Home Articles Get your free assessmentComing soon

Tag: board governance

  • A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    There is a binder on a shelf in the church office. The spine says Information Security Policy. Someone downloaded it in 2019, printed it, added tab dividers, and put it on the shelf, where it has remained.

    It is forty-one pages long. It references a Chief Information Security Officer, a quarterly vulnerability management cadence, and a data classification scheme with four tiers. The church has two full-time staff and a volunteer treasurer.

    Nobody has opened it. Not once. If you asked the office administrator what the policy says about wire transfers, she would tell you honestly that she has no idea.

    That binder is not neutral. It is worse than having nothing, because it lets everyone believe the question has been handled.

    The forty-page policy fails for a reason that has nothing to do with its contents

    The contents are usually fine. Somebody competent wrote them. The problem is structural.

    A policy is not a legal artifact. It is an instruction to human beings about what to do on a Tuesday afternoon when an email arrives asking for a payment change. If the instruction is on page 27 of a document nobody has read, it does not exist. The staff member acts on instinct instead, and instinct is exactly what the attacker is designing for.

    Long policies also fail in the other direction. They contain commitments the organization cannot keep — quarterly access audits, annual penetration testing, a security awareness training program — and once a policy contains one thing you obviously aren’t doing, the whole document loses its authority. People stop treating any of it as real.

    A single page that six people actually follow beats a binder that nobody opens. That is the whole argument, and it holds in organizations far larger than yours.

    So here is the page.

    The page

    Copy this. Change the bracketed parts. Do not add to it — the length is the feature.

    “`
    [CHURCH NAME] — INFORMATION SECURITY POLICY
    Adopted by the Board on [DATE]. Next review: [DATE + 1 YEAR].
    Policy owner: [NAME, ROLE].

    1. RESPONSIBILITY The Board is responsible for this policy. [NAME] is responsible for carrying it out and reports to the Board once a year on whether we are doing what this page says.
    1. MULTI-FACTOR AUTHENTICATION Multi-factor authentication is required on: church email, online banking, the giving/donation platform, the church management system, the payroll system, the website host, the domain registrar, and all social media accounts. No exceptions without written Board approval.
    1. VERIFYING MONEY Any request to send money, change bank details, change payroll direct deposit, or pay a new or altered invoice is verified by voice, on a phone number we already had on file — never a number supplied in the request — before the payment goes out. This applies however the request arrives, including from someone inside the organization.
    1. INDIVIDUAL LOGINS Every person has their own login. Logins and passwords are not shared, not with staff, not with volunteers, not with family members. Passwords are stored in the approved password manager, not on paper, in a spreadsheet, or in email.
    1. WHEN SOMEONE LEAVES When any staff member or volunteer stops serving in a role, their access to every account and building is removed within 14 days. [NAME] runs this from the account inventory and confirms it in writing. This applies to everyone, including clergy and Board members.
    1. BACKUPS Church data — financial records, member records, and documents — is backed up automatically, with at least one copy the church controls and that cannot be altered from a staff computer. Once a year we restore a real file from backup to prove the backup works, and note the date it was tested.
    1. IF SOMETHING LOOKS WRONG If you think you clicked a bad link, entered a password on the wrong page, sent money to the wrong place, or noticed anything unusual in an account: stop, and tell [NAME] and [BACKUP NAME] immediately, by phone. Do not wait to be sure. If money has moved, we call the bank first and report to the FBI at ic3.gov the same day.
    1. NO PENALTY FOR REPORTING No one will be disciplined, dismissed, or embarrassed for reporting a mistake or a suspicion, including their own mistake, and including after money has been lost. Reporting quickly is the behavior this church wants. Hiding a mistake is the only thing that gets anyone in trouble.
    1. REVIEW The Board reviews this policy once a year, on or before [DATE]. “`

    That is the entire policy. It fits on one sheet, single-sided.

    What each clause is doing, so you can defend it

    Your board will ask about some of these. Here is the one-sentence answer for each.

    Responsibility. A policy with no name attached is a wish; naming one person and one annual report is what turns it into something that actually happens.

    Multi-factor authentication. Multi-factor authentication — MFA — is the extra step after your password: a code, a tap on your phone, a key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks, and naming the specific systems matters because churches routinely turn it on for email and forget the giving platform, which is the one holding donor card details.

