Home Articles Get your free assessmentComing soon

Tag: incident response

  • The First 24 Hours: What to Tell Your Congregation

    The First 24 Hours: What to Tell Your Congregation

    It is 4:15 on a Thursday when the bookkeeper realizes something is wrong. That morning she got a notification about a sign-in to the church email account from a city none of you have visited, and now, in the mailbox settings, there is a forwarding rule she did not create.

    By 5:30 the person who helps you with computers has confirmed it: someone else has been in that mailbox for at least eleven days. It holds the counting team’s spreadsheets, scanned checks, the pastoral care list, and four years of correspondence.

    The pastor asks the question every leader asks at this moment, and it is the right one:

    What do we tell people?

    The answer that feels safest — wait until we understand it fully, then send something carefully worded — is almost always the wrong one. Not because the caution is unreasonable, but because of how congregations actually respond to bad news.

    People forgive the incident. They do not forgive the silence

    Congregations are generally forgiving about the incident itself. They understand that a church has two staff and a volunteer treasurer, that email accounts get compromised at corporations with security teams, that nobody was careless in a way that deserves punishment. Most members have clicked something they shouldn’t have.

    What they don’t forgive is finding out late, finding out from somewhere else, or reading a message obviously written to limit liability rather than to inform. A member who learns three weeks later that their giving records were exposed doesn’t think these things happen. They think they knew and didn’t tell me, and that attaches to the leadership permanently.

    The reputational damage from a slow, defensive, lawyer-flavored message is usually larger than the damage from the incident itself. The incident is a thing that happened to you. The silence is a thing you chose.

    What you must know before you speak, and what you can say anyway

    Twelve hours in, you will not know much. Not which records were accessed, not whether anything was downloaded, not whether member data will be misused. Those answers can take weeks.

    Here is the reframe that unlocks the whole problem. There are three things you can almost always say honestly within hours, and they are the three things people actually want:

    What happened, in the plainest terms. Not the technical mechanism — someone gained access to one of our email accounts is enough.

    What you are doing about it. You locked the account, brought in help, and are reviewing what was in there. All true within the first afternoon.

    What you want them to do. This is the part people scan for, and the part most notices bury.

    You don’t need the full scope to say those three things. What you should have before you speak is confirmation from someone competent that an incident occurred and that the immediate hole is closed. Announcing a breach that turns out to be a misconfigured setting is its own kind of damage.

    One constraint worth knowing. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring notification when certain kinds of personal information are exposed — and what counts as personal information, what triggers the duty, how long you have, what the letter must say, and whether a state attorney general has to be told all differ materially from state to state. There is no single national deadline or rule. Ask your attorney what applies to you before the formal notice goes out. Nothing here is legal advice.

    Hours, then days: two different messages

    Separate the two communications in your mind and the timing problem largely dissolves.

    The holding statement goes out within about 24 hours: what happened, what you’re doing, what to watch for, and when they’ll hear from you next. Its job is to make sure nobody learns this from a rumor. The full notice goes out in days, once you know the scope — specific about what was and wasn’t affected, carrying any formal notification your attorney says is required.

    A holding statement you can adapt:

    Subject: An important notice from [Church Name] Dear friends, I’m writing about something that happened here this week, and I want you to hear it from us rather than anywhere else. On Thursday we discovered that an unauthorized person had access to one of our church email accounts. We have locked that account, changed the passwords, and brought in outside help to determine exactly what was accessed and when. We do not yet know the full extent of what was in that mailbox or whether any of it was taken. That review is underway, and I would rather tell you what we know today than wait until we know everything. What we’re asking you to do. Please be cautious about any message that appears to come from the church over the next several weeks — anything asking you to give, click a link, update payment details, or send money or gift cards. The church will never contact you asking for payment, gift cards, banking details, or a password. If you receive something like that, call the office at [number] before you act on it. We will not be offended by the call. This happens to organizations far larger than ours, and what matters now is how we respond. I will write again by [specific date] with what we’ve found. If you have questions before then, call me directly at [number]. [Name] [Role], [Church Name]

    Notice what it doesn’t do: speculate, promise nothing was taken, or apologize in a way that assigns fault to a person. And it sets a specific date for the next message — the easiest way to buy time honestly.

    The follow-up, several days later:

    Subject: Update on the email incident at [Church Name] Dear friends, On [date] I wrote about unauthorized access to one of our church email accounts. Here is what we now know. The account was accessed between [date] and [date]. The mailbox contained [describe plainly: correspondence, some giving records, and documents containing member names and addresses]. We have [no evidence that / evidence that] this information was copied or misused. If your information was affected, you are receiving a separate letter with specific steps, including [credit monitoring / what to watch for]. If you did not receive that letter, our review indicates your information was not in the affected account. What we have changed. Every church account now requires a second step to log in beyond the password, so a stolen password alone is no longer enough. We have reviewed every account for unauthorized forwarding rules, and our board adopted a written security policy on [date]. What we’re still asking of you. Keep treating unexpected messages about the church with suspicion — anything about giving, payments, or account details, and especially anything referring to this incident. Call the office to check. We would much rather field the call. We have reported this to [law enforcement / the appropriate authorities] and are following the notification requirements that apply to us. I’m grateful for the grace you’ve shown this week. If you’d like to talk, my number is [number]. [Name]

    Who speaks, and how it reaches the people least likely to read email

    Decide the voice before you need it. It should be the senior pastor or the board chair — one person, named, with a real phone number in the message. An unsigned notice from “the church office” reads as institutional distancing at exactly the wrong moment.

    Then use every channel, because they reach different people:

    Email, to everyone you have an address for. Fastest, and the record of what you said.

    The website. A short dated notice on the front page. This is where members send their adult children, and where anyone who hears a rumor will check.

    From the front, on Sunday. Two minutes, in plain language, not buried in announcements. Members who hear their pastor say it out loud experience it entirely differently than members who read it, and it visibly signals that the leadership is not hiding. Put a printed copy in the bulletin too.

    A phone tree. The one that gets skipped, and the one that matters most.

    Here is the uncomfortable arithmetic. The members most likely to be targeted by follow-on scams are your older members — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, a 37% increase over 2024, and $7.748 billion in losses, which was up 59% in a single year. The members least likely to read an emailed notice are very often the same people. A written notice reaches the people who need it least.

    So build a short list of members who don’t use email reliably, split it among your deacons, elders, or care team, and call them. The script is three sentences: Something happened with the church’s email. Nobody needs to do anything. But if anyone contacts you claiming to be from the church and asks for money or account details, hang up and call the office.

    Twenty people making six calls each covers a congregation in an evening.

    The instruction that stops them being victimized twice

    Attackers who have been inside a mailbox for eleven days know your members’ names, your pastor’s writing style, your giving cycle, and the fact that you just announced a breach. The second wave is often more profitable than the first: a message that references the incident, expresses concern, and asks the member to “verify” something.

    So give the instruction in a form people can remember under pressure:

    The church will never contact you asking for money, gift cards, banking details, passwords, or account verification — by email, text, or phone. If anyone does, it isn’t us. Hang up or delete it, and call the office on the number in the bulletin.

    Put that sentence in the holding statement, the follow-up, the bulletin, and the phone script, and repeat it in the newsletter a month later. It’s permanent congregational hygiene that happens to be most urgent right now.

    What not to do

    Don’t minimize. “A minor issue with one of our systems” is the phrase that gets quoted back to you when the scope turns out to be larger. Describe it accurately, or as still under review — never smaller than it is.

    Don’t name the staff member. Not in the notice, not from the pulpit, not in conversation. That person is already carrying it, and naming them tells everyone else in your organization that reporting a mistake gets you publicly identified — precisely the behavior you cannot afford. If your board asks who, the answer is: a member of our team was targeted by a convincing message, and they reported it quickly, which is what limited this.

    Don’t promise it can never happen again. You can’t deliver it, and it’s what people remember if there’s a second incident. Say what you have changed instead — stronger, and true.

    Don’t go quiet because of legal advice. Counsel should review the wording of anything you send — that is what counsel is for, and formal notification has requirements you should not guess at. But there is a difference between have a lawyer read this before it goes out and say nothing until the lawyer is comfortable, and the second can run for weeks. Bring your attorney in on day one and give them a deadline. Saying nothing is not neutral; it is a choice, and its consequences compound daily.

    Don’t let the first Sunday pass in silence. If the congregation is in the building and nobody mentions it, you have communicated something.

    What to do this week

    You almost certainly are not in an incident right now, which is exactly why this is the week.

    Write two things and put them in a shared folder labeled clearly enough that a panicking person can find it: the name and mobile number of whoever will speak publicly if this happens, and a draft holding statement — adapt the one above in fifteen minutes by filling in the brackets.

    Then build the phone-tree list: which members don’t use email, and who calls them. On the worst day, that list is the difference between reaching your congregation and merely emailing it.

    Forty-five minutes, and the first 24 hours stop being improvised.

    The best time to work all of this out is before you need it. MissionDefend’s free assessment asks plain-English questions about how your church handles email, donations, member data, and accounts, then hands back a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Data Breach Response: A Guide for Business; National Conference of State Legislatures, Security Breach Notification Laws; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    There is a binder on a shelf in the church office. The spine says Information Security Policy. Someone downloaded it in 2019, printed it, added tab dividers, and put it on the shelf, where it has remained.

    It is forty-one pages long. It references a Chief Information Security Officer, a quarterly vulnerability management cadence, and a data classification scheme with four tiers. The church has two full-time staff and a volunteer treasurer.

    Nobody has opened it. Not once. If you asked the office administrator what the policy says about wire transfers, she would tell you honestly that she has no idea.

    That binder is not neutral. It is worse than having nothing, because it lets everyone believe the question has been handled.

    The forty-page policy fails for a reason that has nothing to do with its contents

    The contents are usually fine. Somebody competent wrote them. The problem is structural.

    A policy is not a legal artifact. It is an instruction to human beings about what to do on a Tuesday afternoon when an email arrives asking for a payment change. If the instruction is on page 27 of a document nobody has read, it does not exist. The staff member acts on instinct instead, and instinct is exactly what the attacker is designing for.

    Long policies also fail in the other direction. They contain commitments the organization cannot keep — quarterly access audits, annual penetration testing, a security awareness training program — and once a policy contains one thing you obviously aren’t doing, the whole document loses its authority. People stop treating any of it as real.

    A single page that six people actually follow beats a binder that nobody opens. That is the whole argument, and it holds in organizations far larger than yours.

    So here is the page.

    The page

    Copy this. Change the bracketed parts. Do not add to it — the length is the feature.

    “`
    [CHURCH NAME] — INFORMATION SECURITY POLICY
    Adopted by the Board on [DATE]. Next review: [DATE + 1 YEAR].
    Policy owner: [NAME, ROLE].

    1. RESPONSIBILITY The Board is responsible for this policy. [NAME] is responsible for carrying it out and reports to the Board once a year on whether we are doing what this page says.
    1. MULTI-FACTOR AUTHENTICATION Multi-factor authentication is required on: church email, online banking, the giving/donation platform, the church management system, the payroll system, the website host, the domain registrar, and all social media accounts. No exceptions without written Board approval.
    1. VERIFYING MONEY Any request to send money, change bank details, change payroll direct deposit, or pay a new or altered invoice is verified by voice, on a phone number we already had on file — never a number supplied in the request — before the payment goes out. This applies however the request arrives, including from someone inside the organization.
    1. INDIVIDUAL LOGINS Every person has their own login. Logins and passwords are not shared, not with staff, not with volunteers, not with family members. Passwords are stored in the approved password manager, not on paper, in a spreadsheet, or in email.
    1. WHEN SOMEONE LEAVES When any staff member or volunteer stops serving in a role, their access to every account and building is removed within 14 days. [NAME] runs this from the account inventory and confirms it in writing. This applies to everyone, including clergy and Board members.
    1. BACKUPS Church data — financial records, member records, and documents — is backed up automatically, with at least one copy the church controls and that cannot be altered from a staff computer. Once a year we restore a real file from backup to prove the backup works, and note the date it was tested.
    1. IF SOMETHING LOOKS WRONG If you think you clicked a bad link, entered a password on the wrong page, sent money to the wrong place, or noticed anything unusual in an account: stop, and tell [NAME] and [BACKUP NAME] immediately, by phone. Do not wait to be sure. If money has moved, we call the bank first and report to the FBI at ic3.gov the same day.
    1. NO PENALTY FOR REPORTING No one will be disciplined, dismissed, or embarrassed for reporting a mistake or a suspicion, including their own mistake, and including after money has been lost. Reporting quickly is the behavior this church wants. Hiding a mistake is the only thing that gets anyone in trouble.
    1. REVIEW The Board reviews this policy once a year, on or before [DATE]. “`

    That is the entire policy. It fits on one sheet, single-sided.

    What each clause is doing, so you can defend it

    Your board will ask about some of these. Here is the one-sentence answer for each.

    Responsibility. A policy with no name attached is a wish; naming one person and one annual report is what turns it into something that actually happens.

    Multi-factor authentication. Multi-factor authentication — MFA — is the extra step after your password: a code, a tap on your phone, a key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks, and naming the specific systems matters because churches routinely turn it on for email and forget the giving platform, which is the one holding donor card details.

    Verifying money. This is the single clause most likely to save you real money, because the fraud that actually hits churches is a convincing email asking for a payment change; a thirty-second phone call to a number you already had defeats every version of it.

    Individual logins. Shared logins make it impossible to know who did what, impossible to remove one person’s access without disrupting everyone, and impossible to use MFA properly.

    When someone leaves. Old accounts are the quietest risk you have — nobody is watching them, and their passwords are often years old and reused elsewhere; a defined window turns “we should get around to that” into a date. CISA’s guidance for small organizations puts it plainly: develop procedures addressing changes in user status, and eliminate shared and unused accounts.

