Cyber Insurance Renewal Calendar: What to Fix 90, 60, and 30 Days Before Renewal
A practical 90/60/30-day cyber insurance renewal calendar for small businesses that need cleaner answers, better evidence, and fewer last-minute surprises.
Read articleSmall Business Security
A practical Google Workspace security review for small businesses. Eight checks, one hour, no jargon. What to fix, what to skip, and when to get help.
Most Google Workspace security problems are not exotic. They are settings that were never turned on, accounts that were never cleaned up, and apps that were approved once and forgotten. The good news: a real review of a small business Workspace takes about an hour, and most of what you find can be fixed the same day, for free.
This is the review we run. You can run most of it yourself. Where something genuinely needs a specialist, we say so, and where something does not apply at your size, we say that too.
You need one thing to start: access to a super admin account, at admin.google.com. If you do not know who your super admin is, that is finding number one, and it is worth the whole exercise on its own.
Super admins can read anything, reset anyone's password, and delete the company's data. So the first question is simply: who has that power?
In the admin console, look at your user list and check which accounts hold the Super Admin role. What good looks like at a small business:
If one person's everyday account is your only super admin, fix that this week. Create a second, dedicated admin account and store its credentials in your password manager.
This is the single highest-value setting in the entire console. Google requires it for admin accounts, but for everyone else the common failure looks like this: two-step verification is "allowed," most people never set it up, and everyone assumes it is on.
Allowed is not enforced. Check it under Security, then Authentication, then 2-Step Verification, and set enforcement to on for the whole organization, with a short grace period for new hires.
Method matters too. An authenticator app or a passkey is meaningfully stronger than codes sent by text message. Phones get SIM-swapped; app codes and passkeys do not travel with your phone number. Move your admins to passkeys or security keys first, then everyone else as convenient.
Cost of all of the above: zero dollars and one mildly grumpy week of people enrolling their phones.
Every agency and small team has them. The social media login three people know. The client's ad account accessed through one shared password in a spreadsheet. The "info@" inbox everyone can open.
Shared logins are how one incident becomes five. When a password is shared, you cannot tell who used it, you cannot turn off one person's access without turning off everyone's, and it usually cannot have real two-step verification because the second factor is one person's phone.
The review step: list every account that more than one person signs into, inside Google and out. For each one, ask whether the platform supports individual seats (most do: Google, Meta Business Manager, most SaaS tools let you invite users with their own logins and roles). Where individual access exists, use it. Where a shared credential truly cannot be avoided, it belongs in a shared vault in a password manager, with two-step verification attached, not in a document or a chat thread.
If your business manages accounts on behalf of clients, this section is not optional. It is the difference between "we had an incident" and "we had an incident and cannot tell the client who did what."
Every time someone clicks "Sign in with Google" on some new tool, or grants an app access to Drive or Gmail, that app receives a standing key to your data. Those keys do not expire on their own. They keep working until someone revokes them, and in most small businesses nobody ever has.
This is not a theoretical risk. Attackers have used stolen app tokens to quietly export data from hundreds of organizations at once, without ever triggering a login alert, because the access looked like an app doing its job.
In the admin console, go to Security, then Access and data control, then API controls. Two things to do there:
This is the check most likely to produce an uncomfortable discovery, and the one most worth repeating a couple of times a year.
Two questions answer most of it. First: when someone creates a share link, who can open it? If the default is "anyone with the link," a pasted URL in the wrong chat exposes the file to the world. The safer default is sharing to specific people, with link-sharing a deliberate choice. Second: is client work in personal My Drive folders or in shared drives? Files in a personal My Drive belong to that person, and when they leave, access gets messy. Shared drives belong to the business. For any team that handles client files, shared drives are the correct home.
When someone leaves on good terms, sloppy offboarding is untidy. When someone leaves on bad terms, or their account was the one compromised, sloppy offboarding is the incident.
