← Back to Index

Ashkaan Security Meeting - Recommendations

Date: September 29, 2025
Duration: ~3 hours
Participants: Quan, Charlie, Kris Neal, Steven Hanna, Ashkaan Hassan (EO, cybersecurity expert)


🎯 Core Security Principles

  1. Principle of Least Privilege — Every user gets bare minimum access to perform their function, nothing more
  2. Top-Level Permissions — Declare permissions at folder/share level, not ad-hoc per file
  3. Single Source of Truth — All company files in Google Drive (no WorkDrive, Dropbox, local storage)
  4. MFA Everything — Multi-factor authentication on every system, no exceptions
  5. Climbing the Tree — 90% protected = extremely unlikely to be attacked (bad guys target low-hanging fruit)

🌐 DNS & Domain Security

Critical Actions

Hosting

Marketing Domain


🔐 Google Workspace Security

Two-Factor Authentication (MFA)

Admin Accounts

Gmail Protection

Gmail Client


📂 Google Drive Security

Team Shares (Shared Drives)

Share Settings (Admin Console → Apps → Google Drive → Sharing)

Sales Documents Exception

Work-in-Progress Files

Backup


⚙️ Zoho Security

User Permissions Audit

Multi-Factor Authentication

Password Policy

Resolved Issues (Sep 29)


🔑 Password Management

Deploy 1Password Business Edition

Why Not Google Password Manager?


👥 Contractor & Remote Worker Security

Current Setup ✅

Best Practice


🎓 Security Awareness Training

Deploy Breach Secure Now (or KnowBe4)

Benefits


🤖 AI Security Policy

Create Company AI Policy


🛠️ Miscellaneous Recommendations

Email Deliverability

Legacy Systems

Website Hosting

Media Assets Folder Cleanup


📊 Priority Matrix

Critical (Do First)

  1. Enable 2FA on Google Workspace (all users)
  2. Deploy 1Password Business Edition
  3. Move DNS to Cloudflare + enable DNSSEC + CAA
  4. Audit Zoho permissions (especially remote workers)
  5. Migrate MFA to 1Password (away from SMS/Zoho OneAuth binary prompts)

High Priority (Next 30 Days)

  1. Design team share folder structure (EOS framework exercise)
  2. Migrate MyDrive files to team shares
  3. Set default shared drive settings (disable overrides, external access, non-member adds)
  4. Deploy Breach Secure Now training
  5. Create AI usage policy

Medium Priority (Next 90 Days)

  1. Backup solution (DropSuite)
  2. Upgrade DMARC to quarantine
  3. Migrate from Superhuman to Gmail (optional, team preference)
  4. Separate admin accounts (Quan)
  5. Create Google Groups for permission management

Low Priority (Ongoing)

  1. Monitor dark web scans
  2. Review phishing simulation results
  3. Periodic permission audits
  4. WP Engine/Flywheel migration (website hosting)
  5. WorkDrive/Dropbox cleanup

🔗 Tools Mentioned


🎯 Ashkaan's Analogies


📝 Follow-Up Actions from Meeting


Meeting Sentiment: Overwhelmingly positive. Team engaged, Ashkaan patient and thorough. Kris felt it was "Chinese to me" but Steven translated well. Quan committed to implementation ("we'll rinse this and figure out optimal path forward"). Charlie concerned about organic folder permissions pitfalls (Ashkaan reassured: team will surface needs organically).

Next Steps: Transcript review → prioritize actions → phase implementation (not flip-of-switch).