In our previous article, Cybersecurity: Loving your (digital) neighbour, we established that protecting the personal data of our congregation is a modern act of stewardship, integrity, and pastoral care. Just as Nehemiah rebuilt the walls of Jerusalem, we are called to post a guard at our digital gates.
However, a wall is only as strong as the watchman who stands upon it. The greatest risk to a church's security is often not a sophisticated external hacker, but a simple human error - a click on a malicious link. This is not a judgment on a lack of faith, but a call to practical wisdom and equipping our ministry teams with a "sound mind" (2 Timothy 1v7) to spot digital deception.
Here is a guide to cultivating a culture of cybersecurity mindfulness and training your team effectively.
1. Understanding the deception: Know the Enemy’s tactics
You cannot spot a lie if you don't know the playbook of the deceiver. Training must begin by clearly defining the most common threats that target Christian organisations.
- Phishing emails: The broad net. These are mass emails designed to look like they come from a trusted source (Google, Microsoft, a bank) to steal login details (passwords).
- Spear phishing: The focused attack. These look like they come from a known individual (the pastor, a staff member, a board member) and often contain an urgent, out-of-character request.
- The gift card scam: A prevalent and painful deception in the church world. The scammer compromises an email account and sends a message (often late on a Friday) claiming an emergency and asking for a purchase of gift cards or a wire transfer. This preys on the Christian spirit of generosity.
Training tip: Use real, anonymised examples of phishing emails your team has received (or find safe examples online) and dissect them together in a group session.
2. The training mindset: A culture of 'pause and verify'
The core of digital deception is an attempt to rush you and bypass your sensible judgment. The goal of your training should be to install a mental "deadbolt" that forces your team to pause.
- Legitimise the question: Create an environment where it is celebrated, not shameful, to ask, "Does this email look right?" Remove the fear of looking silly or incompetent. Most breaches are caused by a single person who hesitated to speak up.
- Implement a 'red flag' rule: For any request involving money, confidential data, or access changes, establish a mandatory second verification step. Never respond to an urgent request for money via email alone. The team must always verify the request with the supposed sender using a secondary method, such as a phone call or a separate instant message.
"For God has not given us a spirit of fear, but of power and of love and of a sound mind" (2 Timothy 1v7).
Our training is about enabling a sound mind, not inducing paranoia.
3. The watchman's checklist: Practical training steps
Give your team a simple, actionable checklist to run through before clicking on a link or replying to a suspicious email. See below:

4. Sound the alarm: The reporting protocol
A successful training programme includes clear instructions on what to do when deception is spotted. Your team needs to know who the digital "guard" is and the steps to sound the alarm.
- Do not click: Never click on links, download attachments, or reply to suspicious emails.
- Forward to a secure contact: Have a designated, secure email address (e.g., securityalert@yourchurch.org) or a specific staff member. The suspicious email should be forwarded as an attachment to preserve the full headers for investigation.
- Immediately change passwords: If anyone on the team believes they may have accidentally clicked a link or entered their password on a suspicious site, they must immediately inform the designated IT person and change their password (and any other passwords that are the same) as quickly as possible.
Cybersecurity is not a distraction from the Great Commission; it is the necessary framework to sustain it, ensuring the work of the Kingdom can flourish without hindrance. By equipping your saints with these practical steps, you are fulfilling the command to be faithful stewards and truly love your digital neighbour.
*Image based on Nehemiah 4v18... "From that day on, half of my men did the work, while the other half were equipped with spears, shields, bows and armour. The officers posted themselves behind all the people of Judah who were building the wall. Those who carried materials did their work with one hand and held a weapon in the other, and each of the builders wore his sword at his side as he worked. But the man who sounded the trumpet stayed with me" (Nehemiah 4v16-18).
Are Christian charities more at risk of hacking?
Christian churches, organisations, and charities are entrusted with managing resources – donations, grants, and assets – to fulfil their missions. …