Skip to content
Back to Blog
·7 min read·guides

Case Study: How a Bengaluru Fintech Used vCISO to Close Series B Security Diligence

Real engagement: a 65-person Bengaluru-based digital lending startup needed SOC 2 Type II readiness in 12 weeks to close their Series B lead investor's diligence requirement. Here's how the Bachao.AI vCISO did it.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Security Built for Fintech

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

The situation

A Bengaluru-based digital lending startup (we'll call them "FinCo" — actual name redacted under the engagement NDA) had completed term sheet negotiation for a ₹120 Cr Series B led by a top-tier global VC. The diligence cover sheet had a clear line item:

"Closing condition: SOC 2 Type II report or equivalent independent security audit, dated within 90 days of close."

FinCo had:

    1. 65 employees (35 engineering, 8 ops, 12 sales, 10 support)
    2. AWS-only infrastructure, single account
    3. No CISO, no security engineer, no formal policies
    4. A two-person DevOps team that "did security on the side"
    5. A 14-week runway to closing
A traditional Big-4 SOC 2 consultancy quoted ₹80L and 8 months. FinCo's CFO did the math: deal slip = ₹15-25 Cr opportunity cost. They needed a different path.

How the engagement was scoped

FinCo's CEO reached Bachao.AI on a Friday. By the following Wednesday we had:

    1. A 2-page Engagement Charter signed by both sides
    2. A named vCISO (former CISO at a listed payments company) assigned 30 hours/week
    3. A backup engineer for evidence collection and tooling
    4. A weekly cadence: Tuesday vCISO call with FinCo CTO + CEO, Thursday async update to the board
Total fee: ₹8L flat for 8 weeks. ₹4L for weeks 9–12 ongoing oversight through the audit.

The 12-week sprint

Weeks 1–2: Current-state assessment

The vCISO ran two workshops. Output:

    1. Asset inventory: 47 production systems, 12 third-party SaaS, 8 contractor accounts
    2. Risk register: 38 risks identified. Top 5 (by residual after planned controls): privileged access, secrets management, audit logging gaps, vendor DPAs missing, backup recovery untested
    3. Initial gap analysis against SOC 2 CC and trust criteria: 24 of 64 controls operational, 18 partial, 22 missing
Weeks 3–4: Policy and procedure sprint

Output: 11 policies drafted and approved by FinCo CEO. Acceptable Use, Access Control, Data Classification, Incident Response, Vendor Risk Management, Encryption, Secure SDLC, Background Verification, Change Management, BCP/DR, AI Use Policy.

Each policy went through one round of review with the CTO before formal approval. Total review time on FinCo's side: ~12 hours.

Weeks 5–7: Control implementation

This was the heaviest phase. The vCISO worked alongside FinCo DevOps to:

    1. Roll out RBAC across all AWS accounts (replacing shared admin access)
    2. Migrate 47 .env-stored secrets to AWS Secrets Manager with rotation
    3. Enable CloudTrail organization-wide with 90-day retention
    4. Deploy automated MFA enforcement on all human IAM users
    5. Set up the first incident response tabletop (the team had never done one)
    6. Implement a vendor DPA collection workflow for the top 20 sub-processors
    7. Run the first backup restore test (took 4 hours, found 1 critical bug in the recovery script — fixed it)
Weeks 8–9: Audit selection and pre-audit cleanup

Bachao.AI's vCISO recommended a mid-tier SOC 2 audit firm with India operations (₹14L all-in for Type II observation period plus reporting). FinCo's prior Big-4 quote was ₹80L.

Audit firm engagement started in week 8. The vCISO sat in every call.

Pre-audit checklist:

    1. Evidence repository organized by control
    2. Sample of 30 random employee access events pulled for the auditor
    3. Mock auditor interview run with the CTO and DevOps Lead
Weeks 10–11: Type I audit observation

Auditor observed control operation. The vCISO defended evidence in real-time and resolved 4 minor findings during the audit itself rather than waiting for the report.

Week 12: Final report + Series B close

Type I report delivered Day 80. FinCo's investor accepted the Type I report as satisfaction of the diligence condition, with FinCo committing to deliver Type II in 6 months (audit observation already running). Series B closed Day 86.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

What it cost

Line itemCost
Bachao.AI vCISO (weeks 1–8)₹8L
Bachao.AI ongoing retainer (weeks 9–12)₹4L
SOC 2 audit firm (Type I)₹6L
SOC 2 audit firm (Type II, observation period)₹8L
Tools (AWS Secrets Manager, MDM, SIEM upgrade)₹3L
Total₹29L
Original Big-4 path: ₹80L + ₹2L/mo retainer for 12 months = ₹104L+.

Savings: ₹75L. Time to compliance: 86 days vs 240 days.

What FinCo's CTO said after the engagement

"We thought a fast SOC 2 path would mean cutting corners. Bachao's vCISO didn't cut corners — they cut waste. We never built slide decks for slide deck's sake. Every artefact we produced has a job: an auditor reading it, a board member reading it, or an engineer following it. The vCISO is still on retainer because it's worth more than the cost."

Pattern this engagement followed

This is the most common shape of a vCISO engagement Bachao.AI runs:

  1. Compliance deadline tied to a business event (funding, customer, regulator)
  2. 8–12 weeks of focused work, not 6 months of advisory
  3. Real evidence collection, not slides
  4. Direct relationship with the audit firm or regulator
  5. Ongoing retainer after the deadline to keep posture current
If this is your situation:

Schedule a 60-minute scoping call →


Related: vCISO 90-Day Methodology · Sample vCISO Deliverables · Virtual CISO Services India 2026 Guide

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

RBI and NPCI-aligned security testing for payment platforms

Free automated scan — risk score in under 2 hours. No credit card required.

Security Built for Fintech
Find your vulnerabilitiesStart free scan →