Avsnitt
-
In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
When an organisation stops being ‘just a merchant’ and becomes a PCI DSS service provider and how this distinction is madeWhether organisations can be a merchant and service provider at the same time and how this should be reflected in the PCI DSS assessmentWhy Requirement 6.4.3 and 11.6.1 are particularly important for modern e-commerce scopingSome examples of systems that are not in the card data environment (CDE) but are still security-impacting and therefore in PCI DSS scopeHow elements such as administrative access, deployment pipelines, cloud consoles, source code repositories, and secrets management tools be considered during scopingAnd more.Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-scoping
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, break down the key steps to establishing control over the use of artificial intelligence (AI) within organisations. Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss:
Why organisations should be paying attention to AI right nowThe most common ways organisations are already using AIThe most significant AI-related risks they currently seeHow organisations can use AI effectively, what ‘good’ looks like, and some simple guardrails against issues and misuseThe top three AI controls and measures all organisations should have in place.Ask Jack and George a question: https://urmconsulting.com/podcasts/establishing-control-over-ai-usage
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
Saknas det avsnitt?
-
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, consider emerging trends in the field of data protection and privacy, and the practical implications for organisations that need to maintain compliance. Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:
What they think will define privacy risk over the next 12 monthsWhy artificial intelligence (AI) will continue to expose weak data protection practicesThe privacy issues that are most likely to grow fastest in practiceWhere regulators are most likely to focus nextThe steps organisations should take now to prepare for the next wave of scrutiny and enforcement.You can register for the STAIRs webinar or watch the recording on URM’s website: https://www.urmconsulting.com/event/stairs-webinar-are-you-readyAsk Rachael and Aimee a question: https://urmconsulting.com/podcasts/next-12-months-in-privacy
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore some of the most misunderstood areas of PCI DSS scoping, focusing on service providers, merchants, and complex modern payment architectures. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
When an organisation stops being “just a merchant” and becomes a PCI DSS service provider, and what really drives that distinctionHow an organisation can be both a merchant and a service provider at the same time, and how this should be handled during a PCI DSS assessmentThe most common mistakes organisations make when deciding how they should be classified for PCI DSS purposesWhether companies providing payment-enabled platforms, but not directly handling PAN, can still fall under the definition of a service providerThe responsibilities that remain when a third-party platform hosts the payment page but payment fields are served directly by a providerAnd more.Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-and-service-providers
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, answer some of the niche and unusual questions around governance, risk and compliance (GRC). Jack and George leverage their extensive experience supporting organisations to strengthen their information security and risk management to discuss: • The key questions clients rarely ask despite being extremely important• Whether a policy is enough on its own• The security policies that are most frequently not followed in practice• How to avoid prioritising compliance over genuine security• The easiest ways to establish whether a control is effective• How to achieve buy-in from executives on managing and mitigating risks before they materialise. Ask Jack and George a question: https://urmconsulting.com/podcasts/unusual-grc-questions
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, answer key, real-world questions around data protection and how organisations can stay compliant. Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:
When data is genuinely anonymous, and how easy it is to lose that statusWhether things like voice, handwriting, CCTV, emojis, avatars and internal gossip really count as personal dataHow employee use of smart glassed and always-on devices can affect organisations and why it mattersWhy redaction still goes wrong so oftenWhy consent remains one of the single most understood aspects of data protection.Ask Rachael and Aimee a question: https://www.urmconsulting.com/podcasts/real-world-data-protection-questions
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a business perspective. Chris and Wayne draw upon their combined 45 years of experience in information security and risk management to discuss:
What good, risk-based decision-making actually looks like in practice, and where it most commonly breaks downThe most concerning information security risks of today that do not get enough attention at the board or executive levelHow organisations can move away from checklist-driven compliance and towards meaningful cyber risk management that supports business objectivesHow organisations should rethink ownership and accountability for information security risk in light of growing dependence on cloud services and third-party providersThe capability or mindset they believe information security leaders must develop now to remain effective risk advisers in the coming years.Ask Wayne and Chris a question: https://urmconsulting.com/podcasts/business-approaches-to-risk-management
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment Card Industry Data Security Standard (PCI DSS) compliance. Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
What ‘severless’ actually means in a PCI DSS context, and how this differs from how it is usually described by cloud providersWhat QSAs look for when deciding whether a severless system falls within PCI scopeHow the balance of responsibilities shifts when an organisation moves from traditional cloud services to severless, and where this causes the most confusion during assessmentsThe parts of a severless setup that tend to bring cardholder data into scope unexpectedly and how to ensure you understand the way information moves through your systemsHow to handle PCI requirements for logs, monitoring and keeping evidence when the systems they rely on disappear almost instantlyMaintaining compliant access control and control over changes to your systems in a severless contextHow to check for weaknesses in severless systems, the risks tied to the external code and libraries that are often used inside serverless functionsAnd more.Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-and-severless-architecture
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk DP, Aimee Brown and Rachael Salter, both Consultants at URM, break down the data protection compliance issues that arise from the use of bring your own device (BYOD) within organisations, and how these can be overcome. Aimee and Racheal draw on over 20 years’ combined data protection experience to discuss:
Why BYOD has become so common, and why it still catches organisations outWhere legal and regulatory risks arise with BYODHow BYOD increases data subject access request (DSAR), breach, and dispute riskWhat a proportionate, people-aware approach to BYOD looks likeHow regulators and insurers are likely to view BYOD going forward.Ask Rachael and Aimee a question:
https://www.urmconsulting.com/podcasts/gdpr-compliance-and-byod
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can effectively manage AI suppliers and navigate the emerging risks associated with artificial intelligence in the supply chain.
Jack and George draw on their experience supporting organisations with AI governance and supplier risk management to discuss:
What AI supplier management is and how it differs from traditional supplier management, including the impact of rapidly evolving AI models and changing service structuresThe key risks associated with AI suppliers, such as data leakage, unauthorised model training, hallucinations, bias, and compliance challengesThe growing issue of shadow AI, and how a lack of visibility over employee use of AI tools can introduce significant security and governance risksHow organisations can adapt due diligence processes to assess AI suppliers, including evaluating data handling practices, model governance, human oversight, and security maturityContractual and governance considerations, such as restricting data use, ensuring transparency on model updates, and defining audit and incident response expectationsThe importance of understanding extended AI supply chains, including dependencies on underlying models and fourth-party providersWhy AI supplier management must be treated as an ongoing activity, with continuous monitoring, internal communication, and reassessment of risk as technologies evolveAsk Jack and George a question:
https://www.urmconsulting.com/podcasts/aI-supplier-management
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Wayne Armstrong, Senior Information Security Consultant and Consultant Manager at URM, breaks down the fundamentals of effective information security risk assessment and treatment. Wayne draws upon over 30 years of experience in IT, information security and risk management to discuss:
What ‘risk’ actually isHow to define a risk and the three component parts that are needed for a risk to existHow to assign value to a riskHow to prioritise risks and determine which can be set aside, as well as how these priorities differ between organisations depending on contextThe risk treatment options available, and the need to revisit your risk assessment.Learn more about this topic: https://www.urmconsulting.com/blog/information-security-risk-assessment-and-treatment-understanding-relevant-risks
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, share their insights on zero trust architecture and its use when complying with the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage 30 years’ combined experience with the PCI DSS to discuss:
What ‘zero trust’ isWhether organisations with zero trust still need segmentation, or whether identity is enoughHow to prove least privilege when access is dynamic and granted on demand, and how to handle sampling for PCI DSS evidence when access changes continuouslyThe biggest zero trust implementation mistakes that cause PCI DSS challenges laterWhich logs matter most to prove that zero trust is actually protecting the cardholder data environment (CDE)And much more.Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/zero-trust-architecture-in-pci-dss
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, both Consultants at URM, discuss context and redaction in handling data subject access requests (DSARs), and how reviewers can use these to fulfil requests in full compliance with the General Data Protection Regulation (GDPR). Aimee and Rachel leverage 20 years’ combined experience in data protection to discuss:
Why redaction the part of DSAR handling that so often goes wrong for organisationsHow reviewers can distinguish between personal data, mixed data, and information that should not be disclosedThe biggest challenges when handling DSARs involving unstructured datasets like email chains, chat logs, or call notesSome of the common redaction mistakes organisations make, and lessons learned from real casesThe practical steps organisations can take to improve the quality and defensibility of their redactions.Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/the-dsar-reviewers-toolbox
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, share their insights on identity and access management (IAM), and the steps organisations can take to ensure their IAM is secure and resilient. Jack and George leverage their extensive experience supporting organisations’ strengthen their information security to discuss:
What IAM is, whether it just covers employees, and how it worksThe components that may feature as part of effective IAM, such as multi-factor authentication (MFA), single sign-on (SSO), monitoring and auditing, etc.Why it is important to enforce IAM best practicesThe problems around IAM that may arise in the future as a result of developing trends and technologies.Ask Jack and George a question
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, provides key insights on achieving and maintaining conformance to Clause 6.3 (Planning of changes) of ISO 27001, the International Standard for Information Security Management Systems (ISMS’). Neil leverages over 20 years of real-world information security knowledge and experience to discuss:
What Clause 6.3 is and why planned ISMS change management is so importantThe common mistakes organisations make when planning ISMS changes under Clause 6.3The seven practical actions he recommends for effective implementation of Clause 6.3, which of these actions organisations most frequently overlook, and whyHow to determine whether your existing change management processes are suitable for Clause 6.3 conformance.Learn more about this topic: https://www.urmconsulting.com/blog/iso-27001-clause-6-3-the-importance-of-planned-isms-change-management
