Google Workspace Security Checklist for Small Businesses
A stolen password can give an attacker access to years of email, shared files, invoices, and customer conversations in minutes. Google Workspace security starts with a few settings that block common attacks before they become a costly disruption.
Small businesses don't need a large internal security team to make meaningful improvements. They do need clear ownership, secure defaults, and regular reviews of the accounts and devices touching company data.
Use this checklist to tighten your Google Workspace tenant without losing sight of everyday productivity.
Build your Google Workspace security baseline
Start with identity controls. Email accounts are often the front door to payroll systems, banking portals, vendor accounts, and cloud software, so protect them before working on less urgent settings.
Require 2-Step Verification for every user
In the Admin console, look under Security , then Authentication and 2-step verification . Require 2-Step Verification for the entire organization after giving staff a short enrollment deadline.
Google already enforces 2-Step Verification for administrator accounts in many Workspace environments. However, every employee needs the same protection. A compromised receptionist, sales, or bookkeeping account can still expose sensitive files and launch convincing phishing messages.
Set up an exception process for staff who need temporary help enrolling. Don't leave broad exemptions in place because someone changed phones.
Quick win: Require 2-Step Verification for all users and confirm each administrator has enrolled.
Use passkeys or security keys for admins
Set a higher standard for Super Admins, finance staff, and anyone with access to customer records. In the same 2-Step Verification area, Google may show an option called "Only security key." Google now treats compatible passkeys and physical security keys as supported methods under that setting.
A physical FIDO2 security key gives your most sensitive accounts strong phishing resistance. Keep two keys for each Super Admin, with one stored securely as a backup. Passkeys are also a practical choice when they are protected by device biometrics or a strong device PIN.
Keep at least two Super Admin accounts. Assign those roles only to named people, and don't use a daily email account as an administrator account.
A locked-out Super Admin can become an outage. Document recovery contacts, backup authentication methods, and who holds each spare security key.
Protect Gmail from spoofing and phishing
Most Workspace incidents begin with email. A well-written fake invoice or Microsoft 365 notification can fool busy employees, even when their passwords are strong.
Turn on Gmail safety protections
In the Admin console, look under Apps , Google Workspace , Gmail , and Safety . Review the phishing, malware, attachment, and spoofing protections in that area. The exact labels can differ as Google updates the console or by license level.
Enable warnings for suspicious links and unauthenticated messages. Also review protections for impersonated employee names and external sender warnings. These settings help staff spot messages that look familiar but come from outside your company.
Test the effect on legitimate vendor email after making changes. A blocked message should create a review task, not an excuse to turn off protection across the domain.
Authenticate every sending domain
Set up SPF, DKIM, and DMARC for your primary domain and any subdomain that sends email. SPF identifies approved mail servers. DKIM adds a cryptographic signature. DMARC tells receiving systems how to handle mail that fails alignment checks.
Create the required DNS records with help from whoever manages your domain. For DKIM, Gmail settings generally include a place to generate a domain key and begin authentication after the DNS record is published.
Start DMARC with a monitoring policy, often p=none
, while you identify authorized senders such as accounting software, marketing platforms, and help desk tools. Move to quarantine or reject only after reports show legitimate mail passes alignment.
Control the devices that access company data
A secure account can still be exposed on an unpatched laptop or a lost phone. Device controls reduce that risk, especially for businesses with remote, hybrid, or field-based teams.
Enroll business phones and computers
Look for Devices , Mobile and endpoints , or Endpoint management in the Admin console. Google changes menu names from time to time, so search the console for "endpoint" or "device management" if needed.
Require screen locks on company phones. Set a reasonable inactivity timeout, and allow remote account wipe for devices that are lost or no longer assigned to an employee. Before a termination or device replacement, remove the Workspace account from the old device and review active sessions.
Basic mobile controls are available in lower Business editions after domain verification. Google Workspace Business Plus includes advanced endpoint management, which gives small teams more detailed device policy options.
Quick win: Inventory every phone, tablet, and laptop signed in with a company account. Remove devices no longer in use.
Restrict unmanaged access where it fits
For staff who handle payroll, health information, legal records, or payment data, don't allow broad access from unknown devices. Use device management policies and access controls to require an approved device where your edition supports it.
Context-Aware Access is a more advanced option that can limit access by device state, location, and user context. It is commonly associated with Enterprise-level licensing and may require Cloud Identity Premium. Confirm feature availability before building policies around it.
Start with the accounts that present the greatest risk. Locking down every personal device on day one can create unnecessary friction for a small team.
Limit app permissions and file sharing
Third-party apps can read email, create files, access calendars, or export contact lists. A free browser extension or meeting scheduler may request far more access than its job requires.
Review OAuth applications before approving them
In the Admin console, search for terms such as "third-party app access," "OAuth app access," or "app access control." For individual users, their security details may list Connected applications .
Set a policy that blocks unapproved third-party apps by default where practical. Then create an approval process for tools requesting Gmail, Drive, Calendar, or Admin SDK permissions. Review the requested scopes, vendor reputation, and business owner before allowing access.
Remove integrations nobody uses. Former employees and abandoned trial tools shouldn't retain a path into your data.
Quick win: Export or review connected apps quarterly, then revoke access for anything unrecognized or inactive.
Set practical Drive sharing rules
Review sharing defaults for Google Drive and Shared Drives. Many small businesses allow anyone with a link to access a file, then forget that the link can be forwarded indefinitely.
Limit external sharing to the people who need it. Use Shared Drives for department-owned records, because files remain with the business when an employee leaves. Review public links and outside collaborators at least quarterly.
Data loss prevention rules can flag or block content such as Social Security numbers, payment card data, payroll files, and customer records. DLP capabilities and covered services vary by Workspace edition, so check your license before designing controls. Begin in audit or warning mode, then adjust rules based on real results.
Monitor alerts and protect admin privileges
Security settings only help when someone notices the warnings. A lean IT team doesn't need to watch dashboards all day, but it should have a short daily review routine and clear escalation contacts.
Route alerts to more than one person
Find Alert Center under the security tools in the Admin console. Configure notifications for suspicious sign-ins, phishing reports, malware, administrator changes, and unusual application activity. Google also supports custom alerts based on audit events, DLP, and other security rules.
Send critical alerts to two people, not one owner who may be on vacation. Decide in advance who can disable an account, revoke sessions, and contact a bank or vendor if fraud is suspected.
Review the Alert Center every business day. A five-minute review can catch unusual forwarding rules, account recovery changes, or sign-ins from unexpected locations.
Use logs to investigate, not guess
Audit logs can show changes to Gmail settings, Drive sharing, user accounts, devices, and administrator actions. Higher Workspace tiers offer deeper investigation capabilities, which can speed up response when an incident affects multiple accounts.
Document a simple response sequence: secure the account, reset credentials or remove passkeys if needed, revoke sessions, inspect forwarding rules and OAuth grants, then review file sharing. Preserve relevant records before deleting anything.
For businesses without internal coverage, managed network monitoring services can help connect endpoint issues, security alerts, and day-to-day support.
Add retention and backup for recoverable data
Google Workspace has strong collaboration and retention tools, but retention is not the same as a full backup. A deleted file, a malicious insider, or a mistaken configuration change can create recovery needs that fall outside a simple retention policy.
Match Vault to your retention needs
Google Vault is included with Google Workspace Business Plus. It supports retention rules, legal holds, search, and eDiscovery for supported Workspace data. Business Starter and Business Standard plans do not include Vault as a standard feature.
If your company has legal, contractual, or recordkeeping duties, write down what information must be retained and for how long. Then configure rules that match those requirements. Avoid setting indefinite retention everywhere without a business reason, because it can increase storage and discovery burdens.
Vault preserves and searches data. It does not replace a restore plan for day-to-day operational recovery.
Use separate backups and test restores
Maintain an independent backup for Gmail, Drive, and Shared Drives when your business needs reliable recovery from deletion, ransomware, or account-level mistakes. Pick a provider that can restore individual messages and files, not only export them.
Test restores on a schedule. Recover one email, one Drive folder, and one Shared Drive file to confirm that permissions and versions are usable. Keep written recovery goals, including how long the business can operate without email or shared documents.
For local businesses, backup and disaster recovery services can support the broader recovery plan for cloud data, endpoints, and systems outside Workspace.
Make security a repeatable business habit
The strongest Google Workspace security checklist is one your team can maintain. Start with 2-Step Verification, secure administrator accounts, Gmail protections, device inventory, and email authentication. Then build stronger controls around app access, alerts, data retention, and backups.
Review the checklist every quarter and after major staff, device, or software changes. Consistent ownership keeps a small issue from becoming a business-wide interruption.

