Sign-in security
2-Step Verification enforcement, security keys and session controls.
Google Workspace is secure by design but rarely configured securely. We review your admin settings, accounts, sharing and email security, and fix the gaps that attackers and accidental leaks exploit.
A configuration review of your Google Workspace tenant with prioritised fixes, and optional hands-on hardening with your administrator.
Most Workspace incidents come from weak sign-in controls, too many administrators, files shared publicly by link, and email that can be spoofed. These are configuration problems, cheap to fix and expensive to ignore. They also matter under the PDPA's Security Principle, since Drive and Gmail hold much of an organisation's personal data.
2-Step Verification enforcement, security keys and session controls.
Super admins and delegated roles reviewed.
External and link sharing, shared drives and exposed files.
Phishing and malware protections and email authentication.
Mobile device management and third-party app access.
Alert centre and audit logs.
High-impact fixes first.
Public links found and closed.
Strong sign-in enforced.
Evidence for the Security Principle.
Fixes your admin can apply.
Read-only admin access agreed.
Settings, accounts and sharing.
Prioritised report.
Optional fixes with your admin.
Confirming changes.
Findings by risk.
Step-by-step fixes.
Publicly shared items.
Recommended roles.
After fixes.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Read-only access is enough for the assessment. Hardening needs admin rights or your administrator's help.
We sequence changes and communicate them to avoid lockouts.
Typically one to two weeks for the assessment.
No. This covers Google Workspace. Cloud infrastructure is a separate assessment.
Yes. It evidences security measures over systems holding personal data.
Tell us your number of users and edition. We will quote a fixed fee.