02 / Custom security implementation

Turn the Plan into a Stronger Defense.

Get hands-on help choosing and implementing the right solutions. We connect each technical change to a documented risk, an operational need, and a clear way to verify completion.

Best fit

Churches with known gaps, an assessment roadmap, or an IT provider that needs additional security expertise.

How it is delivered

A fixed-scope project with an approved change plan, costs, work windows, and acceptance criteria.

The outcome

Configured controls, verification evidence, updated documentation, and an operational handoff.

Practical help from decision to deployment

Select Carefully.
Implement Deliberately.
Verify the Result.

We begin with what you already own. Recommendations account for supported features, licensing, staff capacity, and the cost of maintaining each solution.

01

Design

Compare the options, agree on requirements, and define the intended result.

02

Implement

Pilot the change, communicate with affected users, and roll out in an agreed work window.

03

Verify

Check the configured control and confirm essential ministry workflows still operate.

04

Handoff

Document settings, exceptions, ownership, and the steps your provider needs to maintain it.

Workstream 01

Identity & Email Defense

Make account access harder to steal and easier to govern.

$1,500$3,000

Planning range for standard work.
Expanded work receives a custom proposal.

Scope This Project

What the work can include

  • Plan an MFA or passkey rollout for supported accounts, with recovery and exception handling.
  • Reduce administrator privileges; review external guests, app consent, forwarding, and legacy access.
  • Configure and validate agreed SPF, DKIM, and DMARC changes, accounting for church email senders.
Completion evidence

An account-control checklist, configuration record, tested sign-in and recovery paths, and an administrator handoff.

Workstream 02

Network & Device Protection

Limit the reach of a compromised account, device, or guest connection.

$2,000$5,000

Planning range for standard work.
Expanded work receives a custom proposal.

Scope This Project

What the work can include

  • Design agreed separation for staff, guests, check-in, production, cameras, and connected devices.
  • Harden firewall and remote-management access; document ownership and maintenance.
  • Scope endpoint protection, encryption, supported software, and patch responsibilities.
Completion evidence

An updated network/access map, configuration records, and approved connectivity checks showing critical ministry services still work.

Workstream 03

Backup & Recovery Readiness

Know what can be recovered, by whom, and in what order.

$1,500$3,500

Planning range for standard work.
Expanded work receives a custom proposal.

Scope This Project

What the work can include

  • Map important systems and recovery priorities; identify gaps in existing backup coverage.
  • Configure the agreed retention and protected backup access; assign failure-reporting responsibility.
  • Restore an approved sample to a safe location and document the result.
Completion evidence

A backup coverage matrix, sample-restore record, recovery runbook, and named owners.

Workstream 04

Sensitive Information & AI Safeguards

Keep access proportionate to each person’s ministry responsibilities.

$1,000$2,500

Planning range for standard work.
Expanded work receives a custom proposal.

Scope This Project

What the work can include

  • Review and correct agreed folder, group, application, and external-sharing permissions.
  • Define handling rules for pastoral, donor, children’s, personnel, and financial information.
  • Document approved AI use, restricted data, connected-app permissions, and human approval requirements.
Completion evidence

A permissions record, approved exceptions, staff guidance, and a handoff for future access changes.

Workstream 05

Incident & Financial-Fraud Readiness

Give leaders a practiced response before a difficult decision becomes urgent.

$1,500$2,500

Planning range for standard work.
Expanded work receives a custom proposal.

Scope This Project

What the work can include

  • Define escalation contacts, decision owners, communications channels, and first-response priorities.
  • Document callback and dual-approval procedures for sensitive finance changes.
  • Facilitate a scoped leadership tabletop and capture decisions, gaps, and follow-up work.
Completion evidence

An incident playbook, finance-verification checklist, exercise debrief, and accountable action register.

Work Alongside Your Existing IT Provider.

Keep the people who know your environment involved. We agree on who makes each change, who checks it, and who supports it after handoff.

Help Staff Adopt the Change.

Technical handoff covers the agreed solution. Add a dedicated staff workshop when your team needs broader practice recognizing attacks and using defensive procedures.

Explore on-Site Training

Build a Defense Worthy of Your Mission.

Start with a clear view of your risks, a practical plan, and the right preparation for your people.

Start a Conversation