Church Defense · General guidance for leadership discussion
Know What Is Actually Covered
Ask which systems and data are included, how often copies are made, who receives failures, and who can access the backups. A subscription invoice alone does not answer those questions.
Clarify whether a cloud application’s built-in features meet the church’s recovery needs. Do not assume every service keeps every version indefinitely.
Start with a Safe Sample
With your technical provider, choose an approved, non-sensitive sample and restore it to an isolated location. Never overwrite production data to run a test.
Record what was restored, how long it took, what permissions were needed, and which steps did not work as expected. Dispose of the test copy appropriately.
Plan for the People as Well as the Files
A recovery plan should identify who decides, who has the needed access, and how people communicate if church email is unavailable.
A successful sample restore demonstrates that sample’s result. It does not prove every system can recover within the same time.
Further reading: NIST small business cybersecurity guide.
Apply these questions with the people responsible for your systems. An assessment can help turn them into a prioritized plan for your church.