The Incredible Story of How Hero MotoCorp Moved 6,000 Users to the Cloud in 45 Days - Build What's Next
Case Study

The Incredible Story of How Hero MotoCorp Moved 6,000 Users to the Cloud in 45 Days

7799

Of your peers have already read this article.

5:00 Minutes

The most insightful time you'll spend today!

Hero MotoCorp completed a migration to G Suite in just 45 days to provide 6,000 employees within its business and employees at affiliate companies with the tools for highly secure and efficient collaboration.

Assembling thousands of parts into one motorbike or scooter every 17 seconds is a complex task requiring accuracy and precision. For Hero MotoCorp — an India-headquartered manufacturer of two-wheeler vehicles — workforce collaboration, security, and mobility complement these processes and provide the cornerstone of the organization’s global operations.

Based in New Delhi, Hero MotoCorp is one of the world’s largest makers of two-wheeler vehicles, with a production capacity of 9 million units from five manufacturing plants in India and one each in Colombia and Bangladesh. The business has more than 90 million customers and operates in 37 countries across Asia, Africa, and South and Central America. In its home market, HeroMotoCorp sells one in every two two-wheelers.

Innovation and agility

Innovation and agility are deeply embedded in Hero MotoCorp’s culture and operations. Its Center of Innovation and Technology at Jaipur in Rajasthan, northern India, undertakes extensive product design and development, testing, and validation.

Hero MotoCorp has also established a technology center at Stephanskirchen, near Munich in Germany, to develop new vehicle concepts and technologies.

For several years, Hero MotoCorp relied on a traditional email solution to enable its employees to communicate and complete tasks. However, this solution could not provide the functionality, performance, ease of use, and security the business needed to maintain its market leadership.

“Our Chief Information Officer, Mr. Vijay Sethi, was the first to migrate to and embrace the features of G Suite and set an example to our workforce.”

Sujoy Brahmachari, Sr. GM and CISO, Hero MotoCorp

“Security, in particular, is extremely important — we don’t want our product design and development details falling into the wrong hands,” says Sujoy Brahmachari, Sr. GM and CISO, Hero MotoCorp. “We needed a solution that would allow us to control and monitor the distribution of sensitive information within and outside our organization.”

In early 2015, Hero MotoCorp’s technology team began evaluating email and workplace collaboration applications that could help the business realize its longer-term ambitions.

Collaboration key to success

“We were focused on a product that could drive greater collaboration among our workforce,” says Brahmachari. “In addition, we wanted to use the product on our desktops, laptops, mobile devices, and other devices. Finally, we needed to ensure email, other applications, and data were secure and available as and when we needed them.”

Hero MotoCorp’s evaluation found G Suite met all these requirements while being intuitive and easy to use. Furthermore, the cloud-based suite of intelligent applications provided a lower total cost of ownership than the business’s existing email solution and potential alternatives.

A 45-day migration

The business completed its review and completed the migration in just 45 days in 2015. “We worked closely with Google and our partners to complete the process in an innovative way that prioritized speed,” says Brahmachari. “For example, we migrated only three months’ worth of emails from our incumbent solution to G Suite, rather than the entire data repository.”

“Our teams are very happy and collaborative – employees can use Gmail through G Suite without being concerned about storage limits and can connect with colleagues, partners, customers, and other stakeholders through the chat, video, and audio call capabilities of Hangouts Meet.”

Sujoy Brahmachari, Sr. GM and CISO, Hero MotoCorp

Hero MotoCorp started the migration with a function-wise approach, creating batches and moving them overnight to G Suite. It created an internal video for employees to learn how to work using G Suite. It also created intranet posts to provide easy reference to all employees and established a service desk to respond to questions.

“Our Chief Information Officer, Mr. Vijay Sethi, was the first to migrate to and embrace the features of G Suite and set an example to our workforce,” says Brahmachari.

Deployed to 6,000 users

Hero MotoCorp has deployed G Suite to about 6,000 users in its core business and many users in affiliate companies. The company’s user-focused approach to the deployment, and the intuitive, easy-to-use nature of the product, has prompted the business’s workforce to embrace the full potential of G Suite.

“Our teams are very happy and collaborative — employees can use Gmail through G Suite without being concerned about storage limits and can connect with colleagues, partners, customers, and other stakeholders through the chat, video, and audio call capabilities of Hangouts Meet,” says Brahmachari.

