Cyber Security Policy

Information Security Management System (ISMS)

Information and data security is a critical focal point when working with super funds. Therefore, we are committed to protecting client information by implementing appropriate security controls across our IT services and associated information technology ecosystem. We understand that effective management of cyber and information security risk is fundamental to the successful delivery, operations and management of services to our client funds.

We have obtained certification for the ISO/IEC 27001:2022 Standard “Information security, cyber security and privacy protection—Information security management systems—Requirements.”, with the most recent certificate being issued on 27th March 2025.  

Independent Reviews of our Security Practices

We undertake independent internal audits of our ISMS on an annual basis to ensure ongoing adherence to the ISO27001 standard. The results of these audits are reported to our Board and the Audit, Risk & Compliance Committee.

We conduct annual penetration testing of our network, in partnership with specialist cybersecurity providers, to ensure a continuous cycle of improvement in our cyber security posture.

Layered Approach to Cyber Security

We deploy industry leading cyber security technology to ensure a layered approach to cyber security. This includes but is not limited to:

Third Party Security Assessments

We outsource the management and security monitoring of the IFS Network (Azure & AWS) to Material Service Providers (MSP) with monitoring and supervision of these parties subject to the controls set out in our Outsourcing Policy. We rely on trusted third party cyber security experts to provide ongoing cyber security assessments of IFS’s network environment. We utilise a suite of Software as a Service (SaaS) applications, including services utilised by our clients. These SaaS are described in the table below. Each Material Service Provider is required to provide an annual attestation regarding compliance with CPS234.

Application

Vendor/hosting

Purpose/Utility

Annual Assessment

Xplan
Iress
Financial Advice Platform (CRM, workflows, etc.)
Green Tick Icon
Sami
Regtech
Advice Assurance Program reviews
Green Tick Icon
Online Forms
SmartIQ
Secure data collection for Xplan
Green Tick Icon