Google Workspace security checklist for small business

For most small companies, Google Workspace is the company: email, files, calendar, payroll scans, customer contracts, the password-reset address for every other SaaS account. And it is usually configured the way the founder configured it in year one — one super admin (themselves), 2SV "encouraged," file sharing on "anyone with the link," and three forwarding rules nobody remembers creating. The platform that holds everything is, by default, the easiest door into everything.

The good news: Workspace is also the cheapest major security upgrade a small business can buy. Almost every high-impact control lives in one console, takes minutes, and costs nothing extra. This checklist is the ninety-minute setup pass, plus a thirty-minute monthly ritual that keeps it true. It pairs with the email security checklist (the human layer) and the SPF/DKIM/DMARC checklist (the spoofing layer) — Workspace touches all three.

1. The admin console: who holds the crown jewels

Everything in this checklist starts with one question: who can change the answers?

2. Enforce 2-step verification — and read the exceptions twice

Unenforced 2SV in Workspace is a checkbox, not a control. The enforcement page is Security → Authentication → 2-step verification:

3. OAuth apps: the shadow IT you already approved

The scariest screen in Workspace is Security → API controls → App access control. Every third-party app the team has ever clicked "Sign in with Google" on — CRM trials, PDF converters, that meeting-notes tool — holds a scoped grant to mail, files, or calendar, and most small tenants have never looked at the list.

4. Mail rules: audit forwarding, delegation, and filters

Business email compromise in Workspace rarely breaks the door — it is invited in by a rule the attacker (or a user, "to check email on vacation") created:

5. Sharing defaults: match reality, not paranoia

Drive sharing is where small businesses oscillate between "anyone with the link" (leaks) and "locked down" (users forge workarounds with personal accounts, which leaks worse). Pick defaults that match how the company actually works:

6. Offboarding and the license trap

Workspace's quiet failure mode: an offboarded employee keeps mail flowing for months because deleting the account deletes the mailbox archive someone will need for the contract dispute.

7. Email authentication: your domain, not your provider's problem

Workspace sends mail as your domain; the world has no way to know that unless your DNS says so. This is a fifteen-minute setup with a permanent payoff (the deep how-to lives in the SPF/DKIM/DMARC checklist):

8. Sessions, devices, and the audit trail

9. The mistakes small teams make anyway

10. Close the loop: the monthly 30-minute pass