Home Articles Get your free assessmentComing soon

Tag: breach notification

  • The First 24 Hours: What to Tell Your Congregation

    The First 24 Hours: What to Tell Your Congregation

    It is 4:15 on a Thursday when the bookkeeper realizes something is wrong. That morning she got a notification about a sign-in to the church email account from a city none of you have visited, and now, in the mailbox settings, there is a forwarding rule she did not create.

    By 5:30 the person who helps you with computers has confirmed it: someone else has been in that mailbox for at least eleven days. It holds the counting team’s spreadsheets, scanned checks, the pastoral care list, and four years of correspondence.

    The pastor asks the question every leader asks at this moment, and it is the right one:

    What do we tell people?

    The answer that feels safest — wait until we understand it fully, then send something carefully worded — is almost always the wrong one. Not because the caution is unreasonable, but because of how congregations actually respond to bad news.

    People forgive the incident. They do not forgive the silence

    Congregations are generally forgiving about the incident itself. They understand that a church has two staff and a volunteer treasurer, that email accounts get compromised at corporations with security teams, that nobody was careless in a way that deserves punishment. Most members have clicked something they shouldn’t have.

    What they don’t forgive is finding out late, finding out from somewhere else, or reading a message obviously written to limit liability rather than to inform. A member who learns three weeks later that their giving records were exposed doesn’t think these things happen. They think they knew and didn’t tell me, and that attaches to the leadership permanently.

    The reputational damage from a slow, defensive, lawyer-flavored message is usually larger than the damage from the incident itself. The incident is a thing that happened to you. The silence is a thing you chose.

    What you must know before you speak, and what you can say anyway

    Twelve hours in, you will not know much. Not which records were accessed, not whether anything was downloaded, not whether member data will be misused. Those answers can take weeks.

    Here is the reframe that unlocks the whole problem. There are three things you can almost always say honestly within hours, and they are the three things people actually want:

    What happened, in the plainest terms. Not the technical mechanism — someone gained access to one of our email accounts is enough.

    What you are doing about it. You locked the account, brought in help, and are reviewing what was in there. All true within the first afternoon.

    What you want them to do. This is the part people scan for, and the part most notices bury.

    You don’t need the full scope to say those three things. What you should have before you speak is confirmation from someone competent that an incident occurred and that the immediate hole is closed. Announcing a breach that turns out to be a misconfigured setting is its own kind of damage.

    One constraint worth knowing. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring notification when certain kinds of personal information are exposed — and what counts as personal information, what triggers the duty, how long you have, what the letter must say, and whether a state attorney general has to be told all differ materially from state to state. There is no single national deadline or rule. Ask your attorney what applies to you before the formal notice goes out. Nothing here is legal advice.

    Hours, then days: two different messages

    Separate the two communications in your mind and the timing problem largely dissolves.

    The holding statement goes out within about 24 hours: what happened, what you’re doing, what to watch for, and when they’ll hear from you next. Its job is to make sure nobody learns this from a rumor. The full notice goes out in days, once you know the scope — specific about what was and wasn’t affected, carrying any formal notification your attorney says is required.

    A holding statement you can adapt:

    Subject: An important notice from [Church Name] Dear friends, I’m writing about something that happened here this week, and I want you to hear it from us rather than anywhere else. On Thursday we discovered that an unauthorized person had access to one of our church email accounts. We have locked that account, changed the passwords, and brought in outside help to determine exactly what was accessed and when. We do not yet know the full extent of what was in that mailbox or whether any of it was taken. That review is underway, and I would rather tell you what we know today than wait until we know everything. What we’re asking you to do. Please be cautious about any message that appears to come from the church over the next several weeks — anything asking you to give, click a link, update payment details, or send money or gift cards. The church will never contact you asking for payment, gift cards, banking details, or a password. If you receive something like that, call the office at [number] before you act on it. We will not be offended by the call. This happens to organizations far larger than ours, and what matters now is how we respond. I will write again by [specific date] with what we’ve found. If you have questions before then, call me directly at [number]. [Name] [Role], [Church Name]

    Notice what it doesn’t do: speculate, promise nothing was taken, or apologize in a way that assigns fault to a person. And it sets a specific date for the next message — the easiest way to buy time honestly.

    The follow-up, several days later:

    Subject: Update on the email incident at [Church Name] Dear friends, On [date] I wrote about unauthorized access to one of our church email accounts. Here is what we now know. The account was accessed between [date] and [date]. The mailbox contained [describe plainly: correspondence, some giving records, and documents containing member names and addresses]. We have [no evidence that / evidence that] this information was copied or misused. If your information was affected, you are receiving a separate letter with specific steps, including [credit monitoring / what to watch for]. If you did not receive that letter, our review indicates your information was not in the affected account. What we have changed. Every church account now requires a second step to log in beyond the password, so a stolen password alone is no longer enough. We have reviewed every account for unauthorized forwarding rules, and our board adopted a written security policy on [date]. What we’re still asking of you. Keep treating unexpected messages about the church with suspicion — anything about giving, payments, or account details, and especially anything referring to this incident. Call the office to check. We would much rather field the call. We have reported this to [law enforcement / the appropriate authorities] and are following the notification requirements that apply to us. I’m grateful for the grace you’ve shown this week. If you’d like to talk, my number is [number]. [Name]

    Who speaks, and how it reaches the people least likely to read email

    Decide the voice before you need it. It should be the senior pastor or the board chair — one person, named, with a real phone number in the message. An unsigned notice from “the church office” reads as institutional distancing at exactly the wrong moment.

    Then use every channel, because they reach different people:

    Email, to everyone you have an address for. Fastest, and the record of what you said.

    The website. A short dated notice on the front page. This is where members send their adult children, and where anyone who hears a rumor will check.

    From the front, on Sunday. Two minutes, in plain language, not buried in announcements. Members who hear their pastor say it out loud experience it entirely differently than members who read it, and it visibly signals that the leadership is not hiding. Put a printed copy in the bulletin too.

    A phone tree. The one that gets skipped, and the one that matters most.

    Here is the uncomfortable arithmetic. The members most likely to be targeted by follow-on scams are your older members — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, a 37% increase over 2024, and $7.748 billion in losses, which was up 59% in a single year. The members least likely to read an emailed notice are very often the same people. A written notice reaches the people who need it least.

    So build a short list of members who don’t use email reliably, split it among your deacons, elders, or care team, and call them. The script is three sentences: Something happened with the church’s email. Nobody needs to do anything. But if anyone contacts you claiming to be from the church and asks for money or account details, hang up and call the office.

    Twenty people making six calls each covers a congregation in an evening.

    The instruction that stops them being victimized twice

    Attackers who have been inside a mailbox for eleven days know your members’ names, your pastor’s writing style, your giving cycle, and the fact that you just announced a breach. The second wave is often more profitable than the first: a message that references the incident, expresses concern, and asks the member to “verify” something.

    So give the instruction in a form people can remember under pressure:

    The church will never contact you asking for money, gift cards, banking details, passwords, or account verification — by email, text, or phone. If anyone does, it isn’t us. Hang up or delete it, and call the office on the number in the bulletin.

    Put that sentence in the holding statement, the follow-up, the bulletin, and the phone script, and repeat it in the newsletter a month later. It’s permanent congregational hygiene that happens to be most urgent right now.

    What not to do

    Don’t minimize. “A minor issue with one of our systems” is the phrase that gets quoted back to you when the scope turns out to be larger. Describe it accurately, or as still under review — never smaller than it is.

    Don’t name the staff member. Not in the notice, not from the pulpit, not in conversation. That person is already carrying it, and naming them tells everyone else in your organization that reporting a mistake gets you publicly identified — precisely the behavior you cannot afford. If your board asks who, the answer is: a member of our team was targeted by a convincing message, and they reported it quickly, which is what limited this.

    Don’t promise it can never happen again. You can’t deliver it, and it’s what people remember if there’s a second incident. Say what you have changed instead — stronger, and true.

    Don’t go quiet because of legal advice. Counsel should review the wording of anything you send — that is what counsel is for, and formal notification has requirements you should not guess at. But there is a difference between have a lawyer read this before it goes out and say nothing until the lawyer is comfortable, and the second can run for weeks. Bring your attorney in on day one and give them a deadline. Saying nothing is not neutral; it is a choice, and its consequences compound daily.

    Don’t let the first Sunday pass in silence. If the congregation is in the building and nobody mentions it, you have communicated something.

    What to do this week

    You almost certainly are not in an incident right now, which is exactly why this is the week.

    Write two things and put them in a shared folder labeled clearly enough that a panicking person can find it: the name and mobile number of whoever will speak publicly if this happens, and a draft holding statement — adapt the one above in fifteen minutes by filling in the brackets.

    Then build the phone-tree list: which members don’t use email, and who calls them. On the worst day, that list is the difference between reaching your congregation and merely emailing it.

    Forty-five minutes, and the first 24 hours stop being improvised.

    The best time to work all of this out is before you need it. MissionDefend’s free assessment asks plain-English questions about how your church handles email, donations, member data, and accounts, then hands back a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Data Breach Response: A Guide for Business; National Conference of State Legislatures, Security Breach Notification Laws; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • If You Lose Member Data, Who Do You Have to Tell?

    If You Lose Member Data, Who Do You Have to Tell?

    It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.

    Or: the laptop was in the back of the car outside the hospital, and now it isn’t.

    Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.

    Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?

    The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.

    Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.

    These laws are not just for corporations

    Start here, because this is the assumption that gets churches into trouble.

    The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”

    Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.

    What actually triggers a notice

    Here is the most useful thing in this article, and the part most people have backwards.

    Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.

    NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”

    In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:

    • Social Security number
    • Driver’s license or state identification number
    • A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
    • In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account

    Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.

    That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.

    The obligation usually follows the person, not the church

    This surprises people, and it matters for churches more than for most small organizations.

    These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”

    A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.

    You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.

    What the notices generally have in common

    Details vary by state — always — but the family resemblance is strong.

    A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.

    Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.

    Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.

    Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.

    And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.

    Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.

    The first days: what to do so that you can comply

    Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.

    Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.

    Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.

    Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.

    Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.

    Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.

    Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.

    Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.

    Notifying well is a trust-building act

    There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.

    The pattern runs the other way.

    Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.

    A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.

    Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.

    What to do this week

    Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.

    Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.

    Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.