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk Cyber, Stuart Moran and George Ryan, Consultants at URM, explore recent shifts in cyber security expectations and regulatory requirements faced by organisations in the medical supply chain, both in the UK and across the globe. Stuart and George leverage their extensive experience helping organisations in the medical sector enhance information and cyber security to discuss:
The NHS’ recent open letter to suppliers, which highlights tighter scrutiny and more direct engagement, and what this means for NHS suppliersWhich of the NHS’ new cyber security requirements for suppliers (MFA, continuous monitoring and immutable backups) will be most challenging to embed and whyThe biggest gaps and understanding or readiness among suppliers implementing the Data Security and Protection Toolkit (DSPT), and the practical differences between Categories 2 and 3 of the DSPTHow shifts in standards such as ISO 13485 and the broader medical device regulatory landscape will influence suppliers’ design and manufacturing of their products, particularly around software and AIHow the FDA’s power to deny market access to medical devices with insufficient cyber security may impact UK suppliers operating internationally, and whether this hints at a broader, global trend towards stricter cyber controls.Learn more about this topic:
https://www.urmconsulting.com/blog/iso-13485-and-beyond-key-updates-shaping-the-medical-device-regulatory-landscape https://www.urmconsulting.com/blog/nhs-cyber-security-open-letter-what-does-it-mean-for-suppliersIf you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, answer the niche and unusual questions they encounter around the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
The strangest misconceptions they have heard about PCI DSS and cardholder data securityWhat PCI DSS would look like if it were invented today, and what would be left out entirelyThe simple PCI DSS controls that people routinely misunderstandThe most unusual systems or devices they have seen brought into scopeWhether something can be both technically compliant and completely insecure at the same time, and whether there is such a thing as ‘too compliant’Finer technical details of the Standard, such as Kubernetes network policies, how to evidence a control that never triggers, corporate VPNs that impact segmentation, and more.Ask Alastair and Tibor a question.
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk DP, Stuart Skelly, Senior Data Protection Consultant at URM, provides a break down and analysis of how the Information Commissioner’s Office (ICO’s) enforced UK data protection (DP) regulations in 2025, and how this compares to the action taken by the regulator in previous years. Stuart leverages his 25+ years of specialisation in data protection law to discuss:
The context of changes in ICO enforcement activities between 2024 and 2025 The main headline takeaways from his 2025 analysis, particularly in relation to the ICO’s fining activities What the regulator itself has said recently about new ways in which it’ll tackle enforcement in 2026 and beyond Ongoing DP stories to keep an eye on which might have an impact on the ICO, its fining posture and its ability to enforce any fines it imposes.Learn more about this topic: https://www.urmconsulting.com/blog/analysis-of-enforcement-action-by-the-ico-in-2025-actions-way-down-security-data-breach-fines-way-up
If you enjoyed this episode of InfoSec Insider – Talk DP, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can achieve strong information security governance and asset management that facilitate conformance to ISO 27001, the International Standard for Information Security Management Systems (ISMS). Jack and George draw on their extensive experience supporting organisations’ ISO 27001 certifications to discuss:
How to transform high-level information security policies into day-to-day behaviour across teams, and who should own information security within organisationsDefining clear information security roles and responsibilities, and how to overcome the practical challenges of implementing segregation of dutiesWhat best practice looks like when maintaining contact with authorities, special interest groups, and threat intelligenceThe importance of integrating information security into project managementHow to produce usable (rather than bureaucratic) documented operating procedures that reduce operational riskEffective information handling and asset management, from inventorying assets and acceptable use through to classification and labelling of information.Ask Jack and George a question:
https://www.urmconsulting.com/podcasts/information-security-governance-compliance-and-asset-management
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
-
In this episode of InfoSec Insider – Talk Cyber, Mark O’Kane, Consultant at URM, explains the second of the NIST Cybersecurity Framework’s (CSF’s) five core functions, the Identify function, sharing his insights on what organisations can do in practice to meet its requirements. Mark uses his extensive experience working in information security and risk management to discuss:
Where the Identify function sits within the overall NIST CSFHow your organisation can meet the requirements around identifying and managing assetsThe practical steps provided by the CSF for organisations struggling to understand their cyber security risksHow to identify areas for improvement in your cyber security programme in line with the Identify function’s requirements.Learn more about this topic: https://www.urmconsulting.com/blog/the-core-functions-of-nist-csf-identify
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
- Visa fler