Home
Categories
EXPLORE
True Crime
Comedy
Business
Society & Culture
Sports
Health & Fitness
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
Loading...
0:00 / 0:00
Podjoint Logo
US
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts221/v4/18/45/7a/18457a4b-f209-b3c9-110a-162655667c69/mza_7186689619902158809.png/600x600bb.jpg
InfoSec Insider
URM Consulting
55 episodes
2 days ago
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Show more...
Management
Technology,
Business
RSS
All content for InfoSec Insider is the property of URM Consulting and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
Show more...
Management
Technology,
Business
Episodes (20/55)
InfoSec Insider
Establishing Organisational Control Over AI
In this episode of InfoSec Insider, George Ryan, Consultant at URM, provides key advice and guidance on the impact of artificial intelligence (AI) on organisations, and the steps they can take to establish control over its usage.  George leverages his extensive experience helping organisations strengthen their information and cyber security to discuss:   What ‘AI’ is   How AI and its usage can impact organisations  How organisations can look to control AI among its staff and within its operations.  Learn more about this topic: https://www.urmconsulting.com/blog/establishing-organisational-control-over-artificial-intelligence  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider         You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts         Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
2 days ago
17 minutes

InfoSec Insider
The EU AI Act
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, explores the EU Artificial Intelligence (AI) Act, the world’s first comprehensive regulation on AI by a major regulator.  Maritn draws upon over 20 years of experience in compliance, information management and data protection to discuss: What AI is and how it is defined by the EU AI Act Which entities the Act is applicable to, the different ‘compliance roles’ it defines and the obligations associated with each How AI risk is categorised, and the provisions for and restrictions upon each risk level How the AI Act will be enforced The current UK approach to AI legislation and the impact of the AI Act beyond the EU. Learn more about this topic: https://www.urmconsulting.com/blog/the-eu-artificial-intelligence-act If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider        You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts        Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
1 week ago
24 minutes

InfoSec Insider
The ISO 27001 Certification Process
In this episode of InfoSec Insider, Scott Lloyd, Senior Consultant at URM, offers key advice and guidance on the ISO 27001 certification process, how organisations can ensure they are prepared for a smooth and successful certification assessment.  Scott leverages his extensive experience in the field of information security to discuss: Common misconceptions about certification The ‘must-have’ documentation organisations need to have in place ready for their Stage 1 audit The Stage 2 audit, the difference between minor and major nonconformities and how they affect certification How organisations should handle minor nonconformities so that they do not become majors in the future The 3-year certification cycle and Continual Assessment Visits (CAVs) Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-how-certification-works   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
2 weeks ago
11 minutes

InfoSec Insider
Defending Against Ransomware Attacks
In this episode of InfoSec Insider – Talk Cyber, George Ryan, consultant at URM, provides his insights on the steps organisations can take to protect themselves against ransomware attacks.  George leverages his extensive experience helping organisations strengthen cyber security measures to discuss: What ransomware is and why it has so frequently made headlines in recent years Who is responsible for protecting an organisation against ransomware The role of people, processes and technology in enhancing ransomware defences Which measures organisations with minimal or no cyber security should prioritise. Learn more about this topic: https://www.urmconsulting.com/blog/critical-cyber-security-practices-to-defend-against-ransomware-attacks If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts       Brought to you by URM, the UK’s leading information and cyber security specialists.       
Show more...
3 weeks ago
12 minutes

InfoSec Insider
Getting Ready for STAIRs
In this episode of InfoSec Insider, Martin Brazier, Senior Consultant at URM, breaks down the Social Tenants Access to Information Requirements (STAIRs), a forthcoming information access standard that will give greater rights to tenants of private registered providers (PRPs).  Martin leverages over 20 years of information management and data protection experience to discuss: What the STAIRs are and how they came about What PRPs will need to do to comply with the STAIRs The steps organisations can take now to prepare for STAIRs compliance.  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://www.urmconsulting.com/blog/getting-ready-for-the-social-tenant-access-to-information-requirements-stairs You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.
Show more...
1 month ago
16 minutes

