15-Minute Discovery Call Free · Fixed-Price Assessment · Written Roadmap Included

Most businesses have 5 to 7 critical gaps in their Google Workspace. Most have never looked.

A structured assessment of your Admin Console, DNS records, and devices against the five Cyber Essentials controls. Every finding explained in plain English, with the risk it carries and a roadmap telling you exactly what to fix and in what order. Start with a free 15-minute discovery call.

Best suited to businesses already running on Google Workspace. If you are not on Google Workspace yet, book a discovery call and we will scope the move first.

5 controls

Every check maps to one of the five Cyber Essentials controls

5–7

critical gaps found on the average first assessment

#1 finding

MFA not enforced, one stolen password unlocks everything

2 wks

Written report and roadmap delivered, fixed price agreed up front

The Process

How it works, three steps.

Start with a free 15-minute discovery call. If there is clear exposure, the assessment runs from there at a fixed price, and the written report lands within two weeks.

Book a 15-minute discovery call (free)

Pick a time using the booking link. A Google Meet link is automatically generated. This call costs nothing. You don't need to prepare anything.

Discovery call

A 15-minute conversation about your current setup, how your team uses Google Workspace, how you handle leavers, how your files are organised. If there is clear exposure, the next step is the assessment. The fixed price is confirmed on the discovery call before anything is booked.

The assessment and roadmap

Once payment is confirmed, you grant read-only delegated admin access. Every setting, account, and device in scope is checked against the five Cyber Essentials controls. Within two weeks you receive a written report: every gap found, the risk each one carries, and a prioritised remediation roadmap telling you what to fix first.

Book a Discovery Call

Book a 15-minute discovery call

A short conversation to understand your current setup. No preparation needed. If there is clear exposure, the assessment runs from there, with the fixed price confirmed on the call and the written report delivered within two weeks.

Free to book

The discovery call costs nothing. If there is clear exposure, the fixed-price assessment follows, invoiced before access is granted.

Read-only access only

You add a delegated admin account before the assessment begins, read-only. No passwords shared. Revoke it when the assessment is complete.

No obligation to continue

The roadmap is yours. You can action it yourself, pass it to another provider, or ask GetBulwark to handle the remediation.

Prefer email first? hello@getbulwark.com

Book a discovery call

15 minutes. Free. No preparation required.

15-Minute Operational Discovery

A free 15-minute conversation about your current setup. If there is clear exposure, the full assessment and written roadmap follows.

Book a free 15-minute call
Free discovery call, no cost, no obligation
Read-only access only, revocable at any time
Fixed-price assessment, confirmed on the discovery call
The Assessment

The checks most teams never verify.

Not a surface-level scan. We look inside your Admin Console, your DNS records, and your device management, and every check maps to one of the five Cyber Essentials controls. These are the settings that decide whether one phishing email becomes a nuisance or a real incident.

01Admin account securityCRITICAL
02User account hygieneHIGH
032FA enforcement, all usersCRITICAL
04Email authentication (DMARC, DKIM, SPF)CRITICAL
05External sharing settingsHIGH
06Third-party app permissionsHIGH
07Device management (MDM)HIGH
08Password policiesMEDIUM
09Audit log and alert settingsHIGH
10Gmail security settingsHIGH
11Drive and data residencyMEDIUM
12Endpoint protectionCRITICAL
13Backup coverageCRITICAL
14Leaver and joiner processHIGH
15Less secure app accessCRITICAL
16Email forwarding rulesCRITICAL
17Shared Drive permissionsHIGH
18Google Groups external accessMEDIUM
19Session and login controlsMEDIUM
20Screen lock and remote wipeHIGH
What you receive

A written report. Not a vague summary.

A structured report covering every control checked, the gaps that matter most, and the exact remediation steps. Written so a non-technical business owner can act on it, and detailed enough to hand to an in-house IT team.

  • A clear status for every check, mapped to the five Cyber Essentials controls
  • Risk level for each finding
  • Prioritised remediation list, most critical first
  • Plain-English explanation written for non-technical stakeholders
  • Yours to keep. The assessment covers the review and the written report, with no obligation beyond that.
Security Assessment Report Confidential

20 findings

Across the five controls, action required

6FAIL
7WARN
7PASS
Admin 2FA enforcement FAIL Enforce via Admin Console → Security
DMARC record PARTIAL Policy is p=none, update to p=quarantine
External sharing PASS Restricted to authorised domains ✓
Third-party app access FAIL 23 unreviewed apps, 4 flagged high risk
Backup coverage FAIL No independent backup for Gmail or Drive
Straight Answers

The questions everyone asks before booking

Why pay for an assessment? I can check things myself.

Most of the issues that cause real damage, stale OAuth tokens, permissive sharing policies, misconfigured DMARC, are not visible from inside your own account. You need delegated admin access to see what is actually configured, and you need to know what you are looking for. The assessment is a manual review by someone who checks these settings every day.

What do I actually get?

A manual review of your live Admin Console against the five Cyber Essentials controls, covering identity, email authentication, data access, and device compliance. Every finding is risk-rated, with the business risk in plain English and a specific remediation step. The report is structured so a non-technical founder can act on it, or hand it straight to an in-house IT team.

What access do you need?

Delegated admin access, read-only. That means a GetBulwark account is added to your Admin Console before the assessment and removed when the report is delivered. It cannot make changes, access email content, or delete anything. It takes two minutes to set up.

Do I have to become a client after the assessment?

No. The report is yours regardless. You can ask GetBulwark to handle the remediation as a fixed-price hardening project, take it to another provider, or action it yourself. All three are completely reasonable outcomes.

We already have IT support, is this still worth doing?

Yes, particularly if your current IT support is generalist. Most providers manage tickets and devices. They rarely review Google Workspace configuration at this level of depth. The assessment covers the controls that generalist IT typically does not touch, and the report is written to work alongside an in-house team, not around it.

How long does it take?

The discovery call is 15 minutes. If you proceed with the assessment, read-only access is granted and the review is completed independently. The written report and roadmap are delivered within two weeks.