iExtend achieves internationally recognised information security certification

From

David Sarkis

iExtend has achieved ISO/IEC 27001 (ISO27001) certification, the internationally recognised standard for information security management, providing policy owners, advisers and industry partners with further assurance on how the business manages information security.

ISO27001 provides a comprehensive, risk-based approach to identifying, assessing and managing information security risks across people, processes and technology. It considers all aspects, from the human side such as social engineering, to controls such as multi-factor authentication (MFA) and intrusion detection.

iExtend CEO David Sarkis said as financial advisers increasingly rely on connected technology and exchange growing volumes of sensitive client information, robust information security is fundamental to earning and maintaining trust.

“While protecting customer information has always been a priority for us, as the business continues to grow, we pursued ISO27001 certification to independently validate our security practices against an internationally recognised framework,” he said.

Over the past 12 months, iExtend has further strengthened its Information Security Management System through enhanced governance, policies, staff education and technical controls. “The certification reflects our long-term commitment to protecting the highly sensitive information entrusted to us.”

Mr Sarkis said achieving certification is not simply about receiving a credential.

“It is about embedding information security into our culture and ensuring every member of our team understands their responsibility,” he said.

The certification is one part of iExtend’s broader commitment to caring for Australians experiencing vulnerability, which also involves communicating clearly how the iExtend arrangement works and continually strengthening the safeguards built into the service.

“Trust is not something we earn once,” Mr Sarkis said. “It requires us to keep listening and improving, while maintaining a clear focus on the outcomes of the clients we serve.”

The framework also supports iExtend’s approach to responsible innovation by requiring security risks to be considered when new systems and technologies are assessed, integrated and monitored.

“Advanced technology can create meaningful value for advisers and policy owners and needs to be supported by appropriate governance, risk assessment and human accountability,” he said.

ISO27001 requires organisations to regularly review, assess and strengthen their information security practices.

“Certification is an important milestone, but it isn’t the finish line,” Mr Sarkis said.  “We will continue to strengthen our approach through regular risk assessments, staff education, independent audits and the ongoing review of our security controls.”

iExtend achieved ISO/IEC 27001 certification on 15 July 2026.