Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
History
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts221/v4/18/45/7a/18457a4b-f209-b3c9-110a-162655667c69/mza_7186689619902158809.png/600x600bb.jpg
InfoSec Insider
URM Consulting
66 episodes
3 weeks ago
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Show more...
Management
Technology,
Business
RSS
All content for InfoSec Insider is the property of URM Consulting and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Show more...
Management
Technology,
Business
Episodes (20/66)
InfoSec Insider
PCI DSS: Standards vs. Reality
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore the theory versus the reality of compliance with the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  Whether it would be cheaper to simply pay the fines instead of being PCI DSS compliant How often they see organisations treat PCI as a one-time project versus an ongoing programme The possibility of still suffering a breach while being fully compliant, and whether this has happened in the past The PCI requirements organisations struggle with most in practice How smaller merchants can cope with PCI requirements that were designed with larger organisations in mind The areas where PCI DSS lags behind current security threats And more. Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-standards-vs-reality If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts       Connect with us on LinkedIn       Brought to you by URM, the UK’s leading information and cyber security specialists.   
Show more...
3 weeks ago
33 minutes

InfoSec Insider
Clearview AI Case
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Consultant at URM, breaks down the Upper Tribunal’s recent decision to uphold the ICO’s appeal in the Clearview AI case, sharing his insights on the meaning and impact of this development.  Stuart draws upon over 25 years of specialisation in data protection law to discuss: The Clearview AI case and how it has developed since the ICO’s 2022 decision to impose a £7.5m fine on Clearview The Upper Tribunal’s ruling and how it has clarified the territorial scope of the GDPR, as well as the limits of the Regulation’s Article 2 exemption for law enforcement Why the enforcement limitations of the GDPR mean this ruling may not be as significant a win for the ICO as it initially seems A potential legal challenge to Clearview from well-known data protection activist Max Shrems, potentially signalling hope on the horizon for this case. Learn more about this topic: https://www.urmconsulting.com/blog/icos-appeal-in-clearview-ai-case-upheld If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
4 weeks ago
14 minutes

InfoSec Insider
ISO 27001 - Clause 5.1 Leadership and Commitment Explained
In this episode of InfoSec Insider, Frazer Grudings, Senior Consultant at URM, shares his insights on Clause 5.1 of ISO 27001, which covers the leadership and commitment requirements for an information security management system (ISMS) that is conformant to the Standard.  Frazer draws upon over 15 years of information security experience to discuss: The requirements of Clause 5.1 and what conformance to this Clause involves Why leadership and commitment matter to an ISMS What can go wrong when leadership and commitment are not demonstrated. Learn more about this topic:  https://www.urmconsulting.com/blog/iso-27001-clause-5-1-leadership-and-commitment-explained If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts    Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
1 month ago
17 minutes

InfoSec Insider
PCI DSS – The Overlooked Systems
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer their advice on the systems and controls that are often overlooked in relation to the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  Why the PCI DSS covers systems that don’t store card data, such as DNS servers or time servers Why time synchronisation (NTP servers) is a PCI requirement How card data can leak through system logs and how this can be avoided Printers, custom error messages, IoT devices – why they’re in scope and how to maintain compliance. Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-the-overlooked-systems   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Connect with us on LinkedIn       Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
1 month ago
27 minutes

InfoSec Insider
Data Protection Rights
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, explore individuals’ rights under the GDPR beyond the right of access (the most widely discussed of the data subject rights), and the requirements and obligations on organisations handling these.  Rachael and Aimee draw upon over 20 years’ combined experience in data protection to discuss: The data rights aside from the right of access that tend to unexpectedly consume business resources and why The operational risks posed to small and medium-sized enterprises (SMEs) by rights such as erasure, rectification, restriction, portability, and objection How SMEs can recognise success in handling these rights without drowning in process complexity The common pitfalls that cause unnecessary challenges or regulatory difficulties when dealing with these rights How, in real-world terms, businesses can balance customer empowerment through data rights with maintaining smooth, cost-effective operations. Ask Rachael and Aimee a question. If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts      Connect with us on LinkedIn  Brought to you by URM, the UK’s leading information and cyber security specialists.   
Show more...
1 month ago
42 minutes

InfoSec Insider
7 Top Tips for Communicating in a Crisis
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, shares his top tips on crisis communication, considering the steps organisations can take to prepare before a crisis occurs, while it is happening, and after it’s been dealt with to ensure communication is as effective and seamless as possible.  Martin draws upon his extensive experience helping organisations enhance their business continuity to discuss: What a ‘crisis’ is What crisis communication is and how it fits into business continuity planning Why crisis communications matter 7 top tips on ensuring your organisation can communicate effectively in a crisis, such as planning ahead of time, setting the right tone, listening to feedback, and more. Learn more about this topic: https://www.urmconsulting.com/blog/the-eu-artificial-intelligence-act If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
1 month ago
12 minutes