The sequence that works: suspend the account or reset its password immediately, sign out all of its active sessions, revoke its app passwords and connected app access (remember, those app tokens live on until revoked), transfer the person's files and email to a manager, update anything they administered, and remove them from every shared credential they knew, which is a short task if you did section 3 and an archaeology project if you did not.
Write this down as a one-page checklist now, while nobody is leaving. Offboarding is a terrible thing to design during a resignation.
Workspace does a good job filtering what arrives in your inbox. What most small businesses never set up is the other direction: the DNS records (SPF, DKIM, DMARC) that stop criminals from sending email that pretends to be you. Without them, anyone can spoof your domain to phish your clients, and the first you hear about it is an angry phone call.
Checking is easy and free with any of the public DMARC checkers, and this one is a specialty of ours: if your domain has no DMARC record or one that is set to do nothing, that is a fifteen-minute conversation worth having. Your clients' trust in email from your name depends on it.
For agencies especially, Workspace is only half the surface. Meta Business Manager, ad platforms, scheduling tools, analytics, the client accounts you have partner access to. The review step is an inventory: one list of every platform the business touches, who has access, at what role, and through whose login. You will find at least one former employee still attached to something and at least one client account with more access granted than needed. Trim both. Going forward, prefer partner or agency access models over being handed client passwords; they keep you auditable and make your access easy for the client to revoke, which is a feature, not a slight.
In the spirit of telling you when you do not need us: a business of ten to fifty people on a standard Workspace plan does not need to lose sleep over enterprise tooling. Data loss prevention rules, context-aware access policies, eDiscovery and legal holds, and device management beyond the basics all have their place, and that place is usually a larger company, a regulated industry, or a specific contractual requirement. If a vendor is pitching you those before the eight items above are done, they have the order backwards. The fundamentals in this review block the attacks that actually hit small businesses, and every one of them is included in what you already pay for.
Run this yourself and you will catch most of it. The places where an outside set of hands earns its fee: untangling a real incident, setting up DMARC correctly without breaking your newsletters and invoicing email, restructuring years of accumulated sharing and shadow apps, and producing the written policies and documentation that your own clients increasingly ask to see.
That last one matters more than it used to. Businesses are asking their vendors for proof of security practices. A completed review with documentation is not just protection, it is something you can hand a client.
If you want a second set of eyes on your Workspace, book a free briefing. And if you want the ongoing version, our newsletter The Ridge covers practical security for small businesses every other Tuesday, including the weeks when the honest advice is that you need to do nothing at all. Subscribe here.
Last updated
August 14, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Two, not one and not six. One is a single point of failure if the person leaves or gets locked out; more than a few means too many people can do anything. Admin access belongs in a dedicated account, not the account someone uses for daily email.
Enforce it. Google requires 2SV for admin accounts, but for everyone else the common failure looks like allowed-but-optional, where most people never set it up. Set enforcement to on for the whole organization with a short grace period for new hires, and prefer an authenticator app or a passkey over codes sent by text message.
When a user grants an app access to Drive or Gmail, that app receives a standing token that does not expire on its own. Attackers have used stolen app tokens to quietly export data from hundreds of organizations at once, without ever triggering a login alert. Review connected apps regularly and restrict new third-party app access so admin approval is required.
Usually not. A ten-to-fifty-person business on a standard Workspace plan does not need to lose sleep over enterprise tooling. Those features fit larger companies, regulated industries, or specific contractual requirements. The eight-item review here blocks the attacks that actually hit small businesses, and every one of them is already included in what you pay for.
About one hour for the review itself. Most of what you find can be fixed the same day at no additional cost, since the settings live in the plan you already have.
Related reading
A practical 90/60/30-day cyber insurance renewal calendar for small businesses that need cleaner answers, better evidence, and fewer last-minute surprises.
Read articleNonprofits face the same attacks as any business on a fraction of the budget. There's no nonprofit-specific cyber law — but PCI, grant requirements, and state breach laws still bite. The high-leverage, low-cost controls that matter.
Read articleA plain-English guide to small-business EDR options that actually publish pricing, with official vendor numbers normalized into monthly cost.
Read article