URM Consulting
InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (B...
Author
URM Consulting
Category
Podcast website
Latest episode
Jul 9, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Mitigating Cyber Risks 19.12.2024 21:35
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, breaks down the current state of cyber security in the modern business landscape and the common cyber security failings and challenges he sees organisations face, as well as offering key advice and guidance on what organisations can do to protect against these threats. George leverages his extensive experience assist...
Mistakes to Avoid When Implementing & Maintaining an ISO 27001 ISMS 12.12.2024 18:28
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the common mistakes and challenges organisations come up against on both sides of their certification assessment, i.e., before the external assessment when the Information Security Management System (ISMS) is first being implemented, and after certification has been achieved and the ISMS is being maintained....
Who Needs a ROPA and Why? 05.12.2024 29:05
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, explains records of processing activities (ROPAs), a key document that almost every organisation must create and maintain in order to comply with the General Data Protection Regulation (GDPR). Stuart leverages his 25+ years of specialisation in data protection law to discuss: What a ROPA is, which organi...
ISO 42001 and AI Perspectives 28.11.2024 17:22
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, breaks down the purpose and structure of the recently released ISO 42001, the International Standard for Artificial Intelligence Management Systems (AIMS), as well as explaining the Standard’s use of AI ‘perspectives’. Neil leverages his 20+ years’ working with a range of risk and information security-related standards to d...
Data Protection Considerations for Monitoring Employees 21.11.2024 19:05
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores the challenges of maintaining data protection compliance whilst conducting workplace monitoring, particularly in light of the workforce’s ever-increasing mobility, and how these challenges can be overcome. Martin leverages his 20+ years of experience in information management and data...
What is the CIA Security Triad? 14.11.2024 12:49
In this episode of InfoSec Insider, Les Krause-Whiteing, Senior Consultant at URM, breaks down the concepts of confidentiality, integrity and availability (CIA), the 3 fundamental principles on which strong information security is built, and why they are so important to the effective and comprehensive information security management. Les draws upon his extensive experience helping organisations e...
Data Protection Considerations for Artificial Intelligence (AI) 07.11.2024 20:39
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explores some of the considerations and challenges of maintaining compliance with data protection legislation, such as the General Data Protection Regulation (GDPR), when developing and deploying artificial intelligence (AI) technology. Martin leverages his 20+ years of experience in informatio...
ISO, IAF and Climate Change Considerations 31.10.2024 12:39
In this episode of InfoSec Insider, Stuart Moran, Senior Consultant at URM, explores the addition of climate change considerations to 31 management system standards by the International Standards Organization (ISO) and the International Accreditation Forum (IAF). Stuart draws upon more than 20 years of experience working with a wide range of ISO management system standards to discuss: What the...
Top Tips for GDPR Compliance 24.10.2024 20:13
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides some hints and tips on how to achieve and maintain compliance with the General Data Protection Regulation (GDPR), with a particular focus on the key documentation organisations need to have in place to comply. Stuart leverages over 25 years of experience to discuss: The importance of m...
Common Pitfalls with ISO 27001 17.10.2024 13:32
In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, highlights the common pitfalls and mistakes he frequently sees organisations make when implementing ISO 27001, and explores the steps you can take to avoid these pitfalls. Frazer draws upon his 15+ years of experience assisting organisations to implement ISO 27001 to discuss: The most common mistakes made and challe...
Facial Recognition Technology 10.10.2024 19:03
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Consultant at URM, explores the key challenges of and considerations for maintaining data protection compliance when using facial recognition technology (FRT). Martin leverages his 20+ years of specialism in information management and data protection to discuss: The different types of FRT and what they are used for Real-world...
ISO 9001 Implementation 03.10.2024 30:27
In this episode of InfoSec Insider, Sue West, one of URM’s Senior Consultants, breaks down 2 of her ‘golden rules’ for successful implementation of ISO 9001, the International Standard for Quality Management Systems (QMS’). Sue leverages more than 25 years of experience establishing, managing and auditing QMS’ to provide key insights on: The meaning of top management ‘leadership and commitment’...
Fines Imposed by the ICO in 2023 26.09.2024 14:54
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, provides a break down and analysis of the enforcement actions delivered since the beginning of 2023 by the Information Commissioner’s Office (ICO), the UK’s privacy regulator, to highlight emerging trends and lessons that can be learned from how the ICO enforces data protection legislation such as the UK G...
PCI DSS – New Requirements for E-Commerce 19.09.2024 11:37
In this episode of InfoSec Insider, Alastair Stewart, Payment Card Industry Qualified Security Assessor (PCI QSA) and Senior Consultant at URM, explores some of the new requirements for e-commerce pages in version 4.0 of the PCI Data Security Standard (PCI DSS), providing valuable advice and guidance on what organisations can do to remain PCI DSS compliant as they transition to v4.0. Alastair lev...
Everything You Need to Know about DSARs 12.09.2024 14:32
In this episode of InfoSec Insider – Talk DP, Rachael Salter, Senior Data Protection Consultant at URM, discusses organisations’ obligations under the General Data Protection Regulation (GDPR) when fulfilling data subject access requests (DSARs) and the challenges associated with processing these requests. Rachael leverages her 10+ years of experience working in data protection compliance to prov...
Certificate in Information Security Management Principles (CISMP) Training Course Explained 05.09.2024 10:30
In the episode of InfoSec Insider Wayne Armstrong, Senior Information Security Consultant at URM, discusses the Certificate in Information Security Management Principles (CISMP), a BCS managed, foundation-level information security qualification. Drawing upon his 30+ years’ experience in IT, information security and risk management, Wayne discusses: What the CISMP is What is covered in the CISMP...
GDPR Back to Basics 29.08.2024 27:22
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, takes us ‘back to basics’ with the General Data Protection Regulation (GDPR), breaking down the key data protection concepts and terminology you will need to understand if you want to achieve and maintain compliance with the GDPR. Stuart leverages his 25+ years of specialisation in data protection law to...
A Comparison of ISO 9001 and ISO 27001 24.07.2024 15:53
Sue West offers helpful advice and guidance on how to integrate multiple management systems which are conformant to/certified against ISO standards, with a particular focus on integrating an ISO 9001 quality management system (QMS) and an ISO 27001 information security management system (ISMS). Learn more about this topic: https://www.urmconsulting.com/blog/a-comparison-of-iso-9001-and-iso-27001
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.