InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Episodes

6 hours ago
6 hours ago
31 min
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, examine one of the most frequently misunderstood areas of PCI DSS: the difference between compensating controls and the customised approach. Drawing on their extensive PCI DSS assessment experience, they discuss:
The key differences between compensating controls and customised approaches, and the specific scenarios where each can be used
Why compensating controls are not a “get out of jail free” card for non-compliance and the strict conditions that must be met before they can be applied
The legal, regulatory, technical, and financial constraints that may justify the use of compensating controls
How customised approaches were introduced in PCI DSS v4.0 to support innovative and non-traditional methods of meeting security objectives
Why customised validations require significant planning, documentation, evidence collection, and assessor involvement before they can be approved
And more.
If there's a PCI DSS related issue you'd like us to explore, share it with us here here: https://urmconsulting.com/podcasts/pci-dss-compensating-controls-vs-customized-approach
We use listener questions to guide future discussions and ensure our episodes tackle the challenges that matter most to organisations like yours.You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.

Sep 3, 2026
Sep 3, 2026
40 min
InfoSec Insider Podcast - Season 3, Episode 1 (101)
Benefits of Business Continuity Exercising
In this episode of InfoSec Insider – Talk BC, Phil Knight, Senior Consultant at URM, explores exercising of business continuity plans, and the benefits this can provide to organisations. Phil draws upon his extensive experience supporting organisations to strengthen their business continuity arrangements and resilience to discuss:
What business continuity exercising is
ISO 22301 (the best practice standard for BC management), the business continuity lifecycle and where exercising fits into these
The benefits that exercising can provide to organisations
The consequences or costs of not performing exercises.
Learn more about this topic: https://www.urmconsulting.com/blog/business-continuity-exercising
5 Business Continuity Must‑Dos to Strengthen Your Organisation’s Resilience webinar: https://www.urmconsulting.com/event/5-business-continuity-must-dos-to-strengthen-your-organisations-resilience
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Aug 27, 2026
Aug 27, 2026
45 min
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, share their insights on how to effectively manage the immediate aftermath of a personal data breach. Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:
What actually counts as a data breach and when it needs to be reported to the Information Commissioner’s Office (ICO)
How organisations can assess risk and decide whether affected individuals need to be told
The biggest mistakes organisations make in the first few days following a data breach
How ransomware attacks, supplier incidents, and modern technology are changing breach management
The practical steps organisations can take now to prepare for a breach and demonstrate accountability afterwards.
Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/the-first-72-hours-managing-data-breaches
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.

Aug 20, 2026
Aug 20, 2026
36 min
In this episode of InfoSec Insider – Talk Cyber, Jamie Leavers, Security Consultant at URM, and Lauren Gotting, New Business Director at URM, share real-world lessons learned from conducting hundreds of CE and CE+ assessments, including early assessments against the new Danzell requirements. Jamie and Lauren leverage their extensive experience with the Cyber Essentials scheme to discuss:
Lessons from real CE/CE+ assessments, what assessors are seeing in practice, and what separates successful submissions from failed ones
The Danzell Question Set and key changes introduced in 2026 and how they impact both new applicants and recertifying organisations
How to prepare for certification or recertification, including ractical guidance to ensure your evidence, scope and controls meet assessor expectations.
The common issues and pitfalls most frequently causing delays or failures and how to avoid them entirely.
Learn more about URM’s webinar programme: https://www.urmconsulting.com/events/upcoming-events
Contact webinars@urmconsulting.com for this webinar’s slide deck.
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Aug 13, 2026
Aug 13, 2026
25 min
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide expert advice and guidance on how organisations can maintain the physical security of their information, and where physical security most often goes wrong. George and Jack draw upon their extensive combined experience of helping organisations strengthen their information security to discuss:
Whether organisations are underestimating the importance of physical security in favour of focusing on cyber threats
How hybrid working, flexible offices, and remote employees have changed what ‘physical security’ actually means
The most surprising physical security weakness they’ve encountered that could have led to a major information security breach
Which physical security controls most organisations think is effective, but in reality provide little more than a false sense of security
The top three physical controls they would implement in an organisation with a limited budget and why.
Ask Jack and George a question: https://urmconsulting.com/podcasts/physical-security-controls
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Aug 6, 2026
Aug 6, 2026
37 min
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
The common mistakes they see organisations make when defining their own frequencies
Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
And more.
Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.

Jul 30, 2026
Jul 30, 2026
37 min
In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down cookies compliance under the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulations (PECR). Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:
Why cookies are so important to businesses commercially
What the law actually requires when using cookies
How businesses get cookie compliance wrong in practice
Where consent or pay fits in
What good compliance actually looks like.
Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/gdpr-cookies-compliance
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.

Jul 23, 2026
Jul 23, 2026
11 min
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them. Neil leverages over 20 years of experience working with risk and information security-related standards to discuss:
What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS)
What nonconformities are, and the difference between major and minor nonconformities
The requirements of Clause 10.2 and how organisations can implement them in practice
Common mistakes to avoid when addressing Clause 10.2.
Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Jul 16, 2026
Jul 16, 2026
36 min
In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
And more.
Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.

Jul 9, 2026
Jul 9, 2026
27 min
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations. Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:
Why organisations should be paying attention to AI right now
The most common ways organisations are already using AI
The most significant AI-related risks they currently see
How organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuse
The top three AI controls and measures all organisations should have in place.
Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.






