Updated: April 2026
Hybrid teams rely on Microsoft 365 and Google Workspace to stay productive. But these platforms are also where attackers focus their attention, and the threat landscape in 2026 looks markedly different from even a year ago. Credential phishing targeting Microsoft 365 users has surged, Teams-based impersonation attacks have moved from edge case to established tactic, and ransomware campaigns are increasingly targeting cloud-synced files.
The good news is that both Microsoft and Google have shipped significant security upgrades over the past twelve months. The challenge is that many of these features aren’t enabled by default, and keeping up with what’s changed across two platforms is a job in itself.
Why Hybrid Teams Face Greater Risk
Hybrid working means your data lives across devices, networks, and locations. The same flexibility that makes cloud collaboration work also creates a wider attack surface. Common risks include:
- Data leakage and shadow IT. Employees sharing files through unapproved apps or misconfigured sharing settings remains one of the most common ways sensitive data leaves an organisation, often without anyone realising.
- Credential theft and phishing. Still the number one cause of breaches. Attackers now use QR code phishing, domain spoofing, and multi-stage campaigns that bypass basic email filters. Microsoft 365 users have been a particular target, with researchers documenting sharp increases in credential phishing over the past year.
- Collaboration platform attacks. It’s no longer just email. Teams-based impersonation, where attackers pose as IT staff or executives via calls and messages, has become a real and growing threat. Social engineering has followed users onto every platform they use to communicate.
What’s Changed in Microsoft 365 Security
Microsoft has made some meaningful moves in 2026, and the most significant is the expansion of Defender for Office 365 protections into lower licensing tiers.
Previously, advanced email security features like Safe Links (which scans URLs in real time) and enhanced anti-phishing were only available in higher-tier plans like E5 or as paid add-ons. From 2026, Microsoft is rolling Defender for Office 365 Plan 1 protections into Office 365 E3 and Microsoft 365 E3. URL checking is also being added to E1, Business Basic, and Business Standard plans.
This is a genuine step forward for small and mid-sized businesses. But there’s a catch that matters: these features are not turned on by default. They sit in your tenant, dormant, until an administrator enables and configures them in the Microsoft 365 Defender portal. If nobody flips the switches, your organisation doesn’t benefit.
Beyond email, the key best practices for Microsoft 365 remain:
- Multi-factor authentication and conditional access. Non-negotiable. MFA stops the majority of credential-based attacks, and conditional access lets you set rules based on device, location, and risk level.
- Data loss prevention and encryption. Prevent sensitive data from being shared outside your organisation, whether accidentally or deliberately.
- Regular policy reviews. Microsoft’s recommended security settings evolve based on real-world attack data. If you configured your tenant two years ago and haven’t revisited it, your policies may not reflect current best practices.
A Microsoft 365 pricing increase takes effect on 1 July 2026, covering most commercial suite subscriptions. If you’re approaching a renewal, it’s worth reviewing your licensing alongside your security posture to make sure you’re getting value from the features already included in your plan.
What’s Changed in Google Workspace Security
Google has been busy too. The headline update for 2026 is the general availability of ransomware detection and file restoration for Google Drive, which moved out of beta in March 2026.
When ransomware is detected on a user’s device, Google Drive for desktop now pauses file syncing automatically to prevent encrypted files from overwriting clean cloud copies. Users and admins receive alerts, and affected users can bulk-restore files to pre-infection versions directly from Drive. Google reports its latest detection model identifies 14 times more infections than the beta version.
Both features are enabled by default for all Workspace customers, which is a welcome contrast to Microsoft’s approach. Admins can manage them at the organisational unit level through the Admin console.
Other notable Workspace security developments include:
- Stricter group membership classifications. From Q2 2026, Google Groups is introducing tighter internal and external membership classifications to improve data security around group-based sharing.
- Admin control for Apple Intelligence Writing Tools. A new setting in the Admin console lets administrators disable Apple Intelligence Writing Tools within Workspace iOS apps, preventing work data from being processed through Apple’s on-device AI features. This is off by default, meaning Writing Tools are permitted unless an admin explicitly disables them.
- Guest accounts for external collaboration. Now generally available, allowing organisations to collaborate with external partners in Google Chat without giving them full Workspace access.
The core Google Workspace security practices still apply: enforce context-aware access to restrict system and file access based on device and location, manage Drive sharing settings tightly, and make use of Google’s built-in phishing and malware defences across Gmail and Drive.
Building a Unified Security Policy Across Both Platforms
Many of the organisations we work with use both Microsoft 365 and Google Workspace, or at least have users touching both ecosystems. Security gaps emerge quickly when policies differ between platforms, and the risk multiplies when new features are enabled on one but not the other.
To keep things consistent:
- Apply the same standards everywhere. MFA, conditional access, sharing restrictions, and data loss prevention should work the same way regardless of which platform a user is in.
- Monitor continuously. Flag unusual sign-ins, suspicious file access, and configuration drift across both environments. A quarterly review is the minimum; continuous monitoring is better.
- Train your people. The most sophisticated platform security in the world doesn’t help if someone hands over their credentials to a phishing page. Regular, practical awareness training remains the single most effective defence against social engineering.
Secure Your Hybrid Collaboration with Dr Logic
Keeping two cloud platforms secure, properly configured, and aligned with each other is a significant ongoing commitment. Dr Logic’s cyber security team helps businesses apply best practices across Microsoft 365 and Google Workspace, close configuration gaps, and stay ahead of emerging threats without slowing your team down.
If your hybrid security setup hasn’t been reviewed since these 2026 changes rolled out, now is a good time.
Book a Cyber Health Check and take the first step toward secure hybrid collaboration.
Related Articles
- AI Has Changed the Cyber Threat Landscape – Here’s What Businesses Need to Know
- False Sense of Security: Why Doing ‘Just Enough’ Leaves You Wide Open
- Shadow IT: How to Detect and Manage Unauthorised Apps
FAQs
Are the new Microsoft 365 security features turned on automatically?
No. The expanded Defender for Office 365 protections being added to E3 and lower-tier plans in 2026 are not enabled by default. An administrator needs to configure Safe Links, anti-phishing policies, and URL checking through the Microsoft 365 Defender portal. If nobody enables them, your organisation won’t benefit from the upgrade.
Does Google Workspace's ransomware detection work on Macs?
Yes. The feature works through Google Drive for desktop, which is available on both macOS and Windows. When ransomware is detected on a device, Drive syncing pauses automatically and the user and admin are alerted. File restoration lets users bulk-restore affected files to clean versions.
How often should we review our cloud security settings?
At minimum, quarterly. But given the pace of change across both platforms in 2026, a more proactive approach is better. New features, changed defaults, and evolving attack methods mean that a policy configured even six months ago may no longer reflect best practice. Continuous monitoring combined with periodic reviews gives you the strongest protection.



















































