ISO-Certified Data Security at ASW

Protecting your business with world-class security standards

At ASW, data security isn’t just a feature—it’s a foundation. We are proud to be ISO/IEC 27001 certified, ensuring that every aspect of our operations meets the highest international standards for information security management.

Whether you’re outsourcing finance, IT, legal, or customer service functions, your data is protected by a robust framework of policies, technologies, and practices designed to keep your business safe.

Why ISO 27001 Matters

ISO/IEC 27001 is the global benchmark for information security. ASW has held this certification for over a decade, with annual recertification and biannual audits conducted by Lloyd’s. This ensures that our systems, processes, and people are continuously aligned with best practices in data protection.

Our Security Framework

Technology
Security

  • Firewall rules follow the Principle of Least Privilege (POLP)
  • Antivirus protection on all servers, desktops, and email gateways
  • Regular patching and updates to eliminate vulnerabilities
  • Penetration testing and vulnerability scans
  • Multi-Factor Authentication (MFA) for all systems
  • No external email or USB access unless explicitly approved

Desktop
& Network Security

  • Locked-down environments with no offshore storage capability
  • Thin client architecture to prevent data duplication
  • No printers (dual screens used instead)
  • Secure desktop policy and clean desk enforcement

Physical
Security

  • 24/7 building security in Class A CBD offices
  • Biometric access and photo ID cards
  • CCTV monitoring at all entry/exit points
  • Visitor escort policy and restricted access zones

Human Resource
Security

  • Background and police checks for all new hires
  • Mandatory confidentiality agreements
  • Information security training during onboarding
  • Ongoing development and ethical conduct enforcement

Secure Infrastructure, Seamless Integration

ASW’s IT systems are hosted in a private cloud environment based in Australia, ensuring compliance with local data sovereignty requirements. We work closely with your internal IT team to integrate your tools and maintain secure workflows—whether simple or complex.

Continuous Monitoring & Support

  • 24/7 IT support and system monitoring
  • Centralised security logs reviewed regularly
  • Customisable compliance protocols based on your industry needs

Trusted by Leading Brands

With over 2000 staff across 8 global offices, ASW supports businesses in finance, healthcare, legal, tech, and more. Our commitment to security, transparency, and operational excellence makes us a trusted partner for companies that demand the highest standards.

Business Continuity Plan

As part of the ISMS and ISO27001 certification requirements, ASW has a Business Continuity Management policy in place. We have documented the necessary framework to ensure emergency response, resumption and permanent recovery of ASW business operations during and after a business interruption due to both man-made and natural disasters. Our Recovery Time Objective (RTO) is 48 hours from declaration of a disaster, and our Recovery Point Objective (RPO) is to a point of data consistency up to a maximum of 24 hours prior to the disaster for all systems, and a maximum of 48 hours for email.

During a disaster situation, ASW will formulate a Crisis Management Team who will:

  • Direct all activities and resources required to recover critical applications and then oversee the restoration of normal services in the production environment once the emergency has passed.
  • Communicate to all key stakeholders.
  • Continually review and assess the risks and impact of the recovery process on the business.
  • Make decisions on appropriate actions to address problems as they arise during the recovery process.

Backup and Disaster Recovery

ASW has backup and disaster recovery procedures documented and in place as part of our business continuity plan. We undertake regular backups of our critical systems on a periodic schedule. We perform disaster recovery tests and restoration processes to ensure we can restore our critical systems back to a recovery point objective.

NICK REILLY

Managing Director, Inovayt

The one thing that keeps me up at night is data security and something going wrong with our clients. What sort of checks are being done on the staff? Where are they working out of? What are the security measures in place? Visiting the ASW offices helped alleviate all those concerns. It’s not just a great environment—it’s a secure one.