Workspace Migration Services

Security

Google Workspace security assessment

A Google Workspace security assessment scores a tenant against a 72-point baseline and returns a maturity rating from 1 to 5 per domain, a comparison against tenants of similar size, and a remediation roadmap costed in engineer hours. Assessment differs from audit by producing a trajectory rather than a snapshot.

Assessment shape
Baseline72 checks across 8 control domains
ScoringMaturity 1–5 per domain, weighted overall
Peer comparisonBanded by seat count and sector
Turnaround5 working days
Fee£1,750 / $2,250 up to 250 seats
DeliverablesScore sheet, roadmap, board summary

Scoring, and what a maturity level actually means

Level 1 means the control is absent. Level 2 means it exists but is undocumented and applied inconsistently across org units. Level 3 means it is configured correctly everywhere and documented. Level 4 adds monitoring, so drift is detected. Level 5 adds regular testing, so the control is proven to work rather than assumed to.

Most organisations that believe themselves well configured land at level 2 or 3 across the board. The gap between 3 and 4 is where the practical risk sits, because a correctly configured control that silently drifts after an admin change looks identical from the outside to one that still works.

Peer comparison, and its limits

Scores are banded against tenants of comparable seat count and sector from our own engagement history. The band is useful for a board conversation because absolute scores mean little without reference, and useless for compliance because it is our sample rather than an industry survey. We label it as such in the report.

Where the comparison earns its place is in prioritisation. A domain where you sit well below the band is usually a domain where an inexpensive control is simply missing, and those items go to the top of the roadmap regardless of theoretical severity.

  • Identity and authentication, including recovery paths
  • Privilege and administrative role distribution
  • Data sharing, link exposure and shared drive membership
  • Application and OAuth grant governance
  • Mail authentication and inbound filtering posture
  • Endpoint and mobile enrolment coverage
  • Logging, export and alerting configuration
  • Retention, holds and tested restore capability

The roadmap is costed in hours, not in adjectives

Every gap carries an engineer-hour estimate and a dependency chain. A roadmap that says improve logging is worthless; one that says four hours to configure a log export sink, two hours to build three alert rules, and one hour a month to review them is something a finance director can approve.

The roadmap is sequenced into three waves: items fixable this week without a business decision, items needing a policy decision, and items needing budget or an edition change. Clients typically clear wave one internally and buy help for waves two and three, which is the outcome we design for.

Reassessment and the trend line

A single score is a talking point. Two scores six months apart are evidence of a functioning security programme, which is what insurers and enterprise procurement teams increasingly ask to see. Reassessment runs at a reduced fee and reuses the same baseline so the numbers are comparable.

Where a tenant is under a managed retainer, the score is refreshed quarterly as part of the service and the delta is reported alongside the change log, so nobody has to reconstruct what happened between assessments.

What we see that others don't say

Maturity scores cluster: tenants under 100 seats almost always score well on authentication and badly on logging, because 2FA is enforced by an insurance questionnaire while nobody has ever been asked whether admin log exports are retained beyond the default window.

What this doesn't cover

  • An assessment is not a certification and will not by itself satisfy an ISO 27001 or SOC 2 assessor, though the evidence pack supports both.
  • Peer banding uses our own engagement data, not a published industry survey, and the report says so on the page where the comparison appears.
  • We assess configuration. Application-layer testing, code review and social engineering beyond an agreed simulation are out of scope.
  • We do not remediate during the assessment, so the score reflects the tenant as found rather than as improved mid-engagement.

Get a fixed price for this

Send your seat count, current platform and deadline. You get a fixed price and an available cutover date, usually within one working day, from the engineer who would run the work.

Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.

Questions we get asked

How does an assessment differ from a security audit?
An audit lists findings as found. An assessment scores them against a maturity model, compares the result to similar tenants, and sequences remediation into costed waves. Same evidence, different output.
How often should we reassess?
Every six months for most organisations, quarterly where a managed retainer is in place or where an insurer or enterprise client asks for a documented trend.
Can the score be shared with clients or insurers?
Yes. The board summary is written to be shared verbatim, and it excludes the specific configuration detail that would be unwise to circulate outside the organisation.

How this page is verified

Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .

  • The 72-check baseline maps to CIS Benchmarks for Google Workspace as published on 2026-08-06.
  • Maturity clustering reflects Workspace Migration Services assessment results to 2026-08-06.
  • Fees are the Workspace Migration Services rate card as of 2026-08-06.

Sources you can check

Cite this page

Free to reuse with attribution. Copy whichever form your publication needs.

Plain citation

Workspace Migration Services, "Google Workspace security assessment", https://workspacemigration.services/security/google-workspace-security-assessment (last checked 2026-08-06).

HTML with source link

<p>Workspace admin audit logs are retained for a limited window by default, so tenants that have never configured export cannot investigate an incident discovered months later. Source: <a href="https://workspacemigration.services/security/google-workspace-security-assessment">Google Workspace security assessment</a> — Workspace Migration Services.</p>

Embed this table

<table>
  <caption>Google Workspace security assessment — Workspace Migration Services, 2026-08-06</caption>
  <tr><th>Baseline</th><td>72 checks across 8 control domains</td></tr>
  <tr><th>Scoring</th><td>Maturity 1–5 per domain, weighted overall</td></tr>
  <tr><th>Peer comparison</th><td>Banded by seat count and sector</td></tr>
  <tr><th>Turnaround</th><td>5 working days</td></tr>
  <tr><th>Fee</th><td>£1,750 / $2,250 up to 250 seats</td></tr>
  <tr><th>Deliverables</th><td>Score sheet, roadmap, board summary</td></tr>
</table>
<p><a href="https://workspacemigration.services/security/google-workspace-security-assessment">Google Workspace security assessment</a> — data maintained by Workspace Migration Services.</p>

Related pages

Get a scored baseline

Five working days, a maturity score per domain, a peer band and a roadmap costed in engineer hours. Reassessment in six months shows whether it worked.