RanaPay

RANAPAY INDIA PRIVATE LIMITED

CYBER INCIDENT RESPONSE & CYBER FRAUD POLICY

POLICY NO. 13 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerInformation Security / Fraud Risk / Compliance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Incident Response Document

1. PURPOSE

This Policy establishes the framework for identifying, reporting, containing, investigating, responding to and recovering from cyber incidents and cyber-fraud events affecting RanaPay, its customers, systems, gift-card/voucher products or relevant partners.

2. OBJECTIVES

  • Enable timely detection and escalation.
  • Limit customer and business impact.
  • Preserve evidence.
  • Coordinate with PPI issuers, banks, payment partners and other stakeholders.
  • Support appropriate reporting and legal obligations.
  • Restore secure operations.
  • Prevent recurrence through corrective action.

3. SCOPE

This Policy applies to cyber incidents, suspected cyber fraud, account compromise, credential theft, phishing, malware, unauthorised access, API abuse, data compromise, system disruption, fraudulent gift-card activity and other technology-enabled security events.

4. INCIDENT TYPES

  • Phishing/social engineering
  • Credential compromise
  • Account takeover
  • Malware/ransomware
  • Unauthorised system access
  • API abuse or credential leakage
  • Gift-card/voucher fraud
  • Payment fraud
  • Data breach or suspected leakage
  • Denial-of-service/service disruption
  • Insider misuse
  • Third-party security incident

5. INCIDENT SEVERITY

  • Critical – material customer, financial, data or service impact
  • High – significant impact or credible ongoing threat
  • Medium – contained impact requiring formal investigation
  • Low – limited impact handled through routine security procedures

6. REPORTING

Employees, contractors, partners and relevant stakeholders shall promptly report suspected cyber incidents through designated security or management channels. No person shall intentionally conceal a known material incident.

7. INCIDENT REGISTRATION

  1. Record incident reference.
  2. Record date/time detected.
  3. Identify reporting source.
  4. Classify preliminary type and severity.
  5. Assign incident owner.
  6. Start incident log.
  7. Initiate appropriate response.

8. INITIAL ASSESSMENT

The response team shall determine affected systems, customers, data, transactions, partners, geographic scope, potential financial exposure and whether the incident is ongoing.

9. CONTAINMENT

  • Disable compromised credentials
  • Restrict affected accounts
  • Block malicious access
  • Isolate affected systems where appropriate
  • Suspend affected API keys
  • Block suspicious transaction patterns
  • Coordinate with relevant partners

Containment decisions shall consider customer impact and preservation of evidence.

10. EVIDENCE PRESERVATION

  • System/application logs
  • Authentication records
  • API logs
  • Transaction records
  • Device/network indicators where available
  • Emails/messages
  • Screenshots or documents
  • Partner communications

Evidence shall be preserved in a manner that maintains integrity and limits unauthorised access.

11. INVESTIGATION

The assigned response team shall establish the incident timeline, affected assets, attack method, root cause, customer impact, financial impact and control weaknesses using available evidence.

12. CYBER FRAUD INVESTIGATION

Where fraud is suspected, the case shall be coordinated with the Fraud Prevention & Transaction Monitoring function. Transaction and redemption records shall be reviewed and relevant accounts/products may be restricted according to approved procedures.

13. CUSTOMER PROTECTION

  • Secure or restrict compromised accounts
  • Block compromised voucher/code where possible
  • Review suspicious transactions
  • Coordinate refunds/reversals where applicable
  • Provide security guidance
  • Escalate material customer impact

14. PARTNER COORDINATION

Incidents involving a PPI issuer, bank, payment processor, merchant, technology provider or other partner shall be escalated according to contractual contacts and applicable procedures.

15. REGULATORY / LAW-ENFORCEMENT COORDINATION

Where an incident triggers a legal, regulatory, contractual or law-enforcement reporting obligation, RanaPay shall coordinate the required response through authorised personnel and within applicable timelines.

16. COMMUNICATION CONTROL

External communications concerning material cyber incidents shall be controlled and issued only by authorised personnel. Public or customer communication shall avoid unnecessary disclosure of sensitive security information.

17. RECOVERY

  1. Remove or contain threat.
  2. Validate system integrity.
  3. Restore services from trusted sources where required.
  4. Reset or rotate compromised credentials.
  5. Monitor restored systems.
  6. Confirm partner readiness.
  7. Return to normal operations.

18. POST-INCIDENT REVIEW

After material incidents, a post-incident review shall identify root cause, control failures, lessons learned, corrective actions, owners and target dates.

19. CORRECTIVE & PREVENTIVE ACTION

  • Patch vulnerabilities
  • Improve access controls
  • Rotate credentials/keys
  • Update fraud rules
  • Improve monitoring
  • Enhance customer warnings
  • Review vendor controls
  • Update procedures/training

20. INCIDENT ESCALATION

  • Critical/high severity incident
  • Customer data exposure
  • Material financial loss
  • Ongoing attack
  • Systemic compromise
  • Significant service disruption
  • Partner/regulatory notification
  • Law-enforcement request

21. FRAUD-RELATED TRANSACTION CONTROLS

Suspicious transactions may be held, blocked, reviewed or escalated where supported by the applicable system, partner agreement and law. Decisions shall be documented.

22. THIRD-PARTY INCIDENTS

Third-party incidents affecting RanaPay information, systems or customers shall be logged, assessed and managed through the vendor/partner escalation process.

23. BUSINESS CONTINUITY LINK

Where an incident causes significant service disruption, the Business Continuity & Disaster Recovery Policy shall be activated as appropriate.

24. RECORD KEEPING

  • Incident report
  • Timeline
  • Severity assessment
  • Actions taken
  • Evidence register
  • Partner communications
  • Customer impact assessment
  • Regulatory/law-enforcement records where applicable
  • Root-cause analysis
  • Corrective action plan
  • Closure approval

25. CONFIDENTIALITY

Incident information shall be restricted to personnel with a legitimate need to know. Sensitive evidence and investigation material shall be securely stored.

26. TRAINING & DRILLS

Relevant personnel shall receive incident-response and cyber-fraud awareness training. Periodic tabletop exercises or response drills may be conducted based on risk.

27. MONITORING & REPORTING

  • Incident count by severity
  • Detection and response time
  • Financial impact
  • Customer impact
  • Root causes
  • Repeat incidents
  • Third-party incidents
  • Corrective action ageing

28. AUDIT & TESTING

Incident-response controls may be tested through audits, tabletop exercises, simulated scenarios, evidence reviews and control assessments.

29. POLICY EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or contractual obligations shall not be bypassed.

30. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Information Security / ITDetection, containment, technical investigation and recoveryTechnology/Security Head
Fraud/RiskCyber-fraud assessment and transaction controlsCompliance / Management
ComplianceRegulatory/contractual assessment and escalationManagement
OperationsCustomer/process impact and operational actionsOperations Head
Partner ManagementPPI/bank/payment/vendor coordinationCompliance / Management
Customer SupportCustomer reports and communicationsOperations / Compliance
ManagementMaterial incident decisions and approvalsDirector / Authorised Management

31. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in cyber threats, technology, products, partner arrangements or applicable requirements.

32. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByInformation Security / Fraud / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED INCIDENT RESPONSE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED