Skip to content

Google Drive: security best practices for SMBs

How to secure your Google Drive files in business: permissions, external sharing, DLP and organization best practices.

Updated on 19 August 2024

Protect your business files in the cloud

Google Drive centralizes your company’s files in the cloud. This centralization simplifies collaboration but also creates risks if permissions and sharing are not configured correctly. A file shared by mistake with a public link is accessible to anyone who has the link. This guide covers the security best practices to protect your Google Drive files in business.

Organize with Shared Drives

Shared Drives are the foundation of a secure organization. Unlike My Drive, the files in a Shared Drive belong to the organization, not an individual. When an employee leaves the company, the files remain accessible without intervention.

Create a Shared Drive per team or per project. Define the members and their roles: manager (full control), content manager (add and edit), contributor (add only), commenter or viewer. This permission hierarchy controls precisely who can do what.

Configure sharing rules

External sharing is the main risk. In the admin console, define your organization’s external sharing policy. The options range from a total block to allowing with a warning. For most SMBs, allowing with a warning offers a good balance between security and practicality.

Create a list of trusted domains (customers, partners, suppliers) with which sharing is allowed without restriction. Sharing with unlisted domains triggers a warning that asks the user for confirmation.

Disable link sharing set to “Anyone with the link” at the organization level. This type of sharing creates links accessible to anyone, including people outside your company. Prefer named sharing that identifies each recipient.

Data Loss Prevention (DLP)

DLP rules (Data Loss Prevention) automatically detect and protect files containing sensitive data. You define content-based rules: credit card numbers, social security numbers, health data. When a matching file is detected, DLP can block external sharing, warn the user or notify the administrator.

DLP is available on Business Standard plans and above. For SMBs that handle sensitive data (health, finance, legal), it is an essential layer of protection.

Audit access

The Drive audit log records every action: creation, modification, sharing, download and deletion of files. Review this log regularly to detect abnormal behavior: mass downloads, unusual external shares, access from unexpected locations.

The Drive reports in the admin console provide an overview: number of files shared externally, most active users, types of files stored. These reports help identify risks and adjust policies.

Train users

Technical security is not enough without user awareness. Train your teams on best practices: check permissions before sharing, use Shared Drives for team files, report phishing emails that target Google credentials.

LCMH, a Google Workspace reseller in Alsace, configures Drive security policies and trains teams on best practices.

For overall Google Workspace security, read our article on data protection in Google Workspace.


Sources

  1. Google, Shared Drives. support.google.com/a/answer/7212025
  2. Google, DLP for Drive. support.google.com/a/answer/6321530
  3. Google, Drive Audit Log. support.google.com/a/answer/4579696

Frequently asked questions

What is the difference between My Drive and Shared Drives?
My Drive contains a user's personal files. If the user leaves the company, their files are deleted (unless manually transferred). Shared Drives belong to the organization. The files persist regardless of departures. Use Shared Drives for all team files.
How do you prevent unauthorized external sharing?
In the admin console, configure the external sharing rules: block all external sharing, allow only with trusted domains, or allow with a warning. Enable external sharing alerts to be notified of every share.
Is Google Drive GDPR compliant?
Yes, Google Drive is part of Google Workspace, which is GDPR compliant. Data can be stored in Europe with data regions. Google's DPA (Data Processing Amendment) covers processor obligations. Compliance also depends on your configuration and your practices.

Related Articles