01Recognize the Offensive Playbook
Spear phishing, pastor impersonation, urgent gift-card requests, QR-code lures, fake shared documents, voice cloning, and suspicious sign-in or app approvals. Staff learn the attacker’s objective and the decision that interrupts the attempt.
02Build Everyday Defensive Habits
Use password managers and approved MFA, protect account recovery, verify unusual requests, handle unexpected approvals, and report a suspicious message quickly. Demonstrations use fictional information and safe examples.
03Protect Giving & Financial Decisions
Finance staff and approvers rehearse bank-change callbacks, vendor verification, dual authorization, giving-link checks, and documenting exceptions—even when the request appears to come from a senior leader.
04Use AI with Clear Boundaries
Identify approved tools, understand what must stay out of prompts, review connected-app permissions, and require human approval before sending sensitive communications or changing important information.
05Handle Confidential Ministry Information
Practice safer sharing, permissions, device use, and handling of donor, personnel, children’s, and pastoral information. Make the appropriate reporting and escalation path clear for staff and volunteers.
06Rehearse an Incident Together
Walk through a fictional compromised mailbox or fraudulent payment request. Leadership practices who decides, who calls the bank or provider, who preserves evidence, and how the church communicates.