Business Email Security
Google Workspace Security Configuration
Your business email is the #1 attack vector for small businesses. We lock down your Google Workspace — enforcing MFA, auditing permissions, configuring alerts, and closing the gaps attackers exploit to compromise your entire organization through one inbox.

How Businesses Get Compromised
We break this chain at multiple points. Most businesses have zero protections configured beyond a password.
How It Works
We Audit Your Admin Console
We run a structured evaluation of all 13 security areas in your Google Workspace Admin Console — authentication, email protections, Drive sharing, OAuth apps, mobile devices, admin roles, password policy, alert configuration, and more. We identify exactly what's misconfigured.
We Fix It Live With You
In a guided session, we walk through each finding and implement the fix together. You see every setting change in your own Admin Console as it happens. No black-box changes — you understand what we're doing and why.
We Verify Everything
Post-hardening verification: MFA enforcement confirmed, email authentication tested (SPF/DKIM/DMARC pass), security alerts firing correctly, Drive sharing policies locked down. Nothing left unchecked.
You Receive Your Report
A completion report documenting every change with before/after values, accepted risks with justification, and a verification checklist. Your audit trail for compliance and future reference.
What We Configure
13 security areas evaluated. Every setting tuned to your organization's needs.
MFA Enforcement
2-Step Verification turned on for all users. No opt-out. Hardware key support for admin accounts. 1-day enrollment window forces immediate setup.
Admin Role Separation
Audit Super Admin count (target: max 2). Remove stale admin access. Create scoped roles for IT support, group management, and security review.
Third-Party App Audit
Review all OAuth app grants (we've seen 80+ connected apps). Block high-risk permissions. Restrict future "Sign in with Google" grants to approved apps only.
Drive Sharing Policies
Default sharing set to "Private to owner." External distribution restricted. Link sharing disabled by default. File sharing expiration enabled for external access.
Gmail Security Settings
SPF, DKIM, DMARC configured and verified. Anomalous attachment protection enabled. Unauthenticated email warnings turned on. Group spoofing protection active.
Security Alerts
Real-time alerts for suspicious logins, admin changes, data exports, failed MFA, new device access, and high-permission OAuth grants. Delivered to your security team.
Password Policy
Minimum length raised to 12+ characters. Strong password enforcement enabled. No-reuse policy active. NIST-aligned: no forced expiration (reduces weak password patterns).
Mobile Device Management
Review enrolled devices. Verify management policies are active. Identify unmanaged devices accessing org data. Lock and wipe capability confirmed.
Groups & Directory
Audit group visibility — no public groups exposing member lists. Directory sharing settings reviewed. Contact sharing scoped appropriately.
Sample Completion Report
Every engagement includes a completion report documenting what was changed and verified.
Google Workspace Security Hardening
13-area Admin Console evaluation, guided remediation session, and post-hardening verification.
Overview
Comprehensive Google Workspace hardening covering authentication, email security, Drive sharing, OAuth app controls, admin roles, password policy, mobile device management, alert configuration, and directory settings. All changes made during a live guided session with the client confirming each modification in their own Admin Console.
| Control | Before | After | Status | |
|---|---|---|---|---|
| 2-Step Verification | Enforcement: Off | → | Enforcement: On (all) | Fixed |
| Gmail Safety Settings | 3 protections: Off | → | 3 protections: On | Fixed |
| Drive Sharing | External: Anyone | → | Only users in org | Fixed |
| Password Policy | Min length: 8 | → | Min length: 12 | Fixed |
| Admin Roles | 1 Super Admin | → | 1 SA, 2SV enforced | Pass |
| Third-Party Apps | 82 apps, unrestricted | → | Logged for follow-up | Accepted |
Automated security scan grade — before and after same-day remediation
What You Get
- 13-area Admin Console security evaluation
- MFA enforced for all users with hardware key support
- Admin roles audited and restricted to least privilege
- Third-party OAuth apps reviewed and policy configured
- Drive sharing policies locked down (private by default)
- Gmail safety settings maximized (attachment, spoofing, phishing)
- Email authentication verified (SPF, DKIM, DMARC)
- Password policy upgraded to NIST standards
- Security alerts configured and tested
- Completion report documenting every change with before/after proof