    Verifying money. This is the single clause most likely to save you real money, because the fraud that actually hits churches is a convincing email asking for a payment change; a thirty-second phone call to a number you already had defeats every version of it.

    Individual logins. Shared logins make it impossible to know who did what, impossible to remove one person’s access without disrupting everyone, and impossible to use MFA properly.

    When someone leaves. Old accounts are the quietest risk you have — nobody is watching them, and their passwords are often years old and reused elsewhere; a defined window turns “we should get around to that” into a date. CISA’s guidance for small organizations puts it plainly: develop procedures addressing changes in user status, and eliminate shared and unused accounts.

    Backups. A backup you have never restored is a theory, and the annual restore test is what converts it into a fact — this is also the clause that determines whether a ransomware incident is a bad week or an extinction event.

    If something looks wrong. Most losses become large because somebody waited; naming two people and requiring a phone call removes the ambiguity about who to tell and how.

    No penalty for reporting. Speed is the only thing that reliably recovers money, and speed depends entirely on whether a frightened person feels safe telling you within the hour rather than on Monday.

    Review. A date on the page is what stops this becoming the 2019 binder.

    Getting it adopted on a Tuesday

    The mistake is presenting this as a debate. It is not a debate; it is a housekeeping item that happens to be important.

    Put it on the consent agenda. Consent items are approved as a block without discussion unless a member pulls one. Circulate the page with the board packet a week ahead, with a two-sentence cover note: This replaces our existing information security policy. It is one page so that staff and volunteers will actually follow it. Most boards will pass it without comment, which is the correct outcome.

    Name the owner before the meeting, not during it. An unassigned policy will sit for a year. Ask the person first, privately, so the name in the document is already agreed.

    Set the review date as a real date. Not “annually.” A date, in the calendar, on the same board meeting each year.

    Record it in the minutes. This is the part people skip, and it is the part that matters most beyond the security question.

    Boards of nonprofit organizations carry a duty of care — the general obligation to act with the attention a reasonably prudent person would apply to the organization’s affairs. The specifics vary by state and by your governing documents, and this is not legal advice; ask your attorney what applies to you. But the general shape is consistent: what a board can demonstrate matters. A minute that reads the Board adopted the Information Security Policy, assigned responsibility to the Business Administrator, and set the annual review for the March meeting is evidence that the board considered the risk and acted. A verbal agreement that somebody should look into cybersecurity is not.

    Give a copy to every person it applies to. Staff, yes — but also the volunteer who runs the website, the volunteer counting team, the person with the Facebook password. One page can be handed to someone in a hallway. Forty-one pages cannot.

    Policy without practice is theatre

    Here is the honest limitation. Adopting this page does not mean your church is prepared. It means your church has written down what it intends to do.

    The gap between those two things is real, and it shows up under pressure. The staff member who has read clause 3 in a board packet is not the same as the staff member who has actually made the verification call once and knows it takes thirty seconds and is not awkward. The person named in clause 7 is not ready until they have said the words out loud in a room, with a scenario in front of them.

    The way to close that gap is a tabletop exercise — a short, low-stakes practice run where you talk through a realistic incident around a table and find out who would actually do what. It takes under an hour and it is the subject of its own post in this series. If you adopt the policy and never practice it, you have documentation. If you adopt it and practice it once a year, you have a response.

    Do the page first anyway. Documentation you follow beats intention you never wrote down.

    What to do this week

    Copy the page above into a document, fill in the five bracketed fields — church name, policy owner, backup contact, adoption date, review date — and email it to whoever assembles the board packet with a request to add it to the consent agenda.

    Then, separately, check one thing before the meeting: whether MFA is actually turned on for the giving platform and the church management system, not just email. If it isn’t, you will want to know that before you sign a document saying it is required.

    Thirty minutes, no budget, and your board has a defensible record by the end of the month.

    If you would like something concrete to bring to the same board meeting, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — useful as the evidence behind the annual report clause 1 asks for.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Cybersecurity and Infrastructure Security Agency, Cyber Essentials Starter Kit; Microsoft, mandatory multifactor authentication guidance; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • The Board Member on the Call Wasn’t Real

    The Board Member on the Call Wasn’t Real

    The finance committee meets at seven on Thursday, on video, the way it has since 2020. Four squares on the screen. The treasurer joins eight minutes late, apologises, says the audio on his end is bad, and keeps his camera on anyway.

    He’s brief. The contractor for the roof project needs the deposit moved tonight to hold the crew for next month — the account details came through this afternoon and he’s forwarded them to the administrator. He asks whether anyone objects. Nobody does. His camera freezes twice while he’s talking, which is completely normal on a church Wi-Fi connection, and which is also the reason nobody looks too closely.

    The treasurer was at his daughter’s recital that evening and did not attend the meeting.

    What a deepfake actually is

    Deepfake is a plain word wearing a technical costume. It means a fake image, video, or audio recording generated by software that has studied real recordings of a person until it can produce new ones — a video of someone saying something they never said, or a voice speaking words the person never spoke.

    There’s no mystery in it and nothing exotic. The software needs examples of the person, and it produces convincing new material from them. The more examples it has, the better the result.

    The two forms that matter to a church are different in maturity, and it’s worth being precise about which is which, because the difference determines how you should think about the risk.

    Where the technology actually is

    Synthetic voice is here, it is cheap, and it is fast. This is the mature threat. Software that clones a voice from a short sample is widely available and requires no skill to operate. The FBI’s public warning on generative AI fraud describes criminals using AI-generated audio to impersonate people — a relative in a crisis asking for immediate financial help, or an account holder calling their own bank — in order to extract funds or gain access to accounts. If a caller’s voice sounds exactly like your finance chair, that no longer tells you anything.

    We’ll cover voice cloning on its own in a later post, because it deserves the room.

    Live synthetic video on a call is real but harder. This is where it’s easy to overstate, so here are the actual facts of the best-documented case.

    In January 2024, an employee at Arup — a London-headquartered engineering and design firm — joined a video conference at the company’s Hong Kong office with people who appeared to be the chief financial officer and other colleagues. They were digital recreations. Over the following week the employee made fifteen transfers totalling HK$200 million, roughly US$25 million. Hong Kong police disclosed the case in February 2024, and Arup confirmed in May 2024 that it had been the victim, with a spokesperson saying the firm notified police in January.

    That is one very large fraud against a global firm with thousands of employees, and it should be read as a demonstration rather than as a description of what happens on a typical Tuesday. The everyday version of this attack is still a plain email or a phone call. But the Arup case establishes something that is no longer arguable: a video call is not proof of who you are talking to.

    The FBI’s guidance reflects the same conclusion, noting that criminals generate AI video to depict executives and authority figures in real-time chats or to lend credibility in private communication.

    Why a church is unusually exposed

    Voice cloning needs reference material. Consider what your organization publishes, on purpose, every single week.

    Sermons. Livestreamed services, archived and public. Podcast episodes. Announcement videos. Staff introduction clips on the website. A capital campaign video with the board chair speaking directly to camera for three minutes.

    Most small businesses have almost nothing like this. A church typically has hours of clean, well-recorded audio of its most authoritative voices, freely downloadable, indexed and organized by name.

    None of that is a reason to stop. The livestream is ministry, and taking it down to prevent a hypothetical fraud would be trading something real for something speculative. The right response is not to publish less. It is to stop treating a familiar voice as identification — because for your organization specifically, a familiar voice is public information.

    The rest of the reference material is public too. Your board members are listed on your website or in your 990 filing. Your bank is on your checks. Your building project is in the newsletter. A fraudster does not need to research you; they need to read you.

    The rule that works no matter how good the fake is

    Everything above is about how convincing the impersonation can be. The control below doesn’t care.

    A decision to move money is never made on a call. It is confirmed on a channel the requester did not choose.

    Sit with that second sentence, because it’s the load-bearing part. If the request came in on a video call, confirmation happens by phone. If it came by phone, confirmation happens by a text to the number in your records, or in person, or on a second call you place. The attacker controls the channel they contacted you through — that’s the one thing you can be certain of. So verification has to happen somewhere else.

    This is the same money rule that runs through everything else on this blog: any change to payment details is verified by voice, on a number you already had, before the payment goes out. The deepfake era changes exactly one thing about it. Voice alone is no longer sufficient confirmation. The channel is doing the verifying now, not the sound of the person.

    Three specific mechanisms make that rule practical.

