Google Workspace Security Check
A structured, fixed-scope review of your Workspace environment. We examine how your business is actually configured today, show you exactly where the gaps are, and give you a clear, prioritised plan to close them. .
If you already know your Google Workspace needs attention, you don’t need another generic checklist – you need someone to actually look under the hood. Our Security Check is a hands-on review carried out by our Google Workspace specialists, covering identity, data, devices and third-party access.
You’ll receive a plain-English report with every finding ranked by risk, and a fixed-price quote before we start, based on the size and complexity of your organisation.
What We Examine
Every Security Check covers the same core areas. The depth of the review scales with the number of users, domains and integrations in your environment.
01 · IDENTITY & ACCESS
Users & Authentication
- MFA coverage and enforcement across all users
- Admin and super-admin account exposure
- Password policy and login challenge settings
- Stale, unused or duplicate accounts
- Single sign-on (SSO) configuration, if in use
02 · DATA SHARING
Drive & File Exposure
- Organisation-wide external sharing defaults
- Publicly shared or "anyone with the link" files
- Shared drive ownership and permission sprawl
- Sensitive file exposure (finance, HR, client data)
03 · EMAIL SECURITY
Gmail & Domain Protection
- SPF, DKIM and DMARC configuration
- Phishing and spoofing protection settings
- Attachment and link scanning rules
- Forwarding rules and mail delegation risks
04 · THIRD-PARTY ACCESS
Connected Apps & OAuth
- Apps granted access via "Sign in with Google"
- Scope of data each connected app can reach
- Unused or high-risk integrations
- Marketplace app installation controls
05 · DEVICES
Endpoint & Mobile Management
- Mobile device management (MDM) enrolment
- Remote wipe capability for lost or stolen devices
- Access from unmanaged personal devices
- Session and device activity monitoring
06 · GOVERNANCE
Backup, Retention & Process
- Independent backup coverage for Workspace data
- Data retention and Vault configuration
- Employee onboarding / offboarding process
- Existing security policies and admin practices
A short call to understand your team size, industry, compliance requirements and any specific concerns, so we can confirm scope and provide a fixed-price quote.
You grant us temporary, read-only access to your Workspace Admin console. Nothing is changed during the review — we look, we don't touch.
Our specialists work through each of the six areas above, checking configuration against current best practice and flagging anything that represents real-world risk.
You receive a plain-English report, with every finding rated by risk (Critical / High / Medium / Low) and a clear explanation of what it means for your business.
We walk you through the results on a call, answer questions, and provide a prioritised remediation roadmap — whether you action it yourselves or engage us to do it for you.
What Determines the Cost
Number of Users
More accounts means more configurations, permissions and activity to review.
Integrations in Use
CRMs, accounting platforms and other connected apps add scope to the review.
Organisational Complexity
Multiple domains, shared drives, departments or locations extend the review.
Compliance Requirements
Obligations such as ISO 27001, the Essential Eight or industry-specific rules add checks.
Data Sensitivity
Businesses handling client, financial or health data typically need a deeper review.
Device Footprint
A mix of company-owned and personal devices adds another layer to assess.
As a rough guide, most engagements fall into one of the bands below. Your scoping call will confirm which applies, and you’ll receive a fixed quote before any work begins…
| Business Profile | Typical Scope | Indicative Timeframe |
|---|---|---|
| Small | Up to ~15 users, single domain, minimal integrations | 2–3 business days |
| Medium | ~15–50 users, several integrations, shared drives across teams | 4–6 business days |
| Larger / Complex | 50+ users, multiple domains, compliance obligations, sensitive data | 1–2 weeks |
No surprises. You’ll always receive a fixed quote before we begin – not an hourly estimate that can blow out. If anything during the review suggests the scope needs to change, we’ll discuss it with you before proceeding.
What You Receive
Included in every Security Check
- A full risk-rated findings report covering all six review areas
- A prioritised remediation roadmap, ordered by risk and effort
- A results walkthrough call with one of our specialists
- Plain-English summary suitable for sharing with owners or the board
- An optional fixed-price proposal to implement the fixes for you
Ready to simplify your IT & supercharge your growth?
Contact Us
So that we can better serve you, please complete the form below: