Haripay INDIA PRIVATE LIMITED
CYBER INCIDENT RESPONSE & CYBER FRAUD POLICY
POLICY NO. 13 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | Haripay INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | Haripay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Information Security / Fraud Risk / Compliance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Incident Response Document |
1. PURPOSE
This Policy establishes the framework for identifying, reporting, containing, investigating, responding to and recovering from cyber incidents and cyber-fraud events affecting Haripay, its customers, systems, gift-card/voucher products or relevant partners.
2. OBJECTIVES
- Enable timely detection and escalation.
- Limit customer and business impact.
- Preserve evidence.
- Coordinate with PPI issuers, banks, payment partners and other stakeholders.
- Support appropriate reporting and legal obligations.
- Restore secure operations.
- Prevent recurrence through corrective action.
3. SCOPE
This Policy applies to cyber incidents, suspected cyber fraud, account compromise, credential theft, phishing, malware, unauthorised access, API abuse, data compromise, system disruption, fraudulent gift-card activity and other technology-enabled security events.
4. INCIDENT TYPES
- Phishing/social engineering
- Credential compromise
- Account takeover
- Malware/ransomware
- Unauthorised system access
- API abuse or credential leakage
- Gift-card/voucher fraud
- Payment fraud
- Data breach or suspected leakage
- Denial-of-service/service disruption
- Insider misuse
- Third-party security incident
5. INCIDENT SEVERITY
- Critical – material customer, financial, data or service impact
- High – significant impact or credible ongoing threat
- Medium – contained impact requiring formal investigation
- Low – limited impact handled through routine security procedures
6. REPORTING
Employees, contractors, partners and relevant stakeholders shall promptly report suspected cyber incidents through designated security or management channels. No person shall intentionally conceal a known material incident.
7. INCIDENT REGISTRATION
- Record incident reference.
- Record date/time detected.
- Identify reporting source.
- Classify preliminary type and severity.
- Assign incident owner.
- Start incident log.
- Initiate appropriate response.
8. INITIAL ASSESSMENT
The response team shall determine affected systems, customers, data, transactions, partners, geographic scope, potential financial exposure and whether the incident is ongoing.
9. CONTAINMENT
- Disable compromised credentials
- Restrict affected accounts
- Block malicious access
- Isolate affected systems where appropriate
- Suspend affected API keys
- Block suspicious transaction patterns
- Coordinate with relevant partners
Containment decisions shall consider customer impact and preservation of evidence.
10. EVIDENCE PRESERVATION
- System/application logs
- Authentication records
- API logs
- Transaction records
- Device/network indicators where available
- Emails/messages
- Screenshots or documents
- Partner communications
Evidence shall be preserved in a manner that maintains integrity and limits unauthorised access.
11. INVESTIGATION
The assigned response team shall establish the incident timeline, affected assets, attack method, root cause, customer impact, financial impact and control weaknesses using available evidence.
12. CYBER FRAUD INVESTIGATION
Where fraud is suspected, the case shall be coordinated with the Fraud Prevention & Transaction Monitoring function. Transaction and redemption records shall be reviewed and relevant accounts/products may be restricted according to approved procedures.
13. CUSTOMER PROTECTION
- Secure or restrict compromised accounts
- Block compromised voucher/code where possible
- Review suspicious transactions
- Coordinate refunds/reversals where applicable
- Provide security guidance
- Escalate material customer impact
14. PARTNER COORDINATION
Incidents involving a PPI issuer, bank, payment processor, merchant, technology provider or other partner shall be escalated according to contractual contacts and applicable procedures.
15. REGULATORY / LAW-ENFORCEMENT COORDINATION
Where an incident triggers a legal, regulatory, contractual or law-enforcement reporting obligation, Haripay shall coordinate the required response through authorised personnel and within applicable timelines.
16. COMMUNICATION CONTROL
External communications concerning material cyber incidents shall be controlled and issued only by authorised personnel. Public or customer communication shall avoid unnecessary disclosure of sensitive security information.
17. RECOVERY
- Remove or contain threat.
- Validate system integrity.
- Restore services from trusted sources where required.
- Reset or rotate compromised credentials.
- Monitor restored systems.
- Confirm partner readiness.
- Return to normal operations.
18. POST-INCIDENT REVIEW
After material incidents, a post-incident review shall identify root cause, control failures, lessons learned, corrective actions, owners and target dates.
19. CORRECTIVE & PREVENTIVE ACTION
- Patch vulnerabilities
- Improve access controls
- Rotate credentials/keys
- Update fraud rules
- Improve monitoring
- Enhance customer warnings
- Review vendor controls
- Update procedures/training
20. INCIDENT ESCALATION
- Critical/high severity incident
- Customer data exposure
- Material financial loss
- Ongoing attack
- Systemic compromise
- Significant service disruption
- Partner/regulatory notification
- Law-enforcement request
21. FRAUD-RELATED TRANSACTION CONTROLS
Suspicious transactions may be held, blocked, reviewed or escalated where supported by the applicable system, partner agreement and law. Decisions shall be documented.
22. THIRD-PARTY INCIDENTS
Third-party incidents affecting Haripay information, systems or customers shall be logged, assessed and managed through the vendor/partner escalation process.
23. BUSINESS CONTINUITY LINK
Where an incident causes significant service disruption, the Business Continuity & Disaster Recovery Policy shall be activated as appropriate.
24. RECORD KEEPING
- Incident report
- Timeline
- Severity assessment
- Actions taken
- Evidence register
- Partner communications
- Customer impact assessment
- Regulatory/law-enforcement records where applicable
- Root-cause analysis
- Corrective action plan
- Closure approval
25. CONFIDENTIALITY
Incident information shall be restricted to personnel with a legitimate need to know. Sensitive evidence and investigation material shall be securely stored.
26. TRAINING & DRILLS
Relevant personnel shall receive incident-response and cyber-fraud awareness training. Periodic tabletop exercises or response drills may be conducted based on risk.
27. MONITORING & REPORTING
- Incident count by severity
- Detection and response time
- Financial impact
- Customer impact
- Root causes
- Repeat incidents
- Third-party incidents
- Corrective action ageing
28. AUDIT & TESTING
Incident-response controls may be tested through audits, tabletop exercises, simulated scenarios, evidence reviews and control assessments.
29. POLICY EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or contractual obligations shall not be bypassed.
30. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Information Security / IT | Detection, containment, technical investigation and recovery | Technology/Security Head |
| Fraud/Risk | Cyber-fraud assessment and transaction controls | Compliance / Management |
| Compliance | Regulatory/contractual assessment and escalation | Management |
| Operations | Customer/process impact and operational actions | Operations Head |
| Partner Management | PPI/bank/payment/vendor coordination | Compliance / Management |
| Customer Support | Customer reports and communications | Operations / Compliance |
| Management | Material incident decisions and approvals | Director / Authorised Management |
31. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in cyber threats, technology, products, partner arrangements or applicable requirements.
32. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Fraud / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