InfoSec Insider
ISO 27001 Annex A Business Continuity Controls
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, provides key advice and guidance on the two business continuity-related controls in Annex A of ISO 27001.  Mark draws upon his extensive experience helping organisations implement and certify against the Standard to discuss: The requirements of the business continuity controls and how they help organisations security their assets during a disruption How organisations can meet the requirements of and ensure conformance to Controls A.5.29 and A.5.30 The common mistakes organisations make when implementing and maintaining these controls, and how these mistakes can be avoided. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-business-continuity If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
1 month ago
12 minutes 40 seconds

InfoSec Insider
Supplementing Cyber Essentials
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, provides his insights on the best next steps organisations can take following Cyber Essentials certification to further enhance their security.  George leverages his extensive experience assisting organisations to strengthen their cyber security measures to discuss:   What is covered by the Cyber Essentials scheme The more advanced cyber and information security frameworks organisations can implement having achieved Cyber Essentials How organisations can enhance their cyber and information security without implementing additional frameworks. Learn more about this topic: https://www.urmconsulting.com/blog/supplementing-cyber-essentials If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.     
Show more...
2 months ago
17 minutes 34 seconds

InfoSec Insider
Incident Management Controls in ISO 27001
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights and advice on the six incident management-related controls in Annex A of ISO 27001, which are contained within the ‘Organisational’ and ‘People’ control themes.  Mark leverages his extensive experience supporting organisations to implement ISO 27001 to discuss: The requirements of the incident management controls and how they fit into the overall aim of the ‘Organisational’ and ‘People’ control themes How the incident management controls help organisations address information security incidents How organisations can effectively put these controls into practice. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-incident-management If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts    Connect with us on LinkedIn  Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
2 months ago
13 minutes

InfoSec Insider
The DUA Act
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides his insights on the Data (Use and Access) Act, which received Royal Assent on 19 June.  Stuart draws upon over 25 years of specialisation in data protection law to discuss: The background, scope, and intention of the DUA Act How the DUA Act is expected to impact the UK’s data protection regulatory landscape, and how it may lighten the compliance burden on organisations, particularly in relation to: Automated decision-making International transfers of personal data Data subject access requests (DSARs) The Privacy and Electronic Communications Regulations (PECR) The ‘legitimate interests’ basis for processing Which provisions in the Act may make data protection compliance more difficult When these changes are likely to come into force. Learn more about this topic: https://www.urmconsulting.com/blog/dua-act-finally-becomes-law If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider     You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
2 months ago
32 minutes 6 seconds

InfoSec Insider
Legal, Regulatory and Contractual Controls in ISO 27001
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights into the legal, regulatory and contractual-related controls (A.5.31-37) from Annex A of ISO 27001:2022 and how they can be effectively implemented by organisations.  Mark draws upon his extensive experience assisting organisations to certify against the Standard to discuss: The requirements of the legal, regulatory and contractual controls and how they fit into the overall aim of the ‘Organisational’ control theme How the legal controls help to prevent breaches of legal, statutory, regulatory or contractual obligations related to information security How to put controls A.5.31-37 into practice. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-legal-regulatory-and-contractual   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
2 months ago
13 minutes 28 seconds

InfoSec Insider
Lexcel, SQM and Cyber Essentials
In this episode of InfoSec Insider – Talk Cyber, George Ryan, Consultant at URM, explores the Lexcel Practice Management Standard (Lexcel), the Specialist Quality Mark (SQM) and their relationship with the Cyber Essentials scheme.  George leverages his extensive experience assisting organisations to enhance their cyber security to discuss:  What Lexcel and the SQM are, and why they are needed How these standards relate to cyber security How Cyber Essentials ties these standards, and how certification to the scheme can benefit law firms’ Lexcel/SQM compliance efforts How law firms can strengthen their security further having achieved Cyber Essentials. Learn more about this topic: https://www.urmconsulting.com/blog/understanding-lexcel-and-the-specialist-quality-mark-sqm-how-cyber-essentials-can-benefit-your-practice   If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts      Brought to you by URM, the UK’s leading information and cyber security specialists.    
Show more...
3 months ago
9 minutes 20 seconds

