Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

A Google Workspace security audit of the tenant you already run.

F Creative Studio 360 reviews administration, mail, files, meetings and identity for organisations in any country, against the baseline that applies to them.

Google secures the service. The audit looks at what you configured in it.

The review covers a Google Workspace tenant: the Admin console, Gmail, Google Drive, Google Meet, Google Chat, Cloud Identity and Google Vault.

F Creative Studio 360 does not change the tenant during the audit. Access is read-only, and only for the tenant you authorise.

Mail, files and identity in one tenant
A Google Workspace tenant holds the accounts people sign in with, the mail they send, and the files they share. A gap in any one of those is a gap in the others.
The console is easy to leave open
Sharing defaults, a third-party app, or a super administrator who never steps down are ordinary settings. They are also the settings that decide who can read the tenant.
Apps are part of the review
An app that a user approved can keep access to mail and files after the person has forgotten it. The audit looks at those grants, not only at the built-in settings.
The benchmark that applies to you
The review is mapped to the framework you have to show, wherever the people and the tenant are based.

What the audit covers

Configuration is compared with the CIS Google Workspace Benchmark. Google’s security health view is one input. It records that a control exists. The audit also asks whether that control is set in a way that matches your risk.

Administration
Super administrator accounts, delegated admin roles, 2-Step Verification, security keys, password rules, recovery options and how organisational units are separated.
Mail
Phishing and malware settings, routing, quarantine, confidential mode, attachment rules, allow and block lists, and whether SPF, DKIM and DMARC are in place. We review the settings. We do not send a phishing test.
Files
External sharing, link defaults, shared drive creation, third-party access to Drive, ownership transfer and offline access.
Meet and Chat
Who can join a meeting from outside the organisation, recording and live stream permissions, chat with external people, and how long chat history is kept.
Identity
Single sign-on, session length, context-aware access, device settings, groups, and which identity provider the tenant trusts.
Retention and Vault
Retention rules, legal holds, who can search Vault, and who can export data. These are reviewed when Vault is part of the licence.

Administration reviews include 2-Step Verification. Identity reviews include Context-Aware Access, SAML and apps granted through OAuth 2.0. Mail reviews include SPF, DKIM and DMARC.

How an audit runs

The sequence is the same in any country. People keep using mail, files and meetings while the review is read-only.

  1. 1

    Confirm the tenant

    Which services are in scope, and who can grant read-only administration for the review.

  2. 2

    Read the configuration

    Admin, mail, Drive, Meet, Chat, identity and retention settings, compared with the baseline you named.

  3. 3

    Rate the gaps

    Findings with evidence, ordered by what would change the outcome, including third-party apps that hold broad access.

  4. 4

    Hand back a roadmap

    A summary for leadership and a technical list the team that owns the tenant can apply. The tenant is not changed during the audit.

What you receive

  • A gap view against the baseline you named, with evidence.
  • Notes on sharing, guests, forwarding and super administrator accounts.
  • A view of third-party apps that can read mail or files.
  • A note on retention and Vault, when those are in scope.
  • A remediation roadmap and a summary a board can read.

Standards the audit can align to

F Creative Studio 360 maps the findings to the references that apply where you operate. The usual set is the CIS Google Workspace Benchmark and the NIST Cybersecurity Framework.

The Essential Eight is added only when the organisation is measured against it. Alignment is not a certification. Google Vault is reviewed only when the licence includes it.

Common questions

What is a Google Workspace security audit?+

It is a review of how your Google Workspace tenant is configured: administration, mail, files, Meet, Chat, identity and retention. F Creative Studio 360 compares that configuration with the baseline you need and returns a roadmap. It does not certify the tenant.

Where do you deliver this?+

For organisations in any country. The technical review is the same. The report is mapped to the obligations that apply where you operate, such as the CIS Google Workspace Benchmark or the NIST Cybersecurity Framework. A local rule, such as the Essential Eight, is added only when that organisation is measured against it.

How is this different from a Microsoft 365 security audit?+

The questions are similar: identity, mail, files and meetings. The consoles, licences and controls are not. This audit stays on Google Workspace. A Microsoft 365 audit stays on that tenant. They can be scoped together when an organisation runs both.

How is this different from a cloud security audit?+

A cloud security audit reviews infrastructure accounts: networks, storage, logging and workloads. This audit stays on the Google Workspace tenant people use for mail, files, meetings and chat.

How is this different from a penetration test?+

This audit reads configuration. A penetration test tries to show that a weakness can be used. F Creative Studio 360 does not send phishing mail or change the tenant as part of the audit. A test can be a separate engagement when you want proof as well as a review.

Will you change our tenant?+

No. The audit is read-only unless a remediation engagement is agreed afterwards. People keep working while the review is underway.

How much does it cost, and how long does it take?+

It depends on the size of the tenant and which services are in scope. A scoping conversation with F Creative Studio 360 is the way to get a quote and a sensible duration. There is no obligation to proceed.

Start with the tenant that is already live.

F Creative Studio 360 will look at the services in use and the reason for the review, then say what a sensible audit includes.