InfoSec Insider

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

Episodes

8 hours ago

11 min

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them.  Neil leverages over 20 years of experience working with risk and information security-related standards to discuss: 
What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS)
What nonconformities are, and the difference between major and minor nonconformities
The requirements of Clause 10.2 and how organisations can implement them in practice
Common mistakes to avoid when addressing Clause 10.2.
Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts 
Brought to you by URM, the UK’s leading information and cyber security specialists.     

PCI DSS Scoping

Jul 16, 2026

Jul 16, 2026

36 min

In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:     
When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made
Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment
Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping
Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope
How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping
And more.
Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping        
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         
You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts         
Connect with us on LinkedIn 
Brought to you by URM, the UK’s leading information and cyber security specialists.   

Jul 9, 2026

27 min

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations.  Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:
Why organisations should be paying attention to AI right now
The most common ways organisations are already using AI
The most significant AI-related risks they currently see
How organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuse
The top three AI controls and measures all organisations should have in place.
Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             
Brought to you by URM, the UK’s leading information and cyber security specialists.

Jul 2, 2026

32 min

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, consider emerging trends in the field of data protection and privacy, and the practical implications for organisations that need to maintain compliance.  Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:
What they think will define privacy risk over the next 12 months
Why artificial intelligence (AI) will continue to expose weak data protection practices
The privacy issues that are most likely to grow fastest in practice
Where regulators are most likely to focus next
The steps organisations should take now to prepare for the next wave of scrutiny and enforcement.
You can register for the STAIRs webinar or watch the recording on URM’s website: https://www.urmconsulting.com/event/stairs-webinar-are-you-readyAsk Rachael and Aimee a question: https://urmconsulting.com/podcasts/next-12-months-in-privacy
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn       
Brought to you by URM, the UK’s leading information and cyber security specialists.  

Jun 25, 2026

38 min

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore some of the most misunderstood areas of PCI DSS scoping, focusing on service providers, merchants, and complex modern payment architectures. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
When an organisation stops being “just a merchant” and becomes a PCI DSS service provider, and what really drives that distinction
How an organisation can be both a merchant and a service provider at the same time, and how this should be handled during a PCI DSS assessment
The most common mistakes organisations make when deciding how they should be classified for PCI DSS purposes
Whether companies providing payment-enabled platforms, but not directly handling PAN, can still fall under the definition of a service provider
The responsibilities that remain when a third-party platform hosts the payment page but payment fields are served directly by a provider
And more.
Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-service-providers
 
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        
You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      
 Connect with us on LinkedIn    
 Brought to you by URM, the UK’s leading information and cyber security specialists.   

Jun 18, 2026

36 min

In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, answer some of the niche and unusual questions around governance, risk and compliance (GRC).  Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss: • The key questions clients rarely ask despite being extremely important• Whether a policy is enough on its own• The security policies that are most frequently not followed in practice• How to avoid prioritising compliance over genuine security• The easiest ways to establish whether a control is effective• How to achieve buy-in from executives on managing and mitigating risks before they materialise. Ask Jack and George a question:  https://urmconsulting.com/podcasts/unusual-grc-questions            
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider            
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts          
Brought to you by URM, the UK’s leading information and cyber security specialists.       

Jun 11, 2026

42 min

In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, answer key, real-world questions around data protection and how organisations can stay compliant.  Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:
When data is genuinely anonymous, and how easy it is to lose that status
Whether things like voice, handwriting, CCTV, emojis, avatars and internal gossip really count as personal data
How employee use of smart glassed and always-on devices can affect organisations and why it matters
Why redaction still goes wrong so often
Why consent remains one of the single most understood aspects of data protection.
Ask Rachael and Aimee a question: https://www.urmconsulting.com/podcasts/real-world-data-protection-questions
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider       
You can find more episodes of InfoSec Insider here:     https://urmconsulting.com/podcasts       
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.    

Jun 4, 2026

35 min

In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a business perspective.  Chris and Wayne draw upon their combined 45 years of experience in information security and risk management to discuss:
What good, risk-based decision-making actually looks like in practice, and where it most commonly breaks down
The most concerning information security risks of today that do not get enough attention at the board or executive level
How organisations can move away from checklist-driven compliance and towards meaningful cyber risk management that supports business objectives
How organisations should rethink ownership and accountability for information security risk in light of growing dependence on cloud services and third-party providers
The capability or mindset they believe information security leaders must develop now to remain effective risk advisers in the coming years.
Ask Wayne and Chris a question:  https://urmconsulting.com/podcasts/business-approaches-to-risk-management
            
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider 
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             
Brought to you by URM, the UK’s leading information and cyber security specialists.        

May 28, 2026

24 min

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment Card Industry Data Security Standard (PCI DSS) compliance.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:    
What ‘severless’ actually means in a PCI DSS context, and how this differs from how it is usually described by cloud providers
What QSAs look for when deciding whether a severless system falls within PCI scope
How the balance of responsibilities shifts when an organisation moves from traditional cloud services to severless, and where this causes the most confusion during assessments
The parts of a severless setup that tend to bring cardholder data into scope unexpectedly and how to ensure you understand the way information moves through your systems
How to handle PCI requirements for logs, monitoring and keeping evidence when the systems they rely on disappear almost instantly
Maintaining compliant access control and control over changes to your systems in a severless context
How to check for weaknesses in severless systems, the risks tied to the external code and libraries that are often used inside serverless functions
And more.
Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-severless-architecture
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        
You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      
 Connect with us on LinkedIn 
 Brought to you by URM, the UK’s leading information and cyber security specialists.   

May 21, 2026

30 min

In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down the data protection compliance issues that arise from the use of bring your own device (BYOD) within organisations, and how these can be overcome.  Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:
Why BYOD has become so common, and why it still catches organisations out
Where legal and regulatory risks arise with BYOD
How BYOD increases data subject access request (DSAR), breach, and dispute risk
What a proportionate, people-aware approach to BYOD looks like
How regulators and insurers are likely to view BYOD going forward.
Ask Rachael and Aimee a question:
https://www.urmconsulting.com/podcasts/gdpr-compliance-and-byod
 
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider        
 
You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        
 
Connect with us on LinkedIn 
 
Brought to you by URM, the UK’s leading information and cyber security specialists.     
 

Copyright 2024 URM Consulting. All rights reserved.

Podcast Powered By Podbean

Version: 20241125