URM Consulting

InfoSec Insider

Business EN ↓ 93 episodes

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (B...

Author

URM Consulting

Category

Business

Podcast website

InfoSecInsider.podbean.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

ISO 27001 Access Management Controls 19.06.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, provides his insights on the 4 controls that relate to access management in the ‘Organisational’ control theme of ISO 27001’s Annex A.  Wayne leverages his 30+ of experience with information security to discuss:  The requirements of each of the following 4 controls and how your organisation can go about meeting them:  A...

ISO 27001 Supplier Management Controls 12.06.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the 5 supplier management-related controls in the ‘Organisational’ control theme of ISO 27001’s Annex A.  Wayne draws upon 30+ of experience with information security to discuss:  Why your organisation should consider supplier management as part of information security   What each of the following 5 controls...

Information Risk Assessment and Treatment in ISO 27001 05.06.2025

In this episode of InfoSec Insider, Jack Woods, Consultant at URM, explores information risk assessment and risk treatment in the context of ISO 27001, the International Standard for Information Security Management Systems (ISMS’).  Jack leverages his extensive experience assisting organisations to implement an ISMS and certify to the Standard to discuss: The purpose of a risk assessment How risk...

Technological Controls in ISO 27001 29.05.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, provides his insights on the 34 technological controls in Annex A of ISO 27001 and how these can be implemented by organisations looking to conform or certify to the Standard.  Wayne leverages his 30+ years of experience in information security and risk management to discuss: What the technological controls in ISO 27001...

ISO 27001 – Physical Security Controls 22.05.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the ‘Physical’ control theme from Annex A of ISO 27001, which are a set of security measures aimed at protecting an organisation’s physical assets and environment, such as their buildings, equipment, and paper copies of documents.  Wayne leverages his 30+ of experience with information security to discuss: W...

Sharing Personal Data With the Police 15.05.2025

In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, breaks down the General Data Protection Regulation’s (GDPR’s) requirements for organisations that need to share personal data with the police in order to report a crime, or following a request for data to assist with an investigation.  Martin leverages his 20+ years of experience in information...

ISO 27001 Audits 08.05.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, explains the steps organisations can take to effectively plan, conduct, and action an ISO 27001 internal audit.  Wayne draws upon 30+ years of experience in the information security and risk management field to discuss: The key things to remember when planning your audit programme and to plan specific audits His tips fo...

People Controls in ISO 27001 01.05.2025

In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, provides key insights on the ‘People’ control theme of ISO 27001’s Annex A, which are measures organisations can implement to protect employees and influence their behaviour in relation to information security.  Frazer leverages his over 15 years of experience in the information security field to discuss:   Why ‘people...

ISO 13485 Explained 24.04.2025

In this episode of InfoSec Insider, Stuart Moran, Senior Consultant at URM, offers essential advice on ISO 13485, the International Standard for Medical Devices Quality Management Systems (MDQMS).  Stuart draws upon over 20 years of experience in managing organisation-wide management systems to discuss: What ISO 13485 is and why it’s important for regulatory compliance Which organisations ISO 1348...

Are you processing special category data without knowing it? 17.04.2025

In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Consultant at URM, explains the General Data Protection Regulation’s (GDPR’s) requirements around special category personal data, and how organisations can ensure they are not processing it unknowingly or unnecessarily.  Martin leverages his 20+ years of experience in information management and data protection compliance to discu...

The Impact of AI on PCI DSS Compliance 10.04.2025

In this episode of InfoSec Insider, Alastair Stewart, Senior Consultant and Qualified Security Assessor (QSA) at URM, explores the ways in which artificial intelligence (AI) tools and systems can be leveraged for compliance with the Payment Card Industry Data Security Standard (PCI DSS).  Alastair draws upon over a decade of experience with the PCI DSS to discuss: PCI DSS basics – what the PCI DSS...

10 Top Tips for Maintaining Information and Cyber Security While Homeworking 03.04.2025

In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, shares his top 10 tips on how to embed key cyber security practices and maintain the security of your organisation’s information assets whilst working remotely, whether that be from home or another location.  Frazer draws upon 15+ years in the information security field to explain the importance of and how to implement...

SOC 2 Explained 27.03.2025

In this episode of InfoSec Insider, Chris Heighes, Senior Consultant at URM, breaks down the System and Organization Controls 2 (SOC 2), an information security framework aimed at providing assurance to a service provider’s clients that their data is stored and processed in a secure manner.  Chris leverages his 15+ years of experience in the information security space to discuss: Which organisatio...

PCI DSS V4.0 – How to Reduce Your PCI DSS Scope 20.03.2025

In this episode of InfoSec Insider, Alastair Stewart, Senior Consultant and Qualified Security Assessor (QSA) at URM, provides key advice and guidance on the steps organisations can take to streamline and reduce their Payment Card Industry Data Security Standard (PCI DSS) scope.  Alastair leverages more than a decade of experience with the PCI DSS to discuss: What the PCI DSS defines as ‘in scope’...

New Government Proposal to Prevent Organisations From Paying Ransomware Demands 13.03.2025

In this episode of InfoSec Insider – Talk Cyber, Stuart Skelly, Senior Consultant at URM, explains a recently announced consultation by the UK government into proposals by the Home Office, which would increase its control and visibility of ransomware attacks on organisations operating in the UK.  Stuart leverages his extensive legal background and experience as a governance, risk and compliance co...

ISO 27002 – Purpose and Benefits 06.03.2025

In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, offers key insights on ISO 27001’s supplementary guidance standard, ISO 27002, which provides guidance on implementation of the ISO 27001 Annex A controls.  Frazer leverages his 15+ years of experience to discuss: What ISO 27002 is The ‘attributes’ framework in ISO 27002 and the purpose of this framework The different...

How to Build Customer Trust Through Data Protection 27.02.2025

In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explains the importance of data protection for building and maintaining customer trust, and offers key advice on how to ensure that your data processing practices will help facilitate strong relationships with your customer base.  Martin leverages his 20+ years of experience in information manag...

Developing an ISO 27001 Information Security Policy 20.02.2025

In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, offers key advice and guidance on creating an information security policy that meets the requirements of ISO 27001, the International Standard for Information Security Management Systems (ISMS’).  Frazer leverages his 15+ years of experience supporting organisations to certify against ISO 27001 to discuss: What an info...

Analysis of Fines Imposed by the Information Commissioner’s Office in 2024 13.02.2025

In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Consultant at URM, provides a break down and analysis of how the Information Commissioner’s Office (ICO’s) has enforced UK data protection (DP) regulations in 2024, and how this compares to the action taken by the regulator in previous years.  Stuart leverages his 25+ years of specialisation in data protection law to discuss:    T...

Cyber Security for Small and Medium-Sized Enterprises (SMEs) 06.02.2025

In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, takes a deep dive into the unique cyber security challenges faced by small and medium-sized enterprises (SMEs), and the steps these organisations can take to improve their cyber security postures.  George leverages his extensive experience assisting organisations to enhance their cyber security to discuss: The current...

Top Tips for Implementing an ISO 27001 ISMS 30.01.2025

In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, shares some of his top tips for implementing an information security management system (ISMS) that is both conformant to the requirements of ISO 27001 and effectively enhances an organisation’s information security culture.  Wayne draws upon his 30+ years of experience in information security and risk management to disc...

STAIRs: A New Standard for Social Housing Providers 23.01.2025

In this episode of InfoSec Insider – Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, breaks down the Social Tenant Access to Information Requirements (STAIRs), an upcoming standard with which private registered providers (PRPs) of social housing (such as housing associations) will need to comply.  Stuart leverages his 25+ years of specialisation in data protection law to discuss: What STAI...

DORA - EU Cybersecurity Legislation for Financial Organisations 16.01.2025

In this episode of InfoSec Insider, Chris Heighes, Senior Consultant at URM, takes a deep dive into the Digital Operations Resilience Act (DORA), a new EU regulation for financial entities and their key suppliers to improve their digital operational resilience, which comes into force on 17 January 2025.  Chris Leverages his 30 years of IT experience and 15 years’ experience in information security...

Preparing for a PCI DSS v4 Assessment 09.01.2025

In this episode of InfoSec Insider, Alastair Stewart, Senior Consultant and Qualified Security Assessor (QSA) at URM, breaks down the changes to assessments in v4.0 of the Payment Card Industry Data Security Standard (PCI DSS), and how organisations can prepare for their v4 assessments.  Alastair leverages more than a decade of experience with the PCI DSS to discuss:   The types of evidence the PC...

EDPB Opinion on Data Protection Issues in Artificial Intelligence 02.01.2025

In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, breaks down a recent opinion issued by the EU Data Protection Board (EDPB) in response to questions from the Irish Data Protection Commission (DPC) on the compliant processing of personal data in the development and deployment stages of artificial intelligence (AI) models.  Stuart draws upon his...

Listen to the InfoSec Insider podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.