Home / Security Log
Three anonymised engagements. Real Admin Console findings. Before-and-after audit scores. Every case is a UK business on Google Workspace that had outgrown basic IT — the same type of environment GetBulwark is built for.
All cases are anonymised. Sector, team size, and engagement type are accurate. Client names, industries, and any identifying details have been removed. Findings are taken directly from the scored audit reports delivered to each client.
Provenance: these engagements were conducted by Callum Fraser prior to founding GetBulwark, while working as a Google Workspace specialist at a UK-based Google Cloud Partner. GetBulwark was founded in March 2026 to deliver the same standard of work independently.
LOG_001 · Q1 2026
A 12-person creative agency on Google Workspace Business Starter. No IT function. The person who managed the Google Admin Console had left six months prior. Nobody had taken over admin access formally. Three users had no MFA and the domain DMARC policy was set to p=none — visible to anyone who checked, spoofable by anyone who tried.
Audit findings
p=none — domain spoofable, no enforcement in placeWhat was fixed
p=reject via staged rollout over 2 weeksLOG_002 · Q1 2026
An 8-person recruitment firm that had moved to Google Workspace from a shared-hosting email provider two years earlier. The migration was done by whoever was cheapest at the time. DKIM was never set up. Candidate CV data — names, addresses, salary expectations — was stored in a shared Drive folder accessible to all staff with no access governance in place.
Audit findings
p=none — no rejection or quarantine policyWhat was fixed
p=quarantine immediately, path to p=reject confirmedLOG_003 · Q1 2026
A 22-person professional services firm moving from a legacy Microsoft 365 setup managed by a generalist IT provider. Admin credentials were shared among three people with no audit trail. There was no SSO, no standardised device policy, and user provisioning was manual — new starters were getting access to everything by default. They wanted Google Workspace set up correctly before a single user was migrated.
What was at risk (M365 state)
What was built
p=reject configured on day one — domain protected before first email sentThe gaps in these cases are not unusual. They are the default.
Option A
45 minutes. 20 controls. Written report within 48 hours. Your setup scored out of 215 — same methodology as the cases above.
Book free auditOption B
Answer five questions and get an honest read on whether GetBulwark is right for your business. 60 seconds. No email required.
Is this right for me?Or email hello@getbulwark.com with any questions.