Podcast charts
Published by URM Consulting
The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, share their insights on how to effectively manage the immediate aftermath of a personal data breach. Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss: What actually counts as a data breach and when it needs to be reported to the Information Commissioner’s Office (ICO) How organisations can assess risk and decide whether affected individuals need to be told The biggest mistakes organisations make in the first few days following a data breach How ransomware attacks, supplier incidents, and modern technology are changing breach management The practical steps organisations can take now to prepare for a breach and demonstrate accountability afterwards. Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/the-first-72-hours-managing-data-breaches You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk Cyber, Jamie Leavers, Security Consultant at URM, and Lauren Gotting, New Business Director at URM, share real-world lessons learned from conducting hundreds of CE and CE+ assessments, including early assessments against the new Danzell requirements. Jamie and Lauren leverage their extensive experience with the Cyber Essentials scheme to discuss: Lessons from real CE/CE+ assessments, what assessors are seeing in practice, and what separates successful submissions from failed ones The Danzell Question Set and key changes introduced in 2026 and how they impact both new applicants and recertifying organisations How to prepare for certification or recertification, including ractical guidance to ensure your evidence, scope and controls meet assessor expectations. The common issues and pitfalls most frequently causing delays or failures and how to avoid them entirely. Learn more about URM’s webinar programme: https://www.urmconsulting.com/events/upcoming-events Contact webinars@urmconsulting.com for this webinar’s slide deck. You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide expert advice and guidance on how organisations can maintain the physical security of their information, and where physical security most often goes wrong. George and Jack draw upon their extensive combined experience of helping organisations strengthen their information security to discuss: Whether organisations are underestimating the importance of physical security in favour of focusing on cyber threats How hybrid working, flexible offices, and remote employees have changed what ‘physical security’ actually means The most surprising physical security weakness they’ve encountered that could have led to a major information security breach Which physical security controls most organisations think is effective, but in reality provide little more than a false sense of security The top three physical controls they would implement in an organisation with a limited budget and why. Ask Jack and George a question: https://urmconsulting.com/podcasts/physical-security-controls You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls The common mistakes they see organisations make when defining their own frequencies Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms And more. Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down cookies compliance under the General Data Protection Regulation (GDPR) and Privacy and Electronic Communications Regulations (PECR). Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss: Why cookies are so important to businesses commercially What the law actually requires when using cookies How businesses get cookie compliance wrong in practice Where consent or pay fits in What good compliance actually looks like. Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/gdpr-cookies-compliance If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, shares key advice and guidance on ISO 27001 Clause 10.2 (Nonconformity and corrective action), its requirements and how organisations can meet them. Neil leverages over 20 years of experience working with risk and information security-related standards to discuss: What Clause 10.2 is and why it is important for organisations managing problems with their information security management system (ISMS) What nonconformities are, and the difference between major and minor nonconformities The requirements of Clause 10.2 and how organisations can implement them in practice Common mistakes to avoid when addressing Clause 10.2. Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-10-2-nonconformity-and-corrective-action If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is made Whether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessment Why Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scoping Some examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scope How elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scoping And more. Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations. Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss: Why organisations should be paying attention to AI right now The most common ways organisations are already using AI The most significant AI-related risks they currently see How organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuse The top three AI controls and measures all organisations should have in place. Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, consider emerging trends in the field of data protection and privacy, and the practical implications for organisations that need to maintain compliance. Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss: What they think will define privacy risk over the next 12 months Why artificial intelligence (AI) will continue to expose weak data protection practices The privacy issues that are most likely to grow fastest in practice Where regulators are most likely to focus next The steps organisations should take now to prepare for the next wave of scrutiny and enforcement. You can register for the STAIRs webinar or watch the recording on URM’s website: https://www.urmconsulting.com/event/stairs-webinar-are-you-ready Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/next-12-months-in-privacy If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore some of the most misunderstood areas of PCI DSS scoping, focusing on service providers, merchants, and complex modern payment architectures. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: When an organisation stops being “just a merchant” and becomes a PCI DSS service provider, and what really drives that distinction How an organisation can be both a merchant and a service provider at the same time, and how this should be handled during a PCI DSS assessment The most common mistakes organisations make when deciding how they should be classified for PCI DSS purposes Whether companies providing payment-enabled platforms, but not directly handling PAN, can still fall under the definition of a service provider The responsibilities that remain when a third-party platform hosts the payment page but payment fields are served directly by a provider And more. Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-and-service-providers If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, answer some of the niche and unusual questions around governance, risk and compliance (GRC). Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss: • The key questions clients rarely ask despite being extremely important • Whether a policy is enough on its own • The security policies that are most frequently not followed in practice • How to avoid prioritising compliance over genuine security • The easiest ways to establish whether a control is effective • How to achieve buy-in from executives on managing and mitigating risks before they materialise. Ask Jack and George a question: https://urmconsulting.com/podcasts/unusual-grc-questions If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, answer key, real-world questions around data protection and how organisations can stay compliant. Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss: When data is genuinely anonymous, and how easy it is to lose that status Whether things like voice, handwriting, CCTV, emojis, avatars and internal gossip really count as personal data How employee use of smart glassed and always-on devices can affect organisations and why it matters Why redaction still goes wrong so often Why consent remains one of the single most understood aspects of data protection. Ask Rachael and Aimee a question: https://www.urmconsulting.com/podcasts/real-world-data-protection-questions If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a business perspective. Chris and Wayne draw upon their combined 45 years of experience in information security and risk management to discuss: What good, risk-based decision-making actually looks like in practice, and where it most commonly breaks down The most concerning information security risks of today that do not get enough attention at the board or executive level How organisations can move away from checklist-driven compliance and towards meaningful cyber risk management that supports business objectives How organisations should rethink ownership and accountability for information security risk in light of growing dependence on cloud services and third-party providers The capability or mindset they believe information security leaders must develop now to remain effective risk advisers in the coming years. Ask Wayne and Chris a question: https://urmconsulting.com/podcasts/business-approaches-to-risk-management If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment Card Industry Data Security Standard (PCI DSS) compliance. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: What ‘severless’ actually means in a PCI DSS context, and how this differs from how it is usually described by cloud providers What QSAs look for when deciding whether a severless system falls within PCI scope How the balance of responsibilities shifts when an organisation moves from traditional cloud services to severless, and where this causes the most confusion during assessments The parts of a severless setup that tend to bring cardholder data into scope unexpectedly and how to ensure you understand the way information moves through your systems How to handle PCI requirements for logs, monitoring and keeping evidence when the systems they rely on disappear almost instantly Maintaining compliant access control and control over changes to your systems in a severless context How to check for weaknesses in severless systems, the risks tied to the external code and libraries that are often used inside serverless functions And more. Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-and-severless-architecture If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down the data protection compliance issues that arise from the use of bring your own device (BYOD) within organisations, and how these can be overcome. Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss: Why BYOD has become so common, and why it still catches organisations out Where legal and regulatory risks arise with BYOD How BYOD increases data subject access request (DSAR), breach, and dispute risk What a proportionate, people-aware approach to BYOD looks like How regulators and insurers are likely to view BYOD going forward. Ask Rachael and Aimee a question: https://www.urmconsulting.com/podcasts/gdpr-compliance-and-byod If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can effectively manage AI suppliers and navigate the emerging risks associated with artificial intelligence in the supply chain. Jack and George draw on their experience supporting organisations with AI governance and supplier risk management to discuss: What AI supplier management is and how it differs from traditional supplier management, including the impact of rapidly evolving AI models and changing service structures The key risks associated with AI suppliers, such as data leakage, unauthorised model training, hallucinations, bias, and compliance challenges The growing issue of shadow AI, and how a lack of visibility over employee use of AI tools can introduce significant security and governance risks How organisations can adapt due diligence processes to assess AI suppliers, including evaluating data handling practices, model governance, human oversight, and security maturity Contractual and governance considerations, such as restricting data use, ensuring transparency on model updates, and defining audit and incident response expectations The importance of understanding extended AI supply chains, including dependencies on underlying models and fourth-party providers Why AI supplier management must be treated as an ongoing activity, with continuous monitoring, internal communication, and reassessment of risk as technologies evolve Ask Jack and George a question: https://www.urmconsulting.com/podcasts/aI-supplier-management If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Wayne Armstrong, Senior Information Security Consultant and Consultant Manager at URM, breaks down the fundamentals of effective information security risk assessment and treatment. Wayne draws upon over 30 years of experience in IT, information security and risk management to discuss: What ‘risk’ actually is How to define a risk and the three component parts that are needed for a risk to exist How to assign value to a risk How to prioritise risks and determine which can be set aside, as well as how these priorities differ between organisations depending on context The risk treatment options available, and the need to revisit your risk assessment. Learn more about this topic: https://www.urmconsulting.com/blog/information-security-risk-assessment-and-treatment-understanding-relevant-risks If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, share their insights on zero trust architecture and its use when complying with the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage 30 years’ combined experience with the PCI DSS to discuss: What ‘zero trust’ is Whether organisations with zero trust still need segmentation, or whether identity is enough How to prove least privilege when access is dynamic and granted on demand, and how to handle sampling for PCI DSS evidence when access changes continuously The biggest zero trust implementation mistakes that cause PCI DSS challenges later Which logs matter most to prove that zero trust is actually protecting the cardholder data environment (CDE) And much more. Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/zero-trust-architecture-in-pci-dss If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, discuss context and redaction in handling data subject access requests (DSARs), and how reviewers can use these to fulfil requests in full compliance with the General Data Protection Regulation (GDPR). Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss: Why redaction the part of DSAR handling that so often goes wrong for organisations How reviewers can distinguish between personal data, mixed data, and information that should not be disclosed The biggest challenges when handling DSARs involving unstructured datasets like email chains, chat logs, or call notes Some of the common redaction mistakes organisations make, and lessons learned from real cases The practical steps organisations can take to improve the quality and defensibility of their redactions. Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/the-dsar-reviewers-toolbox If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Connect with us on LinkedIn Brought to you by URM, the UK’s leading information and cyber security specialists.
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, share their insights on identity and access management (IAM), and the steps organisations can take to ensure their IAM is secure and resilient. Jack and George leverage their extensive experience supporting organisations’ strengthen their information security to discuss: What IAM is, whether it just covers employees, and how it works The components that may feature as part of effective IAM, such as multi-factor authentication (MFA), single sign-on (SSO), monitoring and auditing, etc. Why it is important to enforce IAM best practices The problems around IAM that may arise in the future as a result of developing trends and technologies. Ask Jack and George a question If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts Brought to you by URM, the UK’s leading information and cyber security specialists.
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.