Google Workspace security audit
Your company's email, documents, meetings and identities all live inside Google Workspace. A single misconfiguration —a super admin without 2FA, an OAuth app with excessive permissions or a forgotten domain-wide delegation— can give an attacker access to the entire business. We review your Workspace with the same mindset as someone trying to compromise it.
Is your Google Workspace secure, or does it just look secure?
Google secures its infrastructure, but your tenant configuration is your responsibility. Most Google Workspace compromises don't exploit a flaw in Google: they exploit default settings, excessive permissions, uncontrolled third-party apps, malicious forwarding rules and poorly protected admin accounts. A real audit doesn't just review a checklist of settings: it simulates what an attacker would do with a compromised account and shows you how far they could get inside your organization.
What the Google Workspace audit covers
- Admin accounts: number of super admins, 2FA with security keys and least privilege
- Authentication and access: 2-step verification, passkeys, session length and Context-Aware Access
- Third-party and OAuth apps: connected applications, granted scopes and consent phishing risk
- Domain-wide delegation and service accounts: the DeleFriend-style vector
- Gmail: suspicious forwarding rules and filters, SPF/DKIM/DMARC and anti-phishing protection
- Google Drive: external sharing, public links and exposure of sensitive data
- Data loss prevention (DLP) and compliance rules
- Audit and investigation logs: visibility, retention and detection capability
- Device management (endpoint/MDM) and access from unmanaged devices
- Employee offboarding and orphaned accounts
How we run the audit
- Scope and access: We define the scope and obtain audit access (a read-only role or test credentials). We agree which active tests are allowed and within which window.
- Configuration review (CIS): We evaluate the tenant configuration against the CIS Google Workspace Benchmark and hardening guides: accounts, authentication, Gmail, Drive, Chrome and logging.
- Attack surface analysis: We enumerate connected OAuth apps, domain-wide delegations, service accounts, forwarding rules and external shares to identify real attack vectors.
- Controlled offensive simulation: We reproduce real attacker techniques (OAuth abuse, Gmail persistence, delegation abuse) in an agreed environment to confirm the real impact.
- Report and remediation: We document every finding with evidence, severity (CVSS) and business impact, and deliver a prioritized remediation plan with concrete steps for the admin console.
What you get when we finish
- Executive report: risk level of the collaboration environment, for management and the CISO
- Technical report: findings with evidence, CVSS and admin console remediation steps
- A map of OAuth apps and domain-wide delegations with their risk level
- Prioritized hardening checklist against the CIS Google Workspace Benchmark
- Closing meeting with your IT or Workspace administration team
- Optional re-test to verify that critical findings have been fixed
When should you audit your Google Workspace?
- Your company runs everything on Google and has never audited the tenant configuration
- Before or after migrating to Google Workspace, or after rapid user growth
- After an incident or suspicion of unauthorized access, phishing or CEO fraud (BEC)
- When a client, investor or auditor requires you to prove the security of the environment
- To comply with NIS2, ENS or ISO 27001 for email and collaboration
- If you connect many marketplace third-party apps without a review process
Frequently asked questions about the Google Workspace audit
Do you need admin access to our Workspace?
For the configuration review, a read-only admin role or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA).
Does the audit disrupt employees' work?
No. Most of it is configuration and attack-surface analysis, which doesn't affect users. The few active tests are agreed and run in a controlled way so they don't impact operations.
How is this different from the recommendations Google already shows?
Google's panels flag recommended settings, but they don't think like an attacker or chain vectors together. We look for the real compromise path: a forgotten OAuth app, a dangerous domain-wide delegation or a forwarding rule that keeps access even after a password change.
Do you also audit Microsoft 365?
Yes. We apply the same offensive methodology to Microsoft 365 (Entra ID, Exchange Online, SharePoint). If you use both, we audit both environments and their integration points.
Is the report valid for compliance (ENS, ISO 27001, NIS2)?
Yes. The report documents the security posture of your email and collaboration environment against recognized frameworks (CIS Benchmark) and is valid as evidence for ENS adequacy, ISO 27001 certification or NIS2 compliance.