Retour

Explorez tous les épisodes du podcast InfoSec Insider

Plongez dans la liste complète des épisodes de InfoSec Insider. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 100

TitreDateDurée
Benefits of Business Continuity Exercising03 Sep 202600:40:33

InfoSec Insider Podcast - Season 3, Episode 1 (101)

Benefits of Business Continuity Exercising

In this episode of InfoSec Insider – Talk BC, Phil Knight, Senior Consultant at URM, explores exercising of business continuity plans, and the benefits this can provide to organisations.  Phil draws upon his extensive experience supporting organisations to strengthen their business continuity arrangements and resilience to discuss:

  • What business continuity exercising is
  • ISO 22301 (the best practice standard for BC management), the business continuity lifecycle and where exercising fits into these
  • The benefits that exercising can provide to organisations
  • The consequences or costs of not performing exercises.

Learn more about this topic: https://www.urmconsulting.com/blog/business-continuity-exercising

5 Business Continuity Must‑Dos to Strengthen Your Organisation’s Resilience webinar: https://www.urmconsulting.com/event/5-business-continuity-must-dos-to-strengthen-your-organisations-resilience

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts              

Brought to you by URM, the UK’s leading information and cyber security specialists.         

The First 72 Hours Managing Data Breaches27 Aug 202600:45:51

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, share their insights on how to effectively manage the immediate aftermath of a personal data breach.  Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss: 

  • What actually counts as a data breach and when it needs to be reported to the Information Commissioner’s Office (ICO)
  • How organisations can assess risk and decide whether affected individuals need to be told
  • The biggest mistakes organisations make in the first few days following a data breach
  • How ransomware attacks, supplier incidents, and modern technology are changing breach management
  • The practical steps organisations can take now to prepare for a breach and demonstrate accountability afterwards.

Ask Rachael and Aimee a question:  https://urmconsulting.com/podcasts/the-first-72-hours-managing-data-breaches     

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts  

   

Connect with us on LinkedIn  

 

Brought to you by URM, the UK’s leading information and cyber security specialists.      

Cyber Essentials 2026 – Lessons Learned From Actual Assessments20 Aug 202600:36:19

In this episode of InfoSec Insider – Talk Cyber, Jamie Leavers, Security Consultant at URM, and Lauren Gotting, New Business Director at URM, share real-world lessons learned from conducting hundreds of CE and CE+ assessments, including early assessments against the new Danzell requirements.   Jamie and Lauren leverage their extensive experience with the Cyber Essentials scheme to discuss:

  • Lessons from real CE/CE+ assessments, what assessors are seeing in practice, and what separates successful submissions from failed ones
  • The Danzell Question Set and key changes introduced in 2026 and how they impact both new applicants and recertifying organisations
  • How to prepare for certification or recertification, including ractical guidance to ensure your evidence, scope and controls meet assessor expectations.
  • The common issues and pitfalls most frequently causing delays or failures and how to avoid them entirely.

Learn more about URM’s webinar programme: https://www.urmconsulting.com/events/upcoming-events

Contact webinars@urmconsulting.com for this webinar’s slide deck.

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             

Brought to you by URM, the UK’s leading information and cyber security specialists.        

Physical Security Controls13 Aug 202600:25:18

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide expert advice and guidance on how organisations can maintain the physical security of their information, and where physical security most often goes wrong.  George and Jack draw upon their extensive combined experience of helping organisations strengthen their information security to discuss:

  • Whether organisations are underestimating the importance of physical security in favour of focusing on cyber threats
  • How hybrid working, flexible offices, and remote employees have changed what ‘physical security’ actually means
  • The most surprising physical security weakness they’ve encountered that could have led to a major information security breach
  • Which physical security controls most organisations think is effective, but in reality provide little more than a false sense of security
  • The top three physical controls they would implement in an organisation with a limited budget and why.

Ask Jack and George a question: https://urmconsulting.com/podcasts/physical-security-controls

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.       

PCI DSS Periodic Activities06 Aug 202600:37:17

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

  • Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
  • The common mistakes they see organisations make when defining their own frequencies
  • Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
  • How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
  • How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
  • How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
  • And more.

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

 

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts         

 

 Connect with us on LinkedIn 

 

 Brought to you by URM, the UK’s leading information and cyber security specialists.   

GDPR Cookies Compliance30 Jul 202600:37:36

In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down cookies compliance under the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulations (PECR).  Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss: 

  • Why cookies are so important to businesses commercially
  • What the law actually requires when using cookies
  • How businesses get cookie compliance wrong in practice
  • Where consent or pay fits in
  • What good compliance actually looks like.

Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/gdpr-cookies-compliance        

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        

Connect with us on LinkedIn  

Brought to you by URM, the UK’s leading information and cyber security specialists.      

Clause 10.2 of ISO 27001: Nonconformity and Corrective Action23 Jul 202600:11:20

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them.  Neil leverages over 20 years of experience working with risk and information security-related standards to discuss: 

  • What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS)
  • What nonconformities are, and the difference between major and minor nonconformities
  • The requirements of Clause 10.2 and how organisations can implement them in practice
  • Common mistakes to avoid when addressing Clause 10.2.

Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts 

Brought to you by URM, the UK’s leading information and cyber security specialists.     

PCI DSS Scoping16 Jul 202600:36:28

In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:     

  • When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
  • Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
  • Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
  • Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
  • How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
  • And more.

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping        

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts         

Connect with us on LinkedIn 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Establishing Control Over AI Usage09 Jul 202600:27:50

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations.  Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:

  • Why organisations should be paying attention to AI right now
  • The most common ways organisations are already using AI
  • The most significant AI-related risks they currently see
  • How organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuse
  • The top three AI controls and measures all organisations should have in place.

Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             

Brought to you by URM, the UK’s leading information and cyber security specialists.

Next 12 Months in Privacy02 Jul 202600:32:53

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, consider emerging trends in the field of data protection and privacy, and the practical implications for organisations that need to maintain compliance.  Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:

  • What they think will define privacy risk over the next 12 months
  • Why artificial intelligence (AI) will continue to expose weak data protection practices
  • The privacy issues that are most likely to grow fastest in practice
  • Where regulators are most likely to focus next
  • The steps organisations should take now to prepare for the next wave of scrutiny and enforcement.

You can register for the STAIRs webinar or watch the recording on URM’s website: https://www.urmconsulting.com/event/stairs-webinar-are-you-ready Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/next-12-months-in-privacy

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts

Connect with us on LinkedIn       

Brought to you by URM, the UK’s leading information and cyber security specialists.  

PCI DSS and Service Providers25 Jun 202600:38:15

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore some of the most misunderstood areas of PCI DSS scoping, focusing on service providers, merchants, and complex modern payment architectures. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:

  • When an organisation stops being “just a merchant” and becomes a PCI DSS service provider, and what really drives that distinction
  • How an organisation can be both a merchant and a service provider at the same time, and how this should be handled during a PCI DSS assessment
  • The most common mistakes organisations make when deciding how they should be classified for PCI DSS purposes
  • Whether companies providing payment-enabled platforms, but not directly handling PAN, can still fall under the definition of a service provider
  • The responsibilities that remain when a third-party platform hosts the payment page but payment fields are served directly by a provider
  • And more.

Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-service-providers

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts       

 Connect with us on LinkedIn     

 Brought to you by URM, the UK’s leading information and cyber security specialists.   

Unusual GRC Questions18 Jun 202600:36:37

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, answer some of the niche and unusual questions around governance, risk and compliance (GRC).  Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:  • The key questions clients rarely ask despite being extremely important • Whether a policy is enough on its own • The security policies that are most frequently not followed in practice • How to avoid prioritising compliance over genuine security • The easiest ways to establish whether a control is effective • How to achieve buy-in from executives on managing and mitigating risks before they materialise.  Ask Jack and George a question:  https://urmconsulting.com/podcasts/unusual-grc-questions             

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider            

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts          

Brought to you by URM, the UK’s leading information and cyber security specialists.       

Real-World Data Protection Questions11 Jun 202600:42:04

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, answer key, real-world questions around data protection and how organisations can stay compliant.  Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:

  • When data is genuinely anonymous, and how easy it is to lose that status
  • Whether things like voice, handwriting, CCTV, emojis, avatars and internal gossip really count as personal data
  • How employee use of smart glassed and always-on devices can affect organisations and why it matters
  • Why redaction still goes wrong so often
  • Why consent remains one of the single most understood aspects of data protection.

Ask Rachael and Aimee a question: https://www.urmconsulting.com/podcasts/real-world-data-protection-questions

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider       

You can find more episodes of InfoSec Insider here:     https://urmconsulting.com/podcasts       

Connect with us on LinkedIn

Brought to you by URM, the UK’s leading information and cyber security specialists.    

Business Approaches to Risk Management04 Jun 202600:35:18

In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a business perspective.  Chris and Wayne draw upon their combined 45 years of experience in information security and risk management to discuss:

  • What good, risk-based decision-making actually looks like in practice, and where it most commonly breaks down
  • The most concerning information security risks of today that do not get enough attention at the board or executive level
  • How organisations can move away from checklist-driven compliance and towards meaningful cyber risk management that supports business objectives
  • How organisations should rethink ownership and accountability for information security risk in light of growing dependence on cloud services and third-party providers
  • The capability or mindset they believe information security leaders must develop now to remain effective risk advisers in the coming years.

Ask Wayne and Chris a question:  https://urmconsulting.com/podcasts/business-approaches-to-risk-management

            

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             

Brought to you by URM, the UK’s leading information and cyber security specialists.        

PCI DSS and Severless Architecture28 May 202600:24:41

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment Card Industry Data Security Standard (PCI DSS) compliance.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:    

  • What ‘severless’ actually means in a PCI DSS context, and how this differs from how it is usually described by cloud providers
  • What QSAs look for when deciding whether a severless system falls within PCI scope
  • How the balance of responsibilities shifts when an organisation moves from traditional cloud services to severless, and where this causes the most confusion during assessments
  • The parts of a severless setup that tend to bring cardholder data into scope unexpectedly and how to ensure you understand the way information moves through your systems
  • How to handle PCI requirements for logs, monitoring and keeping evidence when the systems they rely on disappear almost instantly
  • Maintaining compliant access control and control over changes to your systems in a severless context
  • How to check for weaknesses in severless systems, the risks tied to the external code and libraries that are often used inside serverless functions
  • And more.

Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-severless-architecture

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      

 Connect with us on LinkedIn 

 Brought to you by URM, the UK’s leading information and cyber security specialists.   

GDPR Compliance and BYOD21 May 202600:30:45

In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down the data protection compliance issues that arise from the use of bring your own device (BYOD) within organisations, and how these can be overcome.  Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:

  • Why BYOD has become so common, and why it still catches organisations out
  • Where legal and regulatory risks arise with BYOD
  • How BYOD increases data subject access request (DSAR), breach, and dispute risk
  • What a proportionate, people-aware approach to BYOD looks like
  • How regulators and insurers are likely to view BYOD going forward.

Ask Rachael and Aimee a question:

https://www.urmconsulting.com/podcasts/gdpr-compliance-and-byod

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

 

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        

 

Connect with us on LinkedIn 

 

Brought to you by URM, the UK’s leading information and cyber security specialists.     

 

AI Supplier Management14 May 202600:21:41

In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can effectively manage AI suppliers and navigate the emerging risks associated with artificial intelligence in the supply chain.

Jack and George draw on their experience supporting organisations with AI governance and supplier risk management to discuss:

  • What AI supplier management is and how it differs from traditional supplier management, including the impact of rapidly evolving AI models and changing service structures
  • The key risks associated with AI suppliers, such as data leakage, unauthorised model training, hallucinations, bias, and compliance challenges
  • The growing issue of shadow AI, and how a lack of visibility over employee use of AI tools can introduce significant security and governance risks
  • How organisations can adapt due diligence processes to assess AI suppliers, including evaluating data handling practices, model governance, human oversight, and security maturity
  • Contractual and governance considerations, such as restricting data use, ensuring transparency on model updates, and defining audit and incident response expectations
  • The importance of understanding extended AI supply chains, including dependencies on underlying models and fourth-party providers
  • Why AI supplier management must be treated as an ongoing activity, with continuous monitoring, internal communication, and reassessment of risk as technologies evolve

Ask Jack and George a question:

https://www.urmconsulting.com/podcasts/aI-supplier-management

 

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider          

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts          

 

Brought to you by URM, the UK’s leading information and cyber security specialists.       

Understanding Relevant Risks07 May 202600:15:18

In this episode of InfoSec Insider, Wayne Armstrong, Senior Information Security Consultant and Consultant Manager at URM, breaks down the fundamentals of effective information security risk assessment and treatment.  Wayne draws upon over 30 years of experience in IT, information security and risk management to discuss:

  • What ‘risk’ actually is
  • How to define a risk and the three component parts that are needed for a risk to exist
  • How to assign value to a risk
  • How to prioritise risks and determine which can be set aside, as well as how these priorities differ between organisations depending on context
  • The risk treatment options available, and the need to revisit your risk assessment.

Learn more about this topic: https://www.urmconsulting.com/blog/information-security-risk-assessment-and-treatment-understanding-relevant-risks

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.     

Zero Trust Architecture in PCI DSS30 Apr 202600:28:11

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, share their insights on zero trust architecture and its use when complying with the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage 30 years’ combined experience with the PCI DSS to discuss:

  • What ‘zero trust’ is
  • Whether organisations with zero trust still need segmentation, or whether identity is enough
  • How to prove least privilege when access is dynamic and granted on demand, and how to handle sampling for PCI DSS evidence when access changes continuously
  • The biggest zero trust implementation mistakes that cause PCI DSS challenges later
  • Which logs matter most to prove that zero trust is actually protecting the cardholder data environment (CDE)
  • And much more.

Ask Alastair and Tibor a question:   https://urmconsulting.com/podcasts/zero-trust-architecture-in-pci-dss

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts       

 Connect with us on LinkedIn

Brought to you by URM, the UK’s leading information and cyber security specialists.   

The DSAR Reviewer’s Toolbox23 Apr 202600:42:30

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, discuss context and redaction in handling data subject access requests (DSARs), and how reviewers can use these to fulfil requests in full compliance with the General Data Protection Regulation (GDPR).  Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:

  • Why redaction the part of DSAR handling that so often goes wrong for organisations
  • How reviewers can distinguish between personal data, mixed data, and information that should not be disclosed
  • The biggest challenges when handling DSARs involving unstructured datasets like email chains, chat logs, or call notes
  • Some of the common redaction mistakes organisations make, and lessons learned from real cases
  • The practical steps organisations can take to improve the quality and defensibility of their redactions.

Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/the-dsar-reviewers-toolbox

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

 

Connect with us on LinkedIn

 

Brought to you by URM, the UK’s leading information and cyber security specialists.    

