Checklist

Church Cybersecurity Checklist: 15 Things Every Ministry Should Fix

Use this practical 15-point church cybersecurity checklist to reduce phishing, account takeover, data loss, finance fraud, unauthorized access, and technology disruption.

DVDerek Voss, Security and IT··16 min read
Laptop showing a login screen on a desk in a dim church office

Churches do not usually think of themselves as attractive technology targets. They should.

A church may store donor information, employee files, volunteer records, children's data, background-check documents, financial records, security footage, pastoral communications, and years of email. It may also control valuable public accounts: the website, domain name, YouTube channel, Facebook page, online giving platform, cloud storage, and bank access.

The point is not to make ministry leaders paranoid. It is to recognize that digital ministry creates digital responsibilities. Cybersecurity is now part of protecting people, stewardship, continuity, and trust.

Here are 15 practical places to start.

Two of these fifteen come down to logins, which is the case we make in password manager, not a shared spreadsheet.

1. Use Multi-Factor Authentication

If an important service offers multi-factor authentication, turn it on. A password should not be the only barrier protecting your church's email, banking, giving, website, domain registration, cloud storage, social media, or church management system.

Prioritize administrator accounts first. Those accounts can often reset other users, change billing, export data, or modify security settings. Protecting them gives you disproportionate value for a relatively small amount of effort.

Where possible, use authenticator apps, passkeys, or hardware security keys rather than relying exclusively on SMS. The exact method matters less than moving beyond password-only access on critical systems.

2. Stop Sharing One Password

A single church login known by the pastor, office manager, media director, former intern, and six volunteers is convenient until someone leaves or the password leaks.

Use individual accounts whenever the platform allows them. Assign permissions based on what a person actually needs. When responsibilities change, update access. When someone leaves, remove it.

This is not about distrusting volunteers. It is about accountability. Individual accounts let you know who has access and often create an audit trail when something changes.

3. Use a Password Manager

Do not solve shared-password chaos with a spreadsheet, shared note, or document everyone can open. A proper password manager is the better pattern for storing and sharing credentials that truly must be shared.

Rather than repeat that topic here, see Your Church Needs a Password Manager, Not a Shared Spreadsheet for the full setup and volunteer-access guidance.

4. Protect the Domain Registrar

The domain name behind your church website and email may be one of the most overlooked digital assets you own. If the registrar account is compromised, an attacker may be able to redirect the website, interfere with email, change DNS records, or make recovery difficult.

Confirm that the church controls the registrar account. Turn on multi-factor authentication. Verify the recovery email and phone number. Confirm automatic renewal and the payment method. Document which leaders have legitimate access.

Do not discover during an emergency that the domain is registered to a volunteer who moved away six years ago.

5. Back Up What Matters

Ask two uncomfortable questions: If this computer disappeared tonight, what would we lose? If our main cloud account became unavailable, what would we lose?

Backups protect against hardware failure, accidental deletion, account compromise, ransomware, and simple human error. Critical information should not exist in only one place.

For local files and large media archives, external drives or network storage may be part of the plan. Cloud services may provide another layer. What matters is having a documented, tested recovery path rather than assuming "it is in the cloud" means it can never be lost.

Shop external backup drives on Amazon: https://www.amazon.com/s?k=external+hard+drive+backup&tag=denniscampb0b-20

Periodically restore a sample file. A backup you have never tested is a theory.

6. Update Church Computers and Devices

Churches are exceptionally good at squeezing another year out of old equipment. Sometimes that is wise stewardship. Sometimes it creates avoidable security risk.

Keep operating systems, browsers, office software, plugins, and security tools updated. Replace devices that can no longer receive appropriate security updates, especially when they handle finance, HR, donor, or administrator data.

Do not forget devices that are easy to ignore: presentation computers, check-in tablets, network-attached storage, smart TVs, control PCs, and office printers with administrative interfaces.

7. Separate Guest Wi-Fi From Sensitive Systems

Congregants and visitors need internet access. They do not need to sit on the same logical network as staff computers, finance systems, children's check-in, cameras, or production infrastructure.

Create appropriate network separation and review which devices can communicate with one another. This is especially important in larger facilities where security cameras, access control, streaming, guest devices, and administrative systems all share the same physical network infrastructure.

For a deeper walkthrough of network separation, read Your Church Wi-Fi Is a Safeguarding Issue.

8. Secure Children's Ministry Systems

Children's check-in systems can contain names, relationships, contact information, allergy notes, pickup authorization, and other sensitive family data. Treat access accordingly.

Use individual credentials. Limit administrative permissions. Remove access when volunteers or staff transition. Avoid exporting family data onto personal devices unless there is a legitimate, approved reason. Secure printed rosters and labels after use.

Children's ministry security is not only about who enters the hallway. It is also about who can see and export the information behind the check-in desk.

9. Add Verification to Financial Requests

Business email compromise is dangerous because the fraudulent message can look ordinary. Someone impersonating the senior pastor, executive pastor, vendor, or employee may ask finance staff to send money, change bank details, purchase gift cards, or update direct-deposit information.

