InfoSec Insider

URM Consulting

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

  1. 3 HR AGO

    Preparing for a PCI DSS Assessment

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, share their perspective on how organisations can most effectively and efficiently prepare for a Payment Card Industry Data Security Standard (PCI DSS) assessment.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:   Practical steps teams can take to ensure the assessment runs smoothly overall What you should have ready before your PCI DSS assessment is even booked and how to determine if your scope definition is clear enough What useable evidence looks like from a practical perspective, and whether to provide everything up front or respond as questions are asked When self-assessment questionnaires (SAQs) vs. full assessed engagements are needed, and what to keep from an SAQ in case a full engagement is required in the future What to do differently if this years’ assessment follows significant amounts of change And more. Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/preparing-for-a-pci-dss-assessment   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider       You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts       Connect with us on LinkedIn   Brought to you by URM, the UK’s leading information and cyber security specialists.

    29 min
  2. 19 FEB

    Workplace Privacy in a Hybrid World: Monitoring, DSARs, and Building Trust

    In this episode of InfoSec Insider – Talk DP, Rachael Salter and Aimee Brown, Data Protection Consultants at URM, explore the challenges of workplace privacy and data protection compliance in a hybrid business landscape, and how these challenges can be overcome.  Rachael and Aimee leverage over 20 years’ combined experience in data protection to discuss: Why employee data is becoming such a significant risk for businesses The legal and ethical boundaries when monitoring employees Why operational challenges make employee data subject access requests (DSARs) and monitoring so difficult Practical steps that small and medium-sized enterprises (SMEs) can take to monitor lawfully and reduce risk How future trends like artificial intelligence (AI) and global rules change workplace privacy. Ask Rachael and Aimee a question: https://urmconsulting.com/podcasts/workplace-privacy-in-a-hybrid-world-monitoring-dsars-and-building-trust URM’s blog on data protection considerations for monitoring employees: https://www.urmconsulting.com/blog/data-protection-considerations-for-monitoring-employees If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider      You can find more episodes of InfoSec Insider here:   https://urmconsulting.com/podcasts      Connect with us on LinkedIn      Brought to you by URM, the UK’s leading information and cyber security specialists.

    35 min
  3. 12 FEB

    Minimising the Impact if a Breach Occurs

    In this episode of InfoSec Insider – Talk Cyber, Jack Woods and George Ryan, both Consultants at URM, outline the steps organisations can take to ensure they are prepared in the event of a cyber breach and able to minimise the impact of a breach as much as possible.  George and Jack leverage their extensive experience helping organisations strengthen their cyber and information security posture to discuss:   The importance of approaching cyber security breaches as a question of ‘when’ not ‘if’, and how to ensure your organisation is appropriately resilient The documentation and procedures organisations should have in place, such as business continuity, disaster recovery, and communication plans, and how to test these plans’ effectiveness through exercising When disconnecting your organisation’s environment, i.e., ‘pulling the plug’, is an appropriate response to an attack Technical measures all organisations should have in place to mitigate the impact of a breach, such as segregation, backups, etc. Ask Jack and George a question: https://www.urmconsulting.com/podcasts/minimising-the-impact-if-a-breach-occurs Learn more about this topic:  https://www.urmconsulting.com/blog/minimising-the-impact-when-a-breach-occurs If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider           You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts           Brought to you by URM, the UK’s leading information and cyber security specialists.

    31 min

About

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.