Identity and Access Management16 Apr 202600:21:46

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, share their insights on identity and access management (IAM), and the steps organisations can take to ensure their IAM is secure and resilient.  Jack and George leverage their extensive experience supporting organisations’ strengthen their information security to discuss:

  • What IAM is, whether it just covers employees, and how it works
  • The components that may feature as part of effective IAM, such as multi-factor authentication (MFA), single sign-on (SSO), monitoring and auditing, etc.
  • Why it is important to enforce IAM best practices
  • The problems around IAM that may arise in the future as a result of developing trends and technologies.

Ask Jack and George a question

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider          

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts   

 

Brought to you by URM, the UK’s leading information and cyber security specialists.       

Clause 6.3 of ISO 27001: The Importance of Planned ISMS Change Management09 Apr 202600:06:21

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, provides key insights on achieving and maintaining conformance to Clause 6.3 (Planning of changes) of ISO 27001, the International Standard for Information Security Management Systems (ISMS’).  Neil leverages over 20 years of real-world information security knowledge and experience to discuss:

  • What Clause 6.3 is and why planned ISMS change management is so important
  • The common mistakes organisations make when planning ISMS changes under Clause 6.3
  • The seven practical actions he recommends for effective implementation of Clause 6.3, which of these actions organisations most frequently overlook, and why
  • How to determine whether your existing change management processes are suitable for Clause 6.3 conformance.

Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-6-3-the-importance-of-planned-isms-change-management

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts   

Brought to you by URM, the UK’s leading information and cyber security specialists.

Cyber Security Expectations in the Medical Supply Chain02 Apr 202600:20:42

In this episode of InfoSec Insider – Talk Cyber, Stuart Moran and George Ryan, Consultants at URM, explore recent shifts in cyber security expectations and regulatory requirements faced by organisations in the medical supply chain, both in the UK and across the globe.  Stuart and George leverage their extensive experience helping organisations in the medical sector enhance information and cyber security to discuss:   

  • The NHS’ recent open letter to suppliers, which highlights tighter scrutiny and more direct engagement, and what this means for NHS suppliers
  • Which of the NHS’ new cyber security requirements for suppliers (MFA, continuous monitoring and immutable backups) will be most challenging to embed and why
  • The biggest gaps and understanding or readiness among suppliers implementing the Data Security and Protection Toolkit (DSPT), and the practical differences between Categories 2 and 3 of the DSPT
  • How shifts in standards such as ISO 13485 and the broader medical device regulatory landscape will influence suppliers’ design and manufacturing of their products, particularly around software and AI
  • How the FDA’s power to deny market access to medical devices with insufficient cyber security may impact UK suppliers operating internationally, and whether this hints at a broader, global trend towards stricter cyber controls.

 

Learn more about this topic:

 

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider          

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        

 

Brought to you by URM, the UK’s leading information and cyber security specialists.

Unusual Questions About PCI DSS26 Mar 202600:20:38

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, answer the niche and unusual questions they encounter around the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:   

  • The strangest misconceptions they have heard about PCI DSS and cardholder data security
  • What PCI DSS would look like if it were invented today, and what would be left out entirely
  • The simple PCI DSS controls that people routinely misunderstand
  • The most unusual systems or devices they have seen brought into scope
  • Whether something can be both technically compliant and completely insecure at the same time, and whether there is such a thing as ‘too compliant’
  • Finer technical details of the Standard, such as Kubernetes network policies, how to evidence a control that never triggers, corporate VPNs that impact segmentation, and more.

Ask Alastair and Tibor a question.

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        

Connect with us on LinkedIn   

 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Review of Enforcement Action by the ICO in 202519 Mar 202600:14:34

In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides a break down and analysis of how the Information Commissioner’s Office (ICO’s) enforced UK data protection (DP) regulations in 2025, and how this compares to the action taken by the regulator in previous years.  Stuart leverages his 25+ years of specialisation in data protection law to discuss:   

  • The context of changes in ICO enforcement activities between 2024 and 2025 
  • The main headline takeaways from his 2025 analysis, particularly in relation to the ICO’s fining activities 
  • What the regulator itself has said recently about new ways in which it’ll tackle enforcement in 2026 and beyond 
  • Ongoing DP stories to keep an eye on which might have an impact on the ICO, its fining posture and its ability to enforce any fines it imposes.  

Learn more about this topic: https://www.urmconsulting.com/blog/analysis-of-enforcement-action-by-the-ico-in-2025-actions-way-down-security-data-breach-fines-way-up

 

If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

 

Brought to you by URM, the UK’s leading information and cyber security specialists.

Information Security Governance, Compliance and Asset Management12 Mar 202600:41:04

In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can achieve strong information security governance and asset management that facilitate conformance to ISO 27001, the International Standard for Information Security Management Systems (ISMS).  Jack and George draw on their extensive experience supporting organisations’ ISO 27001 certifications to discuss:

  • How to transform high-level information security policies into day-to-day behaviour across teams, and who should own information security within organisations
  • Defining clear information security roles and responsibilities, and how to overcome the practical challenges of implementing segregation of duties
  • What best practice looks like when maintaining contact with authorities, special interest groups, and threat intelligence
  • The importance of integrating information security into project management
  • How to produce usable (rather than bureaucratic) documented operating procedures that reduce operational risk
  • Effective information handling and asset management, from inventorying assets and acceptable use through to classification and labelling of information.

Ask Jack and George a question:

https://www.urmconsulting.com/podcasts/information-security-governance-compliance-and-asset-management

 

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider          

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts          

 

Brought to you by URM, the UK’s leading information and cyber security specialists.

The Core Functions of NIST CSF – Identify05 Mar 202600:14:00

In this episode of InfoSec Insider – Talk Cyber, Mark O’Kane, Consultant at URM, explains the second of the NIST Cybersecurity Framework’s (CSF’s) five core functions, the Identify function, sharing his insights on what organisations can do in practice to meet its requirements.   Mark uses his extensive experience working in information security and risk management to discuss:

  • Where the Identify function sits within the overall NIST CSF
  • How your organisation can meet the requirements around identifying and managing assets
  • The practical steps provided by the CSF for organisations struggling to understand their cyber security risks
  • How to identify areas for improvement in your cyber security programme in line with the Identify function’s requirements.

Learn more about this topic: https://www.urmconsulting.com/blog/the-core-functions-of-nist-csf-identify

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider  

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts  

Brought to you by URM, the UK’s leading information and cyber security specialists. 

 

Preparing for a PCI DSS Assessment26 Feb 202600:29:22

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, share their perspective on how organisations can most effectively and efficiently prepare for a Payment Card Industry Data Security Standard (PCI DSS) assessment.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

  • Practical steps teams can take to ensure the assessment runs smoothly overall
  • What you should have ready before your PCI DSS assessment is even booked and how to determine if your scope definition is clear enough
  • What useable evidence looks like from a practical perspective, and whether to provide everything up front or respond as questions are asked
  • When self-assessment questionnaires (SAQs) vs. full assessed engagements are needed, and what to keep from an SAQ in case a full engagement is required in the future
  • What to do differently if this years’ assessment follows significant amounts of change
  • And more.

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/preparing-for-a-pci-dss-assessment

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      

Connect with us on LinkedIn  

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Workplace Privacy in a Hybrid World: Monitoring, DSARs, and Building Trust19 Feb 202600:34:45

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, Data Protection Consultants at URM, explore the challenges of workplace privacy and data protection compliance in a hybrid business landscape, and how these challenges can be overcome.  Rachael and Aimee leverage over 20 years’ combined experience in data protection to discuss:

  • Why employee data is becoming such a significant risk for businesses
  • The legal and ethical boundaries when monitoring employees
  • Why operational challenges make employee data subject access requests (DSARs) and monitoring so difficult
  • Practical steps that small and medium-sized enterprises (SMEs) can take to monitor lawfully and reduce risk
  • How future trends like artificial intelligence (AI) and global rules change workplace privacy.

Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/workplace-privacy-in-a-hybrid-world-monitoring-dsars-and-building-trust

URM’s blog on data protection considerations for monitoring employees: https://www.urmconsulting.com/blog/data-protection-considerations-for-monitoring-employees

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here:   https://urmconsulting.com/podcasts     

Connect with us on LinkedIn     

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Minimising the Impact if a Breach Occurs12 Feb 202600:31:11

In this episode of InfoSec Insider – Talk Cyber, Jack Woods and George Ryan, both Consultants at URM, outline the steps organisations can take to ensure they are prepared in the event of a cyber breach and able to minimise the impact of a breach as much as possible.  George and Jack leverage their extensive experience helping organisations strengthen their cyber and information security posture to discuss:  

  • The importance of approaching cyber security breaches as a question of ‘when’ not ‘if’, and how to ensure your organisation is appropriately resilient
  • The documentation and procedures organisations should have in place, such as business continuity, disaster recovery, and communication plans, and how to test these plans’ effectiveness through exercising
  • When disconnecting your organisation’s environment, i.e., ‘pulling the plug’, is an appropriate response to an attack
  • Technical measures all organisations should have in place to mitigate the impact of a breach, such as segregation, backups, etc.

Ask Jack and George a question: https://www.urmconsulting.com/podcasts/minimising-the-impact-if-a-breach-occurs

Learn more about this topic:  https://www.urmconsulting.com/blog/minimising-the-impact-when-a-breach-occurs

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider          

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts          

Brought to you by URM, the UK’s leading information and cyber security specialists.       

The Core Functions of NIST CSF - Govern05 Feb 202600:18:51

In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, explores the National Institute of Standards and Technology Cybersecurity Framework’s (NIST CSF’s) newly introduced Govern Function, outlining its purpose and significance within version 2.0 of the Framework. Mark examines each of its six Categories in detail, from defining organisational context and risk management strategy to establishing oversight and supply chain risk management, and explain the policies, processes and activities you will need to implement and conduct for conformance with each Category. If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      Connect with us on LinkedIn      Brought to you by URM, the UK’s leading information and cyber security specialists.   

Data Protection by Design and by Default29 Jan 202600:27:40

In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Data Protection Consultants at URM, share their insights on the principle of data protection (DP) by design and by default, particularly as it relates to small and medium-sized enterprises (SMEs).  Rachael and Aimee leverage over 20 years’ combined experience in data protection to discuss:

  • What ‘data protection by design and by default’ means under the UK General Data Protection Regulation (GDPR)
  • Why this approach is so important for SMEs
  • How SMEs can practically implement DP by design and default
  • The common pitfalls SMEs face when applying this principle
  • The emerging and future trends that make DP by design and default even more critical.

Ask Rachael and Aimee a question:  https://urmconsulting.com/podcasts/data-protection-by-design-and-by-default

URM’s blog on data protection impact assessments (DPIAs): https://www.urmconsulting.com/blog/when-and-how-to-conduct-a-data-protection-impact-assessment-dpia

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     

Connect with us on LinkedIn     

 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

 

Reducing the Likelihood of a Security Breach22 Jan 202600:51:39

In this episode of InfoSec Insider – Talk Cyber, Jack Woods and George Ryan, both Consultants at URM, explain the steps organisations can take to reduce the likelihood of suffering a security breach.  George and Jack leverage their extensive experience helping organisations strengthen their cyber and information security posture to discuss:

  • What constitutes a security breach and how they are commonly caused
  • Where to start in strengthening your organisation’s defences and the key measures you should have in place across people, process, technology and supply chain
  • The importance of preparing for if an attack does occur and reducing the impact of a breach.

Ask Jack and George a question: https://www.urmconsulting.com/blog/reducing-the-likelihood-of-a-security-breach

Learn more about this topic: https://www.urmconsulting.com/blog/strengthening-your-cyber-defences-practical-steps-for-every-business

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider         

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts         

Brought to you by URM, the UK’s leading information and cyber security specialists.      

The Defence Cyber Certification15 Jan 202600:13:05

In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, breaks down the Defence Cyber Certification (DCC), a new certification framework developed by the Ministry of Defence (MoD) and IASME for UK defence suppliers.  George draws upon his extensive experience helping organisations strengthen their cyber security to discuss:

  • What the DCC is and who it’s for
  • The four levels of compliance in the DCC, what they mean and how they work
  • How the DCC can benefit organisations in the defence sector
  • The steps involved in achieving the DCC.

Learn more about this topic: https://ratethispodcast.com/infosecinsider       

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       

Brought to you by URM, the UK’s leading information and cyber security specialists.     

Data Protection Considerations for Artificial Intelligence (AI)14 Jan 202600:23:18

In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores the considerations organisations should make to maintain data protection (DP) compliance in their development and deployment of artificial intelligence (AI) systems.  Martin leverages his 20+ years’ specialisation in DP and information management to discuss:

  • What AI is
  • The current AI regulatory framework and how it’s evolving
  • How the 7 core principles of the General Data Protection Regulation (GDPR) apply and relate to AI
  • How to comply with rules around automated decision making and meet data subject rights obligations in your development or use of AI
  • Additional DP factors to consider, such as continuous improvement, appropriate risk mitigations, and using established methods to assess and record decisions.

 

Learn more about this topic: https://www.urmconsulting.com/blog/data-protection-considerations-for-artificial-intelligence-ai

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        

Brought to you by URM, the UK’s leading information and cyber security specialists.   

PCI DSS: Standards vs. Reality18 Dec 202500:33:58

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore the theory versus the reality of compliance with the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: 

  • Whether it would be cheaper to simply pay the fines instead of being PCI DSS compliant
  • How often they see organisations treat PCI as a one-time project versus an ongoing programme
  • The possibility of still suffering a breach while being fully compliant, and whether this has happened in the past
  • The PCI requirements organisations struggle with most in practice
  • How smaller merchants can cope with PCI requirements that were designed with larger organisations in mind
  • The areas where PCI DSS lags behind current security threats
  • And more.

Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-standards-vs-reality

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      

Connect with us on LinkedIn      

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Clearview AI Case11 Dec 202500:14:52

In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Consultant at URM, breaks down the Upper Tribunal’s recent decision to uphold the ICO’s appeal in the Clearview AI case, sharing his insights on the meaning and impact of this development.  Stuart draws upon over 25 years of specialisation in data protection law to discuss:

  • The Clearview AI case and how it has developed since the ICO’s 2022 decision to impose a £7.5m fine on Clearview
  • The Upper Tribunal’s ruling and how it has clarified the territorial scope of the GDPR, as well as the limits of the Regulation’s Article 2 exemption for law enforcement
  • Why the enforcement limitations of the GDPR mean this ruling may not be as significant a win for the ICO as it initially seems
  • A potential legal challenge to Clearview from well-known data protection activist Max Shrems, potentially signalling hope on the horizon for this case.

Learn more about this topic: https://www.urmconsulting.com/blog/icos-appeal-in-clearview-ai-case-upheld

If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     

Brought to you by URM, the UK’s leading information and cyber security specialists. 

