CYBERVED AI PRIVATE LIMITED
CYBER INCIDENT RESPONSE &
CYBER FRAUD POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Information Security / Risk / Fraud / Compliance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Cyber Incident & Fraud Control Policy |
1. PURPOSE
This Policy establishes the framework for identifying, reporting, containing, investigating, resolving and learning from cyber-security incidents and suspected cyber fraud affecting CYBERVED AI PRIVATE LIMITED, its customers, systems, partners or digital services.
2. OBJECTIVES
- Enable timely identification and escalation of cyber incidents.
- Contain threats and reduce customer/business impact.
- Preserve relevant evidence and maintain investigation records.
- Coordinate with PPI, bank, payment, technology and other partners.
- Manage suspected cyber fraud and unauthorised activity.
- Support applicable legal, regulatory and contractual reporting.
3. SCOPE
This Policy applies to employees, contractors, systems, applications, APIs, cloud services, endpoints, customer information, transaction systems, gift-card/voucher platforms and third-party services used by the Company.
4. INCIDENT TYPES
- Unauthorised access
- Credential compromise
- Malware or ransomware
- Phishing / social engineering
- API or application attack
- Data breach or suspected data leakage
- Account takeover
- Payment or voucher fraud
- System disruption / denial of service
- Third-party security incident
5. INCIDENT REPORTING
Employees, contractors and relevant partners shall promptly report suspected incidents through designated security or management channels. Customer reports shall be routed to the appropriate support and security functions.
6. INCIDENT SEVERITY
- Critical – significant security, financial, customer or operational impact
- High – material compromise or high likelihood of harm
- Medium – contained incident with limited impact
- Low – minor event requiring monitoring or corrective action
7. INCIDENT RESPONSE LIFECYCLE
- Detection and reporting
- Initial triage and classification
- Containment
- Investigation and evidence preservation
- Eradication / remediation
- Recovery and service restoration
- Post-incident review
8. INITIAL TRIAGE
The response team shall assess affected systems, customer impact, transaction exposure, security indicators, partner dependency and urgency to determine the appropriate response.
9. CONTAINMENT
- Disable or restrict compromised accounts where appropriate.
- Block malicious indicators or access paths.
- Isolate affected systems where operationally feasible.
- Restrict suspicious transactions or voucher activity.
- Coordinate temporary controls with relevant partners.
10. EVIDENCE PRESERVATION
Relevant logs, transaction records, system images or other evidence shall be preserved where appropriate. Evidence handling shall be documented to support investigation and applicable legal or regulatory processes.
11. CYBER FRAUD RESPONSE
Suspected cyber fraud shall be assessed using transaction records, account activity, authentication information, voucher status, payment records and other available evidence. Fraud cases shall also follow the Fraud Prevention & Transaction Monitoring Policy and Unauthorised Transaction Policy.
12. CUSTOMER PROTECTION
- Identify potentially affected customers.
- Apply proportionate transaction/account controls.
- Coordinate refunds, reversals or disputes where applicable.
- Provide appropriate customer communication.
- Protect investigation-sensitive information.
13. PPI / BANK / PAYMENT PARTNER ESCALATION
Incidents affecting regulated payment or PPI services shall be escalated to the relevant authorised issuer, bank, payment processor or other partner according to contractual and applicable requirements.
14. THIRD-PARTY INCIDENTS
Security incidents reported by vendors or partners that may affect Company systems, customers or data shall be assessed and tracked through the incident-management process.
15. REGULATORY / LAW ENFORCEMENT COORDINATION
Where an incident triggers legal, regulatory, contractual or law-enforcement obligations, the Company shall coordinate with the appropriate authority or partner through authorised personnel and applicable procedures.
16. COMMUNICATIONS
External communications concerning material incidents shall be controlled and approved by authorised management, Compliance/Legal and other relevant functions. Employees shall not make unauthorised public statements about incidents.
17. RECOVERY
Recovery shall prioritise secure restoration of critical systems and services. Systems shall be validated before being returned to normal operation.
18. ROOT CAUSE ANALYSIS
Material incidents shall be reviewed to determine contributing factors, control failures and opportunities for improvement.
19. CORRECTIVE & PREVENTIVE ACTION
Actions may include patching, credential resets, security-control improvements, process changes, employee training, partner remediation or technology enhancements.
20. POST-INCIDENT REVIEW
- Timeline of incident and response
- Impact assessment
- Controls that worked or failed
- Customer/partner impact
- Financial impact
- Root cause
- Corrective actions and owners
21. INCIDENT RECORD
Each material incident shall have a documented record containing classification, timeline, affected assets, actions, evidence, communications, decisions and closure status.
22. FRAUD INTELLIGENCE
Relevant fraud indicators, patterns and lessons may be incorporated into transaction-monitoring rules, customer controls and partner risk assessments.
23. CONFIDENTIALITY
Incident information shall be shared strictly on a need-to-know basis and protected according to information-security and privacy requirements.
24. BUSINESS CONTINUITY
Incident response shall coordinate with Business Continuity & Disaster Recovery arrangements for significant operational disruptions.
25. TESTING & EXERCISES
Incident-response procedures should be periodically tested through tabletop exercises, simulations or other appropriate methods based on risk.
26. TRAINING
Relevant personnel shall receive training on incident reporting, phishing/social engineering, fraud indicators, evidence preservation, escalation and secure communication.
27. EXCEPTIONS
Exceptions to response procedures shall be documented and approved by authorised management, without bypassing mandatory legal or regulatory obligations.
28. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Information Security / IT | Detection, containment, technical investigation and recovery | Security/Technology Head |
| Risk / Fraud | Fraud assessment and transaction controls | Risk/Fraud Head |
| Operations | Customer/service coordination | Operations Head |
| Compliance / Legal | Regulatory, legal and reporting oversight | Compliance / Legal |
| Partner Management | PPI/bank/payment/vendor coordination | Management |
| Management | Material decisions and external communication approval | Director |
| All Personnel | Prompt reporting and cooperation | Security / Management |
29. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and after material incidents, major technology changes, partner changes or significant changes in the threat environment or applicable requirements.
30. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Risk / Fraud / Compliance | |
| Reviewed By | Legal / Management | |
| Approved By | Director / Authorised Signatory |