Why a good password is good stewarding

Tristram Ridley-Jones  |  Features  |  loving your digital neighbour
Date posted:  4 Jun 2026
Share Add       
Why a good password is good stewarding

Image: iStock

In the digital age, Christian organisations, charities, and ministries face unique challenges in protecting sensitive data from donor records, and financial information to confidential pastoral communications.

As stewards of resources and trust, securing digital assets is not just a technical necessity but a moral responsibility.

Following on from the foundational security articles shared on en's website previously (see first article here and second article here), this guide provides a complete framework for adopting password managers and Multi-Factor Authentication (MFA)—the two most crucial and accessible tools for bolstering your organisation's cyber defences.

Why this matters for your ministry

  • Stewardship: Protecting donor funds, volunteer information, and member data is a core act of responsible stewardship.
  • Trust: A data breach can severely damage the trust built with your congregation, donors, and the wider community.
  • Compliance: While often smaller, many organisations handle payment data (requiring PCI-DSS compliance) or personal data (requiring GDPR or similar compliance), making robust security mandatory.
  • Targeted attacks: Ministries are increasingly targeted by phishing and ransomware attacks, often because they are perceived as having both financial resources and generally weaker security protocols than corporate entities.

Part one: The essential role of password managers

A password manager is a secure application that stores, generates, and manages complex, unique passwords for all your online accounts. Instead of memorising dozens of passwords, your staff and volunteers only need to remember one strong master password.

Key benefits for Christian organisations

Choosing the right password manager

When evaluating options, ministries should prioritise security, ease of use, cost-effectiveness, and the ability to manage user groups.

Criteria for selection

  1. Zero-knowledge encryption: The vendor cannot access your stored passwords, only you can. This is non-negotiable.
  2. Team/business features: Look for administrative controls to manage users, enforce security policies (like mandatory MFA), and securely share vaults.
  3. Cost: Several excellent options offer generous plans for non-profits or have affordable team licenses. Prioritise security over a free, personal-use-only product.
  4. Audit logs: The ability to track who accessed or shared a credential is vital for accountability.

Implementation strategy

Phase one: Planning and policy

  1. Define the scope: Identify all staff, volunteers, and systems that will use the manager.
  2. Create a master password policy: Mandate a minimum length (e.g., 16-20 characters) and complexity for the master password (the only password users must remember).
  3. Establish sharing groups: Define secure vaults for common accounts (e.g., "Finance," "Social Media Team," "Donor Database Access").

Phase two: Rollout and training

  1. Pilot group: Start with a small, tech-savvy group to iron out any issues.
  2. Mandatory training: Provide clear instruction on:
    • How to install and set up the master password.
    • How to generate and save new passwords.
    Crucially: The absolute necessity of protecting the master password.
  3. Migration: Dedicate time for staff to move existing passwords into the secure vault. Mandate that all weak, reused passwords are changed immediately to strong, generated ones.

Phase three: Enforcement and review

  • Enforce MFA: Ensure the password manager itself requires MFA for login (see part two of this article, below).
  • Regular audits: Periodically check the password health reports offered by the manager to identify and remediate any remaining weak or reused passwords.

Part two: Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA), sometimes called Two-Factor Authentication (2FA), adds a crucial second layer of security to your accounts. Even if a cybercriminal steals a password, they cannot log in without this second piece of evidence.

The 'something you know, something you have, something you are' principle

MFA requires a user to provide two or more of the following factors:

Why MFA is non-negotiable

A recent security report found that MFA blocks 99.9% of account compromise attacks. If your ministry uses any of the following systems, MFA must be enabled:

  • Email accounts (Gmail, Outlook 365)
  • Donor management systems (e.g., Realm, Planning Center, Salesforce)
  • Cloud storage (Google Drive, Dropbox, SharePoint)
  • Financial/banking portals
  • Social media accounts

MFA implementation tiers: From good to best

Tier one: Acceptable (SMS/email codes)

  • Method: A code is sent via text message (SMS) or email.
  • Security risk: Lower. SMS can be intercepted (SIM-swapping attacks), and email codes rely on the security of the email account itself.
  • Use case: Easy to implement, suitable for volunteer accounts or low-risk systems, but should not be the default for critical staff.

Tier two: Better (authenticator apps)

  • Method: A dedicated app (like Google Authenticator, Microsoft Authenticator, or Authy) generates a rotating six-digit code (Time-Based One-Time Password - TOTP).
  • Security benefit: Codes are generated locally on a trusted device and cannot be intercepted over the network.
  • Use case: Highly recommended standard for all staff, administrators, and mission-critical accounts.

Tier three: Best (hardware security keys)

  • Method: A small physical device (e.g., YubiKey) plugged into a USB port or authenticated wirelessly. Uses modern standards like FIDO/FIDO2.
  • Security benefit: Provides the strongest protection against sophisticated phishing attacks, as the key verifies the website's genuine address before granting access.
  • Use case: Mandatory for high-risk users (Executive Leadership, Finance Directors, Primary IT Administrators).

Policy and rollout for MFA

  1. Inventory: List all software and services used by the organisation and confirm which ones support MFA (most do).
  2. Mandate: Issue a clear, non-negotiable policy that MFA must be enabled on all staff and volunteer accounts accessing ministry resources.
  3. Education: Clearly explain why MFA is necessary, focusing on preventing the loss of donor funds or sensitive member data.
  4. Standardise: Encourage the use of a cross-platform authenticator app (Tier two) as the default standard.

Part three: Integration and next steps

The true power of these tools comes when they work together.

The synergistic security loop

  • Password manager's role: Creates a strong, unique password for every account.
  • MFA's role: Protects those accounts even if the password is stolen.
  • Integration: Many password managers can store and backup the TOTP codes from authenticator apps, providing an additional layer of convenience and backup (though this practice requires extreme care to protect the master password).

Organisational security checklist:

Share
< Previous article| Features| Next article >
Read more articles on:   technology
Read more articles by Tristram Ridley-Jones >>
Comment
Are Christian charities more at risk of hacking?

Are Christian charities more at risk of hacking?

Christian churches, organisations, and charities are entrusted with managing resources – donations, grants, and assets – to fulfil their missions. …

Features
Christians, cybersecurity is important

Christians, cybersecurity is important

In our previous article, Cybersecurity: Loving your (digital) neighbour, we established that protecting the personal data of our congregation …

New here?

Register and get three free articles each month!

Register

Subscribe

Enjoy our monthly paper and full online access for just £40/year

Find out more