Learn
Checklist


Published: June 9, 2026 · Last updated: June 9, 2026
Author: Dan Gericke, Co-founder, ShiftControl — 20+ years in cybersecurity, scaled IT ops from 100 to 700+ employees at ExpressVPN
Read time: 7 minutes
---
A startup IT security checklist is a short, repeatable list of the controls that protect your company’s accounts, data, and apps — written for the person who got handed IT without asking for it. It matters because the things that cause most early-stage breaches are boring and fixable: an admin account with no second factor, an ex-employee who can still log in, a third-party app nobody remembers approving. You don’t need a security team to close those gaps. You need a list and an afternoon.
This is that list. Work top to bottom. Each item tells you what to do, why it matters, and a quick how. Most of it lives inside your Google Workspace admin console, so you already have the keys.
According to the Verizon 2024 Data Breach Investigations Report, the use of stolen credentials appeared in 31% of all breaches over the past decade — the single most common way attackers get in. Identity is the front door. Start there.
---
1. Identity and access
This is the section that matters most. Get it right and most other risks shrink.
Turn on multi-factor authentication everywhere
What: Require a second factor — an authenticator app or a physical security key — on every account, no exceptions.
Why: A password alone is one stolen credential away from a breach. A second factor stops the attacker even when the password leaks.
How: In Google Workspace, go to Security and enforce 2-Step Verification org-wide. Push the same on every other tool that supports it, starting with email, finance, and code.
Give people the least access they need
What: Grant each person access to the apps and data their role requires, and nothing more.
Why: Every extra permission is an extra thing that can be misused or stolen. A marketing hire does not need production database access.
How: Review access by role, not by person. Start access at the floor and add up, rather than copying a colleague’s account and inheriting their sprawl.
Keep admin roles tight
What: Limit who holds admin rights, and use a regular account for everyday work.
Why: Admin accounts can change anything. The fewer that exist, the smaller the target.
How: List every admin today. Remove the ones who don’t need it. Anyone who keeps admin rights gets a separate, MFA-protected admin login they only use for admin tasks.
---
2. Harden Google Workspace
Your Google Workspace is the directory for everything else. Lock the directory and you protect the whole stack.
Enforce 2-Step Verification, don’t just allow it
What: Move 2-Step Verification from optional to required for all users.
Why: Allowed means most people skip it. Enforced means the gap closes for everyone.
How: In the admin console under Security, set 2-Step Verification to mandatory and pick an enrollment deadline. Security keys for admins, authenticator apps for everyone else.
Set account recovery before you need it
What: Configure recovery options and disable user-managed recovery for sensitive roles.
Why: Weak recovery is a side door — an attacker who hijacks a recovery flow walks straight past your second factor.
How: Set admin recovery contacts, and turn off self-service recovery for admin accounts so a real human has to step in.
Count your super admins
What: Know exactly how many super admin accounts exist and keep the number small.
Why: A super admin can read any mailbox, reset any password, and remove any control you set. Each one is a master key.
How: Aim for two — a primary and a backup. Audit the list quarterly and downgrade anyone who crept onto it.
---
3. Third-party app and OAuth visibility
This is the gap almost every startup misses, and it’s the one I’d check first if I walked into your account today.
Find what’s connected to your Google Workspace
What: Pull the list of every third-party app that someone connected to your Workspace with their Google login.
Why: When a teammate clicks “Sign in with Google” on a new tool, that app gets a standing token into your data — often read access to email or Drive. Nobody approved it centrally, and it stays connected long after the tool is forgotten. This is the shadow-IT backdoor.
How: In the admin console, open Security, then API controls, then third-party app access. Most founders are surprised by the count. Block the apps you don’t recognize and restrict which scopes new apps can request.
This is exactly the kind of work ShiftControl’s Permissions Insights surfaces automatically — every connected app, the data it can reach, and a one-click way to cut it off — so you’re not reading raw OAuth scopes by hand.
---
4. Offboarding
The clean test of your security: when someone leaves, is their access gone the same day?
Remove access the day someone leaves
What: Revoke every account and app the moment employment ends, not at the end of the week.
Why: A former employee with active access is the most common identity gap there is. The person who left on good terms is rarely the problem — the lingering login is.
How: Suspend the Google account first to block login, then revoke their connected apps and remove them from groups and shared drives. Run the same list every time so nothing gets missed. For a deeper walkthrough, see our offboarding guide.
This is the work ShiftControl’s offboarding automation does for you — one departure trigger, access gone across every connected app, with a record of what happened.
---
5. SaaS inventory
You can’t secure or budget for tools you can’t see.
Build a list of every app the company pays for and logs into
What: Maintain one running inventory of your SaaS tools, who owns each, and who has access.
Why: Apps you’ve forgotten are apps you can’t secure, and seats nobody uses are money you can’t recover. Visibility is the prerequisite for both.
How: Start with your billing and your Google Workspace connected-apps list. Note the owner and access for each. Revisit monthly — the list grows on its own.
---
6. Logging and an audit trail
When something goes wrong, the question is always: what happened, and when?
