Skip to content
By Best Practices

Top 7 Google Drive Security Mistakes Companies Keep Making

Most Drive exposures come down to unenforced 2-Step Verification and nobody auditing external sharing. Here are the seven mistakes and the fixes.

Top 7 Google Drive Security Mistakes Companies Keep Making, by Deepak Gupta on guptadeepak.com

Almost every Google Drive exposure traces back to the same two things: nobody enforced 2-Step Verification, and nobody has ever looked at the list of files shared outside the company. Fix those two first, in that order. Everything else on this list is real, but those are the ones that turn an ordinary sharing mistake into a disclosure.

Here are the seven mistakes that keep recurring, what Google's current controls actually do about each, and which Workspace edition you need for the control to exist at all. That last point catches people out more than anything else: several of the controls companies assume they have are not included in Business Starter or Business Standard.

A Naming Note Before Anything Else

If your internal documentation still says "G Suite", it is out of date. Google renamed the product to Google Workspace, and you can no longer sign up for G Suite Basic or G Suite Business; the legacy free edition ended in June 2022. The phrase survives only as a label on legacy editions. Google's admin documentation has also moved: most support.google.com/a/ admin articles now redirect to knowledge.workspace.google.com. Old links still resolve, but the admin console paths in any guide written before 2025 are worth re-walking rather than trusting.

Mistake 1: Running Workspace Without Enforced 2-Step Verification

Two-Step Verification is still what Google calls it, and it is still the single highest-value control. The mistake is not failing to offer it. The mistake is leaving it optional, which means the accounts most worth compromising are the ones least likely to have it on.

Admins can enforce 2SV per user, per group, or per organisational unit. Google explicitly discourages SMS and voice codes because of carrier network weaknesses, and it enforces 2SV on administrator accounts. Two details most companies miss:

  • The "Only security key" enforcement option now accepts passkeys as well as security keys, and Google states the two offer the same level of phishing resistance. That removes the old objection that hardware keys are impractical to distribute.
  • The Advanced Protection Program is available to Workspace users under Security, Authentication, Advanced Protection Program. Users self-enrol and admins cannot force enrolment, so treat it as a strongly recommended step for administrators, finance and executives rather than a policy you can push.

Before enforcing, read Google's guidance on avoiding lockouts and set the policy suspension grace period, or your first enforcement day becomes a helpdesk incident.

One claim to ignore: there is no Google announcement of a blanket 2SV mandate for all Workspace end users. The published mandate covers Google Cloud and Firebase console access, with enterprise Cloud Identity organisations created before 3 August 2026 covered from 20 October 2026. Plenty of articles have widened that into something Google did not say.

Mistake 2: Not Knowing What Is Already Shared Outside the Company

Most teams cannot answer a simple question: how many files are visible to people outside the organisation right now? Google will answer it. The file exposure report in the security centre shows sharing events and views on externally visible files, over windows up to 180 days.

Google's own definition of "externally visible" is the useful framing device, because it covers three distinct situations people tend to conflate:

  • Public on the web: anyone on the internet, no sign-in required, indexable.
  • Anyone with the link: no sign-in required, but discovery depends on holding the URL.
  • Shared externally with specific people: named individuals outside your domain.

The middle category is where the damage usually happens, because "anyone with the link" feels private and is not. A link pasted into a ticket, a vendor portal or a chat that later gets exported has no access control behind it at all.

Set the organisation default for new items to Restricted under Drive and Docs sharing settings, which is Google's own recommendation. Then use target audiences so that the convenient one-click option offers a named group rather than the entire company.

Mistake 3: Believing Drive Links Can Be Password Protected

They cannot. Google's canonical sharing documentation documents Viewer, Commenter, Editor and Owner roles, general access options, and expiration, and says nothing about passwords on links, because the feature does not exist. Anything offering it is a third-party add-on sitting between you and your data.

What does exist, and is under-used:

  • Expiration dates on access. Since November 2025 these apply to files and folders in shared drives, not only My Drive. On files, expiration can be set for editors, commenters or viewers; on shared drive folders it applies to the Viewer role only. Make this the default for anything shared with a contractor, an agency or a prospect.
  • Turning off download, print and copy for viewers and commenters. A checkbox under Share, Settings. It is not a protection against a determined person with screen access, and it is a meaningful reduction in accidental redistribution.
  • External sharing allowlists. Restrict sharing to named trusted Workspace domains, which also blocks shares to personal Google accounts, and switch on the warning users see before sharing externally. Changes to these settings can take up to 24 hours to apply.

