Live data from Hacker News

A practical guide to securing Google Workspace for a startup

fleetdm.com

51–60 of 64 posts

Re: A practical guide to securing Google Workspace for a startup

#51

Given Google's capacity for freezing organizations and individuals (even those who are paying customers of its products) from Google services out of the blue and with little to no recourse, I'd most recommend that you secure your startup best by simply not even using google for key parts of its operations if at all possible.

And all the downvotes! From the same site in which so many other people complain about so many ways in which Google hurt them or their business in some way. Absurd.

Re: A practical guide to securing Google Workspace for a startup

#53

My advice is to never, ever, ever rely on Google Workspace for a startup. Office 365 is a little bit less usable, but Microsoft can work with businesses. I used Google Workspace for a startup. Startup went idle for a while. Google sent a message to me warning the account would be terminated unless I logged in on some short timeline. GMail filed its own email as spam. Boom. Everything from that startup was gone. I use…

If your business relies on it, whatever "it" is, then you probably need to pay for it, so that if it has some serious problem, you can call up a human and either beg or yell at them to fix it, depending on the situation.

I've always thought it madness to even rely on gmail for a business, who can cancel you whenever.

Re: A practical guide to securing Google Workspace for a startup

#54
I’m surprised you disable the google drive feature. We’re not that worried about local files leaking even if the laptop is stolen, given apple’s hardware encryption.

On the other hand, the workflow of “manually download file, modify file in app, manually upload file” is clumsy and error prone, often leaving files stranded on the laptop.

On the gripping hand, google drive (as it is called again) seems to crash every few days so perhaps your restriction isn’t much of a limitation :-(

Re: A practical guide to securing Google Workspace for a startup

#56

I was hoping that there will be something in the guide for session hijacking. I recently seen many youtubers having their channel hijacked due to hackers taking over their Google account.

That requires their endpoint to be compromised, doesn't it?

Re: A practical guide to securing Google Workspace for a startup

#57
post #2

This is how we secure Workspace here at Fleet. We figured the guide could be useful to companies of a similar size. The next step would be to enable Endpoint Verification to control access to specific apps such as Drive so it could only be done from up to date, encrypted devices, but that requires a the highest Google subscription.

Super cool, thanks so much for publishing. I’ll even use this for my families Google business personal emails - I have found the Google apps admin to be a bit intimidating and I was nervous to adjust defaults but the quarantine options seem very approachable and valuable.

It’s also been a while since I’ve seen a nice quick Mac OS security settings list to go ahead and toggle.

My only request would be additional guide for iOS security. The iVerify app suggests some good defaults

Re: A practical guide to securing Google Workspace for a startup

#58

Another tip - enabled Advanced Protection Program. You can't enforce this at the GSuite level but for a small company it's easy to just audit for it. We have everyone do this as part of onboarding and we audit once a month.

I enjoy the enhanced security that advanced protection program offers but miss being able to use gmail in exchange mode specifically because it allows receiving push notifications for new emails without having to trust gmail’s iOS app which always spooks me as being an extra tracking app on my phone

Re: A practical guide to securing Google Workspace for a startup

#59
post #35

It never made sense to me that large software suites like these don't offer a secure by default option on creation or as a progressive migration after creation. Why soo many steps...

Secure is very subjective. One of the tasks in the article is enabling email quarantine for encrypted attachments. What if an org receives a lot of encrypted attachments as part of their business, that option would slow them down. Or what if an organization is in a country that can’t easily receive yubikeys, why would they want to enforce those?

Re: A practical guide to securing Google Workspace for a startup

#60
post #7

Thanks for this! THis kind of domain security is usually poorly articulated or just not out in the open. I still think the basis of most risk for small companies is their domains. Lose control of those and well.. you're fucked. Any recs for "high security" domain providers?

You are 100% right that the domain is the keys to the kingdom. Definitely only use registrars and DNS providers that have 2FA. Google has a registrar now, as well as DNS in GCP https://cloud.google.com/domains/docs/register-domain and https://cloud.google.com/dns . By using those you can leverage your Google account's security (use separate accounts for admin level access on GCP and enforce hardware 2FA), and control…

Cloudflare also offers a registrar and 2FA if you don’t want all your eggs in one basket (and I would recommend not putting every egg in one basket since Google occasionally does shut down accounts and you’d even future emails if you are locked out of their registrar)
Post reply on HN