Security
Google Workspace phishing protection
Google Workspace phishing protection combines the 12 advanced Gmail safety toggles, attachment sandboxing on Enterprise editions, external-sender banners, and a quarterly simulation that produces a measured click rate. Enabling the toggles alone typically removes most commodity phishing; the residual risk is targeted mail that carries no attachment and no link.
| Advanced safety toggles | Apps > Gmail > Safety, per org unit |
|---|---|
| Attachment sandbox | Enterprise Standard and above |
| External banner | Gmail Safety, on by default since 2021 |
| Simulation cadence | Quarterly, first run free |
| Typical first click rate | 14–22% of staff on run one |
| Setup effort | Half a day, plus a two-week comms window |
Turn the safety settings on for every org unit, not just the root
Gmail groups its anti-phishing behaviour into three blocks: attachment protection, link and external image protection, and spoofing and authentication protection. Each block is applied per org unit, and each has a separate choice of action — move to spam, or show a warning. Warnings are worth keeping in the first month because they tell you what would have been quarantined before anything is quarantined.
The failure pattern is structural rather than technical. An organisation configures the root org unit properly, then someone creates a child unit for contractors, interns or a newly acquired brand, and inheritance is broken by a single unrelated override. Reviewing the settings org unit by org unit takes twenty minutes and is the single highest-yield hour available in the console.
- Protect against encrypted attachments from untrusted senders
- Protect against attachments with scripts from untrusted senders
- Identify links behind shortened URLs and scan linked images
- Warn on any click to an untrusted domain
- Protect against inbound spoofing of your own domain names
- Protect against spoofing of employee names in the From header
Security sandbox, and when the licence is worth it
Security sandbox detonates attachments in a virtual environment before delivery, which catches malware that has no signature yet. It requires Enterprise Standard, Enterprise Plus, Education Standard or Education Plus, and it adds delivery latency measured in seconds rather than minutes.
For an organisation whose inbound mail is mostly internal and mostly from known suppliers, sandboxing is not usually the reason to move edition. For anyone receiving unsolicited attachments as a matter of routine — recruitment, accounts payable, claims handling, admissions — it is the control that changes outcomes most, and the edition cost per protected inbox is small against a single ransomware event.
The simulation, and why the first one is free
A simulation sends a benign but realistic lure to staff and records who clicked, who submitted credentials and who reported it. The number that matters is not the click rate; it is the report rate, because reporting is the only behaviour that shortens an incident. Organisations that train on clicking alone drive clicks down and reporting down at the same time, which is worse.
The first run is free because it produces the evidence for the conversation that follows. A dated report showing a fifth of staff submitting credentials to a fake sign-in page settles budget arguments that no proposal document ever wins. Subsequent runs are quarterly, with the templates rotated so the exercise measures behaviour rather than memory of the last lure.
What phishing controls cannot do
No inbound filter catches a plain-text message from a real, compromised supplier mailbox asking for a bank detail change. There is no attachment, no link, no spoofed header, and the sending domain has good reputation. Filtering treats it as ordinary business mail because that is what it looks like.
That class of attack is answered by process rather than configuration: a callback rule on payment changes, dual authorisation above a threshold, and a payee-verification step that does not use contact details taken from the requesting email. We write those rules into the runbook during setup, and they are the part clients most often skip.
What we see that others don't say
Almost every tenant we open has the advanced Gmail safety settings left at their default state on at least one org unit, usually the one created for contractors or shared devices, which is precisely the population most likely to click.
What this doesn't cover
- We do not train staff in a classroom. The simulation produces the data; awareness training is delivered by your own L&D function or a specialist provider.
- We cannot stop a compromised supplier mailbox sending you a genuine message with fraudulent instructions. That risk is controlled with payment process, not mail filtering.
- Security sandbox needs Enterprise Standard or above. On Business editions we configure everything else and say plainly what is missing.
- Simulation results are reported anonymised by department by default. Naming individuals is available on request but we advise against it.
Get a fixed price for this
Send your seat count, current platform and deadline. You get a fixed price and an available cutover date, usually within one working day, from the engineer who would run the work.
Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.
Questions we get asked
- Is a free phishing simulation actually useful?
- Yes, as a measurement. One run gives you a dated click and report rate per department, which is what justifies further spend. It is not a training programme on its own.
- Do the advanced phishing settings block legitimate mail?
- Rarely, if you start in warning mode. Run every setting as a warning for two to four weeks, review what was flagged, then switch the confident categories to quarantine.
- Do we need Enterprise for phishing protection?
- No. Everything except security sandbox is available on Business editions. Sandbox needs Enterprise Standard or above, and matters most where unsolicited attachments arrive daily.
How this page is verified
Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .
- Setting names and org-unit inheritance behaviour reflect the Google Workspace admin console as of 2026-08-06.
- Security sandbox edition requirements are from Google Workspace Admin Help as published on 2026-08-06.
- Click and report rates are Workspace Migration Services simulation results across engagements completed to 2026-08-06.
Sources you can check
Cite this page
Free to reuse with attribution. Copy whichever form your publication needs.
Plain citation
Workspace Migration Services, "Google Workspace phishing protection", https://workspacemigration.services/security/google-workspace-phishing-protection (last checked 2026-08-06).HTML with source link
<p>Google Workspace advanced phishing settings are configured per org unit, so a tenant can be fully protected on its default OU and unprotected on a contractor OU created later. Source: <a href="https://workspacemigration.services/security/google-workspace-phishing-protection">Google Workspace phishing protection</a> — Workspace Migration Services.</p>Embed this table
<table>
<caption>Google Workspace phishing protection — Workspace Migration Services, 2026-08-06</caption>
<tr><th>Advanced safety toggles</th><td>Apps > Gmail > Safety, per org unit</td></tr>
<tr><th>Attachment sandbox</th><td>Enterprise Standard and above</td></tr>
<tr><th>External banner</th><td>Gmail Safety, on by default since 2021</td></tr>
<tr><th>Simulation cadence</th><td>Quarterly, first run free</td></tr>
<tr><th>Typical first click rate</th><td>14–22% of staff on run one</td></tr>
<tr><th>Setup effort</th><td>Half a day, plus a two-week comms window</td></tr>
</table>
<p><a href="https://workspacemigration.services/security/google-workspace-phishing-protection">Google Workspace phishing protection</a> — data maintained by Workspace Migration Services.</p>Related pages
Run the first simulation free
We configure the advanced safety settings per org unit, run one simulation, and give you a dated click and report rate by department you can take to a board.