How to run a Google Workspace security investigation in 7 steps
Use the Admin console plus Gmail and Google Drive audit logs to trace who did what, contain affected accounts and restore data: follow a seven-step sequence (Detect → Triage → Contain → Preserve → Eradicate → Notify → Review) and involve legal or the ICO within 72 hours if personal data is at risk.
First week
The first week is all about speed and keeping options open. As soon as suspicious activity is discovered, identify the initial indicator (unusual login, mass sharing, malware alert) and preserve logs: Admin console audit, Gmail message logs and Drive activity are the key records. Use the account activity view to note IP addresses, device types and timestamps. Immediately suspend or force-password-reset for any compromised accounts rather than deleting them — that preserves evidence.
Practical actions in this phase (do these within 48 hours):
- Confirm the indicator of compromise and scope — which accounts and files are affected.
- Isolate the affected users (suspend, revoke tokens) to stop further access.
- Export audit logs and save copies to a secure, read-only location.
Why this matters: acting quickly limits lateral movement and keeps forensic options open; delayed containment often turns a single-account issue into a domain-wide incident.
First month
During the first month you switch from emergency mode to controlled recovery. Triage every affected account and file to decide if data needs restoring, legal action, or specialist forensic analysis. Run searches across Gmail and Drive for indicators discovered during the first week and rebuild a timeline of events. If customer or staff personal data may be involved, note that the ICO expects organisations to report qualifying breaches within 72 hours of becoming aware — factor that into your checklist and record timestamps accordingly (ICO breach reporting).
Bring in external help where your team lacks skills: an incident responder, legal counsel or forensic analyst. If you need ongoing operational support, consider professional Google Workspace support services to manage logs, backups and account hygiene while you recover.
First quarter
Across the first quarter you should complete recovery and start closing the gaps the incident exposed. That means fully restoring lost or altered data from verified backups, patching vulnerable endpoints, rotating keys and reissuing credentials. Use the quarter to harden policies: tighten sharing settings, enforce 2-step verification, and adopt context-aware access or conditional policies if available. Document every change and its business justification so you can show auditors or insurers what you did and why.
Also formalise a communication plan for customers and staff: who says what and when. If regulatory reporting was necessary, compile the incident report with a timeline, impact assessment and mitigation steps — this becomes a template for future responses.
First year
In the first year treat the incident as a learning programme. Run tabletop exercises that replay the incident using the preserved logs, test detection rules, and measure mean time to detect and mean time to contain. Update your onboarding and training so staff know how to spot social engineering and accidental sharing. Consider a periodic third-party security review or penetration test focused on email/drive sharing vectors.
Keep retention and monitoring policies under review: maintain searchable audit logs for an agreed window and ensure backups are accessible and verified. Use the year to embed change into procurement and vendor checks — require access controls and logging from any third-party apps that integrate with Google Workspace.
What to watch for next
After the year mark, watch for creeping drift: admin consoles accumulate unused service accounts, stale OAuth tokens and permissive sharing settings. Schedule quarterly audits that look for broad file sharing, irregular admin role assignments and OAuth apps with wide scopes. Track a small set of metrics (time to detect, time to contain, number of accounts compromised) and review them each quarter; if any metric trends up, trigger a focused investigation. Maintain an incident pack with preserved logs and a clear contact list so future incidents start faster and cleaner.
Follow the seven-step sequence below each time you run an investigation so the work is predictable and reportable.
Seven-step sequence
- Detect — Identify indicators and scope quickly.
- Triage — Prioritise affected assets and users.
- Contain — Suspend accounts and revoke tokens to stop spread.
- Preserve evidence — Export audit logs and snapshot data.
- Eradicate and recover — Remove threats and restore clean data.
- Notify — Inform stakeholders and regulators if needed.
- Review — Learn and harden controls to reduce repeat risk.
Related reading
- our google workspace support for business guide
- Google Workspace support London — practical help for growing UK firms
- What is Google Workspace audit logging and how do I use it?
- Google Workspace support UK SMEs — practical help for growing businesses
- Google Workspace support teams: practical help for UK businesses
FAQ
How quickly do I need to report a Google Workspace incident to the ICO in the UK?
If the incident is a personal data breach that’s likely to result in a risk to people’s rights and freedoms, report it to the ICO within 72 hours of becoming aware; keep a note of when you first detected the issue and what steps you’ve taken. See the ICO’s reporting page for details: ICO breach reporting.
Which Google Workspace logs are essential for an investigation?
Start with Admin console audit logs, Gmail message logs and Drive activity; device and login logs help trace session origin. Export these to a secure store immediately — losing logs is the most common practical blocker to a thorough investigation.
Should I suspend accounts or reset passwords first?
Suspend compromised accounts or revoke tokens immediately to stop further access, then force password resets as part of recovery; suspension preserves the account state for forensic work while reset alone can let an attacker remain active.