    Backups. A backup you have never restored is a theory, and the annual restore test is what converts it into a fact — this is also the clause that determines whether a ransomware incident is a bad week or an extinction event.

    If something looks wrong. Most losses become large because somebody waited; naming two people and requiring a phone call removes the ambiguity about who to tell and how.

    No penalty for reporting. Speed is the only thing that reliably recovers money, and speed depends entirely on whether a frightened person feels safe telling you within the hour rather than on Monday.

    Review. A date on the page is what stops this becoming the 2019 binder.

    Getting it adopted on a Tuesday

    The mistake is presenting this as a debate. It is not a debate; it is a housekeeping item that happens to be important.

    Put it on the consent agenda. Consent items are approved as a block without discussion unless a member pulls one. Circulate the page with the board packet a week ahead, with a two-sentence cover note: This replaces our existing information security policy. It is one page so that staff and volunteers will actually follow it. Most boards will pass it without comment, which is the correct outcome.

    Name the owner before the meeting, not during it. An unassigned policy will sit for a year. Ask the person first, privately, so the name in the document is already agreed.

    Set the review date as a real date. Not “annually.” A date, in the calendar, on the same board meeting each year.

    Record it in the minutes. This is the part people skip, and it is the part that matters most beyond the security question.

    Boards of nonprofit organizations carry a duty of care — the general obligation to act with the attention a reasonably prudent person would apply to the organization’s affairs. The specifics vary by state and by your governing documents, and this is not legal advice; ask your attorney what applies to you. But the general shape is consistent: what a board can demonstrate matters. A minute that reads the Board adopted the Information Security Policy, assigned responsibility to the Business Administrator, and set the annual review for the March meeting is evidence that the board considered the risk and acted. A verbal agreement that somebody should look into cybersecurity is not.

    Give a copy to every person it applies to. Staff, yes — but also the volunteer who runs the website, the volunteer counting team, the person with the Facebook password. One page can be handed to someone in a hallway. Forty-one pages cannot.

    Policy without practice is theatre

    Here is the honest limitation. Adopting this page does not mean your church is prepared. It means your church has written down what it intends to do.

    The gap between those two things is real, and it shows up under pressure. The staff member who has read clause 3 in a board packet is not the same as the staff member who has actually made the verification call once and knows it takes thirty seconds and is not awkward. The person named in clause 7 is not ready until they have said the words out loud in a room, with a scenario in front of them.

    The way to close that gap is a tabletop exercise — a short, low-stakes practice run where you talk through a realistic incident around a table and find out who would actually do what. It takes under an hour and it is the subject of its own post in this series. If you adopt the policy and never practice it, you have documentation. If you adopt it and practice it once a year, you have a response.

    Do the page first anyway. Documentation you follow beats intention you never wrote down.

    What to do this week

    Copy the page above into a document, fill in the five bracketed fields — church name, policy owner, backup contact, adoption date, review date — and email it to whoever assembles the board packet with a request to add it to the consent agenda.

    Then, separately, check one thing before the meeting: whether MFA is actually turned on for the giving platform and the church management system, not just email. If it isn’t, you will want to know that before you sign a document saying it is required.

    Thirty minutes, no budget, and your board has a defensible record by the end of the month.

    If you would like something concrete to bring to the same board meeting, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — useful as the evidence behind the annual report clause 1 asks for.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Cybersecurity and Infrastructure Security Agency, Cyber Essentials Starter Kit; Microsoft, mandatory multifactor authentication guidance; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • If You Lose Member Data, Who Do You Have to Tell?

    If You Lose Member Data, Who Do You Have to Tell?

    It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.

    Or: the laptop was in the back of the car outside the hospital, and now it isn’t.

    Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.

    Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?

    The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.

    Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.

    These laws are not just for corporations

    Start here, because this is the assumption that gets churches into trouble.

    The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”

    Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.

    What actually triggers a notice

    Here is the most useful thing in this article, and the part most people have backwards.

    Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.

    NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”

    In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:

    • Social Security number
    • Driver’s license or state identification number
    • A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
    • In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account

    Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.

    That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.

    The obligation usually follows the person, not the church

    This surprises people, and it matters for churches more than for most small organizations.

    These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”

    A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.

    You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.

    What the notices generally have in common

    Details vary by state — always — but the family resemblance is strong.

    A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.

    Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.

    Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.

    Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.

    And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.

    Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.

    The first days: what to do so that you can comply

    Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.

    Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.

    Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.

    Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.

    Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.

    Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.

    Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.

    Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.

    Notifying well is a trust-building act

    There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.

    The pattern runs the other way.

    Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.

    A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.

    Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.

    What to do this week

    Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.

    Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.

    Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.