Employees can also create, store, and access DocsSheetsSlides, and other file types on Drive — helping to ensure new product development, delivery schedules, budgeting, and other activities needed to keep a leading multinational manufacturer ahead of its competitors can be completed quickly and collaboratively.

Deployed to mobile devices

“With G Suite, information is available in the cloud to any employee at any time. The collaboration this enables plays a vital role in sustaining our leadership position.”

Sujoy Brahmachari, Sr. GM and CISO, Hero MotoCorp

Hero MotoCorp has also been able to give employees access to G Suite on a range of mobile devices — with administrators using mobile management to secure access applications and data on iOS and Android devices. The business is using the feature to require devices to have a screen lock or password; remote-wipe information from lost or stolen devices; and monitor from a central console the devices that access corporate data.

Further, Hero MotoCorp can use G Suite features to set and enforce policies and control system configuration and administration, while taking advantage of independently verified security, privacy, and compliance controls to meet business requirements.

With G Suite deployed and delivering value, Hero MotoCorp is now implementing or evaluating a range of Google technologies. For example, the business is using Google Maps Platform to power navigation for owners of new Hero MotoCorp two-wheelers and use Cloud Vision AI to enable immediate recognition of spare parts. “We are also evaluating Google Cloud data search and management technologies for potential application within the organization,” says Brahmachari.

The business is now well-positioned to accelerate into new markets and product development. “With G Suite, information is available in the cloud to any employee at any time,” says Brahmachari. “The collaboration this enables plays a vital role in sustaining our leadership position.”

Blog

Google Workspace Bolsters Data Security by Adding Client-Side Encryption to Gmail and Calendar

1565

Of your peers have already read this article.

4:30 Minutes

The most insightful time you'll spend today!

Google Workspace extends client-side encryption to Gmail and Calendar, enabling users to maintain data sovereignty and meet regulatory compliance requirements while enhancing privacy and security. Learn more...

Editor’s note: This post originally appeared on the Google Workspace blog.

We consistently hear from our customers that the privacy of their data is top of mind, which is why we’ve built state-of-the-art security and privacy-preserving technologies into our products — to keep customer data private and secure. We’ve put Google AI to work on behalf of our customers to automatically stop the majority of online threats before they emerge. Gmail, for example, automatically blocks more than 99.9% of spam, phishing, and malware. These defenses, together with our unique encryption capabilities like client-side encryption (CSE), help our customers such as Groupe Le Monde, PwC, and Verizon, meet their security, privacy, compliance, and digital sovereignty requirements.

Last year, we enabled CSE for Drive, Docs, Slides, Sheets, and Meet, and today we’re excited to share that CSE is generally available for Gmail and Calendar, enabling even more organizations to become arbiters of their own data and the sole party deciding who has access to it. We recognize sovereign controls are important to customers and have accelerated delivery of these encryption capabilities to support our customers in maintaining control over their data and meeting their regulatory compliance needs.

Guarantee complete control of your data for the most challenging regulations

The expansion of CSE capabilities across Google Workspace helps to significantly reduce the burden of compliance for enterprises and public sector organizations. It gives organizations higher confidence that any third party, including Google and foreign governments, cannot access their confidential data. Workspace already encrypts data at rest and in transit by using secure-by-design cryptographic libraries. Client-side encryption takes this encryption capability to the next level by ensuring that customers have sole control over their encryption keys — and thus complete control over all access to their data. Starting today, users can send and receive emails or create meeting events with internal colleagues and external parties, knowing that their sensitive data (including inline images and attachments) has been encrypted before it reaches Google servers.

Users can continue to collaborate across other essential apps in Google Workspace while IT and security teams can ensure that sensitive data stays compliant with regulations. As customers retain control over the encryption keys and the identity management service to access those keys, sensitive data is indecipherable to Google and other external entities.

One key use case for CSE in this context centers on helping organizations subject to regulatory requirements, such as PwC, remain compliant, by meeting the need for the highest levels of encryption for certain types of communication.

We have been searching for the capability to guarantee that our encrypted communications remain inaccessible to third-parties, including our technology providers, for some time. Google appears to be uniquely positioned with client-side encryption in providing us with complete control over our sensitive data, ensuring that we remain compliant as an organization in the ever changing world of data regulation. These features now being available across Google Workspace represent a pivotal moment for us. We’re enthusiastic about the ability to continue to benefit from the efficiency in working that Workspace provides us with, whilst at the same time maintaining trust with our customers that their confidential data will stay private and compliant,” said Shaun Bookham, UK Operations & Technology Director at PwC.

One of our global telecommunications customers, Verizon, is leveraging CSE to gain complete control over their sensitive data, ensuring that they remain compliant as an organization while supporting customers in highly regulated industries. This opens doors for the company to deliver an exceptional experience for its customers, by extending the level of data protection and privacy to their clients.

“At Verizon, we adhere to governance requirements related to access of our sensitive data while also providing the best experience coupled with deep trust. We have worked alongside Google to develop new encryption solutions and are excited to explore their utilization,” said Russell Leader, Director Collaboration and Mobility at Verizon.

Client-side encryption in action in Gmail

Protecting an organization’s most important assets

The regulatory requirements for separation between an organization’s data and their cloud provider’s environment has resulted in important use cases for client-side encryption — from keeping sensitive R&D data extremely private, even from an organization’s SaaS provider, to scenarios where confidentiality is paramount to the success or failure of a mission-critical operation.

Customers, such as media giant Groupe Le Monde, rely on client-side encryption to protect their most crucial assets. By leveraging client-side encryption across Workspace, Groupe Le Monde can be assured that their communications, appointments, and files will not be subject to leaks, thus helping to keep their journalists safe.

“Client-side encryption gives us the next level of privacy, to ensure integrity within the journalistic process. This allows us to guarantee a higher level of security for our journalists, and to protect our sensitive content,” said Sacha Morard, Chief Technology Officer at Groupe Le Monde.

Another industry-leading Google Workspace enterprise customer uses client-side encryption to protect their most sensitive projects. For these projects, the customer is the sole owner of their encryption keys, thereby protecting their critical intellectual property and maintaining their data sovereignty requirements.

Client-side encryption in action in Calendar.

While each customer’s digital transformation journey is different, with all essential Google Workspace apps now being covered by CSE, companies of all sizes in all industries can benefit from these protections.

Starting today, client-side encryption is available globally to customers with Workspace Enterprise Plus, Education Standard, and Education Plus. To learn more about client-side encryption and how to get started today, watch our presentation from Google Cloud Next ’22 and check out the documentation.

Blog

Ways to Manage Extensions on Windows and Mac If You Haven’t Moved to Chrome Browser Cloud Management

3867

Of your peers have already read this article.

2:00 Minutes

The most insightful time you'll spend today!

Chrome Insider series has detailed insights for enterprises that are yet to explore Chrome Browser Cloud Management to audit and manage installed extensions. This time, they list out 3 options used for managing extensions through Group policy.

Many enterprises are looking to better manage extensions on their corporate devices. Extensions themselves are a great tool for productivity and customization of Chrome. However, some extensions can have the potential for far reaching rights to sites your users visit and devices they browse from, giving IT the desire to closely manage which extensions are in their environment and how they behave. 

In an earlier post in this series, we’ve detailed how Chrome Browser Cloud Management is the easiest way to audit installed extensions and manage them. However, some enterprises may need to still use Group Policy on Windows or plists on Mac to manage extensions. So lets touch on management through those methods, for organizations that haven’t quite made the move to Chrome Browser Cloud Management yet. 

For starters, here are some of the most used options for managing extensions (some also apply to apps) via Windows Group Policy or via Plists on Macs:

Installing or allowing extensions

Blocking extensions

  • Extension Install Block List: These are the extensions that you will not allow to be installed. If they are installed already, they will be disabled. If a user tries to install them, it will be blocked. In the Chrome web store, the Add to Chrome button will be red and advise the user that the extension can’t be installed. 
  • Block External Extensions: This setting will block extensions from external sources being installed. An example of this is if an installed application is adding an extension to Chrome via the registry, this setting will block that extension from loading. 

Advanced management options

  • Extensions Settings: This policy provides a varied amount of functionality and requires a JSON script to be created and formatted in a single line string. This setting can be complex. We recommend using Chrome Browser Cloud Management as almost all of the functionality is included without needing to write JSON as well as the ability to audit installed extensions. If you do want to use this policy, it is covered in detail in the Managing Extensions in your Enterprise technical document. Some of the functionality that you can use within this policy are:
    • Install types: (Allowed, Blocked, Force Installed, Normal Installed) 
      • You can also display a custom message when the extension is blocked via the blocked installed message function.
    • Prevent extensions from altering websites: You can prevent all or specific extensions from running on specific websites. 
    • Managing by permissions: You can allow or block extensions by the specific rights or “permissions” that they require to run. 
      • This provides a baseline of functionality that you will or will not allow extensions to run on your users machines. 
      • If an extension is updated, bought, sold and updates the permissions that it requires, this will dynamically protect your users from permissions that you will not allow. 

Even if you decide that on-premises policy management is how you want to manage extensions long term, you can still use Chrome Browser Cloud Management to get much needed visibility into extensions that may exist in your environment. The newly improved apps and extension list is a great way to get a view of your current extension landscape, giving you more data to make better decisions around extension management.

You can enroll browsers to see this information, but still set policy through your existing tools if that’s your preference. 

Well, that’s it for this edition of Chrome Insider. Here’s where you can find more posts in the series, or you can learn more about Chrome Browser Cloud Management.


A note on Google’s commitment to inclusive naming conventions. The following policies have been deprecated, however will still continue to work until Chrome 95 to give administrators time to migrate to the new policies.– ExtensionInstallWhitelist replaced with ExtensionInstallAllowlist
– ExtensionInstallBlacklist replaced with ExtensionInstallBlocklist

Trend Analysis

2022’s First Cloud CISO Perspectives: Recap of the Megatrends, Releases and News

9327

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

A month into 2022, Google Cybersecurity team has plenty of updates on products, resources and news. Tune into 2022's first Cloud CISO perspectives to power your org's IT decisions and investments based on the ongoing cloud security trends!

I’m excited to share our first Cloud CISO Perspectives post of 2022. It’s already shaping up to be an eventful year for our industry and we’re only in month one. There’s a lot to recap in this post, including the U.S. government’s recent efforts to address critical security issues, like open source software security and zero trust architectures. We’ve also released new resources from our Google Cybersecurity Action Team like the Cloud Security Megatrends and the Boards of Directors whitepaper on cloud risk governance

Cloud Security Megatrends 

We’re often asked if the cloud is more secure than on-prem (and why) so we shared our answer in a recent blog post. At Google Cloud, security by design is our priority. We’ve long adopted zero-trust principles for our baseline security architectures and built a global network that relies on defense in depth layers to protect against configuration errors and attacks. But security is always evolving and that is why we also take advantage of the following megatrends:

  1. Economy of scale: Decreasing the marginal cost of security raises the baseline level of security. 
  2. Shared fate: A flywheel of increasing trust drives more transition to the cloud, which compels even higher security and even more skin-in-the-game from the cloud provider.
  3. Healthy competition: The race by deep-pocketed cloud providers to create and implement leading security technologies is the tip of the spear of innovation. 
  4. Cloud as the digital immune system: Every security update the cloud gives the customer is informed by some threat, vulnerability, or new attack technique often identified by someone else’s experience. Enterprise IT leaders use this accelerating feedback loop to get better protection.
  5. Software-defined infrastructure: Cloud is software defined, so it can be dynamically configured without customers having to manage hardware placement or cope with administrative toil. From a security standpoint, that means specifying security policies as code, and continuously monitoring their effectiveness.
  6. Increasing deployment velocity: Because of cloud’s vast scale, providers have had to automate software deployments and updates, usually with automated continuous integration/continuous deployment (CI/CD) systems. That same automation delivers security enhancements, resulting in more frequent security updates.
  7. Simplicity: Cloud becomes an abstraction-generating machine for identifying, creating and deploying simpler default modes of operating securely and autonomically. 
  8. Sovereignty meets sustainability: The cloud’s global scale and ability to operate in localized and distributed ways creates three pillars of sovereignty. This global scale can also be leveraged to improve energy efficiency.

If you’re an IT decision maker, pay attention to these megatrends that will continue to drive and reinforce cloud security and will outpace the security of on-prem infrastructure well into the future. 

U.S. Federal government cybersecurity momentum 

  • Open source software security: Earlier this month, Google participated in the White House Summit on open source software security. The meeting came at a critical time for the industry following December’s Log4j vulnerabilities and was both a recognition of the challenge and an important first step towards addressing it. The open source software ecosystem is not homogenous, despite the fact that the industry often thinks of or treats it this way. Some of it, like Linux, is highly curated, while other critical software is supported through diffuse communities including technology companies and other stakeholders. There is also a long tail of many other critical projects driven by a dedicated community of maintainers around the world, including Googlers. In light of this reality, we welcomed the chance to share our recommendations to advance the future of open source software security. Some work we’ve done includes founding the Open Source Security Foundation, which has been instrumental already in making security improvements. We’ve also helped drive a number of key security initiatives within the open source community including security scorecards, the SLSA framework to improve the security and integrity of open source packages, and Secure Open Source Rewards to financially incentivize improvements to critical open source security projects.  
  • OMB’s Federal zero trust strategy: The publication of the Office of Management and Budget’s zero trust architecture strategy marks an important step for the U.S. federal government’s efforts to modernize under Executive Order 14028. Google Cloud supports this approach, which recognizes the immense security benefits offered by modern computing architectures. For the past decade, Google has successfully applied zero trust principles through our BeyondCorp and BeyondProd frameworks for providing end-user access and securing our cloud workloads. And we’ve brought these best practices from our own journey to global governments and businesses of any size through solutions like BeyondCorp Enterprise and capabilities like Binary Authorization and Anthos Service Mesh, which are embedded in Anthos, our managed application platform. For Federal agencies embarking on this zero trust journey, the Google Cybersecurity Action Team will offer our expertise by conducting Zero Trust Foundations strategy workshops, which can help organizations in the public and private sectors develop actionable and achievable strategies and plans for zero trust implementation. 

Google Cybersecurity Action Team Highlights 

Here are the latest updates, products, services and resources across our security teams this month: 

Security

  • Democratizing security operations: We recently announced that Siemplify, a leading security orchestration, automation and response (SOAR) provider, is joining Google Cloud to help companies better manage their threat response. Providing a proven SOAR capability with Chronicle’s approach to security analytics is an important step forward in our vision to advance invisible security and democratize security operations for every organization.
  • Security by design: The Highmark Health security team is using “secure-by-design” techniques to address the security, privacy, and compliance aspects of its Living Health solution with Google Cloud’s Professional Services Organization (PSO). Google has long advocated for and followed security by design principles, which is why we’re continuously building enhanced security, controls, resiliency and more into our cloud products and services. 
  • Secure collaboration for hybrid work environments: The Google Workspace team shared its recommendations for businesses as they prepare for the future of work,  where the hybrid/flexible work model is becoming standard practice and a new approach to security is essential.
  • Anthos Policy Controller CIS Benchmark enforcement: A big part of our shared fate philosophy is to build secure products and not just security products. A recent example of this in action is embedding CIS benchmark policy conformance in the Anthos Policy Controller. We believe the more we embed approaches like this into our products, the more application and infrastructure teams can intrinsically embed security at the start and reduce toil for the security team.
  • DevOps for technology-driven organizations and startups: A key success factor for many security programs is the partnership and integration with development teams, and there are some great resources and lessons in our DORA research.
  • Security by design with Chrome OS: ABN AMRO’s Asia-Pacific region team recently shared how they are using Chrome OS and CloudReady to work securely in the cloud, reduce total cost of ownership, and add flexibility for employees. This is a great example of secure by design principles in the use of Chromium.

Risk & Compliance

  • Boards of Directors summary guide to cloud risk governance: The latest whitepaper from the Google Cybersecurity Action Team outlines how boards of directors can prioritize safe, secure, and compliant adoption processes for cloud technologies within their organizations.  
  • TruSight Risk Assessment of Google Cloud: TruSight recently released a comprehensive
    risk assessment report on Google Cloud. Our Enterprise Trust team collaborated on this robust assessment of Google Cloud services to validate the design and implementation of controls. TruSight’s risk assessment of our security controls will help customers accelerate and complete their risk management due diligence.
  • Data governance: Check out this new blog series on data governance where our teams explain the role of data governance, its importance, and the necessary processes to run an effective data governance program. Implementing data governance will help maximize value derived from business data, build user trust, and ensure compliance with required security measures.

Controls and Products

Don’t forget to sign-up for our newsletter if you’d like to have our Cloud CISO Perspectives post delivered every month to your inbox. We’ll be back next month with more updates and security-related news.

Case Study

How the OLX Group Created a Scalable Organization with Collaboration

DOWNLOAD CASE STUDY

4439

Of your peers have already downloaded this article

3:48 Minutes

The most insightful time you'll spend today!

By focussing on win-win outcomes for buyers, sellers, and the communities in which it operates, the OLX Group has become a leading online trading platform with 17 brands, 4,000 employees across the world, and 300 million monthly users.

When the company wanted to improve communication and collaboration between teams around the world without imposing a top down solution, it used G Suite.

The OLX Group wanted to help its leadership team communicate its goals effectively and keep its local teams empowered. The company looked for a solution to address its communication needs and improve collaboration in a simple, easy-to-use way that could be rapidly deployed across its workforce.

“We needed to connect everybody and have a product that we could scale to the whole world. Our leadership and culture embrace change, so there’s always an open door to test new technologies that will help us improve and move fast. Google is, I think, a perfect example of that,” says Ana Garcia, Global Head of Communications at OLX Group.

The OLX Group has found a solution that connects all its teams across the world without compromising autonomy.

“Having a single document where managers in every country can input content at the same time is great. It’s the ultimate collaboration and I think it’s something that only Google can do for you,” she says.

How-to

6 ways Google Workspace helps IT admins safely use BYOD

4181

Of your peers have already read this article.

6:30 Minutes

The most insightful time you'll spend today!

With this widespread remote work, it’s never been more important for IT admins to be certain that every device in their organization is secure, even when that device isn’t company-owned. Here's how Google Workspace ensures that.

Many organizations, including Google, have moved quickly to embrace working from home. With this widespread remote work, it’s never been more important for IT admins to be certain that every device in their organization is secure, even when that device isn’t company-owned. 

We pioneered zero-trust security through our BeyondCorp strategy and leverage it to offer advanced security for G Suite* users to protect secure access for all devices. Admins can enforce these controls across G Suite and other corporate applications and data, ensuring consistent security and user experience across your organization.

Today, we’re laying out six key controls that IT admins can use within G Suite to help keep their organizations safe when using the bring your own device approach (BYOD). You can also review our detailed security checklist here, and learn more from our course on Managing G Suite here

Secure mobile and desktop devices with endpoint management

1 Managing mobile devices with G Suite.gif
Managing mobile devices with G Suite

BYOD devices can differ widely across an organization, with a range of OS versions, hardware modes, patch versions, and more, so it’s impossible to rely on a one-size-fits-all approach to device management. With Google endpoint management, IT admins can easily support a variety of mobile and desktop devices by enforcing measures like minimum software versions and blocking jailbroken or rooted devices, in many cases without requiring full device rights for employee privacy. 

When it comes to managing mobile devices, G Suite offers basic and advanced mobile device management:

  • With basic mobile device management, BYOD devices are secured with baseline security features with no end user friction. Admins can enforce a passcode, get a device inventory, wipe Google accounts remotely, and even remotely install applications on Android devices. 
  • With advanced mobile device management, admins can apply more policy controls over BYOD devices, and Android users can keep their personal data private and separate from their work data with Android Work Profiles. You can also allow and manage work apps on iOS and Android devices.
2 Bringing basic coverage to desktop devices with fundamental device management.jpg
Bringing basic coverage to desktop devices with fundamental device management
3 Managing and securing Windows 10 devices with G Suite.jpg
Managing and securing Windows 10 devices with G Suite

Admins can also manage and secure desktop devices with fundamental device management and enhanced desktop security for Windows. With fundamental device management, when a user logs into G Suite through any browser on a Windows, Mac, Chrome, or Linux device, that device will be automatically enrolled with endpoint management. This provides a base level of security to every desktop device that accesses G Suite data. With enhanced desktop security for Windows, admins can easily manage and secure Windows 10 devices through the admin console.

Enable secure connections without a corporate VPN using context-aware access

4 Context-aware access.jpg
Context-aware access

Context-aware access offers protection from unwanted access to G Suite services without the need for a VPN, and allows admins to set up different access levels based on a user’s identity and the context of the request, taking into account factors such as the country, device security status, and IP address of the request. For example, you can require BYOD devices accessing G Suite to meet encryption and password requirements, or restrict contractors from accessing G Suite from company managed Chromebooks.

