Cyber Security September 10, 2026

Google Workspace Security in 2026: What to Lock Down Before Enabling Gemini

Gemini is a genuinely useful assistant inside Gmail, Docs, and Sheets - but it will happily surface every file your sharing settings have quietly left exposed for years.

Most conversations about "AI security" focus on the AI. In practice, the real risk almost always sits underneath it - in permissions, sharing links, and admin settings that were never properly locked down. Gemini in Google Workspace doesn't create new risk out of nowhere; it just gets very good, very fast, at finding whatever risk was already there.

Before you roll out Gemini to the whole company, fix the foundations.

This guide covers the practical Google Workspace security settings every UK SME should have in place, and the specific checks worth doing before turning on Gemini for staff.


1. Turn on 2-Step Verification for everyone - no exceptions

This is the single highest-impact change available in Workspace, and it costs nothing. A stolen or reused password is the most common way attackers get into a Google account. 2-Step Verification (2SV) - ideally via the Google Authenticator app or security keys rather than SMS - blocks the overwhelming majority of account takeover attempts even when a password leaks elsewhere.

Minimum configuration

  • Enforce 2SV org-wide from the Admin console, with no opt-out.
  • Prefer an authenticator app or security key over SMS codes.
  • Require it especially for anyone with admin or super-admin roles.

Common mistake

2SV enabled "for anyone who wants it" instead of enforced org-wide. In practice, the people who skip it are usually the busiest - often the same people with the widest file access.

2. Clean up Drive sharing before AI starts summarising everything

Every Workspace tenant we've audited has the same pattern: years of "Anyone with the link can view" documents, folders shared to entire domains "just to be safe", and ex-employees who technically still have edit access to live client files. None of this shows up as a dramatic breach - it just quietly sits there.

Gemini changes the practical risk of this mess. A tool that can be asked "summarise anything relevant to the Smith account" will search everything the asking user can access - including that stale shared folder from 2023. The fix isn't disabling Gemini; it's tidying up sharing before you switch it on. If you're not sure how exposed your Drive currently is, a quick sharing audit is usually a faster starting point than trying to review every folder manually.

Drive clean-up checklist

  • Run the Admin console's sharing report to find domain-wide and public links.
  • Restrict external sharing by default; allow it per-folder where genuinely needed.
  • Review shared drives quarterly - HR, finance, and payroll folders especially.
  • Offboard leavers properly: transfer file ownership, then suspend the account.

3. Set up Data Loss Prevention (DLP) rules

Available from Business Standard upward (with more granular rules on Business Plus and Enterprise), DLP lets you automatically detect and block attempts to share sensitive content - card numbers, National Insurance numbers, or custom patterns you define - outside the organisation. It's one of the more overlooked features in a typical managed IT setup, and one of the most useful for a business handling client financial data.

4. Turn on alerting - don't rely on noticing

The Google Workspace Admin console can alert you automatically to suspicious logins, mass file downloads, or a sudden spike in external sharing. Most small businesses never enable these alerts, meaning the first sign of a problem is a client calling to ask why they received a strange email from your domain.


Where Gemini actually fits in

Once the basics above are in place, Gemini is a genuinely useful assistant across Gmail, Docs, Sheets, and Slides - drafting replies, summarising long email threads, and building first-draft reports from raw data. The AI itself isn't the security question; access hygiene is. Get that right first, and Gemini becomes a productivity tool rather than a new source of risk.

Before switching Gemini on for the whole team

  • 2-Step Verification enforced for every account.
  • Drive sharing audited, public/domain-wide links removed.
  • Sensitive shared drives (HR, finance) restricted to the people who actually need them.
  • A written policy on what staff should and shouldn't ask Gemini to summarise or draft.

Google Workspace vs Microsoft 365: the honest answer

We get asked this constantly, and the honest answer rarely changes: both platforms can be made very secure, and both are routinely left wide open by default settings nobody ever revisited. The choice between Workspace and Microsoft 365 usually comes down to which tools your team already uses daily, not which one is inherently safer.


Frequently Asked Questions (FAQ)

Is Google Workspace as secure as Microsoft 365?

Both platforms can be made very secure, and both can be left dangerously open by default. Security in either ecosystem depends almost entirely on configuration - 2-Step Verification, sharing defaults, and admin alerting - not on which vendor you chose.

Does Gemini in Workspace train on our company data?

For Google Workspace business and enterprise editions, Google's standard terms state that workspace content is not used to train Gemini's underlying models. Always confirm this against your specific edition and current Google terms, as policies can change.

Can Gemini expose files I didn't mean to share?

Gemini only surfaces what the logged-in user can already access. The risk isn't Gemini itself - it's years of accumulated "Anyone with the link" sharing and stale permissions in Drive. Clean up sharing settings before rolling Gemini out widely.

Do we need Google Workspace Business Plus to get proper security controls?

Basic and Standard editions cover 2-Step Verification and baseline admin controls. Business Plus and Enterprise add stronger features such as Vault retention, advanced endpoint management, and more granular DLP rules - worth the upgrade once you're handling sensitive client or financial data.

Not sure how exposed your Workspace really is?

We run a practical Google Workspace security audit for UK SMEs - sharing settings, admin alerts, DLP, and a clear plan before you roll out Gemini. Part of our wider cybersecurity services.

Book a Free IT Consultation

Lock down Workspace before you switch on AI

SmartOps IT helps UK SMEs secure Google Workspace and Microsoft 365 environments alike.

Get a Free Security Audit
// koniec footer.php