TECHNOLOGIES: GOOGLE WORKSPACE

Google Workspace Security Review

Google Workspace security lives in admin console settings, not code: a role, sharing default or OAuth grant nobody rechecked becomes the way in. We test what your admins actually configured. CREST-certified testers, fixed price from £3,540 for a 3-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Google Workspace Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Console

Every meaningful Google Workspace control, who holds admin rights, what Drive can share, which apps can connect, lives in the admin console rather than in code you can review.

A Google Workspace tenant is only as secure as the console settings your admins have reviewed

Google publishes its own security checklist for medium and large businesses, built around exactly the settings an admin controls: who holds the super admin role, which domains can receive shared files, and which third-party apps can read Gmail and Drive. The checklist exists because those settings, not a vulnerability in Google’s platform, are what decide whether a tenant holds up under real pressure.

That breadth is the difficulty. A super admin can, in Google’s own words, manage every aspect of your organisation’s account and holds full access to every user’s calendar and event details, while a delegated admin might work from a single scoped privilege instead. Sitting alongside that is domain-wide delegation, where an authorised service account has access to the data belonging to all of your users, and Google’s own guidance is to restrict its scopes and review it regularly, because those scopes limit what data the account can read, not which users it can read it from.

We test the tenant you actually run: the roles assigned, the sharing settings left on, the apps granted access and the recovery paths available if a password is compromised. We never test Google’s own infrastructure, in the same way we test client configuration on Microsoft 365 tenants rather than Microsoft’s platform.

SCOPE

What we review in a Google Workspace tenant

GW-01

Super Admin and Delegated Admin Roles

A super admin can, by Google’s own definition, manage every aspect of your organisation’s account and holds full access to every user’s calendar and event details, while every other admin works from either a prebuilt role, such as User Management or Groups Admin, or a custom role built with only the privileges you choose. We test how many people actually hold the super admin role, whether any custom role grants more than its job needs, and whether a role meant to be limited can still reach data it was never scoped for.

GW-02

2-Step Verification Enforcement and Security Keys

2-Step Verification can be left optional, enforced from a set date, or enforced immediately by organisational unit or group, and Google separately enforces 2SV for administrator accounts on top of whatever policy you set for everyone else. We test whether enforcement is actually active for every admin it is meant to cover, and whether the accounts holding the most privilege are the ones required to use a security key rather than a weaker method.

GW-03

Drive Sharing Outside Your Organisation

External sharing in Drive can be turned off entirely, opened to any Google Workspace domain, or restricted to an allowlist of trusted domains, and Google’s own checklist recommends warning users whenever they share a file outside the domain. We test what the current setting actually allows against what it is meant to allow, and whether an allowlist exists on paper but has drifted since the domains on it were last reviewed.

GW-04

Link Sharing on Individual Files and Folders

Separately from the organisation-wide sharing setting, each file or folder carries its own link sharing option, and a link created as Viewer, Commenter or Editor keeps that permission for anyone who has the link until it is changed. We test what link sharing actually exposes on files in scope, whether sensitive folders rely on a link rather than named access, and whether the indicator that flags an externally shared file is switched on.

GW-05

Shared Drives and Membership Access Levels

A shared drive belongs to the organisation rather than to the people who created it, so files stay in place even after every original member has left, and each member is assigned an access level, Manager, Content Manager, Contributor, Commenter or Viewer, that decides whether they can add, edit, move or only view content. We test shared drive membership against who should actually hold Manager or Content Manager access, and whether a Contributor or Viewer account can still reach more than its access level allows.

GW-06

Third-Party App Access to Core Services

Every third-party or internal app that has requested access to Google data is either left unconfigured, trusted, limited or blocked in the admin console’s API controls, and Google’s own guidance treats an unconfigured app as different from one that has actually been reviewed and approved. We test the current access policy against what those apps can actually do with Gmail, Drive and Calendar data, and whether an app you no longer use still holds a live authorisation.

GW-07

Domain-Wide Delegation to Service Accounts

Authorising a client ID for domain-wide delegation gives that service account access to the data belonging to all of your users, and the OAuth scopes you set only limit the type of data it can reach, not which users it can reach. We test every authorised client ID against the scopes it actually needs, and whether a service account nobody remembers creating is still sitting in the domain-wide delegation list.

