Skip to content
Back to Blog
·11 min read·guides

vCISO Engagement Methodology — How Bachao.AI Delivers in 90 Days

What a vCISO engagement looks like day-by-day at Bachao.AI: 2-week current-state assessment, 4-week policy + risk register sprint, 6-week compliance closure. The exact deliverables, owners, and review checkpoints.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

The 90-day vCISO engagement, plainly

Most Indian startups hire a vCISO because they have a deadline. A SOC 2 audit, a Series A diligence, a SEBI CSCRF cutoff, a customer questionnaire blocking a deal. They don't have time for a six-month "discovery phase."

Bachao.AI's vCISO engagement compresses what large consultancies stretch into 6 months into a structured 90-day sprint with measurable outputs every two weeks.

This page walks through exactly what you get, when you get it, and who at Bachao.AI is on the call.

Pre-engagement: 1 week before kickoff

Before the vCISO clock starts, we do a 60-minute scoping call with the founder + technical leader. We need to understand:

    1. The deadline (audit date, customer ask, deal close)
    2. The current security state (anything documented? incident history? team size?)
    3. The regulatory surface (DPDP, RBI, SEBI, SOC 2, ISO 27001, fintech-specific)
    4. The decision-maker (founder, CTO, board, customer)
Output: a 2-page Engagement Charter signed by both sides. Defines scope, deliverables, escalation, and the dedicated vCISO + backup engineer assigned.

Weeks 1–2: Current-state assessment

The named vCISO leads two structured workshops:

Workshop 1 (Day 2): Asset, data, and people inventory. We walk through every system that handles customer data, every cloud account, every third-party integration. By end of day, you have a CSV of every asset + classification.

Workshop 2 (Day 5): Threat modeling and risk register. We map the top 25 risks your business is exposed to right now, ranked by business impact. Each risk gets an owner and a status (open, mitigated, accepted).

Day 10 deliverable: A 25-page Current-State Assessment Report. Goes to the founder and the board.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Weeks 3–6: Policy, control, and roadmap sprint

This is the phase where most consultants overdeliver on slides and underdeliver on policies. We do it the other way around.

Each week ships 3 of these policies (Indian-statute-aligned, customizable to your business):

    1. Acceptable Use Policy
    2. Access Control Policy (with RBAC mapping)
    3. Data Classification & Handling Policy
    4. Incident Response Policy + playbook
    5. Vendor / Third-Party Risk Management Policy
    6. Business Continuity & Disaster Recovery Policy
    7. DPDP Act 2023 Compliance Procedures
    8. Encryption & Key Management Policy
    9. Secure SDLC Policy
    10. Background Verification Policy
    11. Change Management Policy
    12. Acceptable Use of AI / LLM Policy
Each policy comes with: (a) a 1-page summary the team can read in 5 minutes, (b) a full operational version for auditors, (c) the named owner in your team, (d) the review cadence.

Week 6 deliverable: Complete Policy Set (12 documents) + Risk Register v2 + 12-month Security Roadmap.

Weeks 7–10: Compliance closure sprint

The vCISO works with your engineering team to actually close the gaps. Not "recommend closure" — actually close them.

Typical closures:

    1. MFA enforcement on production access
    2. Centralised secrets management (replacing .env files)
    3. Audit log enrichment for SOC 2 CC7.2 / CC7.3
    4. Backup verification with documented restore test
    5. Vendor DPA collection (for top 20 sub-processors)
    6. Incident response tabletop exercise (one full simulation)
Week 10 deliverable: Closure log against the original risk register. Each item is closed, accepted with documented rationale, or scheduled for the next quarter.

Weeks 11–12: Audit dress rehearsal + handoff

If your engagement is SOC 2 / ISO 27001 / SEBI CSCRF readiness:

    1. Week 11: full evidence collection sprint. We pull every audit log, every policy ack, every meeting note, every approval — into a single auditor-ready package.
    2. Week 12: dress rehearsal with the auditor (we sit in the call, defend the evidence, capture residual gaps).
If your engagement is post-incident or customer-driven:
    1. Week 11: customer questionnaire response (we draft, you review)
    2. Week 12: customer call sit-in (vCISO joins as your security executive)
Day 90 deliverable: Audit-ready package + Handoff Briefing to your internal team for ongoing ownership.

What it costs

Engagement tierHours / monthMonthly feeUse case
Standard20–25 hours₹2LSeries A SaaS, 30-person team, first audit
Embedded30–40 hours₹4LSeries B+ fintech, regulated entity, ongoing
Pre-audit sprint40 hours/week × 8 weeks₹8L flatSOC 2 Type II readiness, SEBI CSCRF

The retention model

vCISO engagement does not end at day 90. After the 90-day sprint, clients transition to one of three models:

  1. Monthly retainer — 10–20 hours/month for ongoing oversight, customer security questionnaire support, quarterly board reporting
  2. Annual audit support — fixed 8-week engagement once a year before audit
  3. On-demand — pay-as-you-need for specific events (incident, due diligence, customer ask)
Most clients stay on retainer. The vCISO has internalized your business; starting over with a new consultant every year is wasteful.

How to start

The first step is a 60-minute scoping call. We review your current state, your deadline, and the right tier for your situation. No hard sell. If your situation is better served by a one-time VAPT or a do-it-yourself approach, we'll say so.

Schedule a vCISO scoping call →


Related: What a vCISO Delivers in the First 30 Days · Sample vCISO Deliverables · vCISO Case Study: Bengaluru Fintech Series B

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →