Skip to Content

Gmail Security for Manufacturers

Lock Down Your Shop
August 26, 2025 by
Jay Stoltzfus
Jay Stoltzfus

It's 7:10 on a Tuesday. Your office manager takes a call from the buyer at your biggest customer, and it isn't about the parts. He wants to know why last month's payments went to a different bank. He has the email in front of him. It came from your address, references the right job numbers, reads the way you write, and it went out at 11:40 on a Saturday night.

Nobody touched a machine. Nobody got past a firewall. Somebody logged into an email account. That's the whole attack. Gmail security for a small manufacturer stopped being an office housekeeping item a long time ago. It's a money problem now.

The invoice was $38,400. You already bought the material, ran the parts, and shipped them. Now you're out the money, your customer's finance department is asking questions, and a relationship you spent nine years building has a crack in it.

The FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025, with reported losses of just over $3 billion, second only to investment fraud across every category they track (2025 IC3 Annual Report). Those aren't Fortune 500 numbers. The shops that get hit look like yours: one owner, one office manager, and an email password that hasn't changed since the last time somebody set up a printer.

Here's the plain-English version we walk through with shops around Parkesburg and across Chester and Lancaster County. No product pitch, no acronym soup. Just what actually keeps someone out of your inbox.

Why Gmail Security Is a Production Problem, Not an Office Problem

Your email account isn't a mailbox. It's the master key to the business. Look at what runs through it on a normal week:

  • Quotes and POs, with pricing you'd rather your competitor never see
  • Prints and revisions buried in threads going back four years
  • The "reset my password" link for your bank, your ERP portal, your vendor portals, and your carrier accounts, all pointed at that one address
  • Vendor invoices with routing numbers sitting right there in the PDF
  • Job updates your customer expects to see coming from you, in your voice

Someone who gets in usually breaks nothing. He reads. For two or three weeks he learns your job numbers, your payment terms, which customer is slow to pay and which one never questions an invoice. He quietly adds a filter so the replies he doesn't want you to see skip your inbox. Then he waits for a big invoice to go out and sends one email.

Two outside forces figured this out before most shop owners did. Cyber insurance carriers now ask whether multi factor authentication is turned on for email before they'll quote your renewal, and a wire fraud claim can get denied when the answer turns out to be no. And Tier 1 customers have started sending vendor security questionnaires that ask the same question in more words. Both of them already decided your email is the soft spot.

How Attackers Actually Get Into a Shop's Email

Phishing that knows your business. The old tells are gone. No broken English, no "Dear Valued Customer." Attackers now feed AI a few of your real emails and get back a message that matches your rhythm and references a job you're actually running. The FBI's 2025 report tracked AI-assisted crime as its own category for the first time: 22,364 complaints and roughly $893 million in losses.

A login page that looks exactly right. You click a link in what appears to be a shared quote, you get a Google sign-in page, you type your password out of habit. The page is a copy. Worse, the good ones relay your two factor code to the real Google in real time while you sit there.

The prompt you approved at 6:05 a.m. Your phone buzzes with an approval request while you're pulling into the lot with coffee in your hand. You tap yes because you're always logging into something. That was the attacker, holding your stolen password, waiting for you to be busy.

A voice you recognize. Voice cloning has gotten cheap. Your office manager gets a voicemail that sounds like you, approving a banking change you never made, so the email that follows feels confirmed.

Doors nobody closed. The quoting app you tried in 2021 still has permission to read your mail. The account for the guy who left in March still works. That contractor you gave access to for one project never got turned off.

A password from somewhere else. The one you use for email is the one you used on a supplier portal that got breached in 2023. It's for sale in a list, along with your address.

An 8 Step Gmail Security Plan for a 20 Person Shop

None of this takes a week. Most of it is an afternoon, one time.

1. Get off free Gmail and onto Google Workspace

If your shop runs on free @gmail.com accounts, nothing else on this list is enforceable. You get no admin console, so you can't require multi factor, can't see who logged in from where, and can't shut off an account the day somebody quits. Workspace is a few dollars per user per month and it puts your business behind your own domain, which your customers notice too.

2. Turn on real multi factor, everywhere, no exceptions

This is the single step that would have stopped the Tuesday morning phone call. Text message codes are better than nothing and weaker than they sound, since they can be intercepted or phished live. An authenticator app is a real step up. Hardware security keys are the strongest thing available, and they're about $30. Owner, office manager, and anyone who touches money gets a key.

3. One password manager, sixteen characters, zero reuse

Nobody remembers 40 good passwords, so people reuse three bad ones. A password manager generates long random ones and fills them in for you, and it means the breach of some vendor's website in 2023 doesn't hand somebody your email. Pick one, roll it out, and let people stop keeping the sticky note under the keyboard.

4. Clean out what's connected to the account

Open the third party access list and look at what has permission to read your mail. Most shops find five to fifteen things, half of them from software nobody uses anymore. Revoke everything you don't recognize or don't currently use. Put a note on the calendar to do it again in six months.

5. Prove your outgoing mail is really yours

Three DNS records (SPF, DKIM, and DMARC) tell the world which servers are allowed to send email using your shop's name. Without them, anyone can send a message that appears to come from you, and your customers have no way to tell. It's an hour of work at your domain host, and it's the difference between a spoofed invoice landing in a buyer's inbox or landing in junk. We wrote out the whole process for stopping someone from spoofing your shop's name.

6. Turn on alerts somebody actually sees

Google will tell you about a login from a new country or a sudden mailbox rule change. That's worth nothing if the alert goes to an address nobody opens. Route security alerts somewhere a human reads them the same day. If your shop runs second and third shift, remember the attacker keeps those hours too, and 9 p.m. on a Thursday is a great time to move money while nobody's watching.

7. Back up the mailbox, because Google isn't a backup

Google keeps your mail available. That's a different job than keeping a copy you can restore. If an account gets wiped, or a departing employee empties four years of customer threads on his last day, Google's window to help you is short and the answer is often no. A mailbox backup is a few dollars a month and it belongs in the same conversation as a real backup and recovery plan for your file server and ERP data.

8. Write down the money rule, then train first shift on it

One page, taped inside the office cabinet: any change to bank details, wire instructions, or a vendor's remit-to address gets verified by phone, using the number you already have on file, never the number in the email. Two people know about every payment over whatever number makes you nervous. Say it out loud at a shop meeting twice a year and give your office manager explicit permission to slow a payment down. Most six figure email fraud dies right there, on a 90 second phone call.

If You Think Someone Is Already In the Account

Move in this order, and move today.

  1. Change the password from a different device, then sign out every active session.
  2. Check filters and forwarding rules first. Attackers hide their tracks there, and deleting the rule is how you stop the bleeding.
  3. Check the recovery email and phone number on the account. If they were swapped, you lose the account entirely when you're locked out.
  4. Revoke every connected app and app password.
  5. If money moved, call your bank in hours, not days. Wire recalls have a short window, and after that the money is gone.
  6. File a report at ic3.gov. It's free, it takes fifteen minutes, and it's how the FBI's recovery team gets involved.
  7. Tell any customer or vendor who may have received a message from that account, before they wire something.

The Quiet Bonus: An Easier Insurance Renewal

Everything on that list happens to be what your cyber insurance application asks about. Multi factor on email, a password manager, backups you can prove, documented procedures for payment changes. Shops that have those in place get through renewal without the scramble, and they don't hand their broker a form with three "no" answers on it. It's the same list a Tier 1 customer's vendor questionnaire runs through, which means one afternoon of work answers two problems. If renewal is coming up, here's what carriers are actually asking manufacturers for.

Gmail Security FAQs for Small Manufacturers

Is a free Gmail account good enough for a small manufacturer?

No. A free account gives you no admin control, so you can't force multi factor authentication, can't see login history across the shop, and can't lock an account when someone quits. It also puts your business behind a gmail.com address instead of your own domain, which customers notice. Google Workspace runs a few dollars per user per month.

Does Google back up my email?

Not in the way you need. Google keeps your mail available, but if an attacker or a departing employee deletes a year of threads, or an account gets wiped, Google's retention window is short and recovery isn't guaranteed. A third party mailbox backup keeps a separate copy you control, and it restores individual messages instead of everything at once.

Is text message two factor authentication good enough?

It's far better than nothing, and it's much weaker than the alternatives. Text codes can be intercepted through SIM swapping and phished in real time on a fake login page. An authenticator app is a large step up, and a hardware key is the strongest option available. Owner and office manager accounts should be on keys.

How do I know if someone else is in my email right now?

Check three things. Open your Google account's recent security activity and look for logins from places nobody has been. Open your mail settings and look at filters and forwarding rules, since attackers add rules that hide replies. Then look at connected apps. Anything you don't recognize gets revoked immediately.

Should a small shop worry about quantum computing breaking email encryption?

Not this year, and probably not this decade for a 20 person shop. It's a real long term research problem, and it's nowhere near the top of your list. The things that actually take money out of a small manufacturer's account are stolen passwords, missing multi factor, and a wire request nobody called to verify.

We run Microsoft 365, not Gmail. Does any of this apply?

Almost all of it. The menus differ, the attacks don't. Multi factor on every account, a password manager, connected app cleanup, mailbox backup, alerting, and a written callback rule for payment changes are the same list on either platform. The two platforms even share the same weak point, which is a person in a hurry.

Not Sure Who Else Is In Your Shop's Email?

Starlux IT is in Parkesburg, and we take care of the manufacturers around us: Coatesville, Downingtown, Gap, and shops across Chester and Lancaster County. We know what a file server full of SolidWorks and Mastercam files is worth to a floor that's trying to run, and we know what a stalled quote costs when the ERP is dragging. Our techs are local, so when something breaks we're on site the same day instead of leaving you on hold with a call center three time zones away. Our managed IT services built for manufacturers include the monitoring that watches your accounts on second and third shift, and a cyber insurance compliance package you can hand straight to your broker at renewal.

Give us 30 minutes. We'll look at how your email is set up right now, show you exactly where the gaps are, and you'll know where you stand whether you hire us or not. No pressure, no jargon, no invoice for the conversation.

Book your free 30 minutes →

Jay Stoltzfus
Jay Stoltzfus August 26, 2025
Share this post
Archive