Épisodes

  • Physical Security Controls
    Aug 13 2026

    In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide expert advice and guidance on how organisations can maintain the physical security of their information, and where physical security most often goes wrong. George and Jack draw upon their extensive combined experience of helping organisations strengthen their information security to discuss:

    • Whether organisations are underestimating the importance of physical security in favour of focusing on cyber threats
    • How hybrid working, flexible offices, and remote employees have changed what ‘physical security’ actually means
    • The most surprising physical security weakness they’ve encountered that could have led to a major information security breach
    • Which physical security controls most organisations think is effective, but in reality provide little more than a false sense of security
    • The top three physical controls they would implement in an organisation with a limited budget and why.

    Ask Jack and George a question: https://urmconsulting.com/podcasts/physical-security-controls

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    

    Brought to you by URM, the UK’s leading information and cyber security specialists.

    Afficher plus Afficher moins
    25 min
  • PCI DSS Periodic Activities
    Aug 6 2026

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

    • Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
    • The common mistakes they see organisations make when defining their own frequencies
    • Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
    • How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
    • How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
    • How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
    • And more.

    Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

    You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        

     Connect with us on LinkedIn

     Brought to you by URM, the UK’s leading information and cyber security specialists.   

    Afficher plus Afficher moins
    37 min
  • GDPR Cookies Compliance
    Jul 30 2026

    In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down cookies compliance under the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulations (PECR). Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:

    • Why cookies are so important to businesses commercially
    • What the law actually requires when using cookies
    • How businesses get cookie compliance wrong in practice
    • Where consent or pay fits in
    • What good compliance actually looks like.

    Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/gdpr-cookies-compliance       

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       

    Connect with us on LinkedIn 

    Brought to you by URM, the UK’s leading information and cyber security specialists.     

    Afficher plus Afficher moins
    38 min
  • Clause 10.2 of ISO 27001: Nonconformity and Corrective Action
    Jul 23 2026

    In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them. Neil leverages over 20 years of experience working with risk and information security-related standards to discuss:

    • What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS)
    • What nonconformities are, and the difference between major and minor nonconformities
    • The requirements of Clause 10.2 and how organisations can implement them in practice
    • Common mistakes to avoid when addressing Clause 10.2.

    Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts

    Brought to you by URM, the UK’s leading information and cyber security specialists.    

    Afficher plus Afficher moins
    11 min
  • PCI DSS Scoping
    Jul 16 2026

    In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:    

    • When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
    • Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
    • Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
    • Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
    • How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
    • And more.

    Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping     

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        

    You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        

    Connect with us on LinkedIn

    Brought to you by URM, the UK’s leading information and cyber security specialists.   

    Afficher plus Afficher moins
    36 min
  • Establishing Control Over AI Usage
    Jul 9 2026

    In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations. Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:

    • Why organisations should be paying attention to AI right now
    • The most common ways organisations are already using AI
    • The most significant AI-related risks they currently see
    • How organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuse
    • The top three AI controls and measures all organisations should have in place.

    Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider    

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts           

    Brought to you by URM, the UK’s leading information and cyber security specialists.

    Afficher plus Afficher moins
    28 min
  • Next 12 Months in Privacy
    Jul 2 2026

    In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, consider emerging trends in the field of data protection and privacy, and the practical implications for organisations that need to maintain compliance. Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:

    • What they think will define privacy risk over the next 12 months
    • Why artificial intelligence (AI) will continue to expose weak data protection practices
    • The privacy issues that are most likely to grow fastest in practice
    • Where regulators are most likely to focus next
    • The steps organisations should take now to prepare for the next wave of scrutiny and enforcement.

    You can register for the STAIRs webinar or watch the recording on URM’s website: https://www.urmconsulting.com/event/stairs-webinar-are-you-ready Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/next-12-months-in-privacy

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider

    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts

    Connect with us on LinkedIn       

    Brought to you by URM, the UK’s leading information and cyber security specialists.  

    Afficher plus Afficher moins
    33 min
  • PCI DSS and Service Providers
    Jun 25 2026

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore some of the most misunderstood areas of PCI DSS scoping, focusing on service providers, merchants, and complex modern payment architectures. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:

    • When an organisation stops being “just a merchant” and becomes a PCI DSS service provider, and what really drives that distinction
    • How an organisation can be both a merchant and a service provider at the same time, and how this should be handled during a PCI DSS assessment
    • The most common mistakes organisations make when deciding how they should be classified for PCI DSS purposes
    • Whether companies providing payment-enabled platforms, but not directly handling PAN, can still fall under the definition of a service provider
    • The responsibilities that remain when a third-party platform hosts the payment page but payment fields are served directly by a provider
    • And more.

    Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-service-providers

    If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

    You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts       

     Connect with us on LinkedIn     

     Brought to you by URM, the UK’s leading information and cyber security specialists.   

    Afficher plus Afficher moins
    38 min