Home Articles Get your free assessmentComing soon

Category: Planning

Deciding what to do before something goes wrong: incident response, budgets, seasonal risk, and the conversations to have with your congregation.

  • The First 24 Hours: What to Tell Your Congregation

    The First 24 Hours: What to Tell Your Congregation

    It is 4:15 on a Thursday when the bookkeeper realizes something is wrong. That morning she got a notification about a sign-in to the church email account from a city none of you have visited, and now, in the mailbox settings, there is a forwarding rule she did not create.

    By 5:30 the person who helps you with computers has confirmed it: someone else has been in that mailbox for at least eleven days. It holds the counting team’s spreadsheets, scanned checks, the pastoral care list, and four years of correspondence.

    The pastor asks the question every leader asks at this moment, and it is the right one:

    What do we tell people?

    The answer that feels safest — wait until we understand it fully, then send something carefully worded — is almost always the wrong one. Not because the caution is unreasonable, but because of how congregations actually respond to bad news.

    People forgive the incident. They do not forgive the silence

    Congregations are generally forgiving about the incident itself. They understand that a church has two staff and a volunteer treasurer, that email accounts get compromised at corporations with security teams, that nobody was careless in a way that deserves punishment. Most members have clicked something they shouldn’t have.

    What they don’t forgive is finding out late, finding out from somewhere else, or reading a message obviously written to limit liability rather than to inform. A member who learns three weeks later that their giving records were exposed doesn’t think these things happen. They think they knew and didn’t tell me, and that attaches to the leadership permanently.

    The reputational damage from a slow, defensive, lawyer-flavored message is usually larger than the damage from the incident itself. The incident is a thing that happened to you. The silence is a thing you chose.

    What you must know before you speak, and what you can say anyway

    Twelve hours in, you will not know much. Not which records were accessed, not whether anything was downloaded, not whether member data will be misused. Those answers can take weeks.

    Here is the reframe that unlocks the whole problem. There are three things you can almost always say honestly within hours, and they are the three things people actually want:

    What happened, in the plainest terms. Not the technical mechanism — someone gained access to one of our email accounts is enough.

    What you are doing about it. You locked the account, brought in help, and are reviewing what was in there. All true within the first afternoon.

    What you want them to do. This is the part people scan for, and the part most notices bury.

    You don’t need the full scope to say those three things. What you should have before you speak is confirmation from someone competent that an incident occurred and that the immediate hole is closed. Announcing a breach that turns out to be a misconfigured setting is its own kind of damage.

    One constraint worth knowing. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring notification when certain kinds of personal information are exposed — and what counts as personal information, what triggers the duty, how long you have, what the letter must say, and whether a state attorney general has to be told all differ materially from state to state. There is no single national deadline or rule. Ask your attorney what applies to you before the formal notice goes out. Nothing here is legal advice.

    Hours, then days: two different messages

    Separate the two communications in your mind and the timing problem largely dissolves.

    The holding statement goes out within about 24 hours: what happened, what you’re doing, what to watch for, and when they’ll hear from you next. Its job is to make sure nobody learns this from a rumor. The full notice goes out in days, once you know the scope — specific about what was and wasn’t affected, carrying any formal notification your attorney says is required.

    A holding statement you can adapt:

    Subject: An important notice from [Church Name] Dear friends, I’m writing about something that happened here this week, and I want you to hear it from us rather than anywhere else. On Thursday we discovered that an unauthorized person had access to one of our church email accounts. We have locked that account, changed the passwords, and brought in outside help to determine exactly what was accessed and when. We do not yet know the full extent of what was in that mailbox or whether any of it was taken. That review is underway, and I would rather tell you what we know today than wait until we know everything. What we’re asking you to do. Please be cautious about any message that appears to come from the church over the next several weeks — anything asking you to give, click a link, update payment details, or send money or gift cards. The church will never contact you asking for payment, gift cards, banking details, or a password. If you receive something like that, call the office at [number] before you act on it. We will not be offended by the call. This happens to organizations far larger than ours, and what matters now is how we respond. I will write again by [specific date] with what we’ve found. If you have questions before then, call me directly at [number]. [Name] [Role], [Church Name]

    Notice what it doesn’t do: speculate, promise nothing was taken, or apologize in a way that assigns fault to a person. And it sets a specific date for the next message — the easiest way to buy time honestly.

    The follow-up, several days later:

    Subject: Update on the email incident at [Church Name] Dear friends, On [date] I wrote about unauthorized access to one of our church email accounts. Here is what we now know. The account was accessed between [date] and [date]. The mailbox contained [describe plainly: correspondence, some giving records, and documents containing member names and addresses]. We have [no evidence that / evidence that] this information was copied or misused. If your information was affected, you are receiving a separate letter with specific steps, including [credit monitoring / what to watch for]. If you did not receive that letter, our review indicates your information was not in the affected account. What we have changed. Every church account now requires a second step to log in beyond the password, so a stolen password alone is no longer enough. We have reviewed every account for unauthorized forwarding rules, and our board adopted a written security policy on [date]. What we’re still asking of you. Keep treating unexpected messages about the church with suspicion — anything about giving, payments, or account details, and especially anything referring to this incident. Call the office to check. We would much rather field the call. We have reported this to [law enforcement / the appropriate authorities] and are following the notification requirements that apply to us. I’m grateful for the grace you’ve shown this week. If you’d like to talk, my number is [number]. [Name]

    Who speaks, and how it reaches the people least likely to read email

    Decide the voice before you need it. It should be the senior pastor or the board chair — one person, named, with a real phone number in the message. An unsigned notice from “the church office” reads as institutional distancing at exactly the wrong moment.

    Then use every channel, because they reach different people:

    Email, to everyone you have an address for. Fastest, and the record of what you said.

    The website. A short dated notice on the front page. This is where members send their adult children, and where anyone who hears a rumor will check.

    From the front, on Sunday. Two minutes, in plain language, not buried in announcements. Members who hear their pastor say it out loud experience it entirely differently than members who read it, and it visibly signals that the leadership is not hiding. Put a printed copy in the bulletin too.

    A phone tree. The one that gets skipped, and the one that matters most.

    Here is the uncomfortable arithmetic. The members most likely to be targeted by follow-on scams are your older members — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, a 37% increase over 2024, and $7.748 billion in losses, which was up 59% in a single year. The members least likely to read an emailed notice are very often the same people. A written notice reaches the people who need it least.

    So build a short list of members who don’t use email reliably, split it among your deacons, elders, or care team, and call them. The script is three sentences: Something happened with the church’s email. Nobody needs to do anything. But if anyone contacts you claiming to be from the church and asks for money or account details, hang up and call the office.

    Twenty people making six calls each covers a congregation in an evening.

    The instruction that stops them being victimized twice

    Attackers who have been inside a mailbox for eleven days know your members’ names, your pastor’s writing style, your giving cycle, and the fact that you just announced a breach. The second wave is often more profitable than the first: a message that references the incident, expresses concern, and asks the member to “verify” something.

    So give the instruction in a form people can remember under pressure:

    The church will never contact you asking for money, gift cards, banking details, passwords, or account verification — by email, text, or phone. If anyone does, it isn’t us. Hang up or delete it, and call the office on the number in the bulletin.

    Put that sentence in the holding statement, the follow-up, the bulletin, and the phone script, and repeat it in the newsletter a month later. It’s permanent congregational hygiene that happens to be most urgent right now.

    What not to do

    Don’t minimize. “A minor issue with one of our systems” is the phrase that gets quoted back to you when the scope turns out to be larger. Describe it accurately, or as still under review — never smaller than it is.

    Don’t name the staff member. Not in the notice, not from the pulpit, not in conversation. That person is already carrying it, and naming them tells everyone else in your organization that reporting a mistake gets you publicly identified — precisely the behavior you cannot afford. If your board asks who, the answer is: a member of our team was targeted by a convincing message, and they reported it quickly, which is what limited this.

    Don’t promise it can never happen again. You can’t deliver it, and it’s what people remember if there’s a second incident. Say what you have changed instead — stronger, and true.

    Don’t go quiet because of legal advice. Counsel should review the wording of anything you send — that is what counsel is for, and formal notification has requirements you should not guess at. But there is a difference between have a lawyer read this before it goes out and say nothing until the lawyer is comfortable, and the second can run for weeks. Bring your attorney in on day one and give them a deadline. Saying nothing is not neutral; it is a choice, and its consequences compound daily.

    Don’t let the first Sunday pass in silence. If the congregation is in the building and nobody mentions it, you have communicated something.

    What to do this week

    You almost certainly are not in an incident right now, which is exactly why this is the week.

    Write two things and put them in a shared folder labeled clearly enough that a panicking person can find it: the name and mobile number of whoever will speak publicly if this happens, and a draft holding statement — adapt the one above in fifteen minutes by filling in the brackets.

    Then build the phone-tree list: which members don’t use email, and who calls them. On the worst day, that list is the difference between reaching your congregation and merely emailing it.

    Forty-five minutes, and the first 24 hours stop being improvised.

    The best time to work all of this out is before you need it. MissionDefend’s free assessment asks plain-English questions about how your church handles email, donations, member data, and accounts, then hands back a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Data Breach Response: A Guide for Business; National Conference of State Legislatures, Security Breach Notification Laws; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Summer Volunteers, Permanent Access

    Summer Volunteers, Permanent Access

    It’s the second Monday in June and the hallway outside the fellowship hall has been turned into a check-in station. There’s a folding table, a laminated sign, a bin of name tags, and a tablet on a stand.

    Behind the table is a seventeen-year-old who is wonderful with children and has never used the check-in system before. Someone shows her how it works in about ninety seconds. She taps in as VBS, because that’s the login on the sticky note attached to the tablet stand, and for the next five days she checks in a hundred and forty children — with their parents’ phone numbers, their allergies, their medications, and the notes about which adult is and isn’t allowed to collect them.

    In August she leaves for college.

    In September, nobody does anything. The VBS login still works. It will still work next June, and the June after that, and the sticky note is still on the stand.

    This isn’t a story about a bad volunteer. She was excellent, and the church was lucky to have her. It’s a story about a pattern that almost every church repeats every summer without noticing: the people with the least training and the shortest tenure are handed access to the most sensitive information the organization holds, and nobody ever takes it back.

    The summer problem, stated plainly

    Vacation Bible School, day camp, sports camps, mission trips, summer interns, the youth trip. For six to ten weeks, a church’s headcount of people-with-access can double.

    They need real access — this isn’t a case where you can hand out nothing. The check-in table needs the check-in system. The registration volunteer needs the registration data. The intern posting daily photos needs the social accounts. The trip coordinator sometimes needs a card to buy fuel and groceries in another state.

    And three things are true of this group at the same time:

    Highest turnover. Many of them serve for one week and are never in the building again in that capacity. Some are students who leave in a fixed month.

    Lowest training. They are recruited late, briefed quickly, and often start on the first morning. Nobody schedules an orientation for a person doing one week of a volunteer job.

    Most sensitive data. Children’s names, ages, photographs, allergies, medical notes, emergency contacts, home addresses, and — in some systems — custody restrictions. There is nothing else in a church’s records more sensitive than that.

    Any two of those would be worth attention. All three, every summer, on a shared login, is the thing to fix — and it is genuinely fixable. This is not a technology problem; it’s a pattern that someone has to own.

    Named accounts, with an end date decided first

    Start here; everything else depends on it.

    A shared login costs you the same four things it costs on a shared office computer: nobody can tell who did what, one leaked password exposes everything, the password never changes because changing it means telling forty people, and every volunteer who ever served still has it.

    There’s a particular version of that for children’s ministry. If a parent raises a concern about how a check-out was handled, or a record was changed, or a photo was posted, a shared login means nobody can establish what happened. That protects nobody — least of all the volunteers, who all become equally unaccountable and therefore equally unclearable.

    Give each summer volunteer their own account, under their own name. Most church management and check-in systems allow unlimited or generous numbers of users, and the ones that charge per user often have a volunteer or limited role at a lower cost or none. Ask your vendor before assuming every extra person is a paid seat.

    If your system genuinely cannot do named volunteer accounts, write that down as a known limitation and raise it at renewal.

    The second half of the pattern is almost embarrassingly simple:

    Nobody gets access without a written end date, and the end date is written down before the access is granted.

    Not “we’ll remove it when they’re done.” That sentence has never once resulted in access being removed. A date. On a list. In the calendar.

    A one-page grid is all you need — a spreadsheet, a shared doc, a printed sheet in a binder. Five columns:

    Name · What they can get into · Start date · End date · Removed (initials and date)

    That’s the whole system. It converts a vague intention into a specific task with a name attached, and it gives you something to hand to an insurer or a board member who asks a fair question.

    Add one calendar entry — mid-September, titled Remove summer access, assigned to a specific person — and this problem is structurally solved for as long as somebody keeps doing it.

    The minimum permissions for the job

    The FTC’s guidance for businesses puts it as the principle of least privilege: each person should have access only to what they need to do their particular job. In a church that translates into a few concrete decisions.

    The check-in volunteer needs to check children in and out. She does not need to edit family records, view giving history, export the directory, or see the full membership database. Most check-in systems have a limited role for exactly this; find it and use it.

    The registration volunteer needs this summer’s registrations. Not the historical file, not the donor records.

    The intern posting photos needs to post. Most social platforms let you grant a person permission to publish without giving them the ability to change the password, remove other administrators, or delete the account. Use that level — and never hand over the account password itself.

    Almost nobody needs a payment card. If a trip leader genuinely does, a dedicated card with a low limit that gets canceled at the end of the trip is far better than a card tied to the operating account. Ask your bank about a virtual or single-use card.

    Two more, a minute each. Turn on multi-factor authentication — the extra code or tap after a password — for any volunteer account that can reach children’s data or money. Microsoft’s research finds it blocks more than 99.2% of account compromise attacks, and it is just as free for a volunteer as for the pastor. And remove the shared passwords from sticky notes on tablet stands; a printed card kept behind the table, changed after the season, is already an improvement.

    Fifteen minutes of orientation, and only three things in it

    You will not get a training session. You’ll get the first five minutes of the first morning, standing at a folding table. So decide in advance what the three things are.

    One: this data is not yours to share. Names, allergies, custody notes, and phone numbers stay in the system and in this building. Not screenshotted, not texted to a co-leader, not typed into a personal spreadsheet, not posted anywhere. “If you find yourself about to photograph the screen, stop and ask me instead.”

    Two: check-out is a security function, not a formality. The person collecting a child is matched to the record every time — when you know them, when there’s a line, when they’re annoyed about it. Custody restrictions are the reason the system exists. A volunteer told this once will hold the line; a volunteer who hasn’t will assume the tags are bureaucracy.

    Three: if anything seems wrong, tell this person. Point at a specific human being. An email that looks odd, a parent who seems agitated, a stranger in the hallway, a screen that logged you into somebody else’s account. Nobody is ever in trouble for asking.

    Then one line about photographs, because summer is when the photo problem happens: know which children have a photo restriction on file, and know that a group of happy kids is not a reason to skip checking. Photo consent deserves its own conversation with your leadership — who may photograph, what may be published where, and how a family opts out — and the summer programs are exactly when a vague policy gets tested.

    The phone in their pocket

    Here’s the modern wrinkle. Many check-in and ministry apps run on personal phones, and a volunteer installing the app on her own device is often the fastest way to get the table staffed.

    That’s a reasonable trade, but be clear-eyed: church data is now on a phone the church doesn’t control, that gets handed to a younger sibling, that may have no screen lock, and that will be traded in eventually.

    Three things make it acceptable:

    Say plainly that the app must be signed out of and deleted when the season ends — and put that on the same one-page grid, with a tick box, so it’s a task rather than a hope.

    Ask for a screen lock and current updates on any phone used for ministry data. That’s not intrusive; it’s the same thing the volunteer’s bank asks of them.

    Prefer a church-owned tablet where you can. One inexpensive tablet in a stand that never leaves the building removes almost all of this, and it’s a strong candidate if you’re buying one device this year.

    And when a volunteer’s access ends, remember that removing their account in the system is what actually matters — an app left on a phone with no working login is just an icon.

    September, and how to say it without awkwardness

    Put the calendar entry in now, whatever month you’re reading this in. Mid-September, one person, thirty minutes:

    Work down the grid and remove every access whose end date has passed. Initial the last column.

    Check each system’s user list separately — check-in, church management, email, the giving platform, the shared drive, the social accounts, the photo library. People collect access in places the grid doesn’t know about.

    Look specifically at the social accounts. They’re the most often forgotten, and the most public when it goes wrong.

    Change any password that was shared during the season, and any that was on a card at a table.

    Then tell the volunteers you did it, in the thank-you note — which brings us to the one thing that actually stops churches from doing any of this.

    It isn’t ignorance. It’s that removing someone’s access feels like an accusation, and in a community built on trust, accusing a faithful volunteer of anything is unthinkable.

    So take the implication away by saying it before it can be inferred, at the start rather than the end:

    “Your access runs through the last week of August. That’s how we do it for everyone, including the pastor’s family. It’s not about trust — it’s that we keep the children’s information locked down to whoever is actually serving right now.”

    Nobody has ever been offended by that. What people are offended by is being singled out, and a policy applied to everybody singles out nobody.

    A church that can say we give named accounts, limited to the role, for a fixed period, and we remove them in September is a church that can answer questions from parents, insurers, and its own board with something better than reassurance. A two-week volunteer with a two-week account is not distrust. It’s ordinary practice, and it protects the volunteer as much as the child.

    What to do this week

    Open the user list for whichever system holds your children’s check-in data and read it top to bottom. Look for names you don’t recognize, accounts called things like VBS or Camp or Front Desk, and people who left. That takes fifteen minutes, and it is usually a surprising fifteen minutes.

    Then make the grid — name, access, start, end, removed — even if the only thing on it today is next summer. And put one entry in the church calendar for mid-September with somebody’s name on it.

    Seasonal access is one strand of a larger question about who can reach what. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including who has access to what, and who removes it — then returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Protecting Personal Information: A Guide for Business; Microsoft, mandatory multifactor authentication guidance.

  • Why Your Church or Nonprofit Needs a Cybersecurity Incident Response Plan

    Why Your Church or Nonprofit Needs a Cybersecurity Incident Response Plan

    Ask a church administrator what they would do if they discovered someone had been reading the church email account for three weeks, and you will usually get a thoughtful pause followed by an honest answer: I’d call our IT guy, I guess. And tell the pastor.

    That is not a plan. That is a reasonable first instinct, and it is what almost every small organization has.

    The problem is not that the instinct is wrong. The problem is that the moment you discover a breach is the single worst moment to be making decisions. You will be frightened, you will be short on facts, and you will be under pressure to do something immediately. People make expensive mistakes in that state — deleting evidence, paying an invoice that was never real, telling a congregation something that turns out to be untrue, or quietly hoping it resolves itself.

    A written plan does not make you a security expert. It makes the decisions in advance, while you are calm.

    What actually happens without one

    Consider a realistic sequence. On a Tuesday, your bookkeeper notices that a vendor payment for the roof project went to an account nobody recognizes. Forty thousand dollars.

    Without a plan, the next four hours look like this. The bookkeeper is not sure whether it is a mistake or a crime, and is afraid of being blamed, so she spends an hour checking her own work. Then she tells the executive director, who forwards the email chain to three people, one of whom replies to the attacker’s address asking for clarification. Someone changes the email password, which alerts the attacker that they have been noticed. Nobody calls the bank, because nobody is certain it is really fraud yet. By the time someone does call, it is 5:15 p.m. and the recall window on the transfer has effectively closed.

    Every one of those steps is a reasonable human response. Together they cost the organization the money.

    With a plan, the same Tuesday looks different. The bookkeeper knows that suspected financial fraud is reported immediately to a named person with no requirement to be certain first. That person knows the bank’s fraud line is the first call, not the fourth, because the number is on the plan. Nobody replies to the suspect email chain because the plan says so. The email account is preserved rather than scrubbed. And the organization has a real chance at recovering funds, because the first hour was spent on the right things.

    The difference is not expertise. It is a page of paper.

    Why small organizations put it off

    The objections are all understandable, and all worth answering directly.

    “We’re too small for something that formal.” Formality is not the point. A one-page plan for a five-person office is complete. The enterprise version — with severity tiers and escalation matrices — exists because those organizations have hundreds of people who need to coordinate. You have four, and they can be named individually.

    “Nothing has ever happened to us.” This is genuinely good news, and it is also the reason to write the plan now. You cannot write a plan during an incident. The only time you can write it is when nothing is wrong.

    “We wouldn’t know what to put in it.” This is the honest one, and it is the easiest to fix. The content is not technical. It is mostly phone numbers and decisions about who is allowed to say what.

    “We’d just call our IT person.” Good — write that down, with the number, and with what to do if they do not answer. Also note that most incidents at churches are not technical problems. A wire fraud, a leaked donor list, and an impersonation scam are not things your IT volunteer can fix. They need a bank, a board, and possibly a lawyer.

    What goes in a plan that fits on one page

    You need six things. None of them require a security background.

    Who to tell, and how fast. One named person is the first call for anything suspicious, with a named backup for when they are on vacation. State plainly that staff and volunteers report suspicions immediately and are never required to be sure first. This single sentence does more work than the rest of the document, because the most common failure in small organizations is delay caused by embarrassment.

    The contact list. Bank fraud line. Payment processor’s fraud contact. IT support. Insurance carrier and policy number. Church management software vendor’s support line. Board chair. An attorney, if you have one. Local FBI field office and the IC3 reporting site at ic3.gov. Gather these once and you never have to search for them under pressure.

    The first-hour instructions. Keep this short and specific. Do not reply to the suspicious message. Do not delete anything — preserve the mailbox as evidence. Disconnect an infected computer from the network but do not wipe it. If money moved, call the bank before anything else. If an account is compromised, change the password from a different device and revoke active sessions rather than just changing the password.

    Who decides and who speaks. Name the person authorized to shut down a system, take the giving page offline, or engage outside help. Name the one person who talks to the congregation, the press, or donors — and state that nobody else does. Uncoordinated communication turns a manageable incident into a credibility problem.

    When you have to notify people. Every state has a data breach notification law, and they differ on timing and thresholds. You do not need to memorize them. You need a line in the plan that says notification requirements are checked with counsel or your insurer before you decide to stay quiet, because “we didn’t realize we had to tell anyone” is not a defense anyone accepts afterward.

    What you do afterward. A short note that within thirty days the organization writes down what happened, what allowed it, and what changed as a result — and that this goes to the board. Incidents are the most persuasive argument for the security budget you have been asking for.

    That is the whole plan. Print it. Put a copy somewhere that does not require logging into the network you may have just lost access to.

    Practice it once

    A plan nobody has read is a document, not a capability. Once a year, take forty-five minutes at a staff meeting and walk through one scenario out loud. Someone reads a situation — “the treasurer just told you a $12,000 transfer went to the wrong account” — and the group talks through who does what.

    You will find gaps every time. The bank’s fraud number turns out to be the general customer service line. Nobody knows the insurance policy number. Two people think the other one is authorized to take the website down. Finding those in a conference room costs you nothing. Finding them on a Tuesday afternoon costs you the incident.

    What your board should know

    Boards are increasingly asking about cyber risk, and they are right to. Directors of a nonprofit have a duty of care, and “we had no plan” is an uncomfortable position to defend to an insurer, a major donor, or a regulator after the fact.

    The reassuring news is that this is a question you can answer well cheaply. A board that hears “we have a written incident response plan, these are the people responsible, we tested it in March, and here are the three things we fixed as a result” is a board that stops worrying. That answer costs an afternoon of writing and forty-five minutes a year of practice.

    It also matters for insurance. Cyber liability policies increasingly ask about incident response procedures on the application, and answering accurately is part of keeping the coverage valid when you need it.

    Start with the phone numbers

    If a full plan feels like too much to sit down and write, start smaller. Open a document and write down the bank’s fraud line, your insurer, your IT contact, and the name of the one person everything gets reported to. That takes fifteen minutes and it is genuinely the most valuable part.

    The rest can follow.

    If you would like help figuring out what your plan should cover — and what else your organization should shore up first — MissionDefend’s free assessment will ask plain-English questions about how you handle email, donations, member data, and accounts, then give you a baseline score and a ranked list of priorities. Paid plans will include a policy generator that drafts an incident response plan tailored to your organization, along with the other essential policies.

    It’s launching soon. Leave your email and we’ll let you know when it opens.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service. Consult qualified legal counsel regarding breach notification obligations in your state.