Home / Services / Sample Report

Monthly security report

Your security report. Produced and delivered every month.

Twenty checks, each mapped to the five Cyber Essentials controls. Every finding explained in plain English, with clear priorities and actions. Written for the person running the business, not just the person running IT.

Sample report, Example Ltd · March 2026 · This is example data, not a real client

0 of 20 checks passing

Above average, a typical first assessment passes around 9 of 20

Client
Example Ltd
Period
March 2026
Users
12
Devices
14
Trend
↑ 2 checks
4 /5 checks
Identity & Access
5 /5 checks
Email Security
3 /5 checks
Data Governance
2 /5 checks
Device Management
Identity & Access 4 / 5 checks
MFA enforced, 12/12 users compliant
Pass
Password policy, strong, 90-day expiry
Pass
Admin roles, 1 super admin (correct)
Pass
0 inactive accounts (>90 days)
Pass
Less secure app access, 2 users have legacy app exceptions
Review
Email Security 5 / 5 checks
SPF, hard fail (-all) configured correctly
Pass
DKIM, google selector verified and passing
Pass
DMARC, reject policy, aggregate reports active
Pass
No suspicious forwarding rules detected
Pass
Gmail safety settings, enhanced pre-delivery scanning on
Pass
Data Governance 3 / 5 checks
External sharing, restricted to domain allowlist
Pass
Shared Drive permissions, correctly scoped
Pass
Google Groups, 1 group allows external posting
Review
Marketplace apps, 3 approved, no unrestricted access
Pass
Data regions, not configured (recommended for regulated clients)
Review
Device Management 2 / 5 checks
Mobile Device Management, enabled and enforced
Pass
Endpoint protection, deployed on 12/14 devices
Pass
OS patch compliance, 1 MacBook pending macOS 15.3.1
Review
Screen lock, 2 mobile devices have no PIN requirement
Action
Remote wipe, confirmed for managed devices only (2 BYOD unmanaged)
Review

Recommended actions this month

High

Enforce screen lock PIN on 2 mobile devices. These devices can access company email and files without a lock screen.

↳ GetBulwark pushes this policy remotely. No action required from users.
Med

Revoke less secure app access for 2 users. Legacy apps are using basic authentication. GetBulwark will contact both users to migrate to OAuth-compatible alternatives.

Med

Restrict external posting on the "general" Google Group. Currently anyone outside the company can send email to this group address.

Page 01

Posture and summary

The first page gives your posture against the five Cyber Essentials controls and the short version of the month: what improved, what still needs work, and whether the environment is moving in the right direction.

Page 02

Finding-by-finding detail

Every control is listed individually with a pass, warning, or fail result. Nothing gets hidden behind “generally good” language. You can see exactly what is live and what is not.

Page 03-04

Actions and evidence trail

The report ends with what changed, what is scheduled next, and what evidence now exists. That is what makes the service defensible rather than just reassuring.

Before Hardening
9 / 20 checks
  • !MFA partly enforced, not universal
  • !DMARC present but not at reject
  • !No backup outside Google
  • !No written evidence the buyer could rely on
After Hardening
18 / 20 checks
  • MFA enforced on every account
  • DMARC at reject with reporting live
  • Daily backup outside Google configured
  • Monthly reporting starts from a clean baseline
What It Proves

The work is actually happening

A monthly report means the client does not have to guess whether the environment is still being checked. There is a dated record of what was reviewed and what changed.

What It Proves

The standard is staying fixed

The point is not a one-off cleanup. The report shows whether MFA stayed enforced, whether DMARC stayed correct, whether device coverage drifted, and whether new gaps appeared.

What It Proves

The buyer has something concrete

This is the document a founder, ops lead, client, insurer, or advisor can actually read. It replaces “I think our IT company handles that” with something specific and current.

Every GetBulwark client receives this report as a 4-page PDF on the 1st of each month. Twenty checks across four areas, each mapped to the five Cyber Essentials controls, every finding explained in plain English, with clear priorities for what to address first.

If nobody has checked your Workspace properly, start there.

Start with a free 15-minute discovery call. If there is clear exposure, a fixed-price assessment follows, with a written risk-rated report that is yours whether you work with GetBulwark or not.

Book a 15-Minute Discovery Call See how it works