InfoSec Insider
Building Cyber Security Resilience Against Phishing
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights into phishing and what organisations can do to protect themselves against it.  George draws upon his extensive experience helping organisations strengthen their cyber security to discuss: What phishing is and the various forms it takes How phishing achieves its goal by influencing behaviour, and how artificial intelligence (AI) impacts this The steps organisations can take to protect themselves against phishing. Learn more about this topic: https://www.urmconsulting.com/blog/building-cyber-security-resilience-against-phishing If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
2 months ago
24 minutes

InfoSec Insider
ISO 27001 People Controls
In this episode of InfoSec Insider, Jack Woods and Mark O’Kane, both Consultants at URM, take a deep dive on the ‘People’ controls theme in ISO 27001, and why these controls matter in today’s hybrid workplaces, how they strengthen information security, and what auditors look for during assessments.  Jack and Mark draw upon their extensive experience supporting organisations’ implementation of the Standard to discuss: How to balance the risk of potential insider threats against the downsides of overzealous background checks when implementing pre-employment screening The practical steps you can take to meaningfully enforce people controls beyond generic policies in the context of remote and hybrid work environments How to ensure incident reporting for information security is both mandatory and non-punitive, so employees feel safe to report without fear of reprisal The types of evidence auditors expect to see in a people controls-focused audit The risks that arise when people controls such as training or NDAs are not routinely reviewed/updated as working patterns or staff roles evolve. Ask Jack and Mark a question: https://urmconsulting.com/podcasts/iso-27001-people-controls If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      Connect with us on LinkedIn      Brought to you by URM, the UK’s leading information and cyber security specialists.
Show more...
2 months ago
36 minutes

InfoSec Insider
AIIAs in ISO 42001
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, explores artificial intelligence impact assessments (AIIAs), a key conformance activity required by ISO 42001, the International Standard for AI Management Systems (AIMS).  Neil leverages over 20 years of experience working with risk and information security-related standards to discuss: What an AIIA is under ISO 42001, and how it differs from a typical risk assessment The role of ISO 42005 and how it relates to AIIAs The seven sections of an AIIA and what each section covers When in the AI lifecycle you need to conduct an AIIA How organisations should balance AIIAs with risk assessments in the context of ISO 42001. Learn more about this topic: https://www.urmconsulting.com/blog/iso-42001-artificial-intelligence-impact-assessments-aiias If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
2 months ago
8 minutes

InfoSec Insider
The People Side of PCI DSS
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer advice on compliance with the Payment Card Industry Data Security Standard (PCI DSS), with a particular focus on the ‘human’ element of security.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: How you can minimise the risk of noncompliance caused by human error or behaviour The compliance complications associated with using wireless devices such as Bluetooth headphones Whether ‘pause-and-resume’ recording in call centres is truly secure How to avoid card data leaking through CCTV cameras in environments such as call centres And more! Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/ the-people-side-of-pci-dss If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:     https://urmconsulting.com/podcasts    Connect with us on LinkedIn    Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
2 months ago
29 minutes

InfoSec Insider
DSARs: A Business Burden vs. a Data Protection Opportunity
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Data Protection Consultants at URM, provide their insights on overcoming data subject access request (DSAR) challenges and how organisations can gain benefits from the fulfilment of DSARs, rather than treating them purely as a business burden.   Rachael and Aimee leverage over 20 years’ combined experience in data protection to discuss: • Whether DSARs can actually enhance customer trust, or are simply a compliance checkbox exercise for organisations• How organisations can reframe DSAR handling as an opportunity to improve their data governance • The hidden costs of DSARs and how you can measure whether those costs bring any tangible benefits• When it is appropriate to push back on a DSAR as ‘manifestly unfounded’ or ‘excessive’ and how to defend this decision to the regulator• How to proactively use DSAR data to inform your privacy strategy and customer engagement.  Ask Rachael and Aimee a question:  https://urmconsulting.com/podcasts/dsars-a-business-burden-vs-a-data-protection-opportunity If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    Connect with us on LinkedIn    Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
3 months ago
24 minutes

InfoSec Insider
Establishing Organisational Control Over AI
In this episode of InfoSec Insider, George Ryan, Consultant at URM, provides key advice and guidance on the impact of artificial intelligence (AI) on organisations, and the steps they can take to establish control over its usage.  George leverages his extensive experience helping organisations strengthen their information and cyber security to discuss:   What ‘AI’ is   How AI and its usage can impact organisations  How organisations can look to control AI among its staff and within its operations.  Learn more about this topic: https://www.urmconsulting.com/blog/establishing-organisational-control-over-artificial-intelligence  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider         You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts         Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
3 months ago
17 minutes

