InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Episodes

Thursday Mar 20, 2025
Thursday Mar 20, 2025
In this episode of InfoSec Insider, Alastair Stewart, Senior Consultant and Qualified Security Assessor (QSA) at URM, provides key advice and guidance on the steps organisations can take to streamline and reduce their Payment Card Industry Data Security Standard (PCI DSS) scope. Alastair leverages more than a decade of experience with the PCI DSS to discuss:
What the PCI DSS defines as ‘in scope’, what system components are and how you can assess the scope of individual systems
The benefits of reducing your scope
How you can go about reducing your scope, including a comprehensive breakdown of the different scope reduction methods available to you, including segmentation, encryption, outsourcing, and more.
Learn more about this topic: https://www.urmconsulting.com/blog/5-ways-to-reduce-your-pci-dss-scope
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Mar 13, 2025
Thursday Mar 13, 2025
In this episode of InfoSec Insider – Talk Cyber, Stuart Skelly, Senior Consultant at URM, explains a recently announced consultation by the UK government into proposals by the Home Office, which would increase its control and visibility of ransomware attacks on organisations operating in the UK. Stuart leverages his extensive legal background and experience as a governance, risk and compliance consultant to discuss:
What is meant by ransomware and a ransomware cyber attack
The Home Office’s proposals – what they are and which organisations they would affect if they come into force
The complications and challenges these proposals could create
How interested organisations can send a response to the Home Office.
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Mar 06, 2025
Thursday Mar 06, 2025
In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, offers key insights on ISO 27001’s supplementary guidance standard, ISO 27002, which provides guidance on implementation of the ISO 27001 Annex A controls. Frazer leverages his 15+ years of experience to discuss:
What ISO 27002 is
The ‘attributes’ framework in ISO 27002 and the purpose of this framework
The different ways ISO 27002 can be used.
Learn more about this topic: https://www.urmconsulting.com/blog/iso-27002-the-unsung-hero
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here:
https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Feb 27, 2025
Thursday Feb 27, 2025
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, explains the importance of data protection for building and maintaining customer trust, and offers key advice on how to ensure that your data processing practices will help facilitate strong relationships with your customer base. Martin leverages his 20+ years of experience in information management and data protection compliance to discuss:
Why customers are now more likely to care about how businesses take care of their data
How to embed transparency and privacy into your organisation’s processing
The importance of making customers feel that they have some control over how their personal data is processed
The types of personal data customers value the most and the least, and the usages of their personal data (e.g., data resale, targeted marketing, etc.) that they do and do not trust.
Learn more about this topic:
https://www.urmconsulting.com/blog/how-to-build-customer-trust-and-loyalty-through-data-protection-best-practice
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Feb 20, 2025
Thursday Feb 20, 2025
In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, offers key advice and guidance on creating an information security policy that meets the requirements of ISO 27001, the International Standard for Information Security Management Systems (ISMS’). Frazer leverages his 15+ years of experience supporting organisations to certify against ISO 27001 to discuss:
What an information security policy is in the context of ISO 27001
How to develop an information security policy and what it should include in order to be conformant to the Standard
The purpose of an information security policy.
Learn more about this topic: https://www.urmconsulting.com/blog/developing-an-iso-27001-information-security-policy
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here:
https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Feb 13, 2025
Thursday Feb 13, 2025
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Consultant at URM, provides a break down and analysis of how the Information Commissioner’s Office (ICO’s) has enforced UK data protection (DP) regulations in 2024, and how this compares to the action taken by the regulator in previous years. Stuart leverages his 25+ years of specialisation in data protection law to discuss:
The types of enforcement action available to the ICO (i.e., reprimands, enforcement notices and fines) and how they differ
How the regulator has enforced the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulation (PECR) in 2024, in terms of:
Its approach to fining public vs. private sector organisations, with examples of notable public sector fines imposed this year
The differences in its approach to enforcing the GDPR vs. the PECR
How the regulator’s enforcement activities compare to the action taken in 2023
The sums of money involved in ICO fines, i.e., the average figure imposed by the ICO in 2024 and how much the ICO brought in for the Treasury this year
How the ICO’s approach to enforcing DP law compares to other, European DP regulators
Emerging trends and upcoming changes, such as the ICO’s crackdown on cookies compliance.
Learn more about this topic: https://www.urmconsulting.com/blog/analysis-of-fines-imposed-by-the-information-commissioners-office-in-2024
If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Feb 06, 2025
Thursday Feb 06, 2025
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, takes a deep dive into the unique cyber security challenges faced by small and medium-sized enterprises (SMEs), and the steps these organisations can take to improve their cyber security postures. George leverages his extensive experience assisting organisations to enhance their cyber security to discuss:
The current state of the cyber security landscape for SMEs and how this differs to their larger counterparts
The issues SMEs are currently facing in addressing and enhancing their cyber security postures
How SMEs can improve their cyber security.
Learn more about this topic: https://www.urmconsulting.com/blog/cyber-essentials-improving-your-cyber-security-as-an-sme
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Jan 30, 2025
Thursday Jan 30, 2025
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, shares some of his top tips for implementing an information security management system (ISMS) that is both conformant to the requirements of ISO 27001 and effectively enhances an organisation’s information security culture. Wayne draws upon his 30+ years of experience in information security and risk management to discuss:
The role of top management in the success of an ISMS implementation project
The approach you should take when creating policies and procedures for an ISMS
How to encourage employees to take ownership of information security as part of their day-to-day responsibilities
The importance of a clear risk assessment, engaging all levels of the organisation from the outset, and of building information security into business processes.
Learn more about this topic: https://www.urmconsulting.com/blog/top-tips-for-implementing-an-effective-iso-27001-conformant-isms
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Jan 23, 2025
Thursday Jan 23, 2025
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, a Senior GRC Consultant at URM, breaks down the Social Tenant Access to Information Requirements (STAIRs), an upcoming standard with which private registered providers (PRPs) of social housing (such as housing associations) will need to comply. Stuart leverages his 25+ years of specialisation in data protection law to discuss:
What STAIRs is and the issues it has been designed to address
The rights that STAIRs will provide to tenants living in private sector-run social housing, and the types of information requests it is likely to be used for
How STAIRs compares to the Freedom of Information Act (FOIA) and to the General Data Protection Regulation’s (GDPR’s) provisions on data subject access requests (DSARs)
What comes next for STAIRs.
Learn more about this topic:
https://www.urmconsulting.com/blog/stairs-a-new-standard-for-social-housing-providers
If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.

Thursday Jan 16, 2025
Thursday Jan 16, 2025
In this episode of InfoSec Insider, Chris Heighes, Senior Consultant at URM, takes a deep dive into the Digital Operations Resilience Act (DORA), a new EU regulation for financial entities and their key suppliers to improve their digital operational resilience, which comes into force on 17 January 2025. Chris Leverages his 30 years of IT experience and 15 years’ experience in information security to discuss:
What DORA is
Which entities are in scope of the Act
How DORA’s requirements differ from those of ISO 27001, the International Standard for Information Security Management Systems (ISMS)
The timelines for implementation of DORA and how it will be enforced.
Learn more about this topic: https://www.urmconsulting.com/blog/the-digital-operations-resilience-act-dora
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.