Google Drive: security best practices for SMBs
How to secure your Google Drive files in business: permissions, external sharing, DLP and organization best practices.
Updated on 19 August 2024
Protect your business files in the cloud
Google Drive centralizes your company’s files in the cloud. This centralization simplifies collaboration but also creates risks if permissions and sharing are not configured correctly. A file shared by mistake with a public link is accessible to anyone who has the link. This guide covers the security best practices to protect your Google Drive files in business.
Organize with Shared Drives
Shared Drives are the foundation of a secure organization. Unlike My Drive, the files in a Shared Drive belong to the organization, not an individual. When an employee leaves the company, the files remain accessible without intervention.
Create a Shared Drive per team or per project. Define the members and their roles: manager (full control), content manager (add and edit), contributor (add only), commenter or viewer. This permission hierarchy controls precisely who can do what.
Configure sharing rules
External sharing is the main risk. In the admin console, define your organization’s external sharing policy. The options range from a total block to allowing with a warning. For most SMBs, allowing with a warning offers a good balance between security and practicality.
Create a list of trusted domains (customers, partners, suppliers) with which sharing is allowed without restriction. Sharing with unlisted domains triggers a warning that asks the user for confirmation.
Disable link sharing set to “Anyone with the link” at the organization level. This type of sharing creates links accessible to anyone, including people outside your company. Prefer named sharing that identifies each recipient.
Data Loss Prevention (DLP)
DLP rules (Data Loss Prevention) automatically detect and protect files containing sensitive data. You define content-based rules: credit card numbers, social security numbers, health data. When a matching file is detected, DLP can block external sharing, warn the user or notify the administrator.
DLP is available on Business Standard plans and above. For SMBs that handle sensitive data (health, finance, legal), it is an essential layer of protection.
Audit access
The Drive audit log records every action: creation, modification, sharing, download and deletion of files. Review this log regularly to detect abnormal behavior: mass downloads, unusual external shares, access from unexpected locations.
The Drive reports in the admin console provide an overview: number of files shared externally, most active users, types of files stored. These reports help identify risks and adjust policies.
Train users
Technical security is not enough without user awareness. Train your teams on best practices: check permissions before sharing, use Shared Drives for team files, report phishing emails that target Google credentials.
LCMH, a Google Workspace reseller in Alsace, configures Drive security policies and trains teams on best practices.
For overall Google Workspace security, read our article on data protection in Google Workspace.
Sources
- Google, Shared Drives. support.google.com/a/answer/7212025
- Google, DLP for Drive. support.google.com/a/answer/6321530
- Google, Drive Audit Log. support.google.com/a/answer/4579696
Frequently asked questions
- What is the difference between My Drive and Shared Drives?
- My Drive contains a user's personal files. If the user leaves the company, their files are deleted (unless manually transferred). Shared Drives belong to the organization. The files persist regardless of departures. Use Shared Drives for all team files.
- How do you prevent unauthorized external sharing?
- In the admin console, configure the external sharing rules: block all external sharing, allow only with trusted domains, or allow with a warning. Enable external sharing alerts to be notified of every share.
- Is Google Drive GDPR compliant?
- Yes, Google Drive is part of Google Workspace, which is GDPR compliant. Data can be stored in Europe with data regions. Google's DPA (Data Processing Amendment) covers processor obligations. Compliance also depends on your configuration and your practices.
Related Articles
Google Workspace: essential admin console settings
Security and management settings to configure from day one of your Google Workspace deployment to protect your business.
Temporary Admin Roles in Google Workspace: What Changes
Google Workspace can now assign an admin role with an expiration date. How it works, which editions get it, its limits, and how to roll it out.
Google Workspace Backup: why and how to back up your cloud data
Google Workspace does not back up your data for you. Why a backup strategy is essential and what solutions exist.
Workspace Client-Side Encryption: the Simple Setup
Google adds a simplified setup for Workspace client-side encryption. What changes, which editions qualify, the real cost, and what it does not solve.
Google Workspace: keep your data in Europe with data regions
How to configure Google Workspace data regions to store your data in Europe and meet digital sovereignty requirements.
Google Workspace vs Microsoft 365: objective comparison for SMBs
Detailed comparison of Google Workspace and Microsoft 365 for SMBs: pricing, features, collaboration, security and AI.