Skip to content
Back to Blog
·9 min read·guides

Sample vCISO Deliverables: Risk Register, Policy Set, 90-Day Roadmap

What does a Bachao.AI vCISO actually hand over? Real (redacted) samples of the Risk Register, the Acceptable Use Policy, the Incident Response Playbook, and the 90-day Security Roadmap.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

What you actually receive

A common reason vCISO engagements feel "fluffy" is that the deliverables are slide decks. This page shows the concrete artefacts a Bachao.AI vCISO produces — the same documents that go into your SOC 2 / ISO 27001 evidence package and that your board sees in security reviews.

These are real samples (redacted from past engagements) of what gets delivered.

1. The Risk Register

Single spreadsheet, 25–60 rows depending on company size. Updated bi-weekly during the engagement and quarterly after.

Each risk row contains:

ColumnExample value
Risk IDR-007
CategoryAccess Control
DescriptionProduction database admin credentials shared across 4 engineers
LikelihoodHigh
Impact₹2–8 Cr (DPDP penalty + customer churn)
Inherent risk score16 / 25
TreatmentMitigate
Mitigation ownerDevOps Lead
Mitigation actions(1) RBAC roll-out, (2) shared admin → individual accounts, (3) audit log retention to 90 days
Target close date2026-08-15
Residual risk score4 / 25
StatusIn progress
Evidence linkconfluence://security/r-007
The board sees a 1-page summary view (top 10 risks by residual score). The auditor sees the full sheet with evidence.

2. Sample policy: Acceptable Use Policy

12 pages, plain English. Excerpt from Section 4 (Cloud and SaaS):

4.1 Approved SaaS list Engineering, finance, and HR may use SaaS tools only from the Approved list maintained in confluence://it/approved-saas. Adding a new tool requires submitting a 1-page Vendor Risk Assessment (template in confluence://templates/vendor-risk) reviewed within 2 working days by the vCISO or designated security owner. > 4.2 Personal device access Personal laptops may access company resources only through the company VPN and only after MDM enrollment. Personal mobile devices may access email and Slack with the company MDM profile installed. Personal devices may not store customer personal data offline. > 4.3 Generative AI use Employees may use approved generative AI tools (currently: ChatGPT Team, Claude.ai with team plan, GitHub Copilot Business) for general productivity. Customer data, source code, financial data, and personal data may not be pasted into any consumer or unapproved AI tool. Suspected accidental paste must be reported within 24 hours.

Every policy includes: scope, approval, definitions, controls, monitoring, enforcement, and review cadence.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

3. Sample policy: Incident Response Playbook

15 pages with decision trees. Excerpt from the Detection-to-Containment section:

Severity 1 (potential data breach) > Within 30 minutes:
  1. On-call engineer pages the vCISO via priority hotline
  2. vCISO opens an Incident Channel in Slack (channel name pattern: #ir-yyyy-mm-dd-)
  3. Affected systems are isolated (network ACL or revoke API keys; documented in playbook)
  4. Forensic snapshot captured before any remediation
> Within 6 hours (CERT-In Rule 3 obligation):
  1. Initial incident report filed to incident@cert-in.org.in using the template in confluence://ir/cert-in-template
> Within 24 hours:
  1. Customer notification draft (template in confluence://ir/customer-notice) reviewed by legal counsel
> Within 72 hours (DPDP Section 8(6)):
  1. DPB India notification if breach of personal data is confirmed
Decision tree maps every observed signal to a severity level (S1–S4), each with prescribed timelines.

4. The 90-day Security Roadmap

Single page Gantt + table. Sample week-1 entries:

WeekOwnerTaskStatusEvidence
W1DevOps LeadEnforce MFA on AWS rootDonescreenshot in confluence://evidence/mfa-aws-root
W1CTOMigrate .env secrets to AWS Secrets ManagerIn progressjira://ENG-432
W1HR LeadSend Acceptable Use Policy to all employeesDoneacks 23 of 28 in google-form
W2DevOps LeadEnable CloudTrail log retention 90 daysDoneaws-config check passed
W2vCISOCustomer security questionnaire (Capgemini)Pending customerdraft in confluence://qs/capgemini-2026-04
The board sees the weekly status. The auditor sees the evidence column.

5. The Compliance Mapping

For SOC 2 / ISO 27001 / DPDP / SEBI CSCRF engagements, the vCISO maintains a control-to-evidence mapping spreadsheet.

Example for SOC 2 CC6.1 (Logical and Physical Access Controls):

ControlOperational evidenceDocument evidenceStatus
CC6.1.a (MFA on critical systems)aws-config snapshot showing MFA enforcedscreenshot in evidence/CC6.1.a.pngOperational
CC6.1.b (RBAC documented)IAM policy review logdoc-id: ACS-001Operational
CC6.1.c (Quarterly access review)last 4 quarters' access review recordssheet-id: ACS-Q-ReviewsOperational
Auditor reads this single sheet and ticks boxes. No follow-up email chains.

6. Board-ready security report (quarterly)

8-slide PDF deck delivered the last week of each quarter. Outline:

  1. Top 5 risks accepted by leadership this quarter
  2. Top 5 risks mitigated this quarter
  3. Open audit findings & treatment status
  4. Customer security questionnaires answered (count + close rate)
  5. Incident summary (count, severity, response time)
  6. Compliance posture (SOC 2 / ISO 27001 / DPDP / SEBI status)
  7. Spend on security (this quarter vs budget)
  8. Next quarter priorities
Goes to the board pack. CFO uses it for D&O insurance renewals.

How to get these

These deliverables are produced for every Bachao.AI vCISO engagement. They're not slides — they're the working artefacts your team uses every day after the engagement ends. The 90-day sprint produces all six. Ongoing retainer keeps them current.

Start a vCISO engagement → — first scoping call is free.


Related: vCISO 90-Day Methodology · vCISO Case Study: Bengaluru Fintech

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →