← All controls

3 Government-backed attack alert routing

Google warns accounts it believes are targeted by state-sponsored attackers, through a system-defined alert rule that has been on by default since October 2018. The alert names the targeted user, so the work here is routing and response: raise the severity so it is not buried, send it to the monitored security address plus a named human, and record the response: password reset, enforced 2-Step Verification and Advanced Protection enrolment (№23), coordinated through an out-of-band call rather than an email reply.

Caveats

Setup steps

  1. Rules › Government-backed attacks

    Status
    Active
    Alert center
    On
    Severity
    High
  2. Rules › Government-backed attacks › Actions

    Email notifications
    On
    Recipients
    security-alerts@<domain> + named responder (internal-domain addresses only)

Ongoing maintenance

How to verify

  1. Open the system-defined rule "Government-backed attacks" and confirm Status = Active, alert center delivery On, and the recipient set is the monitored address plus a named responder.

v0.0.4 Detect policy #33 · #11 ↗