De Novo Perspectives and Affiliates Receive ISO/IEC 27001:2022 Certification
Organizations meet the latest standard for governing information security controls and addressing risks introduced by emerging cyber threats
STAMFORD, CT, June 6, 2025 — De Novo Perspectives (DNP), a leading business process improvement company specializing in information security and data privacy governance, risk management, and compliance solutions, proudly announces that it and its affiliated companies have achieved ISO/IEC 27001:2022 certification. The certification audit was conducted by accredited registrar Performance Review Institute (PRI) Certification.
This achievement reflects De Novo’s implementation of modern information security controls to address evolving cyber threats. Moreover, it validates De Novo’s unique approach to integrating rigorous risk management practices with operational excellence to protect sensitive information and develop cyber resilience in its own environment and that of its clients.
The company is proud to mark a new milestone in its rich information security journey. Notably, De Novo and its affiliate ORRIOS first earned ISO 27001:2013 certification in 2022, while affiliates EXTEND Resources and EXTEND Resources Global, as well as DNP’s OnTrack® GRC platform, now celebrate seven consecutive years of compliance with the internationally recognized ISO 27001 standard.
Howard Hoffmann, CEO of De Novo Perspectives, emphasized the significance of this achievement: “Completing the ISO 27001:2022 certification demonstrates the rigorous nature of De Novo’s information security practices and our expertise in safeguarding sensitive information based on a world-class standard. For our clients, from mid-size to large enterprises, this achievement speaks to the value of our integrated cyber risk analysis process, ability to help them develop a culture of information security, and experience implementing resilient cybersecurity programs that generate confidence and deliver lasting value.”
The scope of this ISO 27001:2022 certification covers De Novo Perspectives and its affiliated companies ORRIOS, EXTEND Resources, and EXTEND Resources Global (ERG), and DNP’s OnTrack® Cybersecurity GRC platform.
Designed to “promote a holistic approach to information security: vetting people, policies and technology,” ISO/IEC 27001:2022 is the latest version of the standard for Information Security Management Systems (ISMS) jointly published by ISO and the International Electrotechnical Commission (IEC). In addition to new monitoring and management requirements, the framework incorporates 11 new controls designed to align with technology and information security advancements.
About De Novo Perspectives
De Novo Perspectives is a professional services firm that provides business and advisory services to clients. Through its affiliated companies, EXTEND Resources, EXTEND Resources Global, and ORRIOS, De Novo offers a comprehensive suite of information security and data privacy services, including cyber resilience for boards of directors, cyber risk assessment, outsourced CISO services, information security program management, third-party risk management, data privacy advisory services, internal audit management, and regulatory compliance support. OnTrack®, a comprehensive security and privacy management platform, is marketed under ORRIOS, a De Novo brand. Visit us at dnp.com.
About EXTEND Resources
EXTEND Resources is an information security and data privacy consulting firm that empowers mid-sized to large enterprises to uncover, quantify, assess, and mitigate cybersecurity and data privacy risks. EXTEND leverages a tailored, integrated approach to help clients oversee and govern cyber risks, protect sensitive information, comply with regulatory and legal requirements, and be prepared to manage a security or privacy incident effectively. EXTEND Resources fosters cyber resilience at every level of an organization. Learn more at extendresources.com.
About ORRIOS
ORRIOS develops software designed to help businesses manage information security, data privacy, and related business risk programs. OnTrack®, our security and privacy management platform, empowers business leaders and their teams to understand their strengths and vulnerabilities, document programs to protect their organizations against the risk of incidents and breaches, support regulatory compliance, and create confidence in their security and privacy posture among their board, clients, and partners. Learn more at orrios.com.