ISO 27001 - Clause 5.1 Leadership and Commitment Explained04 Dec 202500:17:22

In this episode of InfoSec Insider, Frazer Grudings, Senior Consultant at URM, shares his insights on Clause 5.1 of ISO 27001, which covers the leadership and commitment requirements for an information security management system (ISMS) that is conformant to the Standard.  Frazer draws upon over 15 years of information security experience to discuss:

  • The requirements of Clause 5.1 and what conformance to this Clause involves
  • Why leadership and commitment matter to an ISMS
  • What can go wrong when leadership and commitment are not demonstrated.

Learn more about this topic:  https://www.urmconsulting.com/blog/iso-27001-clause-5-1-leadership-and-commitment-explained

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider   

You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts   

Brought to you by URM, the UK’s leading information and cyber security specialists.  

 

PCI DSS – The Overlooked Systems27 Nov 202500:27:42

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer their advice on the systems and controls that are often overlooked in relation to the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: 

  • Why the PCI DSS covers systems that don’t store card data, such as DNS servers or time servers
  • Why time synchronisation (NTP servers) is a PCI requirement
  • How card data can leak through system logs and how this can be avoided
  • Printers, custom error messages, IoT devices – why they’re in scope and how to maintain compliance.

Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-the-overlooked-systems

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    

 

Connect with us on LinkedIn    

 

Brought to you by URM, the UK’s leading information and cyber security specialists.  

Data Protection Rights20 Nov 202500:42:08

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, explore individuals’ rights under the GDPR beyond the right of access (the most widely discussed of the data subject rights), and the requirements and obligations on organisations handling these.  Rachael and Aimee draw upon over 20 years’ combined experience in data protection to discuss:

  • The data rights aside from the right of access that tend to unexpectedly consume business resources and why
  • The operational risks posed to small and medium-sized enterprises (SMEs) by rights such as erasure, rectification, restriction, portability, and objection
  • How SMEs can recognise success in handling these rights without drowning in process complexity
  • The common pitfalls that cause unnecessary challenges or regulatory difficulties when dealing with these rights
  • How, in real-world terms, businesses can balance customer empowerment through data rights with maintaining smooth, cost-effective operations.

Ask Rachael and Aimee a question.

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts     

Connect with us on LinkedIn 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

7 Top Tips for Communicating in a Crisis13 Nov 202500:12:37

In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, shares his top tips on crisis communication, considering the steps organisations can take to prepare before a crisis occurs, while it is happening, and after it’s been dealt with to ensure communication is as effective and seamless as possible.  Martin draws upon his extensive experience helping organisations enhance their business continuity to discuss:

  • What a ‘crisis’ is
  • What crisis communication is and how it fits into business continuity planning
  • Why crisis communications matter
  • 7 top tips on ensuring your organisation can communicate effectively in a crisis, such as planning ahead of time, setting the right tone, listening to feedback, and more.

Learn more about this topic: https://www.urmconsulting.com/blog/the-eu-artificial-intelligence-act

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.    

Building Cyber Security Resilience Against Phishing06 Nov 202500:24:33

In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights into phishing and what organisations can do to protect themselves against it.  George draws upon his extensive experience helping organisations strengthen their cyber security to discuss:

  • What phishing is and the various forms it takes
  • How phishing achieves its goal by influencing behaviour, and how artificial intelligence (AI) impacts this
  • The steps organisations can take to protect themselves against phishing.

Learn more about this topic: https://www.urmconsulting.com/blog/building-cyber-security-resilience-against-phishing

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.      

ISO 27001 People Controls30 Oct 202500:36:45

In this episode of InfoSec Insider, Jack Woods and Mark O’Kane, both Consultants at URM, take a deep dive on the ‘People’ controls theme in ISO 27001, and why these controls matter in today’s hybrid workplaces, how they strengthen information security, and what auditors look for during assessments.  Jack and Mark draw upon their extensive experience supporting organisations’ implementation of the Standard to discuss:

  • How to balance the risk of potential insider threats against the downsides of overzealous background checks when implementing pre-employment screening
  • The practical steps you can take to meaningfully enforce people controls beyond generic policies in the context of remote and hybrid work environments
  • How to ensure incident reporting for information security is both mandatory and non-punitive, so employees feel safe to report without fear of reprisal
  • The types of evidence auditors expect to see in a people controls-focused audit
  • The risks that arise when people controls such as training or NDAs are not routinely reviewed/updated as working patterns or staff roles evolve.

Ask Jack and Mark a question: https://urmconsulting.com/podcasts/iso-27001-people-controls

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     

Connect with us on LinkedIn     

Brought to you by URM, the UK’s leading information and cyber security specialists.

AIIAs in ISO 4200123 Oct 202500:08:19

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, explores artificial intelligence impact assessments (AIIAs), a key conformance activity required by ISO 42001, the International Standard for AI Management Systems (AIMS).  Neil leverages over 20 years of experience working with risk and information security-related standards to discuss:

  • What an AIIA is under ISO 42001, and how it differs from a typical risk assessment
  • The role of ISO 42005 and how it relates to AIIAs
  • The seven sections of an AIIA and what each section covers
  • When in the AI lifecycle you need to conduct an AIIA
  • How organisations should balance AIIAs with risk assessments in the context of ISO 42001.

Learn more about this topic: https://www.urmconsulting.com/blog/iso-42001-artificial-intelligence-impact-assessments-aiias

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.    

The People Side of PCI DSS16 Oct 202500:29:27

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer advice on compliance with the Payment Card Industry Data Security Standard (PCI DSS), with a particular focus on the ‘human’ element of security.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:

  • How you can minimise the risk of noncompliance caused by human error or behaviour
  • The compliance complications associated with using wireless devices such as Bluetooth headphones
  • Whether ‘pause-and-resume’ recording in call centres is truly secure
  • How to avoid card data leaking through CCTV cameras in environments such as call centres
  • And more!

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/ the-people-side-of-pci-dss

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider   

You can find more episodes of InfoSec Insider here:     https://urmconsulting.com/podcasts   

Connect with us on LinkedIn   

Brought to you by URM, the UK’s leading information and cyber security specialists.  

DSARs: A Business Burden vs. a Data Protection Opportunity09 Oct 202500:24:34

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Data Protection Consultants at URM, provide their insights on overcoming data subject access request (DSAR) challenges and how organisations can gain benefits from the fulfilment of DSARs, rather than treating them purely as a business burden.   Rachael and Aimee leverage over 20 years’ combined experience in data protection to discuss:  • Whether DSARs can actually enhance customer trust, or are simply a compliance checkbox exercise for organisations • How organisations can reframe DSAR handling as an opportunity to improve their data governance  • The hidden costs of DSARs and how you can measure whether those costs bring any tangible benefits • When it is appropriate to push back on a DSAR as ‘manifestly unfounded’ or ‘excessive’ and how to defend this decision to the regulator • How to proactively use DSAR data to inform your privacy strategy and customer engagement. 

Ask Rachael and Aimee a question:  https://urmconsulting.com/podcasts/dsars-a-business-burden-vs-a-data-protection-opportunity

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Connect with us on LinkedIn     Brought to you by URM, the UK’s leading information and cyber security specialists.  

Establishing Organisational Control Over AI02 Oct 202500:17:25

In this episode of InfoSec Insider, George Ryan, Consultant at URM, provides key advice and guidance on the impact of artificial intelligence (AI) on organisations, and the steps they can take to establish control over its usage.  George leverages his extensive experience helping organisations strengthen their information and cyber security to discuss:  

  • What ‘AI’ is  
  • How AI and its usage can impact organisations 
  • How organisations can look to control AI among its staff and within its operations. 

Learn more about this topic: https://www.urmconsulting.com/blog/establishing-organisational-control-over-artificial-intelligence 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider        

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        

Brought to you by URM, the UK’s leading information and cyber security specialists. 

The EU AI Act25 Sep 202500:24:19

In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, explores the EU Artificial Intelligence (AI) Act, the world’s first comprehensive regulation on AI by a major regulator.  Maritn draws upon over 20 years of experience in compliance, information management and data protection to discuss:

  • What AI is and how it is defined by the EU AI Act
  • Which entities the Act is applicable to, the different ‘compliance roles’ it defines and the obligations associated with each
  • How AI risk is categorised, and the provisions for and restrictions upon each risk level
  • How the AI Act will be enforced
  • The current UK approach to AI legislation and the impact of the AI Act beyond the EU.

Learn more about this topic: https://www.urmconsulting.com/blog/the-eu-artificial-intelligence-act

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     

 

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     

 

Brought to you by URM, the UK’s leading information and cyber security specialists.    

The ISO 27001 Certification Process18 Sep 202500:11:00

In this episode of InfoSec Insider, Scott Lloyd, Senior Consultant at URM, offers key advice and guidance on the ISO 27001 certification process, how organisations can ensure they are prepared for a smooth and successful certification assessment.  Scott leverages his extensive experience in the field of information security to discuss:

  • Common misconceptions about certification
  • The ‘must-have’ documentation organisations need to have in place ready for their Stage 1 audit
  • The Stage 2 audit, the difference between minor and major nonconformities and how they affect certification
  • How organisations should handle minor nonconformities so that they do not become majors in the future
  • The 3-year certification cycle and Continual Assessment Visits (CAVs)

Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-how-certification-works

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.    

 

Defending Against Ransomware Attacks11 Sep 202500:12:44

In this episode of InfoSec Insider – Talk Cyber, George Ryan, consultant at URM, provides his insights on the steps organisations can take to protect themselves against ransomware attacks.  George leverages his extensive experience helping organisations strengthen cyber security measures to discuss:

  • What ransomware is and why it has so frequently made headlines in recent years
  • Who is responsible for protecting an organisation against ransomware
  • The role of people, processes and technology in enhancing ransomware defences
  • Which measures organisations with minimal or no cyber security should prioritise.

Learn more about this topic: https://www.urmconsulting.com/blog/critical-cyber-security-practices-to-defend-against-ransomware-attacks

If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      

Brought to you by URM, the UK’s leading information and cyber security specialists.       

© My Podcast Data · Projet indépendant · Données issues d'Apple & Spotify