Cyber security policy

Introduction

Cyberspace is a complex environment consisting of interactions between people, software and services. The cyber security policy shall be evolving, regularly updated/ refined in line with technological trends and security challenges posed by the technology directions. This policy provides an overview of what it takes to effectively protect information, information systems & networks and also to provide an insight into NEON IDEAS (NI) approach and strategy for protection of cyber space.

Purpose

The purpose of this policy is to provide directives, procedures and guidelines necessary to maintain cyber security and manage cyber risks proactively. The cyber security policy at NI provides a set of directives that will enable NI to identify, detect and treat Cyber-attacks in a timely manner such that attacks do not impact the confidentiality, integrity and availability of data at NI. Sufficient technological and process controls will be implemented to ensure customers’ personally identifiable information (PII) and organizational data is protected from potential cyber-attacks. This cyber security policy is in line with the leading cyber security standards, guidelines and RBI mandate on cybersecurity framework.

Scope

This policy is created in line with leading practices, standards and regulatory requirements are applicable to all the locations of NI in India including all IT assets, data transiting on its network, data in use, data at rest and all IT processes, all the business processes supported by IT and third parties having access to NI network and data. This Policy sets out NI’s approach to managing cyber security risks.

Objective

The objectives of this policy are to protect information and IT infrastructure in cyber space, build capabilities to prevent and respond to cyber threats, reduce vulnerabilities and minimize damage from cyber incidents. Cyber Security Policy shall also help NI to:

•    Identify and prioritize opportunities for improvement within the context of risk management;

•   Assess progress towards cyber security risks; and

•   Communications among internal and external stakeholders.

Policy communication and Review frequency

Chief Information Security Officer (CISO) shall review its Cyber Security policy at least annually, and/or when major technology changes occur (e.g., new infrastructure/ resources) that may need amendments to the policy. The policy shall be approved by the board;

• CISO shall also review its security controls annually, or when any major change/incident takes place. to ensure that they comply with the organization’s Cyber Security policy. This compliance shall also be checked during internal audits; and

• Cyber Security Policy shall be communicated to concerned personnel annually and whenever there are any modifications.

Cyber Risk

Cyber risks represent the possibility that technologies, processes and practices at NI can be bypassed, allowing unauthorized users to (including but not limited to):

• Modify and/or delete key applications and information, which will affect the accuracy or integrity of processing

• Access or extract protected or sensitive information (e.g., IP, proprietary information, Personally Identifiable Information)

• Disrupt computer-controlled operations or access to online systems.

Roles and Responsibilities

7.1 Organizational Framework

Well-defined roles and responsibilities of Board and Senior Management are imperative, while implementing Cyber Security Governance, Stakeholders include:

• IT Strategy Committee

• CISO and ISO

• Head of respective departments

• IT Steering Committee (operating at an executive level and focusing on priority setting, resource allocation and project tracking)

7.2 Information Steering Committee (ISC)

ISC serves as an effective communication channel for management’s aims and directions and provides an ongoing basis for ensuring alignment of the security programme with organizational objectives. Major responsibilities of the Information Steering Committee, include:

• Developing and facilitating of the implementation of information security policy and cyber security policy, to ensure that all identified information/system security risks are managed.

• Approving and monitoring major information security projects including cyber security and the status of information and cyber security plans and budgets, establishing priorities, approving procedures and guidelines.

• Supporting the development and implementation of Information security management programme including information and cyber security.

• Reviewing the position of security incidents and various information and cyber security assessments and monitoring activities across the NI.

• Reviewing the status of security awareness programs

• Assessing new developments or issues relating to information security including cyber security.

7.3 Chief Information Security Officer (CISO)

A sufficiently senior level official is designated as Chief Information Security Officer (CISO), responsible for articulating and enforcing the policies that NI uses to protect the information assets apart from coordinating the security related issues / implementation within the organization as well as relevant external agencies. The CISO has a working relationship with the IT vertical to develop the required rapport to understand the IT infrastructure and operations, to build effective information/cyber security across the NI, in tune with business requirements and objectives.

Cyber Threats (Threat Landscape)

8.1 Types of Threats
Refer Annexure-1

8.2 Types of Attacks
Refer Annexure-1

Prevention Strategies & Plans

Cyber Resilience

Cyber resilience is defined as ability of department to anticipate, withstand cyber-attacks and the capability to contain, recover rapidly and evolve to improved capabilities from any disruptive impact caused due to cyber-attacks. Below are the best practices to be followed to withstand Cyber-attacks.

9.1 Test preparedness to withstand cyber attacks

Exercising

CISO shall develop various exercises such as crisis simulation exercises like DR Drills which assess the adequacy and consistency of Cyber crisis management plan. Testing exercise shall also be performed to measure the NI’s defensive and responsive capabilities. These exercises & tests are conducted at planned intervals or whenever significant changes occur.

9.2 Risk Assessment

Implementing this Policy and the procedures and processes implemented thereunder will
help securing NI from cyber risks. Cyber Security Incidents can result in a broad range of negative consequences, including reputational loss, financial loss, non-compliance with standards and legislation and liability to third parties. A Cyber Security Incident could occur at any point of the life cycle of the affected information (i.e., at its creation, collection, use, processing, storage, disclosure, deletion or destruction). NI will therefore conduct risk assessment(s) biannually to identify, evaluate and address cyber risks to information system(s) as a part of the existing enterprise wide risk assessment. The enterprise wide risk assessment shall be conducted to include the following parameters pertaining to cyber risks:

• Cyber threat inventory;

• Information system(s) vulnerabilities;

• Potential business impact of threat exploiting vulnerabilities;

• Risk(s) level;

• Risk tolerance criteria; and

• Risk treatment plan.

While preparing a treatment plan for cyber risks, appropriate controls shall be identified in- terms of new technologies/ solutions and cost benefit analysis shall be performed to identify the most feasible treatment technology/ solution required to address cyber risks.

9.3 Reporting and Escalation Cyber Security Incidents

• Information and Cyber Security incidents shall be reported through email to the IS team. The mails shall be sent to ithelpdesk.

• All Information and Cyber Security incidents shall be recorded in a Cyber Security incident database;

• Deployment of suitable technology shall be carried out for incident reporting and guidelines and procedures for timely escalation and action for security incidents shall be documented;

• User community shall be educated on how to identify and report Information and Cyber Security incidents through the ISMS Awareness Trainings;

• Incidents, classified as High or Critical, should be reported to CISO.

9.4 Reporting of Cyber Secure Weakness
• Information and Cyber Security weaknesses, both actual and suspected, shall be reported through different channels like email and tickets.

Policy Categories

10.1 Inventory Management of Business IT Assets

To maintain appropriate protection of NI ’s Information Assets. All information assets will be inventoried, classified and protected in accordance with criticality and sensitivity.

10.2 Preventing execution of unauthorized software

1. NI shall implement technical controls such as application whitelisting and blacklisting to prevent and detect the use of unauthorized software and files.

2. The software running on the end user system must be:

• Installed from a trusted source.

• Licensed and approved.

• Configured securely. The specific security settings may be adopted from Vendor recommended security settings, industry best practices or other trusted sources.

10.3 Physical & Environmental Control

Refer Information Security – Physical & Environmental Policy.

10.4 Network Management & Security

Refer Information Security – Network Security Policy

10.5 User Access Control / Management

Refer Information Security – Access Control Policy.

10.6 Vendor Risk Management

Refer Information Security – Supplier Relationship Policy.

10.7 Removable Media

Refer Information Security – Asset Management Policy.

10.8 Maintenance, Monitoring and Analysis of Audit Logs

Refer Information Security – Operation Security and System Acquisition, Development and Maintenance Policy.

10.9 Vulnerability assessment and Penetration Testing Exercise.

Refer Information Security – Vulnerability Assessment Policy

10.10 Incident Response & Management

Refer Information Security – Incident Management Policy

10.11 Secure Configuration

NI’s systems will be configured for security, reliability and stability and all such configuration will be documented. Systems will follow standard naming conventions for efficient identification in configuring and in problem resolution.

Learning from Cyber Security Incidents

1. Analysis shall be carried out for the Information and Cyber Security Incidents considering the following factors:

• Type of Information and Cyber Security Incident;

• Volume of Security Incidents; and

• Wherever possible, costs incurred due to Information and Cyber SecurityIncidents.

2. The logging, classification, diagnosis and rectification procedures for incident management shall be laid out in detail;

3. The output of the analysis shall be used to improve the security within NI

Training and Awareness

12.1 User/ Employee/ Management Awareness

1. NI shall ensure that the employees are made aware of the sections relevant to them through appropriate sessions/training.

2. To ensure that employees are suitable for the roles they are considered for, they understand their responsibilities in the usage of NI’s information assets. The employees will be informed of the policy changes through various channels.

Annexure - 1

Types of Threats

Threat Possible reason for attack
Corporate espionage
The possible reason for such a threat is an attempt to gain access to trade secrets through dishonest means
Organized crime
The possible reason for such a threat is to achieve financial gain
State-sponsored attacks and advanced persistent threat
The possible reason for such a threat is due to the type of work the NI does and the value of its Intellectual Property

Types of Attacks

Malicious users or Hackers can carry out cyber-attacks using a variety of methods. The following are the common types of attacks:

1. Malware – Software or code snippets designed to cause harm to your computer and/or network security.

2. Social Engineering – Utilizing manipulative methods to obtain (confidential) information through unauthorized methods.

3. Vulnerability/Exploit Attacks– Attacks executed by sophisticated hackers that utilize a combination of knowledge, tools and exploitation of technology weaknesses.

4. Other Attacks

Malware

Malware based attacks include the following:

1. Virus – Software with malicious intent to cause disturbance or damage. When the software is executed, the virus attaches itself to a program/file to replicate and spread throughout your system files (infecting) with the objective of damaging
computer/network operations.

2. Worm – Similar to a virus, a worm is software that replicates and spreads itself, but not only from file to file, but from computer to computer via email and other internet traffic.

3. Trojan Horse – Software that can either hide inside other software or appear to be legitimate software. Unlike a virus or worm, a Trojan Horse does not reproduce or self-replicate, but is spread by opening/launching infected email attachments or internet files.

4. RAT (Remote Access Trojan) – is a malware program that includes a back door for administrative control over the target computer. RATs are usually downloaded invisibly with a user-requested program  such as a game or sent as an email attachment.

5. Spyware – Malicious software that collects and monitors user information and activities on the computer/network without their knowledge that is sent to another entity/individual for purposes such as advertising or other malicious intents.

6. Ransomware – Software that limits or restricts users from accessing their system or certain files until a ransom is paid. Often hackers will employ encryption methods to prevent access to the files until the ransom is paid.

Social Engineering

Social Engineering Attacks include the following:

1. Spoofing – Altering the return address on an email to deceive the receiver of that email message that the email came from someone other than the actual sender.

2. Identity Spoofing (IP Address Spoofing) – A method of deception by using another IP address (that is not your own) to access the network that is usually used as on-line camouflage to mask their activities and/or gain unauthorized entry.

3. Phishing (emails) – Deception that often uses legitimate-style emails with the objective to fraudulently obtain sensitive/confidential information (i.e. asking you to enter your username, password, debit card number, ATM Pin etc.)

4. Spear Phishing – Similar to Phishing, but is targeted to a specific organization or group. It is a realistic email with a link to a malicious website used to download malware or gather private information.

5. Vishing –Like Phishing, except that this method uses telecommunication (phone calls) to solicit personal information.

6. Smishing – Like Phishing, except that this method utilizes cell phone text messages to solicit your personal information.

7. Pharming – Redirection to a fraudulent websites without your consent or knowledge.

8. Baiting – Baiting is in many ways similar to phishing attacks. However, what distinguishes them from other types of social engineering is the promise of an item or good that hackers use to entice victims. Baiters may offer users free music or movie downloads, if they surrender their login credentials to a certain site.

9. Pretexting – Pretexting is another form of social engineering where attackers focus on creating a good pretext, or a fabricated scenario, that they can use to try and steal their victims’ personal information. These types of attacks commonly take the form of a scammer who pretends that they need certain bits of information from their target in order to confirm their identity.

Vulnerability/Exploit Attacks

Capacity based attacks take advantages of vulnerabilities that exist with space of capacity of technology. Examples include:

1. Denial of Service (DOS) Attacks – Flooding a server or network with so many requests for service that it slows down and/or crashes resulting in the prevention of legitimate customers/users from obtaining access.

2. Distributed Denial of Service attacks (DDOS) – A DDOS attack whereby the attacks come from multiple computers at the same time causing the website/network to become disabled. (Botnet/Zombie – Commonly used for DDOS and DOS attacks.)

Exploit based attacks take advantage of vulnerabilities identified in software. Examples include:

1. Man in the Middle (MITM) – An attack used to monitor and potentially modify communications between two users. For example, the attacker could intercept the public key message exchange with a private key and continue to retransmit the message while actively eavesdropping without the users’ knowledge.

2. Man in the Browser – Similar to a MITM attack, however a Trojan Horse is used to intercept and manipulate the communications.

3. Injection Attacks – A type of attack whereby malicious commands are sent to a system/application through unauthorized channels. The commands can allow attackers to create, read, update, or delete data that is available on the system.

4. Cache Poisoning – This type of attack introduces false or malicious data into cache memory and then enables the attacker to use exploit tactics.

5. Logic Bomb– The attacker exploits a logical error in the code of the application to perform malicious activities.

Other Attacks

Other types of cyber-attacks include:

1. Advanced Persistent Threat (APT) – A long term hack with the intent of infiltrating a network/computer to gain unauthorized access for an extended period of time without being detected (stealthy). The objective is generally to obtain valuable information and data for business and/or political motives.

2. Web defacing (Defacement) – Replacing the content of a website typically with negative/anti-company information.

3. Brute-Force Attack– The use of a password cracker to obtain a user’s password and then access their account/system without their knowledge. (Not used in modern times, as most companies have password configurations set up, as required by standard audit procedures)

4. Internal Threats based attack– The threat exposure created by an internal employee in-order to make his/her task easier is used by an attacker for malicious intent.

Neon Ideas logo – Full-Stack Design & Development Agency in Pune, India specializing in branding, UI/UX, web development, digital marketing, and creative solutions

NEON IDEAS

Data Privacy & Protection Policy

Document No: NI/ISMS/ Pol-24

Date of Issue: 02-02-2026

Revision No: 1.0

Date of Revision :00/00/00

Page No: 2 of 9

1. Approval and Authorisation

Completion of the following signature blocks signifies the review and approval of this Procedure

Name Job Title Signature Date
Authored by:-
Pravin Phule
02-02-2026
Reviewed by:-
Dipti Pathak
02-02-2026
Approved by:-
Dipti Pathak
02-02-2026

2. Change History

Version Author Reason Date
00
Initial Document
02-02-2026

Distribution

1. File server
2. Intranet

Documentation status

This is a controlled document. This document may be printed; however, any printed copies of the document are not controlled. The electronic version maintained in the file server and
Commune are the controlled copy.