Home Articles Get your free assessmentComing soon

Tag: mfa

  • A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    There is a binder on a shelf in the church office. The spine says Information Security Policy. Someone downloaded it in 2019, printed it, added tab dividers, and put it on the shelf, where it has remained.

    It is forty-one pages long. It references a Chief Information Security Officer, a quarterly vulnerability management cadence, and a data classification scheme with four tiers. The church has two full-time staff and a volunteer treasurer.

    Nobody has opened it. Not once. If you asked the office administrator what the policy says about wire transfers, she would tell you honestly that she has no idea.

    That binder is not neutral. It is worse than having nothing, because it lets everyone believe the question has been handled.

    The forty-page policy fails for a reason that has nothing to do with its contents

    The contents are usually fine. Somebody competent wrote them. The problem is structural.

    A policy is not a legal artifact. It is an instruction to human beings about what to do on a Tuesday afternoon when an email arrives asking for a payment change. If the instruction is on page 27 of a document nobody has read, it does not exist. The staff member acts on instinct instead, and instinct is exactly what the attacker is designing for.

    Long policies also fail in the other direction. They contain commitments the organization cannot keep — quarterly access audits, annual penetration testing, a security awareness training program — and once a policy contains one thing you obviously aren’t doing, the whole document loses its authority. People stop treating any of it as real.

    A single page that six people actually follow beats a binder that nobody opens. That is the whole argument, and it holds in organizations far larger than yours.

    So here is the page.

    The page

    Copy this. Change the bracketed parts. Do not add to it — the length is the feature.

    “`
    [CHURCH NAME] — INFORMATION SECURITY POLICY
    Adopted by the Board on [DATE]. Next review: [DATE + 1 YEAR].
    Policy owner: [NAME, ROLE].

    1. RESPONSIBILITY The Board is responsible for this policy. [NAME] is responsible for carrying it out and reports to the Board once a year on whether we are doing what this page says.
    1. MULTI-FACTOR AUTHENTICATION Multi-factor authentication is required on: church email, online banking, the giving/donation platform, the church management system, the payroll system, the website host, the domain registrar, and all social media accounts. No exceptions without written Board approval.
    1. VERIFYING MONEY Any request to send money, change bank details, change payroll direct deposit, or pay a new or altered invoice is verified by voice, on a phone number we already had on file — never a number supplied in the request — before the payment goes out. This applies however the request arrives, including from someone inside the organization.
    1. INDIVIDUAL LOGINS Every person has their own login. Logins and passwords are not shared, not with staff, not with volunteers, not with family members. Passwords are stored in the approved password manager, not on paper, in a spreadsheet, or in email.
    1. WHEN SOMEONE LEAVES When any staff member or volunteer stops serving in a role, their access to every account and building is removed within 14 days. [NAME] runs this from the account inventory and confirms it in writing. This applies to everyone, including clergy and Board members.
    1. BACKUPS Church data — financial records, member records, and documents — is backed up automatically, with at least one copy the church controls and that cannot be altered from a staff computer. Once a year we restore a real file from backup to prove the backup works, and note the date it was tested.
    1. IF SOMETHING LOOKS WRONG If you think you clicked a bad link, entered a password on the wrong page, sent money to the wrong place, or noticed anything unusual in an account: stop, and tell [NAME] and [BACKUP NAME] immediately, by phone. Do not wait to be sure. If money has moved, we call the bank first and report to the FBI at ic3.gov the same day.
    1. NO PENALTY FOR REPORTING No one will be disciplined, dismissed, or embarrassed for reporting a mistake or a suspicion, including their own mistake, and including after money has been lost. Reporting quickly is the behavior this church wants. Hiding a mistake is the only thing that gets anyone in trouble.
    1. REVIEW The Board reviews this policy once a year, on or before [DATE]. “`

    That is the entire policy. It fits on one sheet, single-sided.

    What each clause is doing, so you can defend it

    Your board will ask about some of these. Here is the one-sentence answer for each.

    Responsibility. A policy with no name attached is a wish; naming one person and one annual report is what turns it into something that actually happens.

    Multi-factor authentication. Multi-factor authentication — MFA — is the extra step after your password: a code, a tap on your phone, a key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks, and naming the specific systems matters because churches routinely turn it on for email and forget the giving platform, which is the one holding donor card details.

    Verifying money. This is the single clause most likely to save you real money, because the fraud that actually hits churches is a convincing email asking for a payment change; a thirty-second phone call to a number you already had defeats every version of it.

    Individual logins. Shared logins make it impossible to know who did what, impossible to remove one person’s access without disrupting everyone, and impossible to use MFA properly.

    When someone leaves. Old accounts are the quietest risk you have — nobody is watching them, and their passwords are often years old and reused elsewhere; a defined window turns “we should get around to that” into a date. CISA’s guidance for small organizations puts it plainly: develop procedures addressing changes in user status, and eliminate shared and unused accounts.

    Backups. A backup you have never restored is a theory, and the annual restore test is what converts it into a fact — this is also the clause that determines whether a ransomware incident is a bad week or an extinction event.

    If something looks wrong. Most losses become large because somebody waited; naming two people and requiring a phone call removes the ambiguity about who to tell and how.

    No penalty for reporting. Speed is the only thing that reliably recovers money, and speed depends entirely on whether a frightened person feels safe telling you within the hour rather than on Monday.

    Review. A date on the page is what stops this becoming the 2019 binder.

    Getting it adopted on a Tuesday

    The mistake is presenting this as a debate. It is not a debate; it is a housekeeping item that happens to be important.

    Put it on the consent agenda. Consent items are approved as a block without discussion unless a member pulls one. Circulate the page with the board packet a week ahead, with a two-sentence cover note: This replaces our existing information security policy. It is one page so that staff and volunteers will actually follow it. Most boards will pass it without comment, which is the correct outcome.

    Name the owner before the meeting, not during it. An unassigned policy will sit for a year. Ask the person first, privately, so the name in the document is already agreed.

    Set the review date as a real date. Not “annually.” A date, in the calendar, on the same board meeting each year.

    Record it in the minutes. This is the part people skip, and it is the part that matters most beyond the security question.

    Boards of nonprofit organizations carry a duty of care — the general obligation to act with the attention a reasonably prudent person would apply to the organization’s affairs. The specifics vary by state and by your governing documents, and this is not legal advice; ask your attorney what applies to you. But the general shape is consistent: what a board can demonstrate matters. A minute that reads the Board adopted the Information Security Policy, assigned responsibility to the Business Administrator, and set the annual review for the March meeting is evidence that the board considered the risk and acted. A verbal agreement that somebody should look into cybersecurity is not.

    Give a copy to every person it applies to. Staff, yes — but also the volunteer who runs the website, the volunteer counting team, the person with the Facebook password. One page can be handed to someone in a hallway. Forty-one pages cannot.

    Policy without practice is theatre

    Here is the honest limitation. Adopting this page does not mean your church is prepared. It means your church has written down what it intends to do.

    The gap between those two things is real, and it shows up under pressure. The staff member who has read clause 3 in a board packet is not the same as the staff member who has actually made the verification call once and knows it takes thirty seconds and is not awkward. The person named in clause 7 is not ready until they have said the words out loud in a room, with a scenario in front of them.

    The way to close that gap is a tabletop exercise — a short, low-stakes practice run where you talk through a realistic incident around a table and find out who would actually do what. It takes under an hour and it is the subject of its own post in this series. If you adopt the policy and never practice it, you have documentation. If you adopt it and practice it once a year, you have a response.

    Do the page first anyway. Documentation you follow beats intention you never wrote down.

    What to do this week

    Copy the page above into a document, fill in the five bracketed fields — church name, policy owner, backup contact, adoption date, review date — and email it to whoever assembles the board packet with a request to add it to the consent agenda.

    Then, separately, check one thing before the meeting: whether MFA is actually turned on for the giving platform and the church management system, not just email. If it isn’t, you will want to know that before you sign a document saying it is required.

    Thirty minutes, no budget, and your board has a defensible record by the end of the month.

    If you would like something concrete to bring to the same board meeting, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — useful as the evidence behind the annual report clause 1 asks for.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Cybersecurity and Infrastructure Security Agency, Cyber Essentials Starter Kit; Microsoft, mandatory multifactor authentication guidance; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • When the Breach Isn’t Yours

    When the Breach Isn’t Yours

    The email arrives on a Thursday morning, and the subject line is careful in a way that tells you something before you open it: An important update regarding your account.

