2. Enforce 2-step verification. Two-step verification (2SV) is one of the best ways to prevent someone from accessing your account, even if they steal your password. In G Suite, admins have the ability to enforce 2-step verification. 2SV can reduce the risk of successful phishing attacks by asking employees for additional proof of identity when they sign in.
3. Use Security Keys for 2SV. Working with FIDO Alliance standards, Google developed the Titan Security Key—a physical key used to access a Google Account without a traditional password. The key sends an encrypted signature and works only with the sites that it’s supposed to, helping to guard against phishing. G Suite admins can easily deploy, monitor, and manage the security keys at scale from within the Admin console–without installing additional software. At Google, we have had no reported or confirmed account takeovers due to password phishing since we began requiring security keys as a second factor for our employees.