Not every business needs to move to Microsoft 365 - plenty of Perth businesses run Google Workspace well and have no reason to change platforms. What matters more than which platform you're on is whether it's actually configured securely. Most Google Workspace environments we review are running on default settings, with several of the most effective protections switched off. Here's what to check.
Enforce 2-Step Verification for every user
2-Step Verification (2SV) is Google's equivalent of MFA, and it's the single biggest security gap we find in unmanaged Google Workspace environments. From the Admin console, 2SV can be enforced organisation-wide with no exceptions - including for admin accounts, which should always have the strongest protection available (security keys or the Google prompt, rather than SMS codes).
Turn on context-aware access
Available from Business Standard up, context-aware access restricts sign-ins based on conditions like whether the device is managed, its location, or its security posture. This is Google's answer to blocking the most common account takeover pattern - a stolen password being used to sign in from an unfamiliar device or country.
Review third-party app access regularly
"Sign in with Google" makes it easy for staff to connect third-party apps to their account, and each connected app is a potential access point if that app is ever compromised. The Admin console shows every third-party app with access to your domain's data - review this list periodically and revoke anything no longer in use.
Lock down admin accounts specifically
Super Admin accounts should be used only for actual administration, never for daily email and document work. A dedicated admin account, with the strongest available 2SV method and no email inbox actively used day to day, significantly reduces the chance of it being phished.
Set up Google Vault for retention and e-discovery
Available on Business Plus and above, Vault lets you set retention policies on email and Drive files, and supports legal holds and e-discovery searches. This matters for any Perth business with compliance obligations, ongoing legal exposure, or simply a desire not to lose records to accidental deletion.
Apply data loss prevention (DLP) rules
DLP rules, available on Business Standard and above, can automatically flag or block emails and files containing sensitive data patterns - credit card numbers, tax file numbers, or custom patterns you define. This is a practical control against accidental data leakage, not just malicious activity.
Manage device access with endpoint management
Google Workspace's endpoint management can enforce screen lock, encryption, and remote wipe on devices accessing company data - including personal phones used for work email. This is worth enabling even for a small team, since a lost phone with an active Gmail session is a genuine data exposure risk.
Train staff to spot phishing specifically targeting Google accounts
Fake Google security alerts, fraudulent shared-document notifications, and OAuth consent phishing (a fake app asking for permission to your Google account) are common attack patterns aimed specifically at Google Workspace users. See our guide to common phishing email tactics for what these look like in practice.
Not sure if Google Workspace still fits your business?
Good security hygiene matters regardless of platform, but it's worth periodically checking whether Google Workspace is still the right fit as your business grows. We cover the practical triggers in Signs It's Time to Switch from Google Workspace.
Frequently Asked Questions
Does Google Workspace have MFA built in?
Yes - it's called 2-Step Verification (2SV) and it's available on every Google Workspace plan. Admins can enforce it organisation-wide from the Admin console, and it supports security keys, the Google Authenticator app, and prompts sent to a phone. Enforcing it for every user, with no exceptions, is the single highest-impact security change most businesses can make on Google Workspace.
Is Google Workspace secure enough for a small business without an IT team?
The platform itself is enterprise-grade and ISO 27001 certified, so the underlying infrastructure isn't the weak point. The risk is almost always in configuration - 2-Step Verification not enforced, no context-aware access rules, admin accounts without extra protection, or staff never trained to spot phishing. A properly configured Google Workspace environment is genuinely secure; a default, untouched one is not.
What's the Google Workspace equivalent of Microsoft Conditional Access?
Context-aware access, available from Business Standard up, lets admins restrict access based on conditions like device security status, IP address, or location - similar in concept to Microsoft's Conditional Access. It's less granular than Microsoft's implementation but covers the core use cases: blocking sign-ins from unmanaged devices or unexpected locations.
Want a security review of your Google Workspace setup?
We support both Google Workspace and Microsoft 365 for Perth businesses. We'll check your configuration against best practice and fix what's missing.
Get a Free ConsultationFor related reading, see our Cybersecurity Checklist for Perth Small Businesses and MFA Setup for Perth Businesses.