Discovering that an attacker has gained access to Google Workspace is only the beginning of an incident. What security teams do next can determine how much damage the attacker is able to cause.
On September 23, 2026, BleepingComputer will host a live webinar titled "Breach autopsy: How fast-growing companies are breached through Google Workspace" with Material Security.
The webinar will feature Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, examining real, publicly documented Google Workspace breaches and the decisions organizations made during the critical first hours of an incident.
In two of the attacks examined during the webinar, threat actors combined social engineering with malicious OAuth applications to gain access to Google Workspace environments.
But understanding how an attacker got in is only one part of responding to a breach.
Once suspicious access is discovered, security teams must determine what was compromised, what users and data may have been exposed, whether the attacker still has access, and what actions are needed to contain the incident.
For fast-growing companies with lean security teams, making these decisions quickly can be particularly challenging as responders work to understand an attack while simultaneously trying to prevent it from spreading or causing further damage.
The webinar will examine what happened during the earliest stages of real Google Workspace breaches, which response decisions helped limit their impact, and which actions could potentially make an incident worse.
Attendees will also hear which security controls the speakers believe provide the greatest value and what they would build differently if designing a Google Workspace security program from scratch.
The decisions made after a breach matter
... continue reading