This report shows where your organization stands today, the risks that matter most right now, and exactly what to do about them over the next 30 days. It is written to be read by people who are not cybersecurity professionals.
Your email security is genuinely good, largely because Microsoft 365 does a lot for you by default. But if someone locked up your files tomorrow, you could not confidently restore them — and no one has written down who to call. Those two gaps drive most of your score.
Categories are weighted by how much each one actually reduces risk for an organization your size — not treated as equal. The weighted contributions add up to your score of 42.
| Category | Score | Rating | Weight | Contributes |
|---|---|---|---|---|
| Identity & Access | 40% | 20% | 8.00 | |
| Backup & Recovery | 30% | 18% | 5.40 | |
| Email Security | 75% | 15% | 11.25 | |
| Endpoint Security | 65% | 12% | 7.80 | |
| Security Awareness | 25% | 12% | 3.00 | |
| Incident Response | 10% | 10% | 1.00 | |
| Network Security | 60% | 8% | 4.80 | |
| Policies & Governance | 15% | 5% | 0.75 | |
| Overall | 42 | 100% | 42.00 |
Nobody could say whether backups are tested, whether old volunteer accounts were ever closed, or who has administrator access to your giving platform. That is not a failing — it is the most useful thing this assessment found. "Don't know" almost always means no one owns that area, and unowned areas are where problems grow quietly. Each one becomes an action below.
Ranked by how much damage each could cause and how likely it is — not by how hard they are to fix.
Files are copying to a cloud drive, but no one has ever tried restoring them. An untested backup is a hope, not a plan — and the most common discovery during a ransomware incident is that the backup was silently failing for months, or that it was connected in a way that let the attacker encrypt it too.
If this goes wrong: member records, giving history and years of sermon and ministry files become unrecoverable. Recovery costs move from hours to months.
Most of your staff have MFA turned on, which is genuinely good. But two accounts with administrator rights do not — and those are exactly the accounts an attacker wants. A stolen password on a normal account is a problem; a stolen password on an admin account is access to everything.
If this goes wrong: an attacker reads and sends mail as your pastor, changes payroll or giving details, and can lock you out of your own systems.
If a compromise happened on a Sunday morning, no one knows who to call first, who can authorize shutting something down, or who tells the congregation. Decisions get made under pressure by whoever happens to be nearby — which is how small incidents become large ones.
If this goes wrong: hours lost to confusion during the window when fast action matters most, plus a real chance of missing a legal notification deadline.
There is no checklist for removing access when someone leaves, and nobody could confirm whether accounts from past volunteers were ever closed. In most organizations this size, at least a few are still open — often with access to donor or member information.
If this goes wrong: data leaves with people who no longer serve, and a dormant unused account is one of the easiest ways in.
The most common attack on churches is not technical at all. It is a message that appears to come from the pastor asking a volunteer to buy gift cards, or a fake invoice sent to your bookkeeper. Your filters catch many of these; the ones that get through are stopped only by a person who recognizes them.
If this goes wrong: a well-meaning volunteer moves money in good faith, and it is rarely recoverable.
Sequenced so the highest-impact work happens first. Nothing here requires buying software, and most of it is free.
Completing these twelve items moves this organization from 42 to an estimated 71 — from Level 2 to Level 3, Protected. Total cost: about nine hours of someone's time and no new software.
Worth saying plainly, because it is easy to read a report like this and conclude everything is broken. It isn't.
Your answers map to security controls drawn from the CIS Controls and the NIST Cybersecurity Framework. You never have to read either one — that translation is our job.
Each category is scored from 0–100% based on the controls you have in place. Categories are then weighted by how much they reduce real-world risk for an organization of your size and type, and the weighted results are added together: overall = Σ (category score × weight). Backups and identity carry the most weight because they prevent the incidents that actually shut small organizations down; written policies carry the least, because a policy nobody follows protects nothing.
A question answered "Don't know" is never scored as if you had said yes. It is counted as a gap in visibility and generates its own action, because not knowing is a finding in itself.
The assessment takes about 20 minutes and asks plain-English questions anyone on your staff can answer. "Don't know" is a perfectly good answer — it tells us something useful.
Join the launch list We'll email you once when it opens. Nothing else.