top of page

Google Workspace Audit for Small Businesses

For businesses running Google Workspace but unsure if it's configured correctly.

What Is This?

A Google Workspace Audit is a comprehensive review of how your Google Workspace environment is currently configured. I audit your email security, access controls, sharing policies, data loss prevention, compliance settings, and mobile device management to identify gaps between how it's set up and how it should be configured for security and compliance.

The result is a clear report showing what's working, what's misconfigured, and what's missing with specific recommendations to fix it.

Why You Need It

Most businesses activate Google Workspace out of the box using default settings. Default settings prioritize ease of use over security. You might have external sharing turned on too broadly. MFA might not be enforced. Data transfer restrictions might not be in place. Email security might lack anti-phishing protections. File retention might not match your compliance requirements.

A workspace audit finds all of this and tells you exactly what to fix.

Who This Is For

Any small business running Google Workspace. Businesses that set up Google Workspace themselves without IT expertise. Companies that inherited a Workspace setup from someone who left or didn't document it. Organizations preparing for cyber insurance renewal and uncertain their Workspace configuration matches their application. Regulated businesses (healthcare, financial services) that need Workspace configured to compliance standards. Companies that have had a security incident and want to know if Workspace played a role.

What Happens When Google Workspace Isn't Configured Properly
  • External sharing is too permissive. A customer file or internal document gets shared with an open link and the link spreads beyond your control.​

  • MFA isn't enforced. A staff member's password is compromised and an attacker gains access to company email and files with no second factor stopping them.

  • Data transfer isn't restricted. An employee or compromised account can download files to personal devices or forward them outside the organization without triggering an alert.

  • Security policies are missing. Attachments with malware get through to staff inboxes. Phishing emails aren't being flagged.

  • Gmail forwarding rules allow data exfiltration. A compromised account can automatically forward all email to an external address without anyone noticing.

  • Sharing is enabled at the domain level too broadly. Anyone with a link can access sensitive files.

  • Audit logging isn't enabled. If something goes wrong, you have no record of who did what and when.

  • Retention policies aren't set. You're storing data longer than required, creating liability, or deleting data you need to keep for compliance.

  • Device access isn't managed. Someone accessing Google Workspace from a compromised device or unusual location isn't being blocked.

  • Cyber insurance denies a claim because your Workspace configuration doesn't match your application. You stated you have MFA and security policies but they're not actually configured.

What's Included

Email Security Review

  • MFA enforcement status across the organization

  • Email forwarding rules and external access

  • Gmail security sandbox and attachment handling

  • Security toolbox settings (pre-delivery message scanning)

  • Attachment and file type policies

Data Sharing & Collaboration

  • External sharing settings for Drive

  • Shared drive sharing permissions

  • Link sharing permissions and expiration

  • Team Drive access controls

  • Google Meet and collaborative tools access

Compliance & Audit Logging

  • Audit logging enabled and retention

  • Gmail audit settings

  • Drive audit logging

  • Meet audit logging

  • Compliance reports available for your industry

Access Control & Security

  • MFA requirements and enforcement

  • Device policies and mobile device management

  • Password requirements and complexity rules

  • Login challenge frequency and settings

  • API access and OAuth app restrictions

Data Loss Prevention & Retention

  • Vault and retention settings

  • Gmail retention policies

  • Drive file retention

  • Meet recording retention

  • Data transfer restrictions

Security Posture

  • Security checkup and alerts

  • Suspicious sign-in attempts

  • Less secure app access

  • Advanced Protection Program eligibility

Prioritized Recommendations

  • Critical gaps and quick wins

  • Configuration improvements with high security impact

  • Compliance alignment

  • Cyber insurance readiness improvements

What You Get

Written Audit Report
Comprehensive documentation of your Google Workspace configuration with findings, gaps, and specific recommendations.

Executive Summary
High-level overview of your current security posture and the top 5-10 items that need attention.

Detailed Configuration Review
Complete audit of email security, access controls, data sharing, retention, compliance, and device management settings.

Gap Analysis
Specific gaps identified with severity rating (Critical, High, Medium, Low) and security impact.

Prioritized Action Plan
Clear recommendations for what to fix and in what order, with step-by-step guidance where applicable.

Cyber Insurance Readiness
Assessment of how your configuration aligns with what insurance carriers require.

Compliance Alignment (if applicable)
Review against HIPAA, FTC Safeguards, or other regulatory requirements your business faces.

Consultation Call
30-minute call to walk through the audit findings, answer questions, and discuss implementation options.

Pricing

$995 flat

No hourly billing. Fixed price regardless of workspace size or complexity.

Timeline

Audit typically takes 1-2 weeks. I'll review your configuration, test access controls, validate policies, and compile the report. You get the written audit and a 30-minute consultation call to review findings.

What Happens After

You get the audit report. You can:

  1. Use it to make configuration improvements yourself

  2. Use it for cyber insurance applications or renewal

  3. Use it as justification to hire IT support to implement the recommendations

  4. Share it with another IT provider for implementation.

This audit stands on its own. It's yours to use however you want.

Frequently Asked Questions

How is this different from just reviewing Workspace myself?

You could review settings manually, but it's time-consuming and easy to miss configuration gaps. An external audit also carries credibility with cyber insurance carriers and compliance auditors. I also provide specific recommendations and prioritization you might not come up with on your own.

Will you tell me what to do to fix these issues?

Yes. The audit includes specific recommendations for fixing each gap, prioritized by security impact. Some recommendations include step-by-step guidance you can follow. Others are more complex and might benefit from IT support to implement correctly.

How bad is it usually?

Most small businesses have Google Workspace set up with default or partially optimized settings. Common gaps include MFA not enforced everywhere, external sharing too permissive, and data transfer restrictions missing. Usually nothing catastrophic, but usually multiple things worth fixing.

Can this audit be used for cyber insurance renewal?

Yes. That's actually a common use case. Many businesses use the audit to document their Workspace security posture for insurance applications. If the audit identifies gaps, you can fix them before renewing or use the audit to justify a premium increase to the carrier.

What if I'm also running Microsoft 365?

I offer a separate Microsoft 365 Tenant Audit for $995. Many businesses use both Workspace and M365. You can audit them separately or together.

Do I need to do this every year?

Google makes changes to Workspace regularly, and attackers are always finding new ways in. An annual audit is good practice, especially before cyber insurance renewal. If you're implementing recommendations from this audit, you might want a follow-up audit after implementation to verify everything's working correctly.

What if the audit finds something we need to fix immediately?

I'll flag critical issues so you can address them right away. You won't wait for the final report to find out about a serious problem.

Can you implement the recommendations for us?

Yes. I can do that as a separate engagement. The audit findings become the foundation for implementation work, either as a standalone project or as part of an ongoing managed IT relationship.

Ready to know how your Google Workspace is actually configured?

bottom of page