Blog
-

The First 24 Hours: What to Tell Your Congregation
Congregations forgive incidents. They do not forgive being kept in the dark. Two draft messages and a plan for the first 24 hours after a church data breach.
-

A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday
A forty-page policy nobody reads protects nothing. Here is a complete one-page cybersecurity policy for churches, with a clause-by-clause explanation of it.
-

If You Lose Member Data, Who Do You Have to Tell?
If member data is exposed, who must you tell? A plain-English guide to state breach notification laws and what to do in the first days so you can comply.
-

Keep It or Delete It? The Security Control Nobody Talks About
Deleting old data is a security control, not housekeeping. A plain-English retention framework for churches, and where deletion quietly fails.
-

Background Checks: Who Holds Them, For How Long, and How to Destroy Them
Volunteer background checks hold Social Security numbers and dates of birth. Who should keep them, for how long, and how to destroy them properly.
-

The Most Sensitive File in the Building
Care notes, benevolence files, and who’s going through what. Where these records really live, why that’s a problem, and the controls that fit a small staff.
-

What Do You Actually Have? A One-Afternoon Data Inventory
You can’t protect what nobody has written down. A room-by-room, account-by-account way to find every place your church keeps personal information.
-

The Scam Your Congregation Won’t Tell You About
Confidence fraud takes months to build and uses faith as the lever. What it looks like, why victims defend the scammer, and how a leader can respond well.
-

Protecting the Livestream, the Funeral, and the Small Group Call
A funeral stream disrupted with hateful images is a pastoral emergency. The settings, the moderator role, and the thirty-second response that ends it fast.