InfoSec Insider
The EU AI Act
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, explores the EU Artificial Intelligence (AI) Act, the world’s first comprehensive regulation on AI by a major regulator.  Maritn draws upon over 20 years of experience in compliance, information management and data protection to discuss: What AI is and how it is defined by the EU AI Act Which entities the Act is applicable to, the different ‘compliance roles’ it defines and the obligations associated with each How AI risk is categorised, and the provisions for and restrictions upon each risk level How the AI Act will be enforced The current UK approach to AI legislation and the impact of the AI Act beyond the EU. Learn more about this topic: https://www.urmconsulting.com/blog/the-eu-artificial-intelligence-act If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider        You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
3 months ago
24 minutes

InfoSec Insider
The ISO 27001 Certification Process
In this episode of InfoSec Insider, Scott Lloyd, Senior Consultant at URM, offers key advice and guidance on the ISO 27001 certification process, how organisations can ensure they are prepared for a smooth and successful certification assessment.  Scott leverages his extensive experience in the field of information security to discuss: Common misconceptions about certification The ‘must-have’ documentation organisations need to have in place ready for their Stage 1 audit The Stage 2 audit, the difference between minor and major nonconformities and how they affect certification How organisations should handle minor nonconformities so that they do not become majors in the future The 3-year certification cycle and Continual Assessment Visits (CAVs) Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-how-certification-works   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
3 months ago
11 minutes

InfoSec Insider
Defending Against Ransomware Attacks
In this episode of InfoSec Insider – Talk Cyber, George Ryan, consultant at URM, provides his insights on the steps organisations can take to protect themselves against ransomware attacks.  George leverages his extensive experience helping organisations strengthen cyber security measures to discuss: What ransomware is and why it has so frequently made headlines in recent years Who is responsible for protecting an organisation against ransomware The role of people, processes and technology in enhancing ransomware defences Which measures organisations with minimal or no cyber security should prioritise. Learn more about this topic: https://www.urmconsulting.com/blog/critical-cyber-security-practices-to-defend-against-ransomware-attacks If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.       
Show more...
4 months ago
12 minutes

InfoSec Insider
Getting Ready for STAIRs
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, breaks down the Social Tenants Access to Information Requirements (STAIRs), a forthcoming information access standard that will give greater rights to tenants of private registered providers (PRPs).  Martin leverages over 20 years of information management and data protection experience to discuss: What the STAIRs are and how they came about What PRPs will need to do to comply with the STAIRs The steps organisations can take now to prepare for STAIRs compliance.  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://www.urmconsulting.com/blog/getting-ready-for-the-social-tenant-access-to-information-requirements-stairs You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.
Show more...
4 months ago
16 minutes

InfoSec Insider
ISO 27001 Annex A Business Continuity Controls
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, provides key advice and guidance on the two business continuity-related controls in Annex A of ISO 27001.  Mark draws upon his extensive experience helping organisations implement and certify against the Standard to discuss: The requirements of the business continuity controls and how they help organisations security their assets during a disruption How organisations can meet the requirements of and ensure conformance to Controls A.5.29 and A.5.30 The common mistakes organisations make when implementing and maintaining these controls, and how these mistakes can be avoided. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-business-continuity If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
5 months ago
12 minutes 40 seconds

InfoSec Insider
Supplementing Cyber Essentials
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights on the best next steps organisations can take following Cyber Essentials certification to further enhance their security.  George leverages his extensive experience assisting organisations to strengthen their cyber security measures to discuss:   What is covered by the Cyber Essentials scheme The more advanced cyber and information security frameworks organisations can implement having achieved Cyber Essentials How organisations can enhance their cyber and information security without implementing additional frameworks. Learn more about this topic: https://www.urmconsulting.com/blog/supplementing-cyber-essentials If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.     
Show more...
5 months ago
17 minutes 34 seconds

InfoSec Insider
Incident Management Controls in ISO 27001
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights and advice on the six incident management-related controls in Annex A of ISO 27001, which are contained within the ‘Organisational’ and ‘People’ control themes.  Mark leverages his extensive experience supporting organisations to implement ISO 27001 to discuss: The requirements of the incident management controls and how they fit into the overall aim of the ‘Organisational’ and ‘People’ control themes How the incident management controls help organisations address information security incidents How organisations can effectively put these controls into practice. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-incident-management If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts    Connect with us on LinkedIn  Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
5 months ago
13 minutes

InfoSec Insider
The DUA Act
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides his insights on the Data (Use and Access) Act, which received Royal Assent on 19 June.  Stuart draws upon over 25 years of specialisation in data protection law to discuss: The background, scope, and intention of the DUA Act How the DUA Act is expected to impact the UK’s data protection regulatory landscape, and how it may lighten the compliance burden on organisations, particularly in relation to: Automated decision-making International transfers of personal data Data subject access requests (DSARs) The Privacy and Electronic Communications Regulations (PECR) The ‘legitimate interests’ basis for processing Which provisions in the Act may make data protection compliance more difficult When these changes are likely to come into force. Learn more about this topic: https://www.urmconsulting.com/blog/dua-act-finally-becomes-law If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
5 months ago
32 minutes 6 seconds

InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.