Keep a record of who did what
What: Turn on audit logging and keep a basic trail of admin actions, logins, and access changes.
Why: Without a trail, you’re guessing during an incident and empty-handed during a compliance review. With one, you can answer both in minutes.
How: Google Workspace keeps audit logs by default — confirm retention meets your needs and know where to find them. Log access changes for sensitive systems too. If you’re heading toward SOC 2, this record is the evidence auditors ask for.
---
Frequently asked questions
Do I need a security team to do this?
No. Every item here is reachable from your Google Workspace admin console or your apps’ own settings. You need admin access and a couple of focused hours, not a security hire. Tools built for non-technical operators can automate the recurring parts so the list doesn’t depend on you remembering it.
Which item should I do first if I only have an hour?
Enforce multi-factor authentication everywhere and count your super admins. Stolen credentials drive most breaches, so a second factor on every account — especially the admin ones — is the single biggest risk you can remove in under an hour.
How often should I run this checklist?
Do the full pass once now, then review quarterly. Two items deserve a tighter loop: offboarding happens the day someone leaves, and your SaaS inventory gets a quick monthly glance since new apps connect on their own without anyone deciding to add them.
What’s the difference between MFA and 2-Step Verification?
They’re the same idea with different names. Google calls it 2-Step Verification; the rest of the industry says multi-factor authentication. Both mean a second proof of identity beyond your password — an app code or a physical key — so a leaked password isn’t enough to get in.
Are connected third-party apps really a risk?
Yes, and they’re the most overlooked one. Each “Sign in with Google” approval hands an outside app a standing token into your data, often with read access to email or Drive. Those tokens outlive the tool’s usefulness and rarely get reviewed. Auditing them is one of the highest-value hours you’ll spend.
We’re a Google Workspace shop with no IT person. Where does ShiftControl fit?
ShiftControl works inside your Google Workspace to handle the recurring parts of this list — connected-app visibility, access control, and offboarding that finishes — without requiring IT expertise to set up or run. You keep the admin rights; it does the watching and the work. Learn more about single sign-on basics if SSO is on your roadmap too.
---
Run this list once and the riskiest gaps close in an afternoon. The hard part isn’t the first pass — it’s running it every time someone joins, leaves, or connects a new app. If you’d rather not depend on remembering, see what ShiftControl shows you about your own Google Workspace.
---
<script type="application/ld+json">
{
“@context”: “https://schema.org”,
“@type”: “Article”,
“headline”: “The startup IT security checklist (for teams without a security team)”,
“description”: “A practical IT security checklist for startups and SMBs on Google Workspace with no security team — MFA, least privilege, OAuth visibility, offboarding, SaaS inventory, and audit logging.”,
“author”: {
“@type”: “Person”,
“name”: “Dan Gericke”,
“jobTitle”: “Co-founder, ShiftControl”
},
“publisher”: {
“@type”: “Organization”,
“name”: “ShiftControl”,
“url”: “https://shiftcontrol.io”
},
“datePublished”: “2026-06-09”,
“dateModified”: “2026-06-09”
}
</script>
<script type="application/ld+json">
{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “Do I need a security team to do this?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “No. Every item here is reachable from your Google Workspace admin console or your apps’ own settings. You need admin access and a couple of focused hours, not a security hire. Tools built for non-technical operators can automate the recurring parts so the list doesn’t depend on you remembering it.”
}
},
{
“@type”: “Question”,
“name”: “Which item should I do first if I only have an hour?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Enforce multi-factor authentication everywhere and count your super admins. Stolen credentials drive most breaches, so a second factor on every account — especially the admin ones — is the single biggest risk you can remove in under an hour.”
}
},
{
“@type”: “Question”,
“name”: “How often should I run this checklist?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Do the full pass once now, then review quarterly. Two items deserve a tighter loop: offboarding happens the day someone leaves, and your SaaS inventory gets a quick monthly glance since new apps connect on their own without anyone deciding to add them.”
}
},
{
“@type”: “Question”,
“name”: “What’s the difference between MFA and 2-Step Verification?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “They’re the same idea with different names. Google calls it 2-Step Verification; the rest of the industry says multi-factor authentication. Both mean a second proof of identity beyond your password — an app code or a physical key — so a leaked password isn’t enough to get in.”
}
},
{
“@type”: “Question”,
“name”: “Are connected third-party apps really a risk?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Yes, and they’re the most overlooked one. Each Sign in with Google approval hands an outside app a standing token into your data, often with read access to email or Drive. Those tokens outlive the tool’s usefulness and rarely get reviewed. Auditing them is one of the highest-value hours you’ll spend.”
}
},
{
“@type”: “Question”,
“name”: “We’re a Google Workspace shop with no IT person. Where does ShiftControl fit?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “ShiftControl works inside your Google Workspace to handle the recurring parts of this list — connected-app visibility, access control, and offboarding that finishes — without requiring IT expertise to set up or run. You keep the admin rights; it does the watching and the work.”
}
}
]
}
</script>
