Skip to main content
Coverage Alert

Church Cyber Liability in Georgia: The "$30 of Coverage" Trap Every House of Worship Should Know (2026)

Matthew Campbell · churches

The short answer

Many Georgia churches unknowingly carry as little as $30,000 in cyber coverage — often buried inside a property policy that wasn't built to handle a real breach or wire-fraud loss. This post explains what that gap looks like in practice, what cyber liability for houses of worship actually covers, and what to check before your next renewal.

Churches that thought they had cyber coverage have discovered — after the loss — that what they actually had was a small sub-limit inside a property policy. In some cases, that limit was as low as $30,000. For a church hit by wire fraud or a data breach, that number disappears fast.


Here is a common scenario we walk ministries through. An administrator at an established church in suburban Atlanta — a composite of several real wire-fraud situations we’ve seen — received an email that looked identical to correspondence from their general contractor. The church was in the middle of a major sanctuary renovation, and a request to update the ACH payment details for the next subcontractor draw didn’t raise immediate red flags. Forty-eight hours later, $47,000 had been wired to a fraudulent account.

When the church contacted their insurance carrier, the reality set in: their cyber coverage was just a $30,000 add-on sub-limit attached to their commercial property policy. After the policy deductible, their reimbursement was barely over $20,000 — leaving more than half the loss uncovered.

The remainder had to come directly out of building fund reserves, pausing the renovation while leadership regrouped.

The church wasn’t careless. They simply had an add-on limit rather than a dedicated cyber policy built for modern wire-fraud schemes.


What “cyber liability for houses of worship” actually means

Cyber liability for houses of worship is a category of insurance coverage that protects churches against financial losses from data breaches, ransomware attacks, and social engineering fraud — including the wire-fraud schemes that have become increasingly common in construction and capital campaigns. A true standalone cyber policy is structured very differently from a small add-on limit tucked inside a property or general liability policy. At minimum, it should address three separate exposures: a breach of your donor or staff data, a ransomware event that locks your systems, and social engineering fraud where someone tricks a staff member or volunteer into sending money.

Most property policies that mention “cyber” coverage are not standalone cyber policies. They’re a dollar limit — sometimes as low as $10,000 to $30,000 — that sits as a smaller amount inside the larger policy. It’s not wrong for a carrier to offer it that way. It just isn’t enough on its own for a church that processes online giving, stores donor records, or is managing any kind of capital project with wire transfers involved.

The question isn’t whether you have something labeled cyber. It’s whether the coverage was actually designed for the exposure you carry.

The wire-fraud blind spot most churches don’t see coming

Wire fraud — sometimes called “social engineering fraud” — is the fastest-growing cyber loss churches face. A staff member receives what appears to be a legitimate email from a vendor, a contractor, or even their pastor, asking them to change payment details or send a transfer. The email looks right. The timing makes sense. The money moves.

Wire fraud is its own beast inside a cyber policy, and not every policy includes it. Some cyber policies treat social engineering as a separate coverage trigger that requires a specific endorsement — an add-on — to activate. Others include it automatically. Without looking at the actual policy language, you genuinely cannot assume you’re covered.

This is the second half of that construction scenario. Even if a church has a $75,000 sub-limit, policy language may not cover wire fraud at all — because the fraudulent email was directed at a human being, not an automated system breach.

Churches in the middle of a capital campaign or construction project carry elevated wire-fraud risk. Larger transactions, more outside vendors, pressure to keep things moving — it’s exactly the environment bad actors look for.

What a real cyber policy for a church should cover

A standalone cyber liability policy for houses of worship should address all of these areas — not as one combined limit, but as clearly defined coverage sections:

  • Data breach response — notification costs, credit monitoring, and legal expenses if donor, staff, or children’s ministry records are exposed
  • Ransomware / extortion — payments made to restore access to your systems, plus the cost of getting your systems cleaned up afterward
  • Business interruption — lost ministry operations while systems are down (more relevant than many churches realize if online giving is a primary revenue stream)
  • Social engineering / wire fraud — losses from a staff member or volunteer being tricked into sending money or changing payment details
  • Defense costs and regulatory liability — if a breach triggers a complaint or state notification requirement

Premium for a standalone church cyber policy varies depending on the size of your ministry, how much personal data you store, your online giving volume, and whether you have any prior claims. In our experience, standalone coverage for a typical Georgia church usually ranges from several hundred dollars to a few thousand dollars annually. A larger church with extensive school records or an active capital campaign in progress will pay more — but it is almost always modest compared to the wire-fraud exposure.

