Pro Tip: Exercise Caution with G Suite Marketplace Apps

Share this post

G Suite Marketplace Apps are “applications that can be added to an entire domain or to individual G Suite accounts.”

They integrate with the Admin console and make it easy to complete common tasks (mail merges, form publishing, password management, etc.) or connect to frequently used apps like Dropbox or Zoom.

And, they have a “bonus” feature: They want to take over your G Suite!

That’s because installing a G Suite App is an all or nothing proposition. You can’t cherry-pick permissions — installing one requires ceding whatever control of data and functionality the app demands.

There’s no simple way to vet the security expertise behind a given app’s creator (some of these companies are made up of just a few people), but you can mitigate your risk should one of them become compromised:

  1. Establish an approval process. Adding apps to G Suite needs to be a centralized endeavor.
  2. Investigate the permissions required. Do you want to install an app that can send emails on your behalf? Read and delete your Google Drive information? (I’m going to suggest “No” on both of these.)
  3. Install nonessential apps as an “Individual Install” rather than Domain-level. This will scope permissions to a single user.
  4. Consider creating a user with limited permissions. The installed app won’t be able to see most of your company’s folders while still allowing you to use it.

As with many security challenges, it is often our own actions that open the door to nefarious actorsMake sure you know who’s knocking!

Rob Black
Rob founded Fractional CISO in 2017 and has helped dozens of mid-size SaaS and technology companies improve their security posture as a vCISO. He consults, speaks, and writes on IoT and security. Rob has held product security and corporate security leadership positions at PTC ThingWorx, Axeda and RSA Security. He received his MBA from the Kellogg School of Management and holds two Bachelor of Science degrees from Washington University in St. Louis in Computer Science and System Science and Engineering. He is also a Certified Information Systems Security Professional (CISSP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales