Google Workspace is secure by design, but "secure by default" is not the same as "secure for you." Out of the box it leaves several important controls switched off or set loose, and a small business that never opens the admin console is running on those defaults. The good news is that a handful of settings, most of them free on the plan you already pay for, close the gaps that attackers actually use. Here is the short list worth an afternoon.
Start with sign-in
The single biggest win is enforcing 2-Step Verification for everyone, not just offering it. In the Admin console you can require it, and you should, ideally pushing people toward an authenticator app or a passkey rather than SMS codes. While you are there, turn off access to "less secure apps" and legacy sign-in methods that bypass the second step, the same class of back door that lets attackers past MFA elsewhere.
Limit what leaves the building
By default, people can share Drive files broadly and forward mail freely. Tighten external sharing so files are not "anyone with the link" by accident, restrict automatic mail forwarding to outside addresses (a favourite trick for quietly siphoning a mailbox), and review which third-party apps staff have connected to their accounts. Each connected app is a door you did not build; remove the ones nobody uses.
Turn on the alarms
Workspace can warn you about suspicious logins, unusual sharing, and account changes, but someone has to be listening. Set up admin alerts so an odd sign-in from a new country or a sudden mass-download does not pass unseen. On the right editions you also get security dashboards and investigation tools; even on the basics, the alert emails are worth switching on.
Protect the admin account itself
Your super-admin account is the keys to everything, so give it phishing-resistant 2-Step Verification (a passkey or hardware key), do not use it for day-to-day email, and keep the number of admins small. One compromised admin is a far worse day than one compromised mailbox.
A quick baseline
- Enforce 2-Step Verification for all users; prefer app or passkey over SMS.
- Block legacy and "less secure app" sign-in.
- Restrict external Drive sharing and outbound mail forwarding.
- Review and prune connected third-party apps.
- Turn on admin alerts; protect super-admins with a hardware key.