01 / Security audit & roadmap

Know Your Exposure. Lead with Evidence.

A structured cybersecurity audit of your church’s people, processes, and technology. We identify observed weaknesses, explain their ministry impact, and build a practical plan to address them.

Best fit

Churches that need a clear baseline, an independent review, or priorities for their next security investment.

How it is delivered

Remote evidence review, an on-site assessment, or a coordinated multicampus engagement.

The outcome

A leadership scorecard, prioritized findings, and an actionable 30/60/90-day roadmap.

The scope of the review

Examine the Places
Where Ministry and Risk Meet.

Within your selected package, we examine the agreed systems and available evidence across these areas. Unverified controls are marked as unknown, with the next evidence needed.

01

Identity & Privileged Access

Microsoft 365 or Google Workspace accounts; MFA methods and coverage; administrative roles; account recovery; external guests; joiner/leaver processes; and third-party app permissions. Where available, review sign-in policies and relevant audit evidence.

02

Email & Domain Protection

SPF, DKIM, and DMARC configuration; authorized email senders; forwarding rules; delegation; suspicious-message reporting; and administrator recovery. Identify where spoofing protection or risky mailbox settings need attention.

03

Computers & Mobile Devices

An agreed sample of managed devices, patch status, endpoint protection, disk encryption, screen locks, local administrator access, and lost-device procedures. Document unsupported systems and ownership gaps.

04

Network, Wi-Fi & Ministry Technology

Firewall and remote-access settings; separation of guest, staff, children’s check-in, production, cameras, and other connected systems where applicable. Review management access and maintenance responsibility.

05

Giving, Payroll & Payment Workflows

How bank-detail changes, urgent requests, reimbursements, vendor payments, and giving-platform administration are verified and approved. Look for single-person dependencies and opportunities for impersonation fraud.

06

Sensitive Information & Sharing

Permissions and sharing rules around donor, employee, children’s, and pastoral information in the agreed systems. Examine access and handling practices using redacted evidence wherever possible.

07

Website, Social Accounts & Vendors

Ownership, administrator access, account recovery, hosting responsibility, update processes, and third-party access for selected ministry platforms. Review church-controlled settings without testing a vendor’s infrastructure.

08

Backup & Operational Recovery

Backup coverage, separation of administrative access, retention, failure reporting, and restore evidence. Define recovery priorities for giving, communications, check-in, and other essential ministry functions.

09

Staff Readiness & AI Use

Phishing reporting, identity verification, finance safeguards, and guidance on approved AI tools. Review which information staff may share with AI services and who can authorize connected apps or automated actions.

10

Governance & Incident Decisions

Named control owners, escalation contacts, leadership decision rights, vendor responsibilities, and existing incident procedures. Organize findings using NIST CSF 2.0 functions, with scope and evidence limits made clear.

Three assessment levels

Choose the Depth
Your Church Needs.

Scope is measured by systems, accounts, and complexity. Every level produces a leadership readout and a prioritized plan.

Essentials

A clear starting point for smaller churches.

$2,950
Starting price · one-time assessment
  • Remote configuration & process review
  • Up to 15 people accounts / 20 devices
  • One campus and one email environment
  • Leadership report & prioritized action plan
Discuss This Assessment

Multicampus

A coordinated plan for a more complex ministry.

$9,500
Starting price · one-time assessment
  • Multiple locations and environments
  • Scope tailored to your ministry
  • Coordinated leadership & technical reports
  • A roadmap with clear responsibilities
Discuss This Assessment

Every assessment includes a leadership readout and one verification of priority fixes submitted within 60 days. Final scope is confirmed before you commit. Travel, hardware, subscriptions and applicable taxes are additional. Repairs are optional and priced separately.

Included scopeEssentialsComprehensiveMulticampus
PurposeEstablish a focused baselineExamine a broader environment and validate selected controlsCoordinate security across locations and leadership teams
DeliveryRemote evidence and configuration reviewRemote preparation + one on-site labor dayCustom engagement plan
Campuses / email environments1 / 11 / 1Agreed in proposal
Staff & privileged volunteer accountsUp to 15Up to 40Agreed in proposal
Managed endpointsUp to 20Up to 60Agreed in proposal
Firewall / wireless access points1 / up to 41 / up to 10Agreed in proposal
Domains / critical applications1 / up to 52 / up to 8Agreed in proposal
Approved vulnerability checksNot includedSelected church-owned assetsAgreed in proposal
Backup validationEvidence reviewApproved sample restoreAgreed in proposal
Incident exercise / staff briefingRecommendationsLeadership tabletop + short staff briefingAgreed in proposal
Leadership report & roadmapIncludedIncluded, with technical appendixIncluded, with coordinated technical appendix
Priority-fix verificationOne pass within 60 daysOne pass within 60 daysOne pass within 60 days

One email environment means one Microsoft 365 or Google Workspace tenant. Schools, extra tenants, server infrastructure, and complex access arrangements may require additional scope. The Comprehensive briefing is an introduction; a full on-site staff training engagement is separate.

What you receive

A Decision Package.
A Working Roadmap.

  • Executive summary explaining the most important ministry risks and decisions.
  • Findings register with severity, affected systems, supporting evidence, and assessment limits.
  • Asset and ownership summary for the agreed systems.
  • A 30/60/90-day plan identifying responsible owners and recommended actions.
  • Technical appendix for Comprehensive and Multicampus assessments.
  • Leadership readout, optional implementation proposal, and one evidence-based check of priority fixes submitted within 60 days.
See an Illustrative Report
How the engagement works
01

Scope & Prepare

Confirm systems, contacts, evidence requests, access permissions, schedule, and operational constraints.

02

Review & Validate

Examine configuration and process evidence; perform only the checks included in the agreed scope.

03

Prioritize & Brief

Explain likelihood, ministry impact, urgency, and dependencies. Separate observations from assumptions.

04

Plan & Verify

Agree on next steps. Review submitted evidence of priority original fixes within the included window.

Build a Defense Worthy of Your Mission.

Start with a clear view of your risks, a practical plan, and the right preparation for your people.

Start a Conversation