Tool
Workspace security scorecard
Eight controls account for most of the risk in a Google Workspace tenant. Tick the ones you already enforce to get a weighted score, a posture band and your highest-weighted gap. This is the same control list our paid audit works through.
| Posture | Critical — assume compromise is undetected |
|---|---|
| Controls in place | 0 of 8 |
| Highest-weighted gap | 2-step verification enforced for all users, not just admins |
Weightings mirror the control list we audit against. Scoring happens in your browser; nothing is transmitted.
Weightings are not evenly spread. Unenforced 2-step verification and open OAuth access carry the most weight because both give an attacker persistent access without needing to defeat anything else. DMARC sits close behind, since a domain at p=none can be spoofed against your own customers regardless of how well the tenant itself is configured.
Log retention scores lowest but matters after an incident: without exported admin and login logs beyond six months, you cannot establish when access began, which is the first question an insurer or regulator asks.
What this doesn't cover
- A scorecard is self-assessed; it does not verify what the admin console actually says.
- This is not a penetration test and makes no attempt to exploit anything.
- Endpoint, network and non-Google SaaS security are outside this control list.
Questions we get asked
- What is a good Google Workspace security score?
- Anything below 70 out of 100 on this list means at least one control that would let an account takeover succeed unnoticed. Above 90 an audit finds refinements rather than risks.
- Which control is missed most often?
- Third-party OAuth and Marketplace app access. Most tenants leave it open, so any user can grant a stranger's app read access to their entire mailbox and Drive.
Related pages
Want the verified version of this score?
Our audit checks each control against your actual console and logs, then hands back a ranked findings list with an owner and a fix date against every item.