Mistake 4: Sharing Once and Never Reviewing It

Access granted for a two-week project outlives the project by years. The standard failure is an employee or contractor who leaves with personal-account access to a folder nobody remembers exists, or a shared drive where everyone was made a Manager because it was quicker.

Three concrete controls:

  • Use the right shared drive role. Manager, Content manager, Contributor, Commenter and Viewer are not interchangeable. Google's own guidance is that if you do not want members deleting files, they should be Contributor, Commenter or Viewer, because Content manager can delete. Most organisations default everyone to Manager and then wonder how a folder vanished.
  • Make offboarding a Drive task, not just an account task. Suspending an account does not revoke access previously granted to a personal address, and it does not transfer ownership of files that person created.
  • Audit with the logs you already have. Drive log events show file creation, sharing and access. Admin log events show who changed a sharing setting. Takeout log events show bulk data export, which is the quietest exfiltration path in Workspace.

For organisations on the higher editions, trust rules let you express this as policy rather than hygiene: which users' files can be shared externally, which users can receive external files, and who can be invited to shared drives.

Mistake 5: Treating Google Vault as a Backup

This one is worth stating in Google's own words. From the Vault overview: "Vault isn't a data archive. When retention rules expire, any data deleted by users or admins that isn't on hold is subject to standard deletion processes."

Vault does retention, legal holds, search and export across Gmail, Drive, Calendar, Chat, Meet recordings, Groups, Sites and Gemini app messages. Exports are available for fifteen days and then deleted. It is an eDiscovery and retention tool, and it will not restore a folder someone deleted last quarter unless a rule or hold happened to cover it.

Two licensing traps. Vault is included with Business Plus, Enterprise Standard and Plus, Frontline Standard and Plus, Education editions and domain-verified Enterprise Essentials. It is not in Business Starter or Business Standard. And if you change editions, read Google's guidance on preserving Vault data first, because the transition can drop what you assumed was retained.

Mistake 6: Ignoring Third-Party Apps With Drive Access

Every OAuth consent an employee has ever clicked is a standing grant of access to company data, and in most organisations nobody has audited the list. This is the mistake with the widest gap between risk and attention.

Admin console, Security, Access and data control, API controls. Applications get one of four access levels: Trusted, Specific Google data (only the scopes you name), Limited (unrestricted services only), or Blocked. For Gmail, Drive and Chat you can restrict high-risk scopes specifically, such as deleting files in Drive, while still allowing an app to access only files the user explicitly picks.

Worth knowing: an app on the trusted allowlist keeps access to scopes you have otherwise blocked, so the allowlist is an override, not an exception list. Review domain-wide delegation at the same time, since that is where a single compromised service account reads everything.

Related, and worth naming because Google publishes it: its own Cloud Threat Horizons report describes attackers increasingly using trusted cloud storage services, Drive among them alongside SharePoint, Dropbox and GitHub, to host decoy files as part of initial access chains. The defender problem Google names is that the activity looks exactly like normal employee use of cloud storage. That is an argument for logging and detection, not for banning cloud storage.

Mistake 7: Deciding Drive Is Not for Sensitive Files, Instead of Configuring It

The old version of this advice was "do not put sensitive files in Drive". That is not a policy, it is an abdication, and it reliably produces shadow IT instead of security. The honest version is that Drive can hold sensitive data if you configure the controls, and that most of those controls require a specific edition.

Data protection rules (DLP). Scan content and act on it: block external link sharing of files containing sensitive content, warn the user before they share, or audit silently while you tune the rule. Detectors can be predefined or custom, using keywords, word lists, regular expressions and proximity matching, and rules can automatically apply classification labels. Available on Enterprise Standard and Plus, Frontline Standard and Plus, Enterprise Essentials Plus, and Education Fundamentals, Standard and Plus.

Client-side encryption. Content is encrypted in the client before upload, with keys held by an external key service Google cannot access. It requires a key service and an OIDC identity provider, and is limited to Enterprise Plus, Frontline Plus and Education Standard and Plus. This is the control for data where "Google cannot read it" is a contractual or regulatory requirement.

Context-Aware Access. Access policies based on user identity, device security state, IP address and location, available on Enterprise Standard and Plus, Frontline Standard and Plus, Enterprise Essentials Plus, Education Standard and Plus, and Cloud Identity Premium. It is how you stop a valid session on an unmanaged device from being equivalent to one on a managed laptop.

If you are on Business Starter or Standard and handling regulated data, the finding is not that Drive is unsafe. It is that you are on the wrong edition.

What Changed in 2026

Three updates that most guidance written before this year does not include.

