Couverture de InfoSec Insider

InfoSec Insider

InfoSec Insider

De : URM Consulting
Écouter gratuitement

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

Copyright 2026 URM Consulting. All rights reserved.
Economie Management Management et direction
Épisodes
  • PCI DSS Periodic Activities
    Aug 6 2026

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

    • Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
    • The common mistakes they see organisations make when defining their own frequencies
    • Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
    • How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
    • How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
    • How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
    • And more.

    Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

    You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        

     Connect with us on LinkedIn

     Brought to you by URM, the UK’s leading information and cyber security specialists.   

    Afficher plus Afficher moins
    37 min
  • GDPR Cookies Compliance
    Jul 30 2026

    In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down cookies compliance under the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulations (PECR). Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:

    • Why cookies are so important to businesses commercially
    • What the law actually requires when using cookies
    • How businesses get cookie compliance wrong in practice
    • Where consent or pay fits in
    • What good compliance actually looks like.

    Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/gdpr-cookies-compliance       

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       

    Connect with us on LinkedIn 

    Brought to you by URM, the UK’s leading information and cyber security specialists.     

    Afficher plus Afficher moins
    38 min
  • Clause 10.2 of ISO 27001: Nonconformity and Corrective Action
    Jul 23 2026

    In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them. Neil leverages over 20 years of experience working with risk and information security-related standards to discuss:

    • What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS)
    • What nonconformities are, and the difference between major and minor nonconformities
    • The requirements of Clause 10.2 and how organisations can implement them in practice
    • Common mistakes to avoid when addressing Clause 10.2.

    Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts

    Brought to you by URM, the UK’s leading information and cyber security specialists.    

    Afficher plus Afficher moins
    11 min
adbl_web_anon_alc_button_suppression_t1
Aucun commentaire pour le moment