    Your church management system — the one holding your directory, your attendance records, your kids’ check-in data, and every pledge for the last six years — has had what the letter calls a security incident. A third party accessed portions of its environment. The company is working with outside experts and law enforcement. It takes the security of your data very seriously.

    You read it twice. You didn’t click anything. Nobody on staff did anything wrong. Your passwords were fine.

    And you still have to do something about it, today, because eleven thousand names in that database belong to people who trusted your church with them.

    What the words mean, and whether the notice is real

    A breach means someone got into a system and reached information they weren’t supposed to reach. That’s all. It doesn’t necessarily mean a movie-style intrusion or a ransom note. Very often it’s a stolen password used on an ordinary login screen.

    The important part is whose system. When the breach is at a company you buy software from rather than in your own building, security people call it third-party risk — sometimes supply-chain risk. Both terms describe the same simple, uncomfortable fact: the data you’re responsible for lives on computers you don’t control, run by people you’ll never meet.

    You accepted that trade the day you stopped keeping the directory in a filing cabinet, and it was almost certainly the right trade. A cloud giving platform is more secure than a spreadsheet on the office computer, by a wide margin. But it moves the risk rather than removing it, and once every three or four years the bill for that comes due in your inbox.

    This is not hypothetical for churches. In 2020 the fundraising and donor-management company Blackbaud — which the FTC described as serving more than 45,000 organizations including nonprofits, foundations, schools, and healthcare providers — was breached by an attacker who used stolen credentials and stayed inside for three months. Tens of thousands of customer organizations were affected, and millions of individual people. Not one of them did anything to cause it.

    Which brings us to the step everybody skips. Before you act on the notice at all, confirm it’s real.

    Breach notification emails are one of the most effective phishing pretexts in existence. They arrive when you’re rattled. They carry a plausible reason to log in immediately. And they can be sent by anyone — including, routinely, by attackers who read the same news story you did and mailed a counterfeit version to every customer of the breached company they could find.

    So do not click the link in the email — not the one saying Secure your account, not the one offering credit monitoring.

    Instead, open a browser and go to the vendor the way you normally do, from your bookmark or by typing the address you already know, and log in. A real vendor in the middle of a breach response will have a notice on the dashboard, a status page, and a support article. If there’s nothing there, call the support number from your contract or a past invoice, not from the email.

    The FTC gives the same advice about any message claiming your information has been exposed: don’t use a link or a phone number from the message itself.

    What usually gets taken, and what “no financial data” actually means

    Not all exposed data is equal, and vendor notices are often written to blur that. Three broad categories:

    Contact and profile data. Names, addresses, email addresses, phone numbers, birthdays, family relationships, giving history, notes fields. This is what almost always goes, and vendors tend to describe it in the mildest available language. It is not harmless. Your member directory is a targeting list — see below.

    Passwords. The notice may say passwords were hashed. Hashing turns a password into a scrambled string that can’t be reversed directly, which is genuinely better than storing the plain text. But hashes can be attacked by guessing at industrial speed, and a short or common password will fall. Treat “hashed passwords were exposed” as “passwords were exposed, and you have some time.”

    Payment and identity data. Card numbers, bank account and routing numbers, Social Security numbers. Reputable giving platforms generally don’t hold full card numbers — they hand that to a payment processor and keep a token instead. That’s real protection, and it’s why “no card data was involved” is often true.

    Now the caution, and it comes with a documented example.

    “No financial data was affected” is not the same as “nothing was affected.” It is a statement about one category, made early, on incomplete information — and sometimes it is simply wrong.

    Blackbaud told customers in July 2020 that the attacker “did not access credit card information, bank account information, or social security numbers.” According to the FTC, the attacker had in fact taken bank account numbers and Social Security numbers. The SEC, in a separate action, found the company’s own staff learned this within days and that senior management responsible for public disclosures wasn’t told. Customers weren’t corrected until October — three months in which affected people didn’t know they had reason to watch their credit.

    The lesson isn’t that vendors lie. It’s that early breach statements are provisional. Respond to what a breach could plausibly have exposed, not to the most reassuring sentence in the notice, and read the follow-up letters instead of filing them.

    The first forty-eight hours

    Once you’ve confirmed the notice is genuine, this is the whole list.

    Change the password on that service, and stop reusing it. If the same password protects your email, your bank, or your giving platform, change it everywhere it was used. Reuse is what turns one company’s breach into your problem: attackers take the leaked list and try those pairs against every major service. That technique has a name — credential stuffing — and it only works on reused passwords.

    Turn on multi-factor authentication. This is the second step after your password: a code, a tap on your phone, a security key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Turn it on for the breached service and, while you’re thinking about it, for staff email — that’s the account that unlocks everything else.

    Check for things that shouldn’t be there. In the affected system and in your email: mail rules or forwarding you didn’t create, connected or authorized apps you don’t recognize, user accounts belonging to people who left, and any API keys or integrations. Attackers who get in leave doors open behind them, and this is the step most organizations skip after resetting a password.

    Look at who still has access. A breach is a good excuse to do the review you’ve been meaning to do. Remove the volunteer from 2019. Downgrade the three people with full administrator rights who don’t need them.

    Write down what you did and when. A dated page in a notebook. If this becomes a conversation with your insurer, your board, or a lawyer, “we don’t remember exactly” is a bad answer and the notebook is a good one.

    The second wave is aimed at your people

    Here’s what gets underestimated. The most damaging consequence of a member-data breach usually isn’t the breach. It’s the phishing that comes six weeks later, built out of the details.

    Someone now knows that Helen Ortiz gives $150 on the fifteenth of the month by automatic transfer, attends the Tuesday women’s study, and has a granddaughter named Kayla. An email that uses those specifics doesn’t read like a scam. It reads like church.

    So tell your congregation something concrete, and do it before the calls start:

    Our church management provider had a security incident. Some of your contact and giving information may have been included. Because of that, expect more convincing-looking messages over the next few months. Our church will never email or text you asking for gift cards, a wire transfer, or your login details, and we will never change our giving instructions by email. If anything claiming to be from us asks for money in a new way, call the office at the number you’ve always used.

    That paragraph, in the newsletter and said out loud on a Sunday, prevents more harm than anything else on this page.

    What to ask the vendor, in writing

    Email support and keep the thread. You’re entitled to answers, and the written record matters later.

    • What specific categories of data about our organization and our members were involved?
    • Were passwords included, and were they hashed?
    • When did this happen, when was it discovered, and when were we told?
    • What has been fixed, and how do you know the attacker no longer has access?
    • Are you notifying affected individuals directly, or is that our responsibility?
    • Will you provide written notice we can share with our board and our insurer?

    That last one is not a formality. Your board will ask, and so may your insurance carrier.

    And two more for the next vendor, asked before you sign:

    “Do you support multi-factor authentication, and can we require it for every user?” Supporting it isn’t enough — you want to enforce it, including for volunteers.

    “If you have a security incident, what will you tell us, and how fast?” You’re listening for a specific commitment rather than reassurance. A vendor who has thought about this has an answer ready.

    Your own duty to notify

    This part needs care, and it needs a professional.

    Every state, plus the District of Columbia, Guam, Puerto Rico, and the Virgin Islands, has a law requiring notification when personal information is exposed. Those laws differ substantially — in what counts as covered information, in deadlines, in whether a state agency or attorney general must be told, and in what the notice has to say. Some reach nonprofits squarely; some don’t. And because your members may live in several states, more than one law can apply to a single incident.

    The general shape is this: a breach at your vendor may still create a notification obligation for you, because in most of these laws the duty follows whoever owns the relationship with the individual. The vendor may handle it. It may not. “They said they’d take care of it” is not a legal analysis.

    So do two things. Get the vendor’s position in writing, and ask a lawyer licensed in your state — one hour of somebody’s time, early. Your denomination, your insurance carrier, or your board may already have someone. This is not a place to guess, and it’s not something this article can decide for you.

    What to do this week

    Pick your two most sensitive systems — almost certainly your church management software and your giving platform. Log in to each, turn on multi-factor authentication, and look at the user list. Remove anyone who no longer serves, and reduce anyone with administrator rights who doesn’t need them.

    Then write down, on the same page as your other vendors, who to call at each company if something goes wrong.

    Twenty minutes per system, and you’ll have done more than most organizations do after an actual breach.

    MissionDefend’s free assessment covers exactly this ground — who has access to what, which accounts have a second factor, and how member data is handled — in plain English, and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, FTC says Blackbaud’s lax security allowed hacker to steal sensitive data; U.S. Securities and Exchange Commission, SEC Charges Software Company Blackbaud Inc. for Misleading Disclosures About Ransomware Attack; Federal Trade Commission, Data Breach Response: A Guide for Business; Federal Trade Commission, Did you get an email saying your personal info is for sale on the dark web?; Microsoft, mandatory multifactor authentication guidance.

  • The Blackmail Email Every Pastor Eventually Gets

    The Blackmail Email Every Pastor Eventually Gets

    It arrives at 11:40 on a Tuesday night, which is not an accident.

    The subject line is your own old password. Not a password you use now — one you recognize, from years ago, from an account you’d half forgotten. Seeing it sitting there in a subject line does something physical.

    The message says the sender has had access to your devices for months. It says a program on your computer turned on your camera and recorded you. It says there is a list of your contacts — your congregation, your board, your family — and that everything will go to all of them unless a payment in cryptocurrency arrives within 48 hours.

    If you are a pastor, an executive director, or a board chair, there is a good chance you have already received one of these, or will. And there is a very good chance you told no one.

    This article exists mostly for that second part.

    What the message actually is

    These emails are sent by the million. They are not written for you. Nobody selected you, studied you, or sat outside your house. A list of email addresses was purchased, a template was filled in automatically, and the send button was pressed on all of it at once.

    A typical one reads something like this:

    I know [password] is your password. I placed malware on an adult site you visited and it recorded you through your camera. I also copied your contact list. You have 48 hours to send $1,900 in Bitcoin to the address below. If you pay, I delete everything. If you tell anyone, I send it immediately.

    The FBI has been warning about this family of scam since at least 2016, when it published an alert on extortion emails tied to high-profile data breaches. A later alert describes the same tactic directly — messages claiming “I have a recorded video of you,” made more convincing by including “the recipient’s user name or password” taken from a breach.

    The New York State Police, warning residents about the same automated campaigns, stated the bottom line without hedging: despite these claims, the scammer does not have access to the victim’s device or personal information.

    Where the password came from

    This is the detail that makes the email feel real, and it has a boring explanation.

    A data breach is what happens when a company that stored your information gets broken into and that information is taken. Not your computer — theirs. A retailer, a forum, a fitness app, a hotel chain, a professional association, a church management platform. If you made an account there years ago, your email address and password were sitting in their database, and when that database was stolen, yours went with it.

    Those stolen databases get combined, resold, and eventually circulated freely. Millions of email-and-password pairs, sitting in files anyone can obtain.

    So the scammer’s software takes a line from one of those files, drops the password into a template next to the matching email address, and sends. That’s it. The password in your subject line is evidence of one thing only: that a company you once did business with was breached, probably a long time ago, possibly before you were in your current role.

    It is not evidence of a camera, or malware, or anyone watching anything.

    Some versions include your home address instead, or as well. Same explanation — addresses are in those same breached records, and in a hundred commercial marketing databases besides.

    The version with a photo of your house

    A newer variant, which the New York State Police specifically flagged, includes a photo of the recipient’s home.

    It is startling by design. It is also nothing more than an address run through publicly available street-level map imagery — the same pictures anyone can pull up of any address in the country, automatically, at scale. The photo proves the sender has your address. Your address is in the breached data. The chain ends there.

    Knowing that in advance takes most of the force out of it. That is the entire reason this section exists.

    What to actually do, in order

    Do not reply. Not to argue, not to deny, not to ask what they have. Any response tells an automated system that a live human read the message, and moves your address onto a much more valuable list.

    Do not pay, and do not negotiate. The FBI’s guidance on these schemes is explicit: do not communicate with the perpetrators, and do not pay the ransom, because the funds go on to finance further criminal activity. Payment also marks you as someone who pays, which is followed by another demand.

