We have many astaros in different organizations, We had different results
I had as many as 800 alerts in some of them and as low as 1. Some Astaros had NO alerts at all.
The networks that didn´t have any machines using Google DNS had 0 alerts.
In all of the others the number of alerts raised and suddenly stopped.
I think that Sophos discovered the false positive issue (for some reason they marked some google host as a C&C server) and then they change the policy affecting google.
What i would like to hear is an explanation from Shopos, because it gave us a hard time figuring out what was going out, with hundres of email alerts in our admins accounts.