Create a rule that unusual financial requests require verification through a second channel. If an email asks to change vendor banking details, call a known number. If a leader requests an unexpected wire, verify it verbally according to policy.

Technology controls help, but strong financial processes make fraud harder even when a message looks convincing.

10. Train Staff and Volunteers to Recognize Phishing

Many attacks begin with a normal person clicking a convincing message. Training should make skepticism routine without making staff afraid to use email.

Teach people to pause when they see urgency, unexpected attachments, password-reset requests, strange invoices, payment changes, shared-document notifications, or login pages reached through email links.

Encourage reporting. An employee who thinks, "This looks weird, but I do not want to bother IT," is more dangerous than an employee who forwards suspicious messages for a second look.

11. Protect Physical Access to Technology

Cybersecurity is not purely digital. An unlocked office, network closet, production booth, or finance workstation can bypass many of your online controls.

Lock sensitive rooms where practical. Use screen locks on computers. Do not leave administrator sessions open on public or shared machines. Secure removable drives and configuration backups. Know who has building keys and access codes to technology spaces.

If someone can walk into the booth, sit at an unlocked computer, and access YouTube, email, cloud storage, and the church network, the risk is not theoretical.

12. Use Surge Protection and Battery Backup

Security includes availability. A ministry system that cannot operate because power loss corrupted storage or rebooted critical network equipment is still experiencing a technology incident.

Use appropriate surge protection, and consider UPS battery backup for routers, switches, storage systems, finance computers, and other equipment where a sudden shutdown creates operational risk.

Shop UPS battery backups on Amazon: https://www.amazon.com/s?k=UPS+battery+backup+computer+network&tag=denniscampb0b-20

Battery backup is not a substitute for a generator or disaster plan, but it can bridge short power interruptions and provide time for an orderly shutdown.

13. Know Who Owns Every Critical Account

Church technology has a recurring problem: "Kevin set that up." Kevin may have been a volunteer in 2018. The account may still use his personal email address. Nobody knows the recovery answers.

Create an ownership inventory for your domain, website hosting, social channels, Google or Microsoft administration, church management platform, giving system, cloud storage, livestream destinations, email marketing, app stores, and major software subscriptions.

For each account, record the organizational owner, technical administrator, recovery method, billing contact, and renewal date. Store this information securely.

The church should be able to regain control of its essential systems without tracking down a former volunteer on Facebook.

14. Build an Offboarding Checklist

When staff members, contractors, or high-access volunteers leave, remove or adjust their access promptly. Offboarding is not an accusation. It is basic governance.

Your checklist may include email, shared drives, church management software, accounting systems, donor platforms, social media, website administration, Wi-Fi credentials, building access, VPN access, production tools, and device return.

Also review shared credentials the departing person knew. Individual accounts reduce how often passwords need to change, but some shared systems may still require rotation.

15. Create an Incident Plan Before You Need One

What happens if the church Facebook page is hijacked Saturday night? What if the website is defaced? What if someone sends a fraudulent email from the pastor's account? What if the finance computer is infected? What if the giving platform administrator cannot log in?

Write down who makes decisions, who contacts vendors, who communicates with the congregation, where recovery codes are stored, who can access backups, and when legal counsel, insurance, law enforcement, or other professionals should be involved.

Your incident plan does not need to predict every possible attack. It needs to prevent the first two hours of an incident from becoming improvisational chaos.

Turn the Checklist Into an Annual Audit

Cybersecurity weakens quietly. New accounts are created. Old employees remain in systems. Volunteers change roles. Credit cards expire. Recovery phone numbers become outdated. Devices age. Someone creates a new social account and forgets to document it.

Choose a month each year and review:

  • Administrator and user accounts
  • Multi-factor authentication coverage
  • Critical account ownership and recovery details
  • Backups and restore tests
  • Former staff and volunteer access
  • Software and operating-system updates
  • Network and guest access
  • Domain registration and renewal
  • Finance verification procedures
  • Incident-response contacts and documentation

A yearly review will not make a church invulnerable. Nothing will. It will make the organization less dependent on luck.

Cybersecurity Is Stewardship

Churches already protect physical assets. We lock doors, insure buildings, count offerings carefully, run background checks, and create safety procedures because responsible ministry anticipates preventable risk.

Digital systems deserve the same maturity. Your website, member information, financial accounts, children's data, communications platforms, and staff devices are now part of the infrastructure through which ministry happens.

The goal is not fear. The goal is resilience: fewer easy openings, faster recovery, clearer accountability, and better protection for the people who trusted the church with their information.

Start with the fifteen items above. Fix the obvious gaps. Document what you change. Then repeat the process next year.

Affiliate disclosure: Church Tech Magazine may earn a commission from qualifying Amazon purchases made through links in this article.

Keep reading from Church Tech Mag

Gear in this article

As an Amazon Associate, Church Tech Mag earns from qualifying purchases. The price you pay does not change.

DV
Derek Voss

Security and IT. Covers cybersecurity, Wi-Fi, access control, backups and safeguarding.

Keep reading

More in Security & IT

All Security & IT →
Every Monday

One fix, one tool, one deal.

A five-minute email for the person who runs church tech. Free, and easy to unsubscribe.

We only use your email to send the newsletter.