hostme.ie YOUR IT DEPARTMENT
Home› Blog› Security
Security

Google Workspace security for small teams

Review Google Workspace sign-in, sharing, devices and recovery. Check which controls your edition includes, with practical next steps for your small business.

A person holding a phone with a sign-in screen beside an office keyboard.

A lost phone, an old sharing link or a forgotten administrator account can interrupt a small business even when its email platform is secure. Google Workspace provides security controls, but someone still needs to decide who can access business information, configure the available settings and check that recovery works.

Start with accounts, sharing and devices. Check your actual Workspace edition before planning advanced controls: a feature described in Google’s documentation is not necessarily included in your subscription.

1. Protect administrator access and recovery

Keep everyday email separate from privileged administration. Give routine administrators only the roles their work requires and review those roles when responsibilities change. Google’s small-business security checklist recommends an additional super administrator managed by a different person. A sole trader should agree a practical recovery arrangement rather than share one administrator password.

Keep recovery details current and store emergency information securely outside the account it recovers. Record who controls the domain and can help prove ownership. Do not put passwords, recovery codes or private keys in a shared planning spreadsheet.

2. Roll out stronger sign-in without locking people out

Use Google’s 2-Step Verification guidance to plan enrolment and enforcement. Start with administrators and staff handling sensitive information, then complete the wider rollout. Confirm each person has enrolled and has an approved recovery route before the enforcement deadline. Test the process with a small group first.

Prefer phishing-resistant security keys or passkeys where supported by the chosen policy and devices. A passkey can replace password-based sign-in when the administrator enables that option; it is not simply another name for an SMS code. Check the passkey settings before changing the sign-in experience.

For people at elevated risk of targeted attacks, consider the Advanced Protection Programme. It supports passkeys or security keys and restricts some third-party access. Check essential applications and recovery arrangements first; enrolment is not an automatic recommendation for every account.

3. Review sharing and connected applications

Check who can open new files, how external sharing works and whether older public links are still needed. Changing a default is not evidence that every existing file is private. Review sensitive folders and named external collaborators separately, with the information owner deciding what access remains necessary.

Review third-party applications through Google’s app access controls. Check the application’s purpose, requested access and owner before approving or removing it. Removing an integration can interrupt a working process, so record the decision and test the result. Review Gmail forwarding and delegation alongside file access.

Which controls depend on your edition?

  • Security center and investigation: Google’s security center documentation lists supported editions and notes that available settings vary. Do not assume the advanced investigation features are included with Business Starter, Standard or Plus, or confuse them with ordinary audit logs and alerts.
  • Data loss prevention: Drive DLP has licensing and privilege requirements. Gmail and Drive capabilities should be checked separately. A rule also needs a defined purpose, testing and an owner to review findings; it is not a universal switch that prevents all leaks.
  • Context-Aware Access: supported editions, apps and platforms determine where access conditions apply. Pilot any device or location restriction, confirm emergency administrator access and check unsupported clients before a wider rollout.

If an advanced feature is unavailable, document that gap and assess whether it matters to the business. Complete the account and sharing checks already available before buying an upgrade solely because a checklist mentions one.

4. Know what a device action will remove

Keep an inventory of devices accessing company information, including personal devices. Agree screen-lock, encryption and update requirements, then verify how each platform enforces them. Workspace management capabilities depend on the operating system, enrolment, management mode and subscription.

Account wipe and device wipe are different actions. Google’s wipe reference explains which data is removed for each setup. Some actions reset the entire device and remove personal data. Never promise that a wipe always leaves personal photographs untouched.

A pending wipe is not proof that data has been removed. Offline devices may not receive it immediately. Drive for desktop account wipe removes streamed content, while mirrored content can remain; some unsynced edits on macOS can remain too. Verify the actual outcome and handle copies outside the managed application separately. Wiping one device does not close an active account’s access on every other device.

5. Assign someone to review alerts and respond

Decide who reviews the logs and alerts available in your edition, how they are contacted and who can authorise containment. Investigate suspicious activity in context; a location alert alone is not proof of a compromise.

For a suspected compromised account, follow Google’s compromised-account checklist. It begins with temporary suspension, followed by investigation and recovery. Have an authorised administrator preserve relevant evidence, review unexpected access and configuration changes, and restore access only after the cause has been addressed. Arrange specialist incident support where necessary. Do not delete the account or its evidence as a shortcut.

Make the review repeatable

Use a scheduled review, plus checks when someone joins, changes role or leaves. For each issue record the owner, proposed change, business impact, due date and evidence of the result. A quarterly review can be a starting point, with frequency adjusted to your risk and changes.

Common questions

Can an administrator see personal browsing history?

There is no universal answer across company devices, managed browsers and personal profiles. Workspace account logs and Chrome management are different systems. Chrome reporting policies can expose browser, application and security-event information depending on configuration. Check what is managed, the enabled reporting and your organisation’s policy rather than assuming all browsing is visible or private.

Does this replace a backup or recovery plan?

No. Access controls, retention and recovery serve different purposes. Decide what information the business needs to recover, how recovery will be performed and who will test it. Do not treat a security checklist as proof that every deleted or damaged file can be restored.

Get help with your Workspace setup

hostme.ie provides Google Workspace setup, migration and administration support. Agree the scope of a security review or configuration project before work starts; substantial changes are separately scoped from routine ongoing support.

Talk through your Workspace security on WhatsApp

Technical references reviewed on 24 September 2026. Check the linked Google documentation and your Admin console for current availability before making changes.

Got a question about this?
Message me and I'll talk it through — no charge, no jargon.
Message me