e-suvidha

CYBERVED AI PRIVATE LIMITED

CYBER INCIDENT RESPONSE &
CYBER FRAUD POLICY

POLICY NO. 13VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerInformation Security / Risk / Fraud / Compliance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Cyber Incident & Fraud Control Policy

1. PURPOSE

This Policy establishes the framework for identifying, reporting, containing, investigating, resolving and learning from cyber-security incidents and suspected cyber fraud affecting CYBERVED AI PRIVATE LIMITED, its customers, systems, partners or digital services.

2. OBJECTIVES

  • Enable timely identification and escalation of cyber incidents.
  • Contain threats and reduce customer/business impact.
  • Preserve relevant evidence and maintain investigation records.
  • Coordinate with PPI, bank, payment, technology and other partners.
  • Manage suspected cyber fraud and unauthorised activity.
  • Support applicable legal, regulatory and contractual reporting.

3. SCOPE

This Policy applies to employees, contractors, systems, applications, APIs, cloud services, endpoints, customer information, transaction systems, gift-card/voucher platforms and third-party services used by the Company.

4. INCIDENT TYPES

  • Unauthorised access
  • Credential compromise
  • Malware or ransomware
  • Phishing / social engineering
  • API or application attack
  • Data breach or suspected data leakage
  • Account takeover
  • Payment or voucher fraud
  • System disruption / denial of service
  • Third-party security incident

5. INCIDENT REPORTING

Employees, contractors and relevant partners shall promptly report suspected incidents through designated security or management channels. Customer reports shall be routed to the appropriate support and security functions.

6. INCIDENT SEVERITY

  • Critical – significant security, financial, customer or operational impact
  • High – material compromise or high likelihood of harm
  • Medium – contained incident with limited impact
  • Low – minor event requiring monitoring or corrective action

7. INCIDENT RESPONSE LIFECYCLE

  1. Detection and reporting
  2. Initial triage and classification
  3. Containment
  4. Investigation and evidence preservation
  5. Eradication / remediation
  6. Recovery and service restoration
  7. Post-incident review

8. INITIAL TRIAGE

The response team shall assess affected systems, customer impact, transaction exposure, security indicators, partner dependency and urgency to determine the appropriate response.

9. CONTAINMENT

  • Disable or restrict compromised accounts where appropriate.
  • Block malicious indicators or access paths.
  • Isolate affected systems where operationally feasible.
  • Restrict suspicious transactions or voucher activity.
  • Coordinate temporary controls with relevant partners.

10. EVIDENCE PRESERVATION

Relevant logs, transaction records, system images or other evidence shall be preserved where appropriate. Evidence handling shall be documented to support investigation and applicable legal or regulatory processes.

11. CYBER FRAUD RESPONSE

Suspected cyber fraud shall be assessed using transaction records, account activity, authentication information, voucher status, payment records and other available evidence. Fraud cases shall also follow the Fraud Prevention & Transaction Monitoring Policy and Unauthorised Transaction Policy.

12. CUSTOMER PROTECTION

  • Identify potentially affected customers.
  • Apply proportionate transaction/account controls.
  • Coordinate refunds, reversals or disputes where applicable.
  • Provide appropriate customer communication.
  • Protect investigation-sensitive information.

13. PPI / BANK / PAYMENT PARTNER ESCALATION

Incidents affecting regulated payment or PPI services shall be escalated to the relevant authorised issuer, bank, payment processor or other partner according to contractual and applicable requirements.

14. THIRD-PARTY INCIDENTS

Security incidents reported by vendors or partners that may affect Company systems, customers or data shall be assessed and tracked through the incident-management process.

15. REGULATORY / LAW ENFORCEMENT COORDINATION

Where an incident triggers legal, regulatory, contractual or law-enforcement obligations, the Company shall coordinate with the appropriate authority or partner through authorised personnel and applicable procedures.

16. COMMUNICATIONS

External communications concerning material incidents shall be controlled and approved by authorised management, Compliance/Legal and other relevant functions. Employees shall not make unauthorised public statements about incidents.

17. RECOVERY

Recovery shall prioritise secure restoration of critical systems and services. Systems shall be validated before being returned to normal operation.

18. ROOT CAUSE ANALYSIS

Material incidents shall be reviewed to determine contributing factors, control failures and opportunities for improvement.

19. CORRECTIVE & PREVENTIVE ACTION

Actions may include patching, credential resets, security-control improvements, process changes, employee training, partner remediation or technology enhancements.

20. POST-INCIDENT REVIEW

  • Timeline of incident and response
  • Impact assessment
  • Controls that worked or failed
  • Customer/partner impact
  • Financial impact
  • Root cause
  • Corrective actions and owners

21. INCIDENT RECORD

Each material incident shall have a documented record containing classification, timeline, affected assets, actions, evidence, communications, decisions and closure status.

22. FRAUD INTELLIGENCE

Relevant fraud indicators, patterns and lessons may be incorporated into transaction-monitoring rules, customer controls and partner risk assessments.

23. CONFIDENTIALITY

Incident information shall be shared strictly on a need-to-know basis and protected according to information-security and privacy requirements.

24. BUSINESS CONTINUITY

Incident response shall coordinate with Business Continuity & Disaster Recovery arrangements for significant operational disruptions.

25. TESTING & EXERCISES

Incident-response procedures should be periodically tested through tabletop exercises, simulations or other appropriate methods based on risk.

26. TRAINING

Relevant personnel shall receive training on incident reporting, phishing/social engineering, fraud indicators, evidence preservation, escalation and secure communication.

27. EXCEPTIONS

Exceptions to response procedures shall be documented and approved by authorised management, without bypassing mandatory legal or regulatory obligations.

28. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Information Security / ITDetection, containment, technical investigation and recoverySecurity/Technology Head
Risk / FraudFraud assessment and transaction controlsRisk/Fraud Head
OperationsCustomer/service coordinationOperations Head
Compliance / LegalRegulatory, legal and reporting oversightCompliance / Legal
Partner ManagementPPI/bank/payment/vendor coordinationManagement
ManagementMaterial decisions and external communication approvalDirector
All PersonnelPrompt reporting and cooperationSecurity / Management

29. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and after material incidents, major technology changes, partner changes or significant changes in the threat environment or applicable requirements.

30. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByInformation Security / Risk / Fraud / Compliance
Reviewed ByLegal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CYBER INCIDENT & FRAUD CONTROL POLICY

This document is confidential and intended for authorised use only.