Founder & Chief Executive Officer — ShieldByte Infosec

VAISHALI MUTALIK

Cybersecurity LeaderEntrepreneurAuditorAuthor

Cybersecurity you can prove.
Securing a better tomorrow.

Explore my journey
Vaishali Mutalik
02 — My Story

THREE DECADES.
ONE EVOLVING MISSION.

It started with building systems.

Enterprise architecture, business process re-engineering — the unglamorous plumbing of banks, hospitals and government services.

Then with defending them.

The same systems, seen from the other side. Risk instead of features. What breaks instead of what ships.

Then with proving they were defended.

Governance is the harder discipline. Anyone can claim security. An auditor has to demonstrate it — repeatedly, to a standard, in front of a regulator.

Then with building the firm that does it.

ShieldByte Infosec: CERT-In empanelled, 400+ clients, 20+ countries. Moving organisations from reactive, checkbox security to measurable cyber resilience.

Now with the systems that act alone.

Agentic AI does not wait to be asked. Auditing it required a framework that did not exist — so it had to be written.

03 — Career Journey

FOUR CHAPTERS.
ONE DIRECTION.

The arc is what matters — each chapter began because the previous one stopped being enough.

01

CYBERSECURITY

Strategy formulation, IT risk management, security architecture.

C-CISO, CISSP, CISM, CISA, CRISC — the leadership credential stack.

02

GOVERNANCE

Standards, assurance and the discipline of provable security.

ISO 27001, 27701, 22301, 42001 lead auditor. GDPR, DPDP, HIPAA, PCI DSS programmes.

03

ENTREPRENEURSHIP

Founded ShieldByte Infosec — a CERT-In empanelled security and audit firm.

400+ clients across 20+ countries. Sustained 25–30% year-over-year growth.

04

AI SECURITY

Governance for systems that now act on their own.

Authored a three-layer governance framework for auditing agentic AI.

04 — Areas of Expertise

TEN DISCIPLINES.
ONE STANDARD.

  1. 01Cybersecurity Strategy & Architecture
  2. 02Information Security Governance
  3. 03Data Privacy & Regulatory Compliance
  4. 04Third-Party / Vendor Risk Management
  5. 05AI Governance & Agentic-AI Audit
  6. 06Vulnerability Assessment & Penetration Testing
  7. 07Enterprise Risk Management
  8. 08Security Audits, Assurance & Business Continuity
  9. 09IT Governance & Business Process Re-engineering
  10. 10Board & Executive Advisory
05 — Entrepreneurship

ONE THESIS.
THREE INSTRUMENTS.

Trust does not scale by hand. Each exists because a manual, subjective process needed to become a measurable one.

SHIELDBYTE INFOSECTHE FIRMASSESS — audit, VAPT, compliance SHIELDRISK TPRMTHE ENGINEQUANTIFY — vendor risk, scored SHIELDPHISHTHE PROVING GROUNDVERIFY — test the human control A LAYERED SECURITY ARCHITECTURE

ShieldByte Infosec

Founder & Chief Executive Officer
The firm.

A CERT-In empanelled cybersecurity and audit firm helping organisations move from reactive, checkbox security to proactive, measurable cyber resilience.

  • 400+ clients across 20+ countries
  • Banking, financial services, healthcare, IT services, manufacturing
  • Sustained 25–30% year-over-year growth
  • A team with 150+ combined years of security expertise

ShieldRisk TPRM

Co-Founder & Director
The engine.

An AI-powered third-party risk management platform automating vendor evaluation, due diligence and audit through a unified key-risk-indicator dashboard.

  • AI risk engine spanning multiple regulatory frameworks
  • SBOM risk correlation against real-world vulnerabilities
  • Automated vendor scoring and real-time KRI dashboards

ShieldPhish

Founder
The proving ground.

Phishing simulation and email security — because the control that fails most often is the human one, and the only way to measure it is to test it.

  • Continuous phishing simulation programmes
  • Behavioural risk measurement, not annual training theatre
06 — Global Reach

TWENTY-PLUS
COUNTRIES.

Regulatory regimes spanning GDPR (EU), the DPDP Act (India), HIPAA (US) and PCI DSS — advising boards across global geographies from a base in Mumbai.

  • 01IndiaHeadquarters
  • 02United StatesHIPAA · SOC 2
  • 03United Arab EmiratesAdvisory
  • 04SingaporeIMDA AI Governance
  • 05AustraliaAssurance
  • 06APACRegional programmes
SINGAPORE AUSTRALIA APAC UNITED STATES UAE MUMBAI
07 — Impact

MEASURED
IN OUTCOMES.

08 — Author
Own Your Power — book cover

OWN YOUR
POWER.

Life hacks, mindset & success strategies for modern women.

“This is your life. Own it.”

A no-nonsense, heartfelt guide for modern women navigating careers, family and entrepreneurship. From boardrooms to bedrooms, playdates to pitch decks — a reminder that your power was never meant to be small. Written under the same philosophy she brings to the boardroom: plan, prioritise, protect your peace.

Founder. Leader. Mom. Human. Still figuring it out.

09 — National Leadership

APPOINTED,
NOT APPLIED FOR.

Selected Member & Co-AuthorCERT-In Working Group on National Cybersecurity-Audit Standards, Subgroup 03

Appointed by the Indian Computer Emergency Response Team, Ministry of Electronics & IT, Government of India. Co-authored the national “AI Security Auditing Guidelines” framework.

Co-Chair, Call for PresentationsCERT-In SAMVAAD

Invited by CERT-In to co-chair the Call-for-Presentation sessions at its annual national conference for empanelled cybersecurity-auditing organisations, Mahabalipuram — reviewing and curating submissions from across the sector.

MemberISC2 India Task Force

Contributing to the national cybersecurity professional agenda; recognised publicly among India’s cybersecurity leaders.

MemberISACA — Mumbai Chapter

Active member; honoured as Woman Achiever 2021 for exceptional contribution to cybersecurity.

Awards & Honours
Professional Certifications & Credentials — 25+

Security Leadership

  • C-CISO — Chief Information Security Officer
  • CISSP
  • CISM
  • CISA
  • CRISC
  • ECSA — Certified Security Analyst

ISO Lead Auditor

  • ISO 27001:2022 — Information Security
  • ISO 27701:2019 — Privacy
  • ISO 22301:2019 — Business Continuity
  • ISO 42001:2023 — AI Management
  • ISO 9001:2015 — Quality
  • ISO 31000 — Risk Management

Privacy & Cyber Law

  • CDPSE — Data Privacy Solutions Engineer
  • DPDPA Certified Professional
  • GDPR Certified Practitioner (UK)
  • Data Protection Officer — Univ. of Derby
  • HIPAA Certified Professional
  • Diploma in Cyber Law
  • Digital / Internet Investigator

Technology & Operations

  • CPISI — PCI Security Implementer
  • CNSS — Network Security Specialist
  • Fortinet NSE
  • ITIL Foundation — ISO 20000 ITSM
  • SSAE 18
  • Oracle Certified DBA
Education

Post Graduate Diploma — Data Protection Officer, University of Derby (UK) · Diploma in Cyber Law · Master’s Degree, Mumbai University · Bachelor’s Degree, Mumbai University

— Original Contributions & Innovations

WORK THAT
DID NOT EXIST
BEFORE.

  1. 01
    Three-Layer Governance Framework for Auditing Agentic AI

    An original audit framework — Agent Governance, Agent Behaviour Assurance and Operational Risk Control — producing a calculable Agentic Audit Composite Score (AACS). Published in the CERT-In SAMVAAD proceedings.

  2. 02
    National AI Security Auditing Guidelines

    Co-authored India’s national framework for secure, ethical and auditable artificial intelligence, issued under CERT-In, Government of India, and aligned to ISO/IEC 42001, ISO 23894, the NIST AI RMF and the EU AI Act.

  3. 03
    ShieldRisk — AI Vendor-Risk Engine

    Pioneered an AI-powered engine that automates third-party risk assessment across multiple regulatory frameworks, replacing manual, subjective due diligence with a scalable, objective model.

  4. 04
    SBOM Risk Correlation Model

    An advanced model correlating software bill-of-materials data with real-world vulnerabilities and compliance risk, enabling proactive third-party mitigation with far greater precision.

  5. 05
    Natural-Language Audit Acceleration

    Natural-language automation of audit evidence review and reporting — cutting manual audit effort by over 70% while improving accuracy and compliance coverage.

  6. 06
    Cross-Domain AI Integration

    Unified AI across phishing defence, compliance, vendor risk and governance into a single cyber-risk framework, adaptable across industries and regulatory geographies.

10 — Publications & Thought Leadership
Peer-reviewed · Sole author

Auditing Agentic AI Systems

A Three-Layer Governance Framework for Autonomous Intelligence

“As AI systems evolve from assisting humans to acting autonomously, assurance must evolve from validating outputs to assuring decision pathways.”

Published in the official proceedings of CERT-In SAMVAAD, the national cybersecurity-audit conference of the Indian Computer Emergency Response Team, Ministry of Electronics & Information Technology, Government of India — held at BITS Pilani, K.K. Birla Goa Campus. Maps an agentic-AI audit regime to ISO/IEC 42001, the NIST AI RMF, the Singapore IMDA Model AI Governance Framework, and India’s DPDP Act and CERT-In directions.

Strengthening TrustEnsuring AccountabilityEnabling Autonomous Intelligence
In the Press
Women Times Magazine cover featuring Vaishali Mutalik
Women Times MagazineThe Guardian of TrustCover feature — The 10 Innovative Women Leaders in Cybersecurity
Business Talkz Plus feature: India's Cybersecurity Crossroads
Business Talkz PlusIndia’s Cybersecurity CrossroadsAuthored op-ed — securing the nation’s digital future
The Cyber 50: India's Elite Founders List
Indian Startup TimesThe Cyber 50: India’s Elite FoundersRecognising vision, leadership and impact
The Enterprise World
The Enterprise WorldBuilding a Cyber-Resilient FutureEntrepreneurial excellence and growth in cybersecurity
Publications
  • Auditing Agentic AI SystemsCERT-In SAMVAAD · BITS Pilani, Goa
  • AI Security — Governance & AdoptionISC2 SECURE India · The Ritz-Carlton, Bangalore

    Invited panel speaker at the inaugural edition, by formal invitation of the ISC2 Managing Director, APAC.

  • Preparing for the Quantum EraBombay Exhibition Centre, Mumbai

    Post-quantum cryptography readiness roadmap for India — panelist alongside the CISO of Mastercard.

  • Next-Gen ForensicsFICCI · Mumbai
  • SheLeadsTechISACA Pune · International Women’s Day

International speaker and coach on cybersecurity, governance, risk & compliance, ICT, and women in business leadership.

Media & Featured Profiles
11 — Contact

LET’S TALK CYBERSECURITY.

LinkedInin/vaishalimutalik Emailvaishali@shieldbyteinfosec.com SpeakingKeynotes, panels, conferences AdvisoryBoard & executive advisory CollaborationPartnerships & ventures