Ask a church administrator what they would do if they discovered someone had been reading the church email account for three weeks, and you will usually get a thoughtful pause followed by an honest answer: I’d call our IT guy, I guess. And tell the pastor.
That is not a plan. That is a reasonable first instinct, and it is what almost every small organization has.
The problem is not that the instinct is wrong. The problem is that the moment you discover a breach is the single worst moment to be making decisions. You will be frightened, you will be short on facts, and you will be under pressure to do something immediately. People make expensive mistakes in that state — deleting evidence, paying an invoice that was never real, telling a congregation something that turns out to be untrue, or quietly hoping it resolves itself.
A written plan does not make you a security expert. It makes the decisions in advance, while you are calm.
What actually happens without one
Consider a realistic sequence. On a Tuesday, your bookkeeper notices that a vendor payment for the roof project went to an account nobody recognizes. Forty thousand dollars.
Without a plan, the next four hours look like this. The bookkeeper is not sure whether it is a mistake or a crime, and is afraid of being blamed, so she spends an hour checking her own work. Then she tells the executive director, who forwards the email chain to three people, one of whom replies to the attacker’s address asking for clarification. Someone changes the email password, which alerts the attacker that they have been noticed. Nobody calls the bank, because nobody is certain it is really fraud yet. By the time someone does call, it is 5:15 p.m. and the recall window on the transfer has effectively closed.
Every one of those steps is a reasonable human response. Together they cost the organization the money.
With a plan, the same Tuesday looks different. The bookkeeper knows that suspected financial fraud is reported immediately to a named person with no requirement to be certain first. That person knows the bank’s fraud line is the first call, not the fourth, because the number is on the plan. Nobody replies to the suspect email chain because the plan says so. The email account is preserved rather than scrubbed. And the organization has a real chance at recovering funds, because the first hour was spent on the right things.
The difference is not expertise. It is a page of paper.
Why small organizations put it off
The objections are all understandable, and all worth answering directly.
“We’re too small for something that formal.” Formality is not the point. A one-page plan for a five-person office is complete. The enterprise version — with severity tiers and escalation matrices — exists because those organizations have hundreds of people who need to coordinate. You have four, and they can be named individually.
“Nothing has ever happened to us.” This is genuinely good news, and it is also the reason to write the plan now. You cannot write a plan during an incident. The only time you can write it is when nothing is wrong.
“We wouldn’t know what to put in it.” This is the honest one, and it is the easiest to fix. The content is not technical. It is mostly phone numbers and decisions about who is allowed to say what.
“We’d just call our IT person.” Good — write that down, with the number, and with what to do if they do not answer. Also note that most incidents at churches are not technical problems. A wire fraud, a leaked donor list, and an impersonation scam are not things your IT volunteer can fix. They need a bank, a board, and possibly a lawyer.
What goes in a plan that fits on one page
You need six things. None of them require a security background.
Who to tell, and how fast. One named person is the first call for anything suspicious, with a named backup for when they are on vacation. State plainly that staff and volunteers report suspicions immediately and are never required to be sure first. This single sentence does more work than the rest of the document, because the most common failure in small organizations is delay caused by embarrassment.
The contact list. Bank fraud line. Payment processor’s fraud contact. IT support. Insurance carrier and policy number. Church management software vendor’s support line. Board chair. An attorney, if you have one. Local FBI field office and the IC3 reporting site at ic3.gov. Gather these once and you never have to search for them under pressure.
The first-hour instructions. Keep this short and specific. Do not reply to the suspicious message. Do not delete anything — preserve the mailbox as evidence. Disconnect an infected computer from the network but do not wipe it. If money moved, call the bank before anything else. If an account is compromised, change the password from a different device and revoke active sessions rather than just changing the password.
Who decides and who speaks. Name the person authorized to shut down a system, take the giving page offline, or engage outside help. Name the one person who talks to the congregation, the press, or donors — and state that nobody else does. Uncoordinated communication turns a manageable incident into a credibility problem.
When you have to notify people. Every state has a data breach notification law, and they differ on timing and thresholds. You do not need to memorize them. You need a line in the plan that says notification requirements are checked with counsel or your insurer before you decide to stay quiet, because “we didn’t realize we had to tell anyone” is not a defense anyone accepts afterward.
What you do afterward. A short note that within thirty days the organization writes down what happened, what allowed it, and what changed as a result — and that this goes to the board. Incidents are the most persuasive argument for the security budget you have been asking for.
That is the whole plan. Print it. Put a copy somewhere that does not require logging into the network you may have just lost access to.
Practice it once
A plan nobody has read is a document, not a capability. Once a year, take forty-five minutes at a staff meeting and walk through one scenario out loud. Someone reads a situation — “the treasurer just told you a $12,000 transfer went to the wrong account” — and the group talks through who does what.
You will find gaps every time. The bank’s fraud number turns out to be the general customer service line. Nobody knows the insurance policy number. Two people think the other one is authorized to take the website down. Finding those in a conference room costs you nothing. Finding them on a Tuesday afternoon costs you the incident.
What your board should know
Boards are increasingly asking about cyber risk, and they are right to. Directors of a nonprofit have a duty of care, and “we had no plan” is an uncomfortable position to defend to an insurer, a major donor, or a regulator after the fact.
The reassuring news is that this is a question you can answer well cheaply. A board that hears “we have a written incident response plan, these are the people responsible, we tested it in March, and here are the three things we fixed as a result” is a board that stops worrying. That answer costs an afternoon of writing and forty-five minutes a year of practice.
It also matters for insurance. Cyber liability policies increasingly ask about incident response procedures on the application, and answering accurately is part of keeping the coverage valid when you need it.
Start with the phone numbers
If a full plan feels like too much to sit down and write, start smaller. Open a document and write down the bank’s fraud line, your insurer, your IT contact, and the name of the one person everything gets reported to. That takes fifteen minutes and it is genuinely the most valuable part.
The rest can follow.
If you would like help figuring out what your plan should cover — and what else your organization should shore up first — MissionDefend’s free assessment will ask plain-English questions about how you handle email, donations, member data, and accounts, then give you a baseline score and a ranked list of priorities. Paid plans will include a policy generator that drafts an incident response plan tailored to your organization, along with the other essential policies.
It’s launching soon. Leave your email and we’ll let you know when it opens.
No spam and no sales calls — just one email when it’s live.
Related reading
- what to say to your congregation in the first day
- who you are legally required to notify after an exposure
- whether your insurance would actually pay for any of this
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service. Consult qualified legal counsel regarding breach notification obligations in your state.

