Built for churches & nonprofits

Protect the people who trust you with their information.

MissionDefend helps your church or nonprofit find its most important cybersecurity risks, build a practical improvement plan, and show leadership exactly what's being done — no IT degree required.

We're putting the finishing touches on it — get notified when it opens.

What you actually get

This is the report. Not a description of one.

Every assessment ends with a document like this one — a score you can explain to your board, the risks that matter most right now, and a 30-day plan with named owners and honest time estimates. Here is a complete example for a 120-member church.

MissionDefend
Grace Chapel (example)
120 members · 6 staff · 2 volunteers
Prepared for the board and leadership team
42
OUT OF 100
Level 2 — Developing

You have real protections in place. The gaps are in the places that matter most.

Your email security is genuinely good. But if someone locked up your files tomorrow, you could not confidently restore them — and no one has written down who to call.

Identity & Access40%
Security Awareness25%
Backup & Recovery30%
Incident Response10%
Email Security75%
Network Security60%
Endpoint Security65%
Policies & Governance15%

Your top risks right now

1. Your backups have never been testedCriticalAn untested backup is a hope, not a plan.
2. Two admin accounts have no MFACriticalExactly the accounts an attacker wants.
3. No written incident response planHighNobody knows who to call first.

Week 1 of your plan

Turn on MFA for the two admin accounts30–60 minutes · Owner: IT volunteer
Restore one file and one mailbox from backup1–2 hours · Owner: IT volunteer
List every admin account, confirm each is still needed45 minutes · Owner: Church administrator
See the full sample report Download the PDF

No email required. This is the same report your organization would receive.

Why it matters

Small organizations carry big responsibilities.

Your organization holds donor records, giving history, member information, and access to funds — the very things attackers look for. Most churches and nonprofits don't have a security professional on staff, and most "solutions" are built for enterprises with IT departments. MissionDefend meets you where you are.

You hold sensitive data

Donor and member records, giving history, counseling notes, background checks — information people trusted you to keep safe.

Attackers target trust

Fake invoice emails, gift-card scams impersonating your pastor, hijacked giving pages — small organizations are targeted precisely because defenses are light.

You don't have time for this

You're running a ministry, not an IT department. You need clear priorities and practical next steps — not a 400-page framework.

By the numbers

This isn't hypothetical, and it isn't rare.

Small organizations are targeted more often than most leaders realize — and the numbers below come from the FBI, Cloudflare, and independent research, not from us.

7×

Nonprofits, community groups, and other civil-society organizations were attacked at more than seven times the rate of other websites over the past year.

Cloudflare Project Galileo, Feb 2025 – Jan 2026, across 3,400+ protected organizations
41%

of small organizations reported at least one cyberattack in a single year — with a median of four separate attacks.

Hiscox Cyber Readiness Report
$123,005

was the average loss per business email compromise report in 2025 — the scam where an attacker impersonates a leader or vendor to redirect a payment. Derived from 24,768 complaints and $3,046,598,558 in reported losses.

FBI Internet Crime Complaint Center, 2025 Internet Crime Report
191,561

phishing and spoofing complaints were filed in 2025, making it the single most-reported cybercrime in America.

FBI Internet Crime Complaint Center, 2025 Internet Crime Report
The real math

Getting ready costs a fraction of recovering.

Most of what actually protects a church or nonprofit is free — turning on multi-factor authentication, reviewing who has access, writing down a rule about verifying payment requests. The rest is the price of a few streaming subscriptions.

Preparing

Building a solid baseline

$0 – $2,000 / year

For a typical 5–100 person organization, plus a few afternoons of someone's time.

  • Multi-factor authentication — free on Microsoft 365 and Google Workspace
  • Access review — free, one afternoon, repeated quarterly
  • A verify-by-phone rule for any payment change — free, and it stops the most expensive attack outright
  • Password manager and tested backups — typically a few dollars per person per month, often discounted for nonprofits
  • Written policies and a one-page incident plan — staff time, not budget
  • Fifteen minutes of training, twice a year, on the scams actually aimed at churches

Nothing here requires an IT department, a consultant, or a capital request. The hardest part is knowing which of these to do first — which is exactly what the assessment tells you.

Recovering

What one incident costs

$123,005

Average reported loss from a single business email compromise in 2025 — 24,768 complaints against $3,046,598,558 in losses — before anything below is counted.

  • Money that rarely comes back. Recovery depends on catching it within hours, and most organizations don't.
  • Emergency IT, legal, and notification costs — at emergency rates, from people you've never worked with.
  • Weeks of staff time spent on the incident instead of on ministry.
  • The letter you have to send. Telling every member and donor that their information was exposed — and that you didn't have basic protections in place.
  • Giving that quietly slows. In consumer research, 75% said they'd stop engaging with an organization after a cyber incident and 66% said they'd no longer trust it with their data.
  • Families who drift away. Nobody announces they're leaving over a data breach. They just stop coming, and you never get to make the case.

The financial loss is the part you can put on a spreadsheet. For a church, it's usually the smaller half of the damage — trust is what took twenty years to build, and it isn't covered by insurance.

Put plainly: a year of doing this properly costs less than most churches spend on coffee. A single successful impersonation email costs more than many churches raise in a quarter — and the harder cost, the one measured in families who quietly stop attending, doesn't show up on any invoice at all.

How it works

From "where do we even start?" to a clear plan.

Take the assessment

Answer plain-English questions about how your organization uses email, handles donations, stores member data, and manages accounts. No jargon, no trick questions — about 30 minutes.

Get your prioritized plan

See your security baseline score and a ranked list of what to fix first. Every recommendation explains the risk in plain language and walks you through the fix — most cost nothing but time.

Show your leadership

Generate a board-ready report that shows where you stand, what's being done, and how you're improving over time. Assign tasks, track progress, and reassess to confirm what's actually fixed.

After the assessment

Finding the gaps is the easy part.

A report tells you what's wrong. Closing the gaps takes assigned owners, written policies you didn't have to draft from scratch, and a way to show your leadership six months later that it stuck.

Policy templates

Start from editable templates for the policies you're expected to have — acceptable use, passwords, data handling, incident response — in plain language you can adapt and adopt.

Remediation tasks

Turn recommendations into assigned, trackable tasks so improvements actually happen — whether it's staff, a volunteer, or your outside IT helper.

Progress you can prove

Watch your score move as you close gaps, then reassess to confirm it held. Improvement you can show leadership — not a to-do list that never ends.

Who it's for

Built for ministries and missions, not IT departments.

  • Churches and nonprofits with roughly 5–100 staff or regular volunteers
  • Organizations using Microsoft 365 or Google Workspace
  • Teams that process donations and keep member or donor records
  • Leaders without a dedicated cybersecurity professional on staff

"We knew we should be doing something about security — we just didn't know where to start, and every consultant quote was more than our whole tech budget."

— The conversation happening in board meetings everywhere. MissionDefend is the practical starting point.

Straight talk

What MissionDefend is — and what it isn't.

Trust is our whole business, so we'll be honest about ours. MissionDefend gives you a strong, practical baseline. It doesn't replace specialized services when you need them.

MissionDefend is…

  • A practical baseline assessment of your security posture
  • A prioritized, plain-language improvement plan
  • A way to generate essential policies and track real progress
  • A tool to show leadership and boards what's being done

MissionDefend is not…

  • A penetration test or a full security audit
  • Antivirus or endpoint-protection software
  • Legal advice or a compliance certification
  • A guarantee that you'll never have a security incident
From the blog

Practical security guidance for ministry leaders.

Plain-English articles on the scams aimed at churches and nonprofits, how to protect the information people trust you with, and what to do when something goes wrong.

Read the blog
Cyber insurance

Most organizations don't know what their policy actually covers.

Cyber liability insurance is worth having. It is also the most misunderstood policy a church or nonprofit buys — because two policies with the same name can cover almost entirely different things, and the gaps tend to sit exactly where the real risk is.

We wrote a plain-English guide to what these policies contain, what they quietly leave out, and the questions worth asking before you renew. No insurance background needed. Every term is decoded the first time it appears.

MissionDefend is not an insurance company, agency or broker. We don't sell insurance and we're not paid by anyone who does.

  • 1The attack you're most likely to face is often the one that's capped. Losses from a fraudulent wire are frequently limited to a fraction of the main policy limit — sometimes a tenth of it.
  • 2An endorsement is not a policy. More than half of US cyber policies are add-ons to another policy, and they collect about 4% of the premium.
  • 3Your application becomes a promise. Answer a security question inaccurately and an insurer can void the policy from the day it started.
  • 4Insurance restores, it doesn't improve. Policies exclude the cost of ending up more secure than you were before the incident.
Questions

Frequently asked questions

When does the assessment launch?

Soon — we're in the final stages of building it. If you leave your email, we'll tell you the moment it opens and give early sign-ups first access. In the meantime we're publishing practical guidance on the blog that you can start acting on today.

Do I need to be technical to use MissionDefend?

No. The assessment is written in plain English for pastors, executive directors, office administrators, and volunteers. If you can answer "who has access to your donor records?" you can complete it. Where a fix requires technical steps, we walk you through them or give you exactly what to hand to your IT helper.

How long does the assessment take?

Most organizations finish the initial assessment in about 30 minutes. You can save your progress and come back anytime, and you can invite a colleague to answer the sections they know best.

Is our information safe with you?

We take that responsibility seriously — it's the entire reason we exist. Your assessment answers are encrypted in transit and at rest, we collect only what the assessment needs, and we never sell your data.

Does this replace a security audit or penetration test?

No, and we're upfront about that. MissionDefend gives you a baseline: it helps you find and fix the fundamentals first. If your organization later needs a formal audit or penetration test — for a grant, an insurer, or a regulator — you'll walk into it far better prepared.

We already have an IT volunteer / outside IT company. Is this still useful?

Yes — it makes them more effective. MissionDefend gives you a shared, prioritized list so your IT helper spends time on what matters most, and gives leadership visibility into what's actually getting done.

What does the free assessment include?

The free assessment gives you your baseline score and your top-priority risks. Paid plans add the full improvement plan, policy templates, task assignment, progress tracking, and board-ready reporting.

Be first in line when the free assessment opens.

Your congregation and your donors trust you with their information. We're finishing the assessment now — leave your email and we'll let you know the moment it's ready, along with a few practical things you can do in the meantime.

Get notified at launch

No spam, no sales calls — just one email when it's live.