FYI: Google Workspaces's High-Priority Security Events Take 4 Hours to Trigger

35 points by apimade ↗ HN
Do not rely on Google Workspace's Security Alerts and Events for anything critical.

If your organisation suffers a targeted phishing attack, you'll notice that alerts within your Security Centre don't trigger or fire very quickly. In fact, it might take several hours - which we found out a few weeks ago trying to monitor and test incident response on a VIP's account.

I've attempted to ask Google on this several times - as well as asking simply, "should I rely on Google's Security Alert Centre for Incident Response", to which they respond each time with:

---

Upon checking the following Help Center article [1], we can confirm that this is working as intended:

“Note: Gmail alert notifications may arrive up to 4 hours after an alert rule is triggered.” [1] https://support.google.com/a/answer/9104586?hl=en#zippy=%2Cuser-reported-phishing

Kindly note that I'm just an email away if you have any other questions about your matter.

4 comments

[ 2.2 ms ] story [ 132 ms ] thread
What are the alternatives with similar coverage & faster response times?
CanIPhish and KnowBe4 both support GMail addons which would skip Google's in-product process for reporting, and trigger alerts immediately. Outside of avoiding the in-Gmail/native process entirely, I'm unsure if it's even _possible_ to have faster response times or coverage within Google Workspace.

Microsoft's Office365 suite on the other hand appear to have 1 minute intervals for base plan alerts: https://learn.microsoft.com/en-us/purview/alert-policies

If you run an Enterprise and can't switch to O365, as a workaround without buying new tooling - I'd suggest:

Creating a custom Chrome addon for Gmail which replaces the "Report phishing" button's onClick() event to forward the email to phishing@yourcompany.com, and enforce it on all workplace devices.

Microsoft only just released these capabilities to their lowest tiers after having one of their MSA keys popped by Chinese threat actors. It would be silly to migrate from an enterprise that generally cares about their network to one that has only now started caring.
Did they? Because I’m in a lower O365 tier and those features haven’t actually made it down to me yet.