GW-08

External Collaboration in Groups, Chat and Calendar

Groups can be set to Private so only members of your domain can view them, Chat can be limited so only approved people are allowed to message or create spaces with external users, and Calendar has a separate organisation-wide limit on how much detail people outside the organisation see, down to free/busy status only. We test whether each of these three settings matches what your organisation actually intends, since a gap in any one of them lets internal content reach an external account.

GW-09

Account Recovery for Admins and Users

Users can reset their own password using a recovery phone number or email address they add themselves, but anyone with 2-Step Verification turned on can only use a recovery email for that reset, and where an organisation runs single sign-on or Password Sync this setting does not apply at all. We test who has recovery information configured, whether admin accounts rely on the same self-service path as everyone else, and what actually happens when a user without recovery information asks to get back in.

GW-10

Email Authentication and Security Monitoring

SPF names the servers allowed to send as your domain, DKIM signs outgoing mail with a key pair generated in the admin console, and DMARC tells receiving servers what to do with mail that fails either check, typically starting at monitor-only and moving up to quarantine or reject as confidence grows. Alongside that, admin email alerts flag events such as suspicious sign-in attempts or a setting changed by another admin, and the audit and investigation tool searches sign-in activity and configuration changes across the tenant. We check that all three DNS records are actually in place and consistent, and that alerts and audit logs reach someone who will act on them.

OUR PROCESS

Google Workspace Security Review: From Scope to Attestation

01

Scope and Access

We agree which Workspace tenant, organisational units and admin accounts are in scope, plus at least one login for each distinct role and privilege tier you use.

02

Configuration and Role Mapping

We map every super admin, delegated admin and custom role against the privileges each one actually holds, alongside the current Drive, Groups, Chat and Calendar sharing settings.

03

Manual Testing

A CREST-certified tester manually tests OAuth app grants, domain-wide delegation, 2-Step Verification enforcement and account recovery paths, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Google Workspace pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Google Workspace Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,540–£5,200
3 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,320–£12,670
6 to 8 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Google Workspace Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Google Workspace tenant?

We need at least one account for each distinct role you use, including a super admin login and any delegated or custom admin roles, plus a small number of standard user accounts. Read access to your current sharing settings, API controls and domain-wide delegation list speeds up several checks, but is not required to start.

Will testing touch our live data?

Testing focuses on configuration, roles, sharing settings, OAuth grants and recovery paths, rather than the content of your mail or files. Where proving a finding needs a real file or message, we agree the exact test data with you first and remove anything we create once testing is complete.

Is this hosted on our infrastructure or Google’s?

Google Workspace runs entirely on Google’s infrastructure, so there is nothing for you to host. The test is scoped to the tenant configuration you control, admin roles, sharing settings, connected apps and recovery options, not to Google’s platform itself.

How long does a Google Workspace security review take?

A single tenant with a typical set of admin roles and connected apps sits in our 3-day single-tenant scope, with a report usually landing around 5 working days after kickoff. A tenant with more delegated admin roles, a larger number of authorised OAuth apps or several domain-wide delegated service accounts extends that scope.

What is out of scope for a single-tenant review?

Testing Google’s own infrastructure, data centres or multi-tenant hosting is never in scope, and we do not run denial-of-service testing against any Google service. A separate application that only happens to connect to your tenant through an API is scoped and quoted as its own engagement.

Does Google have a customer penetration-testing policy we need to follow?

Google’s published policy for its Cloud Platform confirms customers do not need to contact Google before testing their own Cloud Platform infrastructure, provided testing stays within their own projects and avoids denial-of-service activity. That policy is written for Cloud Platform infrastructure rather than Workspace admin console configuration specifically, so we confirm Google’s current terms and any account-specific conditions for your tenant during scoping.

Do you need our source code or admin access?

No. There is no source code in a standard Workspace tenant. We test with the role accounts and access you provide, and do not need standing admin access beyond what is needed to verify a specific finding during the engagement.

Are your testers CREST certified?

Yes. Every Google Workspace engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Google Workspace tenant

Google Workspace security lives in admin console settings, not code: a role, sharing default or OAuth grant nobody rechecked becomes the way in. We test what your admins actually configured. CREST-certified testers, fixed price from £3,540 for a 3-day single-tenant scope, quoted within 24 hours.