From Bytes to Brick: Church Security Lessons from the Cyber World
I recently find myself having more and more conversations with people regarding House of Worship or church security. Through these interactions I have realized that through my role in Cyber Security and my work in Church Security that I may have a unique perspective at the convergence of these skills. When my partner in Patriot Security Group and I discussed starting this venture, we were motivated by extending the impact of our knowledge beyond our local church that we met serving at. To do so, we have taken on new church locations, and he has spoke to church leaders at two conferences about the importance of church safety teams. Now, I have decided to organize and share my thoughts with the church community in hopes of assisting the house of worship community provide a peaceful, safe environment that encourages authentic worship.
Over the past 5 years, I have been able to interact and meet with many new people. As we are getting to know each other the conversation drifts to asking what we each do for a living. I usually share my day job in Cyber Security and our business of providing private armed security for churches. The reaction is usually the same. The person I am meeting either questions why churches need security or recognizes the importance of security in churches. I understand where both of these perspectives come from. Growing up, we never had police, security, or safety volunteers in the building. Each type of response comes from a place of recognizing that times have changed or becoming aware that times have changed. I understand where both perspectives come from. Traditionally churches have been places of peace, rest, and welcome. And while this is the typical state for many churches, a sense of alertness and preparedness is required.
Over the past few years most churches have looked at the best way to improve the safety and security of their worship services. Some choose to employ off-duty law enforcement or private security. Some churches have organized volunteer safety teams, and others have a collection of like minded individuals that may have organized at some level to be ready to step in addressing safety concerns. Each of these approaches has its benefits and challenges. This article is not intended to compare what the best option is for each church, but one thing is common amongst all of these approaches. The most effective approach is the one that includes planning and preparedness. If we are to be good stewards of the facilities, resources, and time of the members and guests of the congregation, then we must spend some time assessing risk, preparing, and training for the risk that all churches could face. This is complicated in extremely rural churches as well as in urban locations, where the strain on public emergency services may mean that response times to events on your campus could take longer than average to respond. One advantage I have found through my years in both plain clothes and uniformed Security in churches is that there are many individuals that appreciate a visible and prepared organization. I have had police officers tell me that they chose to attend our church with their family because of the visible and prepared Security and Safety team. These preparations are not only important to protect the persons and property of the church, but it protects the mission of the church too. The father that sits facing the door of the restaurant on Friday night with a determination and vigilance to protect his family is the same father that has his hands raised in worship on Sunday morning knowing that a group is equipped and trained to address the unexpected event.
The task of being prepared can be daunting to the Pastor, Deacon, or Church Leader that recognizes the need to prepare and equip members or vendors of the church to react to threats that they could be faced with. I recently had a Pastor ask my opinion on something, because, “I don’t see the world the way that you do.” In my day-to-day work, I am one of many leaders for a Cyber-Security Team of a Fortune 100 company. I have noticed that there are many concepts in the Cyber-Security approach that converge with the Physical Security needs of Churches. When I speak with Church leaders and Safety team members one theme is consistent. They recognize that they need training. The question is what type of training is best. I believe that training should be guided by either standards, certifications, or procedures. Physical Security has standards to refer to such as NIST SP800-53 or IEC 27001, but these are mostly focused on the features of facility design, lighting and access controls. The Cyber Security industry has documented standards, certifications, and best practices that can be used to relate to physical security and provide guidance for developing an Emergency Operations Procedure that can become the basis for training a church Security or Safety team.
The first cyber-security best practice that can apply to churches is documenting your vulnerabilities. In cyber Security, this involves taking inventory of your IT systems and looking for known risk or threat of attack for these systems. For physical security, this is best accomplished through performing a risk assessment of your facility and safety/security program. There are formal risk assessments that can be performed that look at your facility, programs, procedures implemented and controls applied. Another approach is just to brainstorm all of the Safety or Security threats that you and your team may want to consider. This conversation’s goal should just be to list everything out. Each church may have a different matrix of threats depending on location, building construction, ministry programs or other factors. Once you have all the threats documented, the challenge is how do you begin to address everything. Just like trying to eat the elephant you start one bite at a time. In Cyber Security and in Church security, each of the threats identified has an associated Risk and a Likelihood of occurrence. The risk can best be thought of as how bad of a day would it be if this event happened. The likelihood of occurrence is fairly self explanatory. When most Security teams think about risk and training the first thing I hear about is how do we want to prepare for an active shooter. I understand where these questions come from, since many churches began considering what their security plans and needs were in response to multiple church shooting events. If I were assigning a risk to an active shooting event, I would list it as high risk as the consequences of a shooting would be severe. According to the Violence Project, over the last 25 years, there have been 246 shootings involving Churches. This averages out to just under 10 church shootings a year. Contrast this with the fact that there are just under 400,000 religious congregations meeting each week and the likelihood of an active shooter on church property is around 0.0025%. In spite of this low likelihood of occurrence, many church safety teams focus a disproportionate amount of time preparing for these events. As the safety program progresses, these teams begin to evolve how they see risk. Either through direct experience or through conversations with other teams, Safety leaders begin to consider other risks such as medical events, missing children, disruptive individuals or severe weather.
The next Cyber-Security concept that can apply to Church Security is the concept of compensating controls. A compensating control could be something in place to reduce the impact of the risk or reduce the likelihood of occurrence. Choosing to have a uniformed presence visible near an entrance or lobby could reduce the likelihood of acts of disruption or violence since the threat actor would know someone is present that is equipped to respond quickly to their attempts. Utilizing Access control systems and locking interior doors could reduce the risk of a break-in, but when utilized during normal operations could reduce the risk by limiting movement through the facility or access to pastors or children’s areas for people without a purpose to access those areas. One caveat to consider is that compensating controls should support the mission of the church and not interfere with creating the environment that leads to meeting the church's goals and objectives. Having no security may lead to congregants choosing a different church where they feel safer, but the inverse is also true. You may alienate just as many congregants if you had stadium style bag checks and metal detectors at every entrance.
Lastly, the development of an Emergency Operations Procedure closely mirrors the cyber-security incident response plans. Organizations that are looking to develop an EOP can start with defining the threats using the brainstorming exercise that was previously discussed. These threats can then be categorized as high or low risk and high or low likelihood of occurring. After categorization, the team should focus on addressing threats that are high risk and highly likely to occur followed by Low Risk and Highly Likely, or High Risk and Low likelihood of occurrence. Lastly, Low Risk, Low likelihood of occurrence should be addressed. These categorizations can also guide what compensating controls should be prioritized as well as where the churches training time and budget should be used for.
Once you have developed your priority list of threats and an Emergency Operations Procedure you are ready to start training the teams and staff of the church. As a church leader it may be beneficial to include non-safety team members in the training. Consider the role of ushers, greeters, and children’s ministry members in identifying potential issues for the Security and safety team to address. This inclusion drives a see something, say something culture. The easiest training to perform is the cheapest. Table Top Drills are often used in Cyber-security to discover if all potential risks are being addressed for a particular threat event. These table-top drills should be a discussion amongst each team about what action will or should be taken in response to a given event. I attended a Cyber-security conference recently and one of the best take-aways was a deck of cards with 6 cyber security scenarios that I could discuss how we would respond to each of the events. The next type of training that can be very effective is to drill these events. We all remember doing fire drills in school as a kid, but once you become responsible for a safe evacuation, you realize how much can be learned from performing an evacuation drill of your facility. The drills also help educate key volunteers and leaders about what to expect during an actual evacuation. The order and calmness that these volunteers exhibit will help to keep a potential panic moment become an orderly evacuation and reunification of parents and children. The most common style of training is the traditional instructor-led skills training. This training can have a high level of impact as well as a high level of volunteer engagement. This style training could also have the highest potential cost. There are ways to manage the potential cost. Nurses, paramedics and other medical professional members of the church may be able to teach skills such as CPR, AED, and Stop the Bleed for little to no cost. One last often overlooked training opportunity is one that I learned from friends in the fire service. This is referred to as a hot-wash or an After event report. This hot-wash is performed as soon as possible after the event has ended and should include all persons involved, any key witnesses, and any leaders of these teams. The longer you wait after the event, the more each person can replay the event in their mind and each replay may impact how the event is remembered or what is considered to be pertinent. This review should identify anything that needs to be updated or resolved immediately. Lastly, an evaluation of the EOP vs what happened should be performed. This will identify issues with the plan or with the execution that should be addressed.
In summary, a church is only as prepared for each scenario as the procedures and processes that they have defined and trained for. While there are multiple converged parallels between cyber security and church security, one of the best take-aways is the prioritization of risk based on how risky a threat is to the church and the likelihood that the threat could occur. Providing secure and safe environments can lead to an atmosphere that encourages an authentic worship and connection for the protectors and all in the congregation.
Jay Dill