InfoSec Insider
ISO 27001 Information Security Management Controls
In this episode of InfoSec Insider, Mark O’Kane, Consultant at URM, offers his insights into the information security management controls within Annex A of ISO 27001, which comprise the first eight controls of Annex A’s ‘Organisational’ control theme.  Mark leverages his extensive experience supporting ISO 27001 implementations to discuss: What the organisational controls are, and how the first eight fit into the overall aim of the ‘Organisational’ control theme The role of management and senior leadership in relation to information security, and how leadership is linked to the creation of information security policies The importance of segregation of duties and clearly defined roles and responsibilities in addressing information security risk How maintaining contact with authorities, special interest groups, and threat intelligence sources can help you address both security risks that may materialise and security incidents that have occurred Common challenges and mistakes associated with implementing these controls, and how they can be overcome. Learn more about this topic:  https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-information-security-management If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider   You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts     Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
3 months ago
16 minutes 32 seconds

InfoSec Insider
ISO 27001 Access Management Controls
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, provides his insights on the 4 controls that relate to access management in the ‘Organisational’ control theme of ISO 27001’s Annex A.  Wayne leverages his 30+ of experience with information security to discuss:  The requirements of each of the following 4 controls and how your organisation can go about meeting them:  A.5.15 – Access control  A.5.16 – Identity management  A.5.17 – Authentication information  A.5.18 – Access rights.  Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-access-management  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
3 months ago
24 minutes 54 seconds

InfoSec Insider
ISO 27001 Supplier Management Controls
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the 5 supplier management-related controls in the ‘Organisational’ control theme of ISO 27001’s Annex A.  Wayne draws upon 30+ of experience with information security to discuss:  Why your organisation should consider supplier management as part of information security   What each of the following 5 controls cover and how to implement them:  A5.19 – Information security in supplier relationships  A5.20 – Addressing information security within supplier relationships  A5.21 – Managing information security in the ICT supply chain  A5.22 – Monitoring, review and change management of supplier services  A5.23 – Information security for use of cloud services.   Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-a-5-organisational-controls-supplier-management   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    Brought to you by URM, the UK’s leading information and cyber security specialists. 
Show more...
3 months ago
20 minutes 9 seconds

InfoSec Insider
Information Risk Assessment and Treatment in ISO 27001
In this episode of InfoSec Insider, Jack Woods, Consultant at URM, explores information risk assessment and risk treatment in the context of ISO 27001, the International Standard for Information Security Management Systems (ISMS’).  Jack leverages his extensive experience assisting organisations to implement an ISMS and certify to the Standard to discuss: The purpose of a risk assessment How risk fits into ISO 27001 and its requirements How to conduct an information security risk assessment The actions you can take to treat the risks you identify. Learn more about this topic:  https://www.urmconsulting.com/blog/information-risk-assessment-and-treatment-in-iso-27001 If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:   https://urmconsulting.com/podcasts    Brought to you by URM, the UK’s leading information and cyber security specialists.
Show more...
4 months ago
18 minutes 14 seconds

InfoSec Insider
Technological Controls in ISO 27001
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, provides his insights on the 34 technological controls in Annex A of ISO 27001 and how these can be implemented by organisations looking to conform or certify to the Standard.  Wayne leverages his 30+ years of experience in information security and risk management to discuss: What the technological controls in ISO 27001 are designed to achieve How you can go about selecting the most appropriate technological controls for your organisation How the guidance contained in ISO 27002, the supplementary standard to ISO 27001, can help your organisation meet the Standard’s requirements in relation to technological controls The constraints that may prevent your organisation from implementing certain controls, and how these can be overcome The importance of balancing security and operational effectiveness and efficiency. Learn more about this topic:  https://www.urmconsulting.com/blog/implementing-technological-controls-in-iso-27001 If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here:   https://urmconsulting.com/podcasts    Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
4 months ago
14 minutes 10 seconds

