forumNew topic

The whole team logs into the same Google Drive account with the same password, how risky is this, what's the alternative?

NNecati K***MemberCommunity member
Joined
Oct 2023
Message
324
#1

Shared Google Drive account — nobody knows who made changes.

EErcanMember
Job title
Accountant
Joined
Sep 2024
Message
92
Most Helpful#2

Shared cloud accounts are risky. Solution: Everyone should have their own Google account. Organize team files using 'Shared Drive' (Google Workspace). Access can be controlled.

İİbrahim Y***MemberCommunity member
Joined
Feb 2026
Message
3
#3

we were doing this too..... anyway when we got google workspace we set up shaed drive, it was great

PPolat K***MemberCommunity member
Joined
May 2023
Message
329
#4

Google Workspace > Shared Drives > Access permissions can be set granularly.

ÖÖzge T***Member
Job title
Quality control inspector
Sector
Jewelry
Organization type
workshop
Joined
Feb 2023
Message
193
#5

Thanks for writing this, that's the right way. Forgotten test environments are more often the entry point than live systems.

SSerkan Ç***MemberCommunity member
Joined
Sep 2024
Message
2
#6

This thread is archived.

İİlknur O***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
chain store
Joined
Feb 2025
Message
109
#7

If I understood correctly, you're saying: When making decisions, write down the worst-case scenario too, not just the best.

If you post the result here, it will help others too.

JJülide S***ExpertCommunity member
Joined
Sep 2023
Message
184
#8

There are three things to check when doing this. An untested backup is not a backup.

The biggest time-waster for us was not knowing who had the final say. Of course, it varies if your situation is different.

GGökhan B***Expert
Job title
Information Security Specialist
Sector
Software
Organization type
8-person team
Joined
Nov 2023
Message
20
#9

i'm writing this so you don't make the same mistake then btw security isn't absolute; it's about making attacks not worth the effort.

if I were you, Id go this route.

CCem D***Member
Job title
Human Resources Specialist
Sector
Accounting & advisory
Organization type
8-person team
Joined
Feb 2026
Message
84
#10

We need to make a distinction here. The biggest time-waster for us was not knowing who had the final say.

If I were you, I'd go this route.

IIrmak Ö***Member
Job title
Company Owner
Sector
Security services
Organization type
two-branch business
Joined
Apr 2023
Message
53
#11

I felt relieved reading this answer, so it's not just me. The real issue isn't the number, but what it's based on.

Good luck with that.

ÖÖzgür C***MemberCommunity member
Joined
Feb 2026
Message
32
#12

We experienced almost the exact same thing last year. honestly just because everyone does it doesn't mean it's right.

An untested backup is not a backup. I'm also curious if anyone does it differently.

AAli Ş***ExpertCommunity member
Joined
Aug 2024
Message
1
#13

im in the same situation, thats why Im asking. tbh mistakes made on the cloud account sharing side are usually reversible but expensive.

if I were you Id go this route.

KKemal U***VeteranCommunity member
Joined
Nov 2025
Message
1
#14

I've been down this road, let me tell you. If you scold false alarms, nobody will report again.

If you have questions, write them; I'll answer as best I can.

AAycan T***Member
Job title
Data entry clerk
Sector
Leather
Organization type
boutique agency
Joined
Apr 2023
Message
334
#15

I'm writing this so you don't make the same mistake. Don't hesitate to ask; those who don't ask always pay more.

Having backups accessible on the same network and with the same identity makes them part of the target. Good luck with that.

VVeli Ç***New member
Job title
Call center representative
Sector
Machinery manufacturing
Organization type
cooperative
Joined
Jun 2026
Message
387
#16

I feel the same way. An untested backup is not a backup.

Good luck with that.

BBarış K***Veteran
Job title
Network Administrator
Sector
Cleaning services
Organization type
medium-sized business
Joined
Sep 2024
Message
61

Doki · Mobile app · 2024

#17

There are three things to check when doing this. If 2FA is on, a stolen password alone is useless.

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
#18

Let me summarize what's been said so far. Just because everyone does it doesn't mean it's right.

HHavva G***MemberCommunity member
Joined
Feb 2023
Message
384
#19

Do you think this works at any scale? People defend habits, not processes. Resistance comes from there.

GGizem Ş***MemberCommunity member
Joined
Apr 2022
Message
253
#20

Let me summarize what's been said so far. An automated scan report is not the same as a penetration test.

Mistakes made on the cloud account sharing side are usually reversible but expensive. Proven by experience.

Reply