Business Email Security

Google Workspace Security Configuration

Your business email is the #1 attack vector for small businesses. We lock down your Google Workspace — enforcing MFA, auditing permissions, configuring alerts, and closing the gaps attackers exploit to compromise your entire organization through one inbox.

How businesses get compromised — attack chain diagram showing spoofed email to lateral movement

How Businesses Get Compromised

Spoofed email from "your domain"
Employee clicks link
Credentials harvested
Inbox access (no MFA)
Lateral movement to Drive, Calendar, Contacts

We break this chain at multiple points. Most businesses have zero protections configured beyond a password.

How It Works

1

We Audit Your Admin Console

We run a structured evaluation of all 13 security areas in your Google Workspace Admin Console — authentication, email protections, Drive sharing, OAuth apps, mobile devices, admin roles, password policy, alert configuration, and more. We identify exactly what's misconfigured.

2

We Fix It Live With You

In a guided session, we walk through each finding and implement the fix together. You see every setting change in your own Admin Console as it happens. No black-box changes — you understand what we're doing and why.

3

We Verify Everything

Post-hardening verification: MFA enforcement confirmed, email authentication tested (SPF/DKIM/DMARC pass), security alerts firing correctly, Drive sharing policies locked down. Nothing left unchecked.

4

You Receive Your Report

A completion report documenting every change with before/after values, accepted risks with justification, and a verification checklist. Your audit trail for compliance and future reference.

What We Configure

13 security areas evaluated. Every setting tuned to your organization's needs.

🔐

MFA Enforcement

2-Step Verification turned on for all users. No opt-out. Hardware key support for admin accounts. 1-day enrollment window forces immediate setup.

👤

Admin Role Separation

Audit Super Admin count (target: max 2). Remove stale admin access. Create scoped roles for IT support, group management, and security review.

🔗

Third-Party App Audit

Review all OAuth app grants (we've seen 80+ connected apps). Block high-risk permissions. Restrict future "Sign in with Google" grants to approved apps only.

📁

Drive Sharing Policies

Default sharing set to "Private to owner." External distribution restricted. Link sharing disabled by default. File sharing expiration enabled for external access.

📧

Gmail Security Settings

SPF, DKIM, DMARC configured and verified. Anomalous attachment protection enabled. Unauthenticated email warnings turned on. Group spoofing protection active.

🚨

Security Alerts

Real-time alerts for suspicious logins, admin changes, data exports, failed MFA, new device access, and high-permission OAuth grants. Delivered to your security team.

🔑

Password Policy

Minimum length raised to 12+ characters. Strong password enforcement enabled. No-reuse policy active. NIST-aligned: no forced expiration (reduces weak password patterns).

📱

Mobile Device Management

Review enrolled devices. Verify management policies are active. Identify unmanaged devices accessing org data. Lock and wipe capability confirmed.

👥

Groups & Directory

Audit group visibility — no public groups exposing member lists. Directory sharing settings reviewed. Contact sharing scoped appropriately.

Sample Completion Report

Every engagement includes a completion report documenting what was changed and verified.

Completion Report

Google Workspace Security Hardening

13-area Admin Console evaluation, guided remediation session, and post-hardening verification.

Overview

Comprehensive Google Workspace hardening covering authentication, email security, Drive sharing, OAuth app controls, admin roles, password policy, mobile device management, alert configuration, and directory settings. All changes made during a live guided session with the client confirming each modification in their own Admin Console.

7
Areas Fixed / Confirmed
1
Accepted Risk
31
Devices Under MDM
1
Super Admin (2SV On)
ControlBeforeAfterStatus
2-Step VerificationEnforcement: OffEnforcement: On (all)Fixed
Gmail Safety Settings3 protections: Off3 protections: OnFixed
Drive SharingExternal: AnyoneOnly users in orgFixed
Password PolicyMin length: 8Min length: 12Fixed
Admin Roles1 Super Admin1 SA, 2SV enforcedPass
Third-Party Apps82 apps, unrestrictedLogged for follow-upAccepted
C
Pass

Automated security scan grade — before and after same-day remediation

What You Get

  • 13-area Admin Console security evaluation
  • MFA enforced for all users with hardware key support
  • Admin roles audited and restricted to least privilege
  • Third-party OAuth apps reviewed and policy configured
  • Drive sharing policies locked down (private by default)
  • Gmail safety settings maximized (attachment, spoofing, phishing)
  • Email authentication verified (SPF, DKIM, DMARC)
  • Password policy upgraded to NIST standards
  • Security alerts configured and tested
  • Completion report documenting every change with before/after proof