to foreign IP addresses or unfamiliar cloud services, internal devices scanning other internal devices, DNS requests to unusual domains, and traffic on ports that should not be in use. A business-grade firewall logs all of this. A consumer router logs none of it.

▸ Real World Example

A small CPA firm's firewall logs showed a consistent 2GB outbound transfer every night at 2am for three weeks before anyone noticed. Investigation revealed that a workstation had been compromised with data exfiltration malware that had been quietly copying client tax files to a cloud storage service in Eastern Europe every night while the office was empty.

✓ Key Takeaway

You cannot detect what you cannot see. If your network has no logging, no firewall, and no monitoring, you have no way of knowing whether you are currently being compromised.

→ Action Item

Ask your IT provider to show you last week's firewall logs. If they cannot produce them or you have no firewall generating logs, you have no visibility into your own network.

Critical Knowledge

Advanced — What business owners must know to make informed decisions.

These lessons cover topics that most IT people never explain to business owners. Understanding them helps you ask better questions, make better decisions, and hold your vendors accountable.

Advanced 7 min read
Lesson 12

PCI DSS — What Card-Processing Businesses Are Required to Do

PCI DSS — the Payment Card Industry Data Security Standard — is a set of security requirements that apply to any business that accepts, processes, stores, or transmits credit or debit card data. This is not a government regulation but it is contractually required by your payment processor and the card brands. Non-compliance can result in monthly fines from your processor, loss of the ability to accept cards, and direct liability for fraudulent charges following a breach. The standard has 12 core requirements covering network security, access control, encryption, logging, vulnerability management, and regular testing. For small businesses the most critical requirements are network segmentation of cardholder data environments, strong access controls, encryption of card data in transit, and annual self-assessment questionnaires.

▸ Real World Example

A small restaurant was found non-compliant after a card breach that exposed 800 customer cards. Their processor charged them $25,000 in non-compliance fines, required a forensic investigation at their expense ($15,000), and held back $40,000 in processing reserves pending the investigation. The root cause was their POS system being on the same network as their guest Wi-Fi — a basic segmentation failure that would have cost under $1,000 to fix properly.

✓ Key Takeaway

If you process credit cards and your POS system shares a network with anything else — guest Wi-Fi, cameras, employee computers — you are almost certainly out of PCI compliance right now and exposed to significant financial liability in the event of a breach.

→ Action Item

Contact your payment processor and ask them to send you your current PCI compliance status and your required Self-Assessment Questionnaire type. If you have never completed one, you are non-compliant.

Advanced 7 min read
Lesson 13

Incident Response — The First 60 Minutes of a Breach

The decisions made in the first 60 minutes of discovering a breach determine whether an incident becomes a manageable problem or a catastrophic disaster. Most businesses make critical mistakes in this window because they have no plan and panic drives the response. The most common mistakes are: continuing to use compromised systems which allows attackers to observe your response, deleting files or logs in an attempt to clean up which destroys forensic evidence, paying a ransom without legal and insurance consultation, and failing to notify stakeholders in a timely manner which can create additional legal liability. A proper incident response follows a documented plan: isolate, document, notify, investigate, remediate, and review.

▸ Real World Example

A small manufacturing company discovered ransomware on a Monday morning. With no incident response plan, the owner spent three hours trying to remove the malware himself, inadvertently destroying forensic evidence. He then paid the ransom without consulting his cyber insurance carrier — which voided his claim. He spent $47,000 in ransom and recovery costs that would have been largely covered by his policy if he had called his insurer first.

✓ Key Takeaway

The two most important calls in the first 60 minutes of a breach are to your IT provider and your cyber insurance carrier — in that order. Do not pay ransom, do not delete files, and do not continue using compromised systems until you have professional guidance.

→ Action Item

Write a one-page incident response plan this week. It should include: who to call (IT provider, cyber insurance, legal), how to isolate systems (physically unplug from network), what not to do (delete files, pay ransom without consultation), and where your most recent backup is located.

Advanced 6 min read
Lesson 14

How to Evaluate Your IT Provider's Security Work

Most small business owners have no way to evaluate whether their IT provider is doing a good job because they do not know what good looks like. This is by design — complexity keeps clients dependent. A competent IT provider who has properly secured your network should be able to immediately produce: a current network diagram showing all devices and segments, a firewall rule summary explaining what is allowed and why, documentation of all credentials and where they are stored, a log of recent changes made to the network, and a summary of known vulnerabilities and remediation status. If your IT provider cannot produce any of these on request, you do not know what you have and neither do they.

▸ Real World Example

A business owner hired a new IT provider after feeling uncertain about their current one. The new provider asked for the network documentation from the previous vendor. The previous vendor produced a single Word document with a hand-drawn network diagram that was three years out of date, no firewall rule documentation, and a sticky note with the admin password. The business had been paying $800 per month for managed IT services for four years.

✓ Key Takeaway

You are paying for a result, not just activity. Ask for documentation. Ask for explanations. If your IT provider cannot explain what they have done and why in plain English, demand better or find someone who can.

→ Action Item

Email your current IT provider today and ask for three things: a current network diagram, a summary of your firewall rules, and a list of any outstanding security issues. The response — or lack of response — will tell you everything.

Advanced 5 min read
Lesson 15

What a Proper Network Documentation Package Looks Like

Network documentation is the difference between a business that can recover from a disaster in hours and one that takes weeks. Proper documentation includes a physical and logical network diagram showing every device, IP address, VLAN, and connection; a credential inventory stored securely with role-based access; a firewall rule log with the business justification for each rule; ISP circuit information including account numbers and support contacts; hardware inventory with serial numbers, purchase dates, and warranty status; and a change log recording every modification made to the network. Without this documentation, every technician who touches your network starts from scratch, every outage takes longer to resolve, and every vendor transition is a crisis.

▸ Real World Example

A business owner whose IT person left unexpectedly spent three weeks and $8,000 in emergency consulting fees to reverse-engineer their own network because there was no documentation. They discovered two forgotten servers, a misconfigured firewall rule that had been exposing a database port to the internet for two years, and three vendor VPN connections whose owners could not be identified.

✓ Key Takeaway

Network documentation is not something you create after something goes wrong. It is something you maintain continuously so that you are never dependent on any single person's knowledge of your systems.

→ Action Item

Ask for a copy of your network documentation today. If it does not exist, make creating it a condition of your next IT contract renewal. LiveWire includes a complete documentation package with every project we complete.

Coming Soon

Ready to go beyond the basics?

These 15 lessons are the foundation. The LiveWire Security Academy premium program goes much deeper — video walkthroughs of real firewall configurations, live network scanning demonstrations, downloadable policy templates, incident response playbooks, vendor evaluation scorecards, and direct Q&A with a working network engineer. This is not a generic online course. It is built from 15 years of real small business network work in the field.

Video: How to read your firewall logs in real time
Video: Live network scan demonstration — see what attackers see
Template: Vendor access policy for small businesses
Template: Incident response plan — fill in the blank
Checklist: PCI DSS self-assessment for small businesses
Checklist: 47-point network security audit you can do yourself
Live Q&A sessions with a working network engineer
Certificate of completion for staff training documentation

No spam. No sales calls. Just a notification when the program launches and an early access discount for waitlist members.

Now you know what to look for.

Most of the businesses we talk to recognize at least three of these issues in their own network. A free assessment takes 30 minutes and tells you exactly where you stand.

Schedule Your Free Assessment No sales pitch. No obligation. Just answers.