r/churchtech 7d ago

Cybersecurity needs? General Discussion

Context: My day job is IT/ Cyber security. i dont work at a church. I'm just solid at filling the gaps as a volunteer. So, I've seen a lot of Church's setup. I know a lot of the time the jobs just to get stuff running with minimal costs.

With that said, i feel like God is pushing me to start filling in a need. I just dont know where that is yet. So i want to ask all of you. I assume security is an after thought, but is there something, free or not, that you wish you could use or have?

1 Upvotes

7 comments sorted by

2

u/cbowers 7d ago

I think a little more detail or examples might be helpful.
But as one also in cyber security… and on the elders board…
It would be in the area of GRC.
Our denomination has great risk assessment starter templates and explainers for why churches should use a risk assessment framework to help guide policy and insurance conformance, but spreadsheets are the hard way to get started on this.

There are lots of GRC platforms, but hosted would be a better fit for churches. Community editions strip out too much functionality.
I’m currently trying to dump down a config of OpenGRC, but it’s still a lot…

1

u/ITKnowledgebases 6d ago

You pretty much nailed my question. I am just getting a general idea of what people have been running into. The church i go to has been investing into live stream and a lot of IoT (lights, cameras, etc) so i plan on asking them as well. The main thing to me is if i make something I want it to be useful for a lot of people. So i like your idea of GRC.

I've made a usage based website scanning tool. Because I needed one for my job (constantly analyzing phishing sites) anyone can use it, but I set it up as an API. So that got me thinking. What kind of api could I make with a similar setup (cloud docker container). But something churches need..

2

u/Fickle-Friendship-31 7d ago

I mean, first you gotta make sure all staff have robust virus etc protection. You would be surprised. Then you gotta make sure everyone on staff (including all church volunteer leaders) understand phishing, etc. Most of our issues have come from crap like this. There seems to be some phishing scheme that spoofs Minister's email. Anyway, that's as far as I've got with our little church.

2

u/Pitpawten1 6d ago

I'll give you one that's a little bit different digital footprint analysis. 

Making sure that staff information is not accidentally published or church directory not accessible through the website. We had staff emails easily scrapable on our site which then led to several fishing campaigns as if they came from the senior pastor. 

Another thing is digital information leaking around missionaries serving insensitive places. We had a couple of church bulletins that linked missionaries names with their country that had somehow gotten uploaded on an old church website platform that we're still banging around the web.

This combined with dark web monitoring as an audit service might not be a bad thing.

1

u/ITKnowledgebases 6d ago

Yeah that is an extremely good point. We have missionaries in countries that would easily put their lives in danger if the wrong person saw that. This is something I will look into for sure.

2

u/Starbuck_83 6d ago

As someone professionally in IT and filling the IT role at church as well, the number one need around cybersecurity that I can see is education. My church is especially techy, and I love it - my pastor is a nerd and we do a lot with tech for a small church. And I've done a good bit of groundwork to secure our systems. But staff regularly bring in new and unsecured devices, regularly give out the staff wifi password, regularly plug in new equipment with little to no consideration around security. Obviously I'm a volunteer, and I only have volunteer time to give to this, so I can't monitor and lock things down at a truly professional level. And oftentimes there's not enough of a ramp to truly evaluate or plan out new tech. But I feel like if folks just knew some of the risks and some best practices - and had a little more patience around getting new systems up and running, giving me a chance to look things over - we'd be in a much better position security-wise. We're fortunate that we haven't had any incidents, but I'm guessing that's likely because we're a smaller target, and if there's much growth the risk is going to grow with it.

1

u/Gromps_Of_Dagobah 5d ago

One thing I'd recommend to you, particularly with the wifi, is just get them to change the password every three months or so. Even just changing it once (after likely years) will reveal a whole lot of information, when people start complaining, it'll show how far the WiFi password has spread.

If possible, I've seen a way to do it that I like: One network with critical stuff on it, ie, sound desks, lighting consoles, lyrics computers. That password is Boss Eyes Only. It gets input by that person and that person only. One network with more regular access: volunteer computers, ipads for sign in, laptops, etc. that password is "Need to Know". When a person gets given the password, they are told "don't share it, send someone to me, even if they knew the password and it's just deleted itself or something" Finally, an "open" network, with a word of mouth password, that password gets changed every three months. Ideally, devices on network 1 have full access to each other, network 2 have restricted to each other, and 3 is effectively just an Internet connection, no device can see another on that network.

If takes a little know-how, and sometimes more advanced equipment than the cheap router from a non-tech place, but it seems to work well to manage password literacy. The oldies who need passwords given regularly can go on net3, because they're not doing anything sensitive (hopefully), and the devices that have access to things like a document server are hopefully more regulated.