    A shared verbal passphrase for leadership. Agree on a word or short phrase, in person, among the small group of people who can authorize payments — pastor, treasurer, board chair, administrator. It is never written in email, never stored in a shared drive, never said on a video call. When a request to move money arrives from a person rather than a process, the recipient asks for it. The FBI recommends exactly this technique for families targeted by AI voice fraud: “Create a secret word or phrase with your family to verify their identity.” A leadership team is the same idea with a different roster.

    Pick something unguessable and unGoogleable. Not the church’s founding year, not the pastor’s dog. A random pair of words is ideal, and you should agree in advance that anyone may ask for it without it being awkward, including from the senior person in the room.

    A callback rule. No payment instruction is executed on the strength of the call it arrived on. The administrator hangs up, dials the number already in the personnel file or the vendor contract, and confirms. It adds ten minutes and defeats the entire category.

    Dual approval above a threshold. Pick a dollar figure appropriate to your budget and require two named people to approve anything above it — with the second approval given through a channel other than the one the request came in on. This is the control that survives even when the first person is completely fooled, and it’s why it belongs in your written policy rather than in someone’s habits.

    Write all three down. A control that lives only in the treasurer’s head disappears the moment the treasurer is on vacation, which is the week the request will arrive.

    Tells on a live call, and why they expire

    If you find yourself on a call and something is off, there are things worth trying.

    Ask the person to turn their head fully to one side, or to stand up and step back from the camera. Current systems handle a straight-on face far better than a sharp profile or an unusual angle, and artifacts often appear at the edges — around the ears, the jawline, the hairline, or where hair meets background.

    Ask them to hold a hand up beside their face. Hands are still difficult.

    Better than either: ask something only the real person would know, and make it specific and recent. Not “what’s our budget” — anything published is available. Ask what they ordered at lunch on Tuesday, or what the sanctuary thermostat has been doing, or the name of the person who fixed the parking lot lights. A synthetic impersonation is usually driven by someone reading from research, and research does not include last Tuesday’s lunch.

    Now the honest caveat, which matters more than the tips: these tells are expiring. Every one of them exists because the technology has a current limitation, and current limitations do not stay current. Head turns will get better. Hands will get better. The list above may be substantially useless in two years, and there is no version of it that stays reliable.

    That’s not a reason to skip them. It’s the reason the procedure matters more than the perception. A passphrase and a callback rule work identically whether the fake is crude or flawless, because they never ask anyone to judge how real something looks. They’re the only part of this article with a shelf life.

    If it already happened

    Move fast; recovery is a race measured in hours.

    Call your bank’s fraud line first, before anything else, and ask them to attempt a recall. Wire transfers are hardest to reverse and ACH transfers sometimes possible — either way, the first hour matters more than everything you do afterward.

    Report to the FBI at ic3.gov, and say business email compromise even if the request arrived by video, because that’s the category the Bureau’s recovery process runs on. The FBI’s Recovery Asset Team ran 3,574 domestic cases in 2025 and froze $507,042,623, and that process works dramatically better inside the first 24 to 72 hours.

    Tell your board and your insurer the same day. Many policies have prompt-notice requirements, and a delay can affect coverage.

    Then look at the mailbox. These attacks are frequently preceded by someone reading email inside your organization for weeks. Change passwords from a different device, sign out all sessions, enable multi-factor authentication if it isn’t on, and check every mailbox for forwarding rules nobody remembers creating.

    For scale: the FBI logged 24,768 business email compromise complaints in 2025, with losses of $3,046,598,558 — an average of about $123,005 per report. This is where the money in fraud actually goes, and a synthetic voice or face is simply a new way to open the same door.

    What to do this week

    Choose a passphrase with your leadership team — pastor, treasurer, board chair, administrator — in person or on a call where you can see each other, and agree it is never written down or emailed. Then send one message to whoever executes payments, in your own words: no payment or change of payment details goes out on the strength of a call, however convincing. Hang up, call the number we already have, confirm.

    That’s twenty minutes, and unlike every visual tell in this article, it doesn’t stop working next year.

    Procedures are what hold up when the technology stops helping you tell real from fake. MissionDefend’s free assessment asks plain-English questions about how your organization approves payments, handles email, and manages accounts, then returns a baseline score and a ranked list of what to fix first — including whether your money controls depend on someone recognizing a voice.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud; South China Morning Post, UK multinational Arup confirmed as victim of HK$200 million deepfake scam; CNN, Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.