The $30,000 trap — and how to check if you’re in it

Here’s the practical test: pull out your current church policy (or ask your agent for the declarations page) and look for any mention of “cyber,” “data breach,” or “technology.” If you find it, note the dollar amount. Then ask two questions:

  1. Is this a standalone policy, or a sub-limit inside my property or general liability coverage?
  2. Does it specifically include social engineering or wire-fraud loss?

If the answer to the first question is “it’s a sub-limit” — and especially if that number is under $100,000 — you may be carrying a gap you don’t know about. That doesn’t mean your property policy is bad. It means the cyber piece wasn’t built for a real cyber event.

I’ll be straight with you: a $30,000 cyber sub-limit isn’t fraud on the insurer’s part. It was probably priced and positioned honestly. But it’s easy for a church to read “cyber coverage included” and assume they’re protected in a way they’re simply not.

The small takeaway: check the limit, check whether wire fraud is specifically included, and find out if your limit is standalone or shared with something else. Those three questions take ten minutes and could make the difference between an uncovered loss and a protected budget.

If you’d like an experienced set of eyes on what your policy actually provides, request a coverage review — no pressure, and if what you have is solid, we’ll tell you that too.


Frequently Asked Questions

Does a standard church property policy cover cyber losses?

Most standard church property policies include little to no meaningful cyber protection. Some include a small sub-limit — often $10,000 to $30,000 — labeled as “data breach” or “cyber” coverage, but that amount is rarely enough to cover the notification costs, legal fees, and lost funds from a real incident. A standalone cyber policy is structured specifically for these events.

Is wire fraud covered under cyber liability?

Wire fraud — where a staff member is tricked into sending money to a fraudulent account — is not automatically included in every cyber policy. Many policies require a specific endorsement to trigger social engineering coverage. Churches with active construction projects or large vendor payments should verify explicitly that wire fraud is addressed in their policy language, not just assumed.

Does Georgia law require churches to carry cyber insurance?

Georgia does not require churches to carry cyber insurance. However, Georgia has data breach notification laws that apply to any organization — including nonprofits and churches — that stores personal information. If your church experiences a breach, you may be legally required to notify affected individuals and state authorities, which can be costly without the right coverage in place.

How much does standalone cyber coverage cost for a church?

Cost varies based on the size of your ministry, the volume of donor and personal data you store, and your online giving activity. In our experience, standalone policies for Georgia churches typically range from several hundred to a few thousand dollars annually. Larger churches with extensive school records or active capital campaigns will pay more — but standalone coverage is almost always cost-effective relative to the financial exposures it addresses.

Should a church with online giving prioritize cyber coverage?

Yes — any church that processes online donations is storing financial data and is a potential target. Beyond the direct fraud risk, a breach that exposes donor payment information can trigger notification requirements, legal costs, and significant damage to the trust your congregation has placed in you. Protecting that trust is part of good stewardship.

What’s the difference between a cyber sub-limit and a standalone cyber policy?

A sub-limit is a smaller dollar amount that lives inside a larger policy — your property or general liability — and shares the structure and terms of that policy. A standalone cyber policy is its own separate contract, with limits and coverage triggers designed specifically for cyber events. Sub-limits tend to be smaller, narrower in scope, and often exclude wire fraud entirely. Standalone policies are purpose-built for the kind of losses churches are actually experiencing.

Related Articles

Risk Management

Our Church Is Starting a Building Project — What Changes on Our Insurance?

Tell your agent before you sign the construction contract, not when the building is done. A building project touches your insurance in four places: who insures the structure while it's going up, the contractors on your property, your existing buildings during the work, and your limits once the new space opens.

Matthew Campbell · August 28, 2026
Risk Management

Does Our Church Security Team Have Its Own Liability Coverage?

Usually not on its own. A church security team is covered by the church's liability policy only as far as the policy allows — and armed volunteers, off-duty officers, and use of force are exactly where policies get narrow. Who is on the team, whether they carry, and what your carrier has in writing decide the answer.

Matthew Campbell · August 28, 2026

Have a question about your ministry's coverage?

We're here to help. Give us a call or request a coverage review — we'll start with a conversation, not a sales pitch.

MinistrySure is an independent insurance agency in Loganville, Georgia specializing exclusively in churches, Christian schools, colleges, and faith-based ministries. Led by brothers Michael and Matthew Campbell — with 30 years of combined experience in church insurance — MinistrySure serves 700+ Georgia ministries as a preferred Brotherhood Mutual agency.