InfoSec Insider

URM Consulting

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy. 

  1. 2d ago

    Cyber Security Training, Awareness and Benefits of Tailored Training

    In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide practical advice on how organisations can improve cyber security training and awareness, and why tailoring training to specific roles, responsibilities and risks can help build a stronger security culture. George Ryan and Jack Woods draw upon their experience of helping organisations strengthen their information security to discuss: The difference between cyber security training, awareness and competence, and why organisations should understand the distinction Why a one-size-fits-all approach to cyber