InfoSec Insider
ISO 27001 – Physical Security Controls
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, breaks down the ‘Physical’ control theme from Annex A of ISO 27001, which are a set of security measures aimed at protecting an organisation’s physical assets and environment, such as their buildings, equipment, and paper copies of documents.  Wayne leverages his 30+ of experience with information security to discuss: Why the physical security controls are important and what physical controls are recommended by ISO 27001 Whether you still need to consider physical security when all your data is stored in and accessible from the cloud The benefits of controls such as access cards and visible IDs for staff accessing business premises The relevance of physical controls for remote workers How to overcome the common pitfalls associated with operating and managing physical security controls. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-2022-annex-a-physical-controls  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider   You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts  Brought to you by URM, the UK’s leading information and cyber security specialists.   
Show more...
4 months ago
18 minutes 5 seconds

InfoSec Insider
Sharing Personal Data With the Police
In this episode of InfoSec Insider – Talk DP, Martin Brazier, Senior Data Protection Consultant at URM, breaks down the General Data Protection Regulation’s (GDPR’s) requirements for organisations that need to share personal data with the police in order to report a crime, or following a request for data to assist with an investigation.  Martin leverages his 20+ years of experience in information management and data protection compliance to discuss:   The legislative framework governing police access to personal data, including Part 3 of the Data Protection Act 2018 The lawful bases under the UK GDPR for sharing personal data with the police, and when each may apply Considerations for compliance with the purpose limitation and data minimisation principles when providing the police with personal data What to consider when sharing special category and criminal offence data with the police, including applicable conditions under the DPA 2018 Whether individuals need to be informed of any data sharing Practical guidance on how to ensure any data shared is lawful, proportionate, and compliant with the data protection principles. Learn more about this topic: https://www.urmconsulting.com/blog/sharing-personal-data-with-the-police  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:    https://ratethispodcast.com/infosecinsider   You can find more episodes of InfoSec Insider here:    https://urmconsulting.com/podcasts   Brought to you by URM, the UK’s leading information and cyber security specialists.  
Show more...
4 months ago
15 minutes 5 seconds

InfoSec Insider
ISO 27001 Audits
In this episode of InfoSec Insider, Wayne Armstrong, Senior Consultant at URM, explains the steps organisations can take to effectively plan, conduct, and action an ISO 27001 internal audit.  Wayne draws upon 30+ years of experience in the information security and risk management field to discuss: The key things to remember when planning your audit programme and to plan specific audits His tips for auditors when they are conducting audits The key considerations when reporting on audit results When you may need to follow-up on audit findings and when you can consider an audit closed. Learn more about this topic: https://youtu.be/5nFz8nhIZdE If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider    You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts  Brought to you by URM, the UK’s leading information and cyber security specialists.      
Show more...
4 months ago
23 minutes 17 seconds

InfoSec Insider
People Controls in ISO 27001
In this episode of InfoSec Insider, Frazer Grudgings, Senior Consultant at URM, provides key insights on the ‘People’ control theme of ISO 27001’s Annex A, which are measures organisations can implement to protect employees and influence their behaviour in relation to information security.  Frazer leverages his over 15 years of experience in the information security field to discuss:   Why ‘people controls’ warrants its own control theme  How screening and pre-employment policies can help  His hints and tips for effectively implementing the people controls and for a successful people controls audit.   Learn more about this topic:  https://www.urmconsulting.com/blog/implementing-and-auditing-people-controls-from-iso-27001-2022  If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here:   https://urmconsulting.com/podcasts      Brought to you by URM, the UK’s leading information and cyber security specialists.   
Show more...
5 months ago
21 minutes 47 seconds

InfoSec Insider
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.