Live data from Hacker News

A practical guide to securing Google Workspace for a startup

fleetdm.com

1–10 of 64 posts

Re: A practical guide to securing Google Workspace for a startup

#2
This is how we secure Workspace here at Fleet. We figured the guide could be useful to companies of a similar size. The next step would be to enable Endpoint Verification to control access to specific apps such as Drive so it could only be done from up to date, encrypted devices, but that requires a the highest Google subscription.

Re: A practical guide to securing Google Workspace for a startup

#4
post #2

This is how we secure Workspace here at Fleet. We figured the guide could be useful to companies of a similar size. The next step would be to enable Endpoint Verification to control access to specific apps such as Drive so it could only be done from up to date, encrypted devices, but that requires a the highest Google subscription.

I'm excited to see how Guillaume is sharing our security journey as Fleet grows!

Re: A practical guide to securing Google Workspace for a startup

#6

Love how everything is out in the open....big fan of transparency !

Thanks. There is no need to keep most security controls for common tools secret, and the more organisations discussing how they do it the better.

For example, a small org with no security people or a non-profit could be made much more secure by following this, so why not publish it?

Re: A practical guide to securing Google Workspace for a startup

#7
Thanks for this! THis kind of domain security is usually poorly articulated or just not out in the open. I still think the basis of most risk for small companies is their domains. Lose control of those and well.. you're fucked. Any recs for "high security" domain providers?

Re: A practical guide to securing Google Workspace for a startup

#10
post #7

Thanks for this! THis kind of domain security is usually poorly articulated or just not out in the open. I still think the basis of most risk for small companies is their domains. Lose control of those and well.. you're fucked. Any recs for "high security" domain providers?

You are 100% right that the domain is the keys to the kingdom.

Definitely only use registrars and DNS providers that have 2FA. Google has a registrar now, as well as DNS in GCP https://cloud.google.com/domains/docs/register-domain and https://cloud.google.com/dns. By using those you can leverage your Google account's security (use separate accounts for admin level access on GCP and enforce hardware 2FA), and control who gets access using IAM. AWS has similar options.

Post reply on HN