The 25 Google Ads security checks Black Cat runs
Black Cat SSPM evaluates 25 security policies against your Google Ads configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Google Ads — what access Black Cat needs, and why.
Access control & privilege
14 checks · highest severity: high
Governance & compliance
7 checks · highest severity: high
Access control & privilege (14)
- Email-Only User Access severity: low
- Excessive Admin Users severity: medium
- Stale Pending Invitation severity: low
- Stale User Access severity: medium
- Account With No Admin Users severity: high
- Account With Single Admin User severity: low
- Stale Standard User Access severity: low
- Stale Admin Invitation severity: medium
- Self-Granted User Access severity: medium
- Stale Read-Only Invitation severity: low
- Stale Email-Only User Access severity: low
- Stale Admin Access severity: high
- User Access Without Inviter severity: medium
- Stale Standard Access Invitation severity: low
Governance & compliance (7)
- Account Budget Without End Date severity: medium
- Budget Without Spending Limit severity: high
- Billing Setup Pending severity: high
- Canceled Account in MCC Hierarchy severity: medium
- Billing Setup Without Payments Account severity: high
- Cancelled Billing Setup severity: medium
- Pending Account Budget severity: low
Other checks (4)
severity: medium Active External Data Link fix difficulty: medium #
Review and remove unauthorized external data links from the Google Ads account
- Navigate to Tools & Settings > Setup > Linked accounts
- Review the list of linked accounts and external data connections
- Identify any links that are no longer needed or were not authorized
- Click Remove on unauthorized or stale linked accounts
- Document approved external data links in your third-party access policy
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Recent Sensitive Change fix difficulty: medium #
Review recent sensitive changes in Google Ads to ensure they were authorized
- Navigate to Tools & Settings > Billing & Payments > Change History or use the Change History report in campaigns
- Filter the change history by the change type flagged in the finding (e.g., budget changes, billing, user access)
- Identify who made the change and when it occurred
- Confirm with the account owner or manager that the change was authorized
- If the change was unauthorized, revert it and investigate the source of the change
- Consider enabling additional access controls or approval workflows to prevent future unauthorized changes
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.e.1 DORA (SaaS Security) DORA-9.10
severity: high Recent Admin Role Change fix difficulty: medium #
Review the recent access role change to confirm it was authorized and did not result in unauthorized privilege escalation
- Navigate to Tools & Settings > Change History or the Campaigns > Change History report
- Filter by change type User Access and look for ACCESS_ROLE field changes within the last 72 hours
- Identify who made the change and which user's role was modified
- Confirm with the account owner that the role change was intentional and authorized
- If the change was not authorized, revert the role to its previous value immediately
- Investigate the actor's account for signs of compromise and consider resetting their credentials
- Update your access change log and notify your security team if unauthorized escalation is confirmed
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.e.1 DORA (SaaS Security) DORA-9.10
severity: high Suspended Account in MCC Hierarchy fix difficulty: medium #
Investigate and resolve the account suspension to restore ad delivery and prevent data loss
- Navigate to the affected account in Google Ads and review the suspension notice
- Identify the suspension reason (policy violation, billing failure, suspicious activity)
- If billing-related, update the payment method under Tools & Settings > Billing > Settings
- If policy-related, review the Google Ads policies that were violated and remediate the offending ads or landing pages
- Submit an appeal via the Google Ads Help Center if the suspension appears to be in error
- Monitor the account status after submitting the appeal and document the outcome
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC7.1 NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1