    Check the password. Go to haveibeenpwned.com — a free, long-established service that lets you enter an email address and see which known breaches it has appeared in. It will usually name the company and the year, which turns an unnerving mystery into a mundane fact you can look at.

    Change that password anywhere it is still in use. This is the one genuine action item in the whole episode. If the password in that email is still protecting your church email, your bank, your donor database, or anything else, change it today. Different password for every account — which in practice means a password manager, because nobody can hold forty of them in their head.

    Turn on multi-factor authentication on your email and anything financial. That’s the extra code or phone tap after the password. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. It means a stolen password on its own is no longer enough to get into anything, which is exactly the situation you want to be in the next time a database somewhere is breached — and there will be a next time.

    Report it. File at ic3.gov. The FBI asks that you include the email with its header information and the cryptocurrency address, and use the keyword “Extortion E-mail Scheme.” Your report takes five minutes and joins thousands of others that let investigators trace where the payments go.

    Then delete it and block the sender.

    The part that matters most: tell someone

    Here is the thing the scam is actually built on. Not malware. Not surveillance. The fear of being seen.

    The message is engineered around a specific instruction — don’t tell anyone — because isolation is the mechanism. A person who forwards the email to a colleague within ten minutes almost never pays. A person who sits with it alone at midnight sometimes does.

    For church and nonprofit leaders this pressure lands harder than it does on most people, and it’s worth saying why. Your role is bound up with your reputation in a way that an accountant’s isn’t. You have a congregation, a board, a family, and a sense that the position requires you to be beyond question. That’s precisely the leverage the sender is counting on — and they’re counting on it without knowing a single thing about you.

    So say it plainly, in a staff meeting or an elders’ meeting, before anyone receives one:

    If you get one of these, forward it to me or to [name] the same day. Nobody who receives one of these has done anything wrong. Everyone gets them.

    Say the last part out loud, because it is true and because the person who eventually needs it will not be in a state to work it out for themselves. Receiving a threatening email is not a moral event. It means an address of yours is on a list, along with tens of millions of others.

    If you lead an organization, receiving one yourself is a gift of a teaching moment. Mentioning it — briefly, matter-of-factly, without drama — at the next staff meeting does more to protect your people than any policy document. It tells them this happens to leaders too, and that the response here is a shrug and a report, not shame.

    If a threat is ever genuinely credible

    Almost all of these are bluffs. Not all threats are.

    If someone contacts you with something specific and real — an actual image, an actual private message, knowledge that could only come from an actual relationship — that is a different situation, and it is not one to handle alone or by paying.

    It is a matter for law enforcement, and for one trusted colleague or board member you tell immediately. Contact your local FBI field office or file at ic3.gov, and preserve everything: the messages, the account names, the timestamps. Do not delete, and do not pay. Paying an extortionist who genuinely holds something has never once ended the demands.

    And if the person being threatened is a minor, or if a minor is involved in any way, that goes to law enforcement immediately — not to an internal conversation first.

    The instinct in all of these cases is silence, and silence is the one thing that reliably makes it worse. Whatever the circumstances, a leader facing this should have at least one other person in the room.

    What to do this week

    Take the ten minutes: put your work email address into haveibeenpwned.com, see which breaches it turns up, and change any password from that list still in use. While you’re there, turn on multi-factor authentication for your email account if it isn’t already on.

    Then, at your next staff or board meeting, spend sixty seconds saying the sentence out loud — if you ever get a threatening email demanding payment, forward it to me the same day; everybody gets these and nobody is in trouble. That sentence is the whole defense, and it has to be said before it is needed.

    MissionDefend’s free assessment walks through the basics in plain English — how your organization handles email, donations, member data, and accounts — and hands back a baseline score with a ranked list of what to fix first. Password reuse and missing multi-factor authentication are usually near the top of that list, and they are usually the cheapest things on it to fix.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Extortion E-mail Schemes Tied to Recent High-Profile Data Breaches; FBI Internet Crime Complaint Center, Online Extortion Scams Increasing During The Covid-19 Crisis; New York State Police, New York State Police warns of nationwide automated sextortion scams; Microsoft, mandatory multifactor authentication guidance.