
Funeral home cybersecurity should begin with the systems your team depends on: email, case records, payments, the website, and backups. Assign an owner, protect account access, verify unusual requests through a separate known channel, and test recovery. The practical aim is to keep serving families while protecting the information they have entrusted to you.
This is an operating guide for small U.S. funeral homes and related providers, not a claim that one checklist establishes legal compliance. Have your IT provider and appropriate adviser adapt the work to your systems, contracts, insurance, and state requirements.
Give funeral home cybersecurity a named owner
Make a short inventory of the systems used to run a case, including who administers them and who can help after hours. Record the business owner of each account and the route to support. Include the website, domain registration, obituary publishing, electronic signatures, and any supplier portal that staff use outside the main case system.
Ask your IT provider to review the inventory with a staff member who knows the workflow. Identify what would stop if the primary email account or one office computer became unavailable. Keep emergency contacts accessible through an approved method that does not depend entirely on the failed account.
Protect individual accounts and recovery access
Use individual staff accounts where the service supports them, and plan how authorized coverage works when someone is absent. The National Institute of Standards and Technology's cybersecurity basics recommends multifactor authentication, particularly phishing-resistant methods, strong passwords, password managers, software updates, and protected, tested backups. Multifactor authentication adds another verification factor beyond a password.
Ask the provider to prioritize business email, administrators, financial systems, and case-management access. Confirm who holds recovery access and how it is protected. Avoid leaving the business dependent on a former employee's personal telephone or email address.
When a role changes, review access as part of the handoff. The FTC's personal-information guidance supports limiting access to job needs and removing access for departing workers. Give staff an approved way to share work without sharing a password.
Verify changes to payment instructions
Treat a changed bank account, unusual refund request, or urgent request for private case information as a reason to verify independently. Use a telephone number or contact route already held in your records, rather than one supplied in the suspicious message. Staff should know that pausing for verification is supported by management.

Build a simple payment-change rule: the person receiving the request records it, a designated approver confirms it through the known channel, and the change is documented before payment. Adjust responsibilities to your staffing; even a small firm can separate receiving a message from deciding that its instructions are authentic.
Use an invented example in training, such as a supposed florist asking for a new payment destination. Do not circulate a real family's record as a training sample. Ask staff what they would do next, then make the correct contact route easy to find.
Prove that backups can restore useful work
Ask your IT provider to demonstrate recovery of an agreed sample of information in a safe test environment. Confirm what is backed up, how the backup is protected, and which recent work might be missing after restoration. A successful backup notification alone does not answer whether the business can resume an arrangement.
Choose the test with operational staff: a sample schedule, an approved document, and access to a necessary workflow. Keep real confidential information protected during the exercise. Record who performed the test, what was recovered, and what failed; assign corrective work with a date for review.
Also ask what happens if the cloud supplier itself is unavailable. An export, an alternate contact process, and a documented recovery route serve different purposes. Have the provider explain the limits rather than assuming the word “cloud” means every interruption is covered.
Prepare a response staff can start
Write a short response card for a lost device, suspicious account access, or suspected data exposure. Tell staff whom to contact, how to preserve what they observed, and how to reach help without using a potentially compromised channel. Keep technical containment decisions with the people trained and authorized to make them.
The FTC's data-breach response guide addresses securing operations, fixing vulnerabilities, and assessing notifications. Notification duties depend on the incident and applicable law; your adviser should determine them promptly rather than staff guessing a deadline or announcing an unverified breach.
Review the plan with the on-call team, not just the weekday office. A useful cybersecurity program gives the person who sees a problem a clear next action, protects evidence, and keeps families informed through verified information when communication is needed.
Step by step
Put it to work this week
Assign each action to a named person and record what remains unresolved.
Map essential accounts
List the owner, administrator, support contact, recovery route, and operational dependency for each essential service.
- Who does it
- Manager and IT provider
- When
- This week
Check access and verification
Review MFA and departing-staff access, then rehearse a changed payment instruction using a fictional example.
- Who does it
- Office manager
- When
- This week
Test recovery and response
Agree on a safe restore test and make incident contacts available outside the primary email system.
- Who does it
- IT provider and manager
- When
- This week
Questions professionals ask
- Where should a small funeral home start with cybersecurity?
Begin with business email, administrator access, case-management systems, and payment workflows. Identify who owns each account, enable suitable multifactor authentication, and agree on recovery access with your IT provider. Then test backups and rehearse how staff independently verify an unusual request.
- Are cloud backups enough for a funeral home?
A cloud backup is useful only within its actual coverage and recovery limits. Ask what information it includes, how it is protected, and whether a sample can be restored safely. Also plan for supplier downtime and determine what recent work could be missing after recovery.
- What should staff do with a suspicious payment-change email?
Pause the change and notify the designated approver. Verify through a known contact route already held by the business, not the contact details in the message. Preserve the message according to the firm's incident process and document any independently confirmed instruction before acting.
Sources and references
These references support the guidance in this article. Each entry names the source and the date we checked it. Open the links for more detail, and confirm current requirements, availability, or costs with the relevant organization before relying on them.
- NIST — Cybersecurity Basics · checked
Establish measures to protect and test your backups.
- FTC — Protecting Personal Information · checked
Keep only what you need for your business.
- FTC — Data Breach Response · checked
Check state and federal laws or regulations for any specific requirements for your business.