Skip to content
Back to Blog
·7 min read·guides

Sample MSSP Monthly Report: What Indian Buyers Get

A real (redacted) example of the monthly report Bachao.AI MSSP customers receive. SLO scorecard, S1+S2 incident log, detection coverage map, and the next-30-day detection roadmap.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

What's in the monthly report

This is the actual structure of the monthly board-ready PDF report a Bachao.AI MSSP customer receives. The version below is redacted from a real April 2026 report for a mid-tier Indian fintech (workloads + names anonymised).

Section 1: SLO scorecard (1 page)

MetricTargetThis monthLast monthYoY
Mean Time to Detect< 4 min2.8 min3.1 min-32%
Mean Time to Respond (S1)< 22 min17 min19 min-28%
Mean Time to Respond (S2)< 60 min41 min44 min-15%
Detection coverage (MITRE)90%91% (+1)90%+6pt
False-positive rate< 8%5.2%6.1%-22%
S1 eventsreference21+1
S2 eventsreference1411+27%
S3 eventsreference8791-4%
S4 events (suppressed)reference1,4201,280+11%
Status: All SLOs met. MTTD trending down month-over-month. Detection coverage up 1 point after AWS Backup attack technique rule added.

Section 2: S1 incident log (1 page per incident)

For each S1 (potential breach) event:

IR-2026-04-007 — Suspected credential stuffing on customer login > Detected: 2026-04-12 03:47 IST Detection rule: cred-stuffing-velocity-001 Source: Cloudflare logs + Okta event 0x91 Initial severity: S2 (auto-escalated to S1 at 03:51 after credential validation succeeded for 4 accounts) > Timeline:
    1. 03:47 — first detection (Tier 1)
    2. 03:51 — escalation to S1 (Tier 2 review)
    3. 03:54 — incident commander paged
    4. 03:58 — affected accounts force-logged-out, MFA forced
    5. 04:02 — customer security team Slack channel updated
    6. 04:18 — customer CTO call (vCISO joined)
    7. 06:30 — affected customer accounts (4) emailed
    8. 12:15 — DPB India notification submitted (precautionary; investigation ongoing)
> Outcome: 4 customer accounts compromised via credential reuse from a third-party breach. No customer transaction loss. DPDP Section 8(6) notification filed precautionary; not legally required as no fiduciary breach. > Detection improvements: enriched cred-stuffing rule to factor in geo-velocity (3 customer accounts logged in from same IP within 90s); FP rate expected unchanged. > Total time-to-containment: 11 minutes. Total time-to-customer-notification: 2 hours 43 minutes.

S1 events get this level of detail in the monthly report. The customer's CTO and CFO read it. The board sees the abbreviated summary.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Section 3: S2 incident log (1 page summary)

Single table of all 14 S2 events with: ID, time detected, type (cred stuffing, brute force, anomalous data access, etc.), source, time to triage, outcome.

Examples:

    1. IR-2026-04-022 (data access anomaly): engineer queried customer table outside normal hours. Confirmed legitimate (BCP testing). Closed in 38 min.
    2. IR-2026-04-031 (suspicious IAM action): contractor IAM key used from new country. Confirmed legitimate (employee on holiday). Closed in 22 min after geo-confirmation.
    3. IR-2026-04-039 (suspected phishing on employee): credential-grabber URL clicked but session token not exfiltrated. Force-rotated cred. Closed in 41 min.

Section 4: Detection coverage map (1 page)

MITRE ATT&CK tactics × detection rule count:

TacticRules deployedCoverage %Gaps to close in May
Initial Access2395%(none)
Execution1992%T1059.006 (Python script execution) — adding rule
Persistence3189%T1547.014 (AppCert DLLs) — Windows-only, customer is Linux/macOS — N/A
Privilege Escalation2491%T1548.005 (UAC bypass) — Windows-only — N/A
Defense Evasion3887%T1070.001 (clear Linux logs) — adding rule
Credential Access2793%(none)
Discovery1995%(none)
Lateral Movement1889%T1021.005 (VNC) — service not in use — N/A
Collection1486%T1119 (automated collection) — adding rule
Exfiltration2291%(none)
Impact1788%T1486.002 (DB-level encryption ransomware) — adding rule
Coverage scoring uses customer's actual environment. Windows-only or service-not-deployed techniques are scored N/A, not failed.

Section 5: Threat intelligence brief (1 page)

Sector-specific intel from the past month, filtered to customer's vertical:

    1. 3 active credential-stuffing campaigns observed against Indian fintechs this month — lists in confluence://intel/2026-04-fintech-cred-stuffing
    2. Indian APT group "OperationStarlight" observed targeting digital lending platforms — TTPs included in detection rule update
    3. New CERT-In advisory CIVN-2026-0312 (Jenkins plugin RCE) — customer environment not affected, action: confirmed at week 1

Section 6: 30-day detection roadmap (1 page)

Week ofDetection ruleWhy added
W1 MayT1059.006 (Python script execution)Closing gap identified in April coverage review
W1 MayT1070.001 (clear Linux logs)Same as above
W2 MayCustomer-specific: API rate-limit abuseCustomer launching new public API; pre-emptive coverage
W2 MayT1119 (automated collection)Same as above
W3 MayT1486.002 (DB ransomware)Same as above
W3 MayInsider-threat: data export anomaly (volume)Quarterly insider-threat sprint
W4 MayPurple team exercise scenarios (8)Scheduled
W4 MayCustomer rule review: tune cred-stuffing geo-velocityBased on IR-2026-04-007 lesson

Section 7: SOC team and customer feedback (half page)

Named SOC lead, hunt engineer, and incident commander assigned to the account. Customer SOC liaison name. Any escalation pattern observations.

Customer-side feedback summary from the past month (collected via post-incident surveys for S1+S2 events).

Section 8: Compliance posture summary (half page)

    1. DPDP Act 2023: status of obligations covered by SOC operations
    2. RBI cyber framework: alignment status
    3. CERT-In Rule 3 (6-hour reporting): 100% compliance this month
    4. ISO 27001 Annex A controls operationally evidenced this month
Audit-ready evidence count for the month appended.

This is what a customer's CISO actually uses. Not a slide deck — an operational record.

See how Bachao.AI's MSSP works →


Related: MSSP Methodology · MSSP Case Study: NBFC MTTR

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →