Cybersecurity Best Practices for Churches: A Practical Guide
Protect church accounts, giving, member data, staff devices, websites, and ministry continuity with a realistic cybersecurity plan for small teams.
By the ChurchPress team at Amplify Digital Media
Key takeaways
- +Protect email and financial accounts first with unique passwords, multi-factor authentication, and limited administrator access.
- +Maintain tested backups and an incident plan so ministry can continue after an account compromise, device failure, or ransomware event.
- +Treat cybersecurity as ongoing stewardship with named owners, training, vendor review, and prompt removal of old access.
01
Why churches need a cybersecurity plan
Churches hold information that deserves careful stewardship: contact records, giving history, staff files, children's information, prayer requests, volunteer screening material, and account credentials. They also depend on email, websites, streaming, online giving, and cloud platforms to operate. A compromised inbox or administrator account can disrupt ministry, redirect money, expose people, and damage trust.
A church does not need a large IT department to improve its security. It needs a clear owner, a short list of critical systems, consistent access practices, and rehearsed steps for responding under pressure. CISA recommends that houses of worship assign roles, assess vulnerabilities, protect critical data, maintain backups, and plan for continuity and incident response.
02
Secure email, finance, and administrator accounts first
Email is often the key to every other account because password resets arrive there. Begin with senior leaders, finance staff, communications staff, and anyone who administers email, the website, giving, payroll, accounting, donor management, or social media. Require a unique password for every service and store passwords in an organization-approved password manager.
Turn on multi-factor authentication everywhere it is available. Prefer phishing-resistant methods such as security keys or passkeys for the most powerful accounts; authenticator apps are a useful baseline where those methods are not supported. Avoid shared administrator logins and text-message codes when a stronger option is practical.
- Give every person an individual account
- Keep the number of administrators as small as practical
- Store recovery codes in a protected church-controlled location
- Review access immediately when staff or volunteer roles change
03
Defend against phishing and payment fraud
Churches are vulnerable to messages that imitate a pastor, vendor, denominational leader, or staff member and request gift cards, credentials, bank changes, or urgent payments. Generative AI can make these messages polished and personal. Teach staff that urgency and familiarity do not prove identity.
Require an independent verification step for changes to bank details, payroll, wire instructions, or large purchases. Call a known number or confirm face to face; do not use contact information supplied in the suspicious message. Configure email protections offered by your provider and monitor the church's domain for unauthorized changes.
04
Protect devices, networks, and the church website
Keep operating systems, browsers, plugins, routers, and applications on supported versions with automatic security updates enabled. Encrypt church laptops and phones, use screen locks, and enable remote management or wiping where appropriate. Separate guest Wi-Fi from staff systems and change default router and device passwords.
For the website, use a maintained platform, HTTPS, least-privilege accounts, multi-factor authentication, and a controlled domain registrar account. The domain is a critical asset: protect it with a long unique password, strong MFA, registrar lock, accurate recovery contacts, and restricted DNS access. Remove abandoned plugins, integrations, forms, and user accounts rather than leaving them available indefinitely.
05
Collect less data and control what remains
Inventory where sensitive information lives and why the church retains it. Limit access by role, set retention periods, and securely delete records that no longer serve a legitimate ministry, legal, or financial need. Do not put counseling notes, background checks, children's records, or donor exports in general shared drives.
Review vendors that process giving, background checks, email, forms, member records, livestreams, or children's information. Understand what data they receive, who can access it, how the church retrieves it, and what happens when the relationship ends. Security claims do not replace a written agreement and sensible configuration.
06
Back up critical information and test recovery
Back up the information required to continue ministry and meet legal or financial obligations. Keep at least one protected copy that is not continuously writable from ordinary staff devices or the same administrator account. A synced folder is useful, but synchronization alone may copy deletion or ransomware damage.
Test restoration at least twice a year. Confirm that the church can recover key records, website content, financial files, and the information needed to communicate if the main systems are unavailable. Record who can authorize a restore and how credentials are accessed during an emergency.
07
Prepare an incident response plan before a crisis
Write a one-page plan listing who leads the response, how to contact vendors and insurers, how to preserve evidence, who can authorize financial decisions, and how leaders will communicate if normal email is compromised. Include lost devices, fraudulent payments, exposed data, website takeover, ransomware, and compromised social accounts.
If an incident occurs, contain the problem without destroying evidence, use a clean communication channel, contact the relevant provider and qualified professionals, and follow applicable notification and reporting requirements. Laws and contractual duties vary by location and data type, so churches should obtain legal and insurance guidance suited to their situation. This guide is operational education, not legal advice.
08
Create a sustainable security rhythm
Name one accountable leader and schedule a quarterly review of administrators, former staff access, recovery contacts, updates, backups, domains, vendors, and recent suspicious messages. Train staff and key volunteers at onboarding and refresh the training annually with examples drawn from the tools they actually use.
Measure progress with simple evidence: critical accounts protected by MFA, unused accounts removed, a successful backup restore, current vendor contacts, and an incident exercise completed. Cybersecurity is not a one-time software purchase. It is a repeatable ministry practice that protects people and keeps the church able to serve.
Put it into practice
Your action plan
- 1Protect email and financial accounts first with unique passwords, multi-factor authentication, and limited administrator access.
- 2Maintain tested backups and an incident plan so ministry can continue after an account compromise, device failure, or ransomware event.
- 3Treat cybersecurity as ongoing stewardship with named owners, training, vendor review, and prompt removal of old access.
- 4Give every person an individual account.
- 5Keep the number of administrators as small as practical.
How to know it worked
A first-time visitor can complete the page's main task on a phone without help, and the responsible owner can keep the information current.
Frequently asked questions
Quick answers
What is the most important cybersecurity step for a small church?
Protect email, financial, domain, and administrator accounts with unique passwords and strong multi-factor authentication. Then remove unnecessary access and verify that account recovery belongs to the church rather than a former staff member or vendor.
Does a church need cyber insurance?
Insurance can help transfer part of the financial risk and provide incident resources, but coverage, exclusions, and security requirements vary. Review options with a qualified broker and legal adviser; insurance does not replace access controls, backups, training, or an incident plan.
How often should churches train staff about phishing?
Provide training at onboarding and at least annually, with short reminders when new scams appear. Finance staff, senior leaders, and account administrators benefit from more frequent practice because they are common targets for impersonation and payment fraud.
Should church staff share passwords?
No. Give each person an individual account so access can be limited, audited, and removed. When a service cannot support multiple users, store the credential in an approved password manager and plan to replace that service or reduce its privileges.
Sources and further reading
Your next step
Put these ideas into a church website built around your ministry.
ChurchPress is free to build and preview. No credit card required.
Create Your Free Website