Are Christian charities more at risk of hacking?

Tristram Ridley-Jones  |  Comment  |  loving your digital neighbour
Date posted:  9 Jun 2026
Share Add       
Are Christian charities more at risk of hacking?

Photo by Towfiqu barbhuiya on Unsplash

Christian churches, organisations, and charities are entrusted with managing resources – donations, grants, and assets – to fulfil their missions. This stewardship now extends to the digital realm.

As financial operations increasingly rely on technology, cybersecurity is no longer only an IT issue but a fundamental aspect of financial integrity and missional continuity. For finance teams and treasurers, safeguarding digital assets is as crucial as maintaining physical security.

This article outlines the specific cyber risks facing faith-based and non-profit entities and provides practical steps for enhancing digital defence.

The unique risk profile of faith-based and non-profit entities

While all organisations face cyber threats, Christian non-profits and charities present a distinctive target profile:

  • Reliance on donor trust: A significant data breach, especially one affecting donation records or financial transparency, can instantly erode the trust of congregations and donors, severely impacting fundraising efforts.
  • Decentralised operations: Many churches and smaller charities rely on volunteers, part-time staff, and decentralised financial management (e.g. various committees or local groups handling specific budgets), leading to potentially inconsistent security practices and wider attack surfaces.
  • Limited IT resources: Unlike large corporations, these organisations often operate with small, non-specialised IT teams, or rely entirely on outsourced IT support or non-technical volunteers, making robust, professional-grade security challenging to implement.
  • Valuable data targets: Beyond bank account access, these organisations hold sensitive personal data (membership lists, pastoral care notes, high-net-worth donor information) which is attractive to cybercriminals for identity theft or targeted phishing campaigns.
  • Mission-driven vulnerability (spear phishing): Scammers often exploit the charitable nature and urgency of mission work (e.g. a "crisis funding request" or "urgent mission wire transfer") to trick finance staff into making fraudulent payments.

Core cybersecurity threats for finance and treasury

Finance teams and treasurers are primarily targeted because they control the organisation's liquid assets. The most common threats include:

1. Business Email Compromise (BEC) and payment fraud

This is the most financially damaging threat. A criminal infiltrates or spoofs the email account of a senior leader (e.g. the pastor, executive director, or board member) and emails the treasurer or finance clerk with an urgent request for a wire transfer to a new or "updated" vendor account.

2. Ransomware and data breach

Ransomware attacks encrypt critical financial systems (accounting software, donor databases, payroll files), halting operations. For a church or charity, this can mean an inability to process donations, pay staff, or track expenditures, potentially crippling the organisation for weeks.

3. Weak access controls

The use of shared passwords, default vendor passwords (for cloud platforms or accounting software), or former staff/volunteer accounts that remain active provide easy entry points for attackers.

Essential cybersecurity pillars for finance teams

Treasurers and finance personnel must champion these four security pillars:

I. Secure payment protocols (the 'call back' rule)

This is the single most important defence against BEC (Business Email Compromise).

  1. Mandatory verbal verification: Any new vendor payment set-up, change to existing bank details, or urgent wire transfer must be verbally verified by calling the requestor (or the vendor) using a known, pre-existing phone number, not a number provided in the suspicious email.
  2. Dual authorisation: Require two authorised signers or finance members to approve all transfers above a low threshold (e.g. £1,000).
  3. Segregation of duties: The person who initiates a payment request should not be the same person who authorises the payment, nor the person who reconciles the bank statement. This internal control is vital.

II. Technology fundamentals

Ensure the organisation implements these non-negotiable technical controls:

  • Multi-Factor Authentication (MFA): Implement MFA on all cloud services, especially banking portals, accounting software (e.g. QuickBooks Online), email (Google Workspace, Microsoft 365), and donor management systems. MFA is the strongest defence against password theft.
  • Strong password policy: Enforce the use of unique, complex passwords, ideally managed through a reputable password manager. Discourage the sharing of passwords among staff or volunteers.
  • Regular backups: Implement automated, regular, and off-site or cloud-based back-ups of all critical financial data. Test the restoration process periodically. A robust back-up is the only guaranteed recovery from a ransomware attack.

III. Data management and retention

Finance teams handle PII (Personally Identifiable Information) and PCI data (Payment Card Industry data).

  • Data minimisation: Only retain financial records and personal data for as long as legally or operationally necessary. Deleting old, unnecessary data reduces the scope of a potential breach.
  • Secure storage: Ensure all sensitive financial documents, digital or physical, are encrypted when stored and accessed only via secure, dedicated workstations.
  • PCI compliance: If the organisation accepts credit card donations (even through third-party services), the finance team must understand and adhere to basic PCI data handling requirements (e.g. never storing full credit card numbers).

IV. Training and awareness

Security is only as strong as its least-trained member.

  • Phishing simulation: Conduct regular, realistic phishing exercises tailored to the mission context (e.g. emails about "urgent mission trip funding" or "board meeting changes").
  • Role-specific training: Finance staff should receive specialised training focused on identifying suspicious payment requests, bank security features, and secure use of financial applications.
  • Reporting culture: Establish a clear, non-punitive process for staff and volunteers to immediately report suspicious emails, calls, or security anomalies without fear of reprisal.

For Christian organisations, financial stewardship is a ministry. In the digital age, protecting the resources entrusted to them requires proactive cybersecurity.

By prioritising strong payment protocols, implementing fundamental technical controls like MFA and back-ups, and fostering a culture of security awareness, treasurers and finance teams can ensure that their digital assets remain secure, allowing the organisation to focus its resources entirely on serving its mission.

Share
< Previous article| Comment| Next article >
Read more articles on:   ministry  /  mission  /  money  /  technology
Read more articles by Tristram Ridley-Jones >>
Features
Why a good password is good stewarding

Why a good password is good stewarding

In the digital age, Christian organisations, charities, and ministries face unique challenges in protecting sensitive data from donor records, and …

Features
Christians, cybersecurity is important

Christians, cybersecurity is important

In our previous article, Cybersecurity: Loving your (digital) neighbour, we established that protecting the personal data of our congregation …

About en

Our vision, values and history

Read more

Subscribe

Enjoy our monthly paper and full online access for just £40/year

Find out more