Security
Google Workspace security
A Workspace security audit checks the admin console against a fixed control list: authentication, external sharing, OAuth app access, mail authentication, logging retention and leaver process. Findings arrive as a ranked list with an owner and a fix date, not a score.
Most Workspace tenants fail on the same four controls: unenforced 2-step verification, unreviewed third-party OAuth grants, Drive links shared to anyone with the link, and DMARC left at p=none years after it was published.
These pages describe what we check, what we change, and what remains your decision.
Pages in this section
- Google Workspace security auditA fixed-fee review of your Workspace tenant: admin roles, external sharing, OAuth apps, mail authentication and 2FA coverage, with a prioritised fix list.Duration: 5 working days from access being granted
- DMARC setup for Google WorkspaceConfigure SPF, DKIM and DMARC on Google Workspace and move to an enforcing policy without blocking legitimate mail from your own tools.SPF: One TXT record, include Google, under 10 DNS lookups
- Google Workspace offboarding, done without data lossArchive a Google Workspace user without losing data: transfer Drive ownership, archive the mailbox on an Archived User licence, revoke tokens, suspend.Correct first step: Transfer Drive ownership, not suspend
- Google Workspace backup and retentionWhy Vault is retention rather than backup, the deletion scenarios it cannot recover, and how to design Workspace retention that survives an audit.Gmail trash: 30 days, then unrecoverable by an administrator
- Google Workspace phishing protectionAdvanced phishing and malware settings, security sandbox, banner rules and a free phishing simulation, configured and measured against your own click rate.Advanced safety toggles: Apps > Gmail > Safety, per org unit
- Google Workspace security assessmentA scored assessment of your Workspace tenant against a 72-point baseline, with a maturity score, a peer comparison and a costed remediation roadmap.Baseline: 72 checks across 8 control domains
- Google Workspace email deliverabilityDiagnose and fix Workspace mail landing in spam: SPF lookup limits, DKIM key length, DMARC alignment, bulk sender rules and reputation recovery.SPF DNS lookups: Hard limit of 10, includes nested
- Zero trust for Google WorkspaceContext-Aware Access needs Enterprise Standard or above. A 3-phase rollout of device trust, session limits and app allowlisting, without locking admins out.Licence: Enterprise Standard+ or Cloud Identity Premium
- Business email compromise preventionThe controls that actually stop BEC on Google Workspace: payment callback rules, display-name spoof blocking, forwarding alerts and supplier verification.Display-name spoof blocking: Impersonation of directors in the From header
What this doesn't cover
- An audit is not a penetration test and does not attempt to exploit anything.
- We do not sign compliance certifications; we produce the evidence your assessor asks for.
- Endpoint and network security outside Workspace is out of scope unless quoted separately.
Questions we get asked
- What does a Google Workspace security audit cover?
- Authentication and 2SV enforcement, admin role sprawl, external sharing defaults, OAuth and marketplace app grants, SPF, DKIM and DMARC alignment, log retention, and the leaver process end to end.
- How long does an audit take?
- Five working days for up to 250 users: two days of console review and log sampling, one day of interviews, two days of write-up and remediation planning.
Not sure which of these you need?
Send us the shape of your estate — seat count, current platform, and the deadline you are working to — and we will tell you which of these pages applies and what it costs.