Control data access with app access control

5 Helping protect against unwanted app access with app access control.jpg
Helping protect against unwanted app access with app access control

It’s important to protect all devices in your organization—corporate or BYOD—from malicious apps trying to gain access to corporate data. Using app access control, admins can take steps to prevent these apps from tricking users into mistakenly granting access to corporate data. With this feature, admins can choose which third-party apps are allowed to access users’ G Suite data by explicitly trusting, limiting, or blocking access for apps.

Enforce 2-Step Verification

6 Enforcing additional verification steps for increased assurance.jpg
Enforcing additional verification steps for increased assurance

With 2-Step Verification, admins can reduce the risk of unauthorized access by asking users for additional proof of identity when signing in. And you can now use the Advanced Protection Program—our strongest protection for users at risk of targeted attacks. With the Advanced Protection Program for the enterprise, we’ll enforce a specific set of policies for enrolled users including security key enforcement, blocking access to untrusted apps and enhanced scanning for email threats

If you choose not to use security keys for any reason, you have multiple other options to enforce 2-Step Verification on BYOD devices. For Android and iOS, you can use Google promptGoogle Authenticator, text message, or phone call options for a second verification step.

Prevent data loss and leakage with data loss prevention

7 Data loss prevention helps protect sensitive data.gif
Data loss prevention helps protect sensitive data

We know that as an admin, one of your highest priorities is to keep internal information safe and secure. That’s why we developed data loss prevention (DLP) policies to help protect sensitive information in Drive, Docs, Sheets, Slides, and Gmail from loss, misuse, or being accessed by unauthorized users. With G Suite DLP, admins can choose which types of data are sensitive and exactly how to protect them. Our controls enable easy detection of a wide variety of common info types, and administrators can supplement this with custom content detectors to meet their organization’s needs. You can also classify files in Drive automatically using DLP rules (beta) to categorize your data by sensitivity levels. DLP works on all the devices in your organization, including BYOD ones, since the protection is at the data and application level. 

In addition to DLP, you can use DXP for iOS devices to restrict the copy/pasting of G Suite data to other accounts, personal or otherwise. DXP for iOS can also restrict users’ ability to drag and drop files from specific apps within their G Suite account. Similarly, you can use Google endpoint management to configure Android devices to prevent data sharing between personal and work profiles.

Make retention and eDiscovery possible on all your devices with Vault

8 Satisfy your information governance needs with Vault.jpg
Help satisfy your information governance needs with Vault

To support your organization’s retention and eDiscovery needs, Vault enables corporate data that’s stored in G Suite and accessed by BYOD devices to be available for all your information governance needs. No matter the owner of the device, your organization’s data stored in Gmail, Drive, Chat, Groups, Voice, and Meet are accessible to Vault.

Using the zero-trust security model, the G Suite features above work together to keep your data protected and organization secure across all devices, whether they’re corporate-owned or BYOD.

(*Google Workspace was previously G Suite)

More Relevant Stories for Your Company

Research Reports

Download the Forrester Study to Explore the Benefits of AI for IT Operations in Cloud Environment

Organizations are currently modernizing their businesses in order to meet the increasing complexity of today’s business landscape. In effect, business leaders must evaluate the best way to mitigate the challenges which plague their cloud operations, all while meeting customers’ growing expectations around digital experience (DX) through agility, automation, and proactive

Case Study

How the UK’s Football Association Turns to Tech to Ensure its 29 Teams Deliver World-Class Performance

The FA is an iconic British institution responsible for overseeing all aspects of football in the UK, from the grassroots club level across the country to the national teams who play at Wembley. However, even icons like The FA must evolve to stay at the top of their game and

Blog

No-code Development Platforms Help Employees Reclaim their Time and Talent

As offices reopen, businesses aren’t keeping to a single formula. Many are embracing hybrid models, with employees splitting time between home and the office. Some are staying 100% remote. Others are returning the full workforce to offices with a greater focus on digitization.   Regardless of their model, one thing is

Webinar

No user left behind: Empowering collaboration with security

Your employees need to work from home to keep your business running. The traditional network-based on-premise approach to security is broken when your end-users are accessing core apps in the cloud from anywhere on any device.Our primary goal is to ensure that security does not get in the way of

SHOW MORE STORIES