Security
Google Workspace security audit
A Google Workspace security audit reviews admin role assignment, external file sharing, third-party OAuth grants, mail authentication and two-factor coverage against a documented baseline. The output is a prioritised remediation list with an owner and an effort estimate per item, not a console screenshot dump.
| Duration | 5 working days from access being granted |
|---|---|
| Fixed fee | £1,750 / $2,250 up to 250 seats |
| Controls reviewed | 72 checks across 8 domains |
| Output | Prioritised fix list, exec summary, evidence pack |
| Access needed | Delegated admin with audit and reports rights |
| Re-test | Included once, within 90 days |
The eight domains we review
The audit is deliberately narrow and repeatable. It covers admin roles and privilege distribution, authentication including two-factor coverage and recovery options, external sharing and link exposure, third-party OAuth grants and marketplace applications, mail authentication with SPF, DKIM and DMARC, endpoint and mobile management policy, logging and alerting configuration, and retention including Vault holds.
Each domain produces findings with a severity, a plain description of the exposure, and the exact console path to fix it. Severity is assigned on exploitability and blast radius rather than on a vendor scoring table, because a super-admin account without two-factor authentication matters more than a dozen cosmetic policy gaps.
- Admin roles: how many super admins, and whether any are shared or service accounts
- Authentication: 2FA enforcement coverage, recovery phone and code exposure
- External sharing: link-shared files, external shared drive members, domain allowlists
- OAuth and marketplace: every app holding Gmail, Drive or admin scopes
- Mail authentication: SPF record depth, DKIM key length, DMARC policy state
- Devices, logging, alerting and retention configuration
What we do not do, and why that matters
This is a configuration review, not a penetration test. We do not attempt to breach accounts, phish your staff or test application code. That work exists and is valuable; it is a different engagement with a different scope document and different indemnities.
The reason to be explicit is that many organisations buy a configuration review believing it constitutes assurance against attack. It does not. What it does is remove the failures that are visible from the admin console, which is where a large share of real-world Workspace incidents actually begin.
How the remediation list is built
Every finding gets an owner, an effort estimate in hours, and a dependency note where fixing one thing requires another first. Enforcing two-factor authentication across a domain, for example, is a fifteen-minute setting and a three-week communications exercise, and pretending otherwise produces a list nobody executes.
Roughly two-thirds of findings in a typical tenant are fixable inside a day by one competent administrator. The rest need a decision from someone with authority over how the business works, and those are flagged as decisions rather than tasks so they do not sit unowned in a spreadsheet.
The re-test, and why it is included
An audit that is never re-tested is an expensive document. One re-test is included within ninety days, covering every finding marked as remediated. The re-test produces a short delta report suitable for sending to a board, an insurer or a client's procurement team.
Where clients need this repeatedly, for cyber insurance renewals or client due-diligence questionnaires, we run it quarterly on a retainer at a reduced rate. The value there is the trend line rather than any single report.
What we see that others don't say
In the tenants we audit, third-party OAuth grants are the most consistently under-managed control: it is common to find applications holding broad Drive or Gmail scopes that were authorised years earlier by someone who has since left the organisation.
What this doesn't cover
- This is not a penetration test. We review configuration; we do not attempt exploitation, phishing simulation or code review.
- We do not certify compliance. The evidence pack supports ISO 27001, SOC 2 and Cyber Essentials work, but certification decisions belong to your assessor.
- We do not audit third-party SaaS platforms outside Workspace, beyond listing the OAuth grants they hold against it.
- We do not make changes during the audit. Remediation is separate, deliberately, so the review stays independent of the work it recommends.
Questions we get asked
- What access do you need for a Workspace security audit?
- A delegated admin account with reports and audit rights. We do not need super-admin access to review configuration, and we prefer not to have it so the engagement stays read-only by construction.
- How long does the audit take?
- Five working days from access being granted. Larger or multi-domain tenants add time in proportion to the number of org units and shared drives rather than to seat count.
- Will this satisfy a client security questionnaire?
- The evidence pack answers most Workspace-specific questions in standard questionnaires and supports Cyber Essentials or SOC 2 preparation. It is not a certification and does not replace an assessor.
- Can you fix the findings as well?
- Yes, quoted separately after the report. Keeping the review and the remediation commercially separate means the findings list is not shaped by what is convenient to sell.
How this page is verified
Reviewed by Pearl Lemon Cloud security desk, Workspace security and compliance reviewers. Last checked .
- Control checklist maps to CIS Benchmarks for Google Workspace and Google's own security best-practice guidance as published on 2026-08-06.
- Fee and duration reflect the Pearl Lemon Cloud rate card as of 2026-08-06.
- OAuth grant observations are drawn from Pearl Lemon Cloud audit engagements completed to 2026-08-06.
Sources you can check
Related pages
- Retention and restore gaps we find
- Tenant limits and audit log retention
- Workspace for accountancy practices
- Score your tenant against our control list
- Audit and remediation fees
- Fix mail authentication with DMARC
- Offboard leavers without losing data
- Score your tenant in five minutes
- Talk to a Workspace consultant
- Security expectations for law firms
Book a security audit
Five working days, fixed fee, one re-test included. You get a prioritised fix list with owners and hours, and an evidence pack you can send to clients.