URM Consulting
InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (B...
Author
URM Consulting
Category
Podcast website
Latest episode
Jul 9, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
The Defence Cyber Certification 15.01.2026 13:05
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, breaks down the Defence Cyber Certification (DCC), a new certification framework developed by the Ministry of Defence (MoD) and IASME for UK defence suppliers. George draws upon his extensive experience helping organisations strengthen their cyber security to discuss: What the DCC is and who it’s for The four levels...
Data Protection Considerations for Artificial Intelligence (AI) 14.01.2026 23:18
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores the considerations organisations should make to maintain data protection (DP) compliance in their development and deployment of artificial intelligence (AI) systems. Martin leverages his 20+ years’ specialisation in DP and information management to discuss: What AI is The current AI re...
PCI DSS: Standards vs. Reality 18.12.2025 33:58
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore the theory versus the reality of compliance with the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: Whether it would be cheaper to simply pay the...
Clearview AI Case 11.12.2025 14:52
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Consultant at URM, breaks down the Upper Tribunal’s recent decision to uphold the ICO’s appeal in the Clearview AI case, sharing his insights on the meaning and impact of this development. Stuart draws upon over 25 years of specialisation in data protection law to discuss: The Clearview AI case and how it has developed since the...
ISO 27001 - Clause 5.1 Leadership and Commitment Explained 04.12.2025 17:22
In this episode of InfoSec Insider, Frazer Grudings, Senior Consultant at URM, shares his insights on Clause 5.1 of ISO 27001, which covers the leadership and commitment requirements for an information security management system (ISMS) that is conformant to the Standard. Frazer draws upon over 15 years of information security experience to discuss: The requirements of Clause 5.1 and what conforma...
PCI DSS – The Overlooked Systems 27.11.2025 27:42
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer their advice on the systems and controls that are often overlooked in relation to the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: Why the PCI D...
Data Protection Rights 20.11.2025 42:08
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, explore individuals’ rights under the GDPR beyond the right of access (the most widely discussed of the data subject rights), and the requirements and obligations on organisations handling these. Rachael and Aimee draw upon over 20 years’ combined experience in data protection to discuss: The da...
7 Top Tips for Communicating in a Crisis 13.11.2025 12:37
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, shares his top tips on crisis communication, considering the steps organisations can take to prepare before a crisis occurs, while it is happening, and after it’s been dealt with to ensure communication is as effective and seamless as possible. Martin draws upon his extensive experience helping organisations enhance the...
Building Cyber Security Resilience Against Phishing 06.11.2025 24:33
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights into phishing and what organisations can do to protect themselves against it. George draws upon his extensive experience helping organisations strengthen their cyber security to discuss: What phishing is and the various forms it takes How phishing achieves its goal by influencing behaviour, and...
ISO 27001 People Controls 30.10.2025 36:45
In this episode of InfoSec Insider, Jack Woods and Mark O’Kane, both Consultants at URM, take a deep dive on the ‘People’ controls theme in ISO 27001, and why these controls matter in today’s hybrid workplaces, how they strengthen information security, and what auditors look for during assessments. Jack and Mark draw upon their extensive experience supporting organisations’ implementation of the...
AIIAs in ISO 42001 23.10.2025 8:19
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, explores artificial intelligence impact assessments (AIIAs), a key conformance activity required by ISO 42001, the International Standard for AI Management Systems (AIMS). Neil leverages over 20 years of experience working with risk and information security-related standards to discuss: What an AIIA is under ISO 42001, and...
The People Side of PCI DSS 16.10.2025 29:27
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer advice on compliance with the Payment Card Industry Data Security Standard (PCI DSS), with a particular focus on the ‘human’ element of security. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: How you ca...
DSARs: A Business Burden vs. a Data Protection Opportunity 09.10.2025 24:34
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Data Protection Consultants at URM, provide their insights on overcoming data subject access request (DSAR) challenges and how organisations can gain benefits from the fulfilment of DSARs, rather than treating them purely as a business burden. Rachael and Aimee leverage over 20 years’ combined experience in data p...
Establishing Organisational Control Over AI 02.10.2025 17:25
In this episode of InfoSec Insider, George Ryan, Consultant at URM, provides key advice and guidance on the impact of artificial intelligence (AI) on organisations, and the steps they can take to establish control over its usage. George leverages his extensive experience helping organisations strengthen their information and cyber security to discuss: What ‘AI’ is How AI and its usage can imp...
The EU AI Act 25.09.2025 24:19
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, explores the EU Artificial Intelligence (AI) Act, the world’s first comprehensive regulation on AI by a major regulator. Maritn draws upon over 20 years of experience in compliance, information management and data protection to discuss: What AI is and how it is defined by the EU AI Act Which entities the Act is applicab...
The ISO 27001 Certification Process 18.09.2025 11:00
In this episode of InfoSec Insider, Scott Lloyd, Senior Consultant at URM, offers key advice and guidance on the ISO 27001 certification process, how organisations can ensure they are prepared for a smooth and successful certification assessment. Scott leverages his extensive experience in the field of information security to discuss: Common misconceptions about certification The ‘must-have’ docu...
Defending Against Ransomware Attacks 11.09.2025 12:44
In this episode of InfoSec Insider – Talk Cyber, George Ryan, consultant at URM, provides his insights on the steps organisations can take to protect themselves against ransomware attacks. George leverages his extensive experience helping organisations strengthen cyber security measures to discuss: What ransomware is and why it has so frequently made headlines in recent years Who is responsible f...
Getting Ready for STAIRs 04.09.2025 16:57
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, breaks down the Social Tenants Access to Information Requirements (STAIRs), a forthcoming information access standard that will give greater rights to tenants of private registered providers (PRPs). Martin leverages over 20 years of information management and data protection experience to discuss: What the STAIRs are an...
ISO 27001 Annex A Business Continuity Controls 07.08.2025 12:40
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, provides key advice and guidance on the two business continuity-related controls in Annex A of ISO 27001. Mark draws upon his extensive experience helping organisations implement and certify against the Standard to discuss: The requirements of the business continuity controls and how they help organisations security their assets...
Supplementing Cyber Essentials 31.07.2025 17:34
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights on the best next steps organisations can take following Cyber Essentials certification to further enhance their security. George leverages his extensive experience assisting organisations to strengthen their cyber security measures to discuss: What is covered by the Cyber Essentials scheme The...
Incident Management Controls in ISO 27001 24.07.2025 13:00
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights and advice on the six incident management-related controls in Annex A of ISO 27001, which are contained within the ‘Organisational’ and ‘People’ control themes. Mark leverages his extensive experience supporting organisations to implement ISO 27001 to discuss: The requirements of the incident management contro...
The DUA Act 17.07.2025 32:06
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides his insights on the Data (Use and Access) Act, which received Royal Assent on 19 June. Stuart draws upon over 25 years of specialisation in data protection law to discuss: The background, scope, and intention of the DUA Act How the DUA Act is expected to impact the UK’s data protection...
Legal, Regulatory and Contractual Controls in ISO 27001 10.07.2025 13:28
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights into the legal, regulatory and contractual-related controls (A.5.31-37) from Annex A of ISO 27001:2022 and how they can be effectively implemented by organisations. Mark draws upon his extensive experience assisting organisations to certify against the Standard to discuss: The requirements of the legal, regula...
Lexcel, SQM and Cyber Essentials 03.07.2025 9:20
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, explores the Lexcel Practice Management Standard (Lexcel), the Specialist Quality Mark (SQM) and their relationship with the Cyber Essentials scheme. George leverages his extensive experience assisting organisations to enhance their cyber security to discuss: What Lexcel and the SQM are, and why they are needed How...
ISO 27001 Information Security Management Controls 26.06.2025 16:32
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights into the information security management controls within Annex A of ISO 27001, which comprise the first eight controls of Annex A’s ‘Organisational’ control theme. Mark leverages his extensive experience supporting ISO 27001 implementations to discuss: What the organisational controls are, and how the first ei...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.