"Restricted access" became "limited access". In April 2026 Google discontinued the legacy per-item restricted access feature inside shared folders and migrated those items to the limited access setting, with no change to who can open them. You can audit which of your files are affected with the Drive search operator owner:me is:limitedaccess. Note the terminology trap: this is a different thing from the admin-level "Restricted" general access setting discussed under mistake 2.

Unified data protection rules arrived in September 2026. Admins can now combine audience conditions and data-sensitivity conditions in a single rule, building sharing boundaries that evaluate both what the data is and who is receiving it. Rollout began 14 September 2026 for Enterprise Standard and Plus, Enterprise Essentials, Frontline Standard and Plus, and Education Standard and Plus.

External sharing insights got better in reporting. Since August 2026, Drive Inventory Reporting in BigQuery consolidates direct permissions, group memberships and public links into clearer signals, and distinguishes human users, service accounts and published files. It is disabled by default; switch on "External sharing calculations" in the Drive inventory report settings.

A Thirty-Day Plan

  1. Week one. Enforce 2SV for administrators, then for everyone, with a grace period configured. Move admins to security keys or passkeys.
  2. Week one. Run the file exposure report. Count what is public on the web. Fix those first; they are indexable.
  3. Week two. Set the default general access for new items to Restricted. Create target audiences for the groups that actually share internally.
  4. Week two. Audit API controls. Block high-risk scopes for Drive, and review domain-wide delegation grants.
  5. Week three. Check your edition against the controls you assumed you had. Decide whether DLP, trust rules or client-side encryption justify an upgrade, in writing.
  6. Week three. Add Drive access review to the offboarding checklist, including transfer of file ownership.
  7. Week four. Turn on external sharing warnings, set expirations as the norm for external shares, and put the security health page on someone's monthly calendar.

How This Guide Was Verified

Every product claim here was checked against Google-owned documentation in September 2026. Sources were the Workspace admin knowledge base, the Drive and Vault help centres, the Workspace Updates blog for the November 2025, April 2026, August 2026 and September 2026 changes, Google Cloud documentation for the console 2SV mandate, and the Google Cloud Threat Horizons report for the cloud-storage abuse finding. No third-party sources were used for product facts, because on this topic Google is the only authority. Edition availability is quoted as Google lists it. It is also the detail most likely to change, so confirm it in your own admin console before planning around it.

This is a documentation-verified configuration guide. It makes no claim to have tested any third-party tool, and it reports no vendor-supplied statistics. For the controls that sit around Drive rather than inside it, see the guide to data security practices that hold up.

Last verified: September 2026. Checked: 2SV enforcement and passkey options; Advanced Protection availability; general access and target audience settings; sharing expiration scope; the absence of link passwords; shared drive roles; Vault scope and editions; DLP and client-side encryption editions; API controls access levels; file exposure report definitions; and the 2026 Workspace Updates changes.

Frequently Asked Questions

Can I put a password on a Google Drive link?

No. Google's sharing documentation covers roles, general access settings and expiration dates, and has no password option for links. If you need a password gate, the file needs to live somewhere else, or the recipient needs a Google identity so you can share with them by name.

How do I see everything my company has shared externally?

Use the file exposure report in the security centre, which reports sharing events and views on externally visible files for windows up to 180 days. Google counts three states as externally visible: public on the web, anyone with the link, and shared with specific people outside your domain. For deeper analysis, Drive Inventory Reporting in BigQuery consolidates permissions, group memberships and public links.

Is Google Vault a backup?

No. Google states directly that Vault is not a data archive, and that when retention rules expire, data not on hold is subject to standard deletion. Vault is for retention, legal hold, search and export. If you need restore-from-a-point-in-time, that is a separate capability.

Which Workspace edition do I need for real security controls?

It depends on the control. Basic sharing restrictions and external sharing allowlists work across editions. Data protection rules generally require Enterprise Standard or above, Frontline Standard or above, Enterprise Essentials Plus, or an Education edition. Client-side encryption is limited to Enterprise Plus, Frontline Plus and Education Standard and Plus. Vault starts at Business Plus.

Should employees use personal Google accounts for work files?

No, and this is the failure mode behind most of the others. A personal account is outside your admin console entirely: you cannot enforce 2SV on it, cannot see its sharing in your logs, cannot apply data protection rules, and cannot revoke it at offboarding. Restrict external sharing to allowlisted Workspace domains, which also blocks shares to personal accounts.

Should files live in My Drive or a shared drive?

Shared drives, for anything the company owns. Files in My Drive belong to an individual and leave with them, which turns every departure into a file recovery exercise. Shared drives are owned by the organisation, and their five access levels give you the granularity to stop everyone being able to delete everything.

Get new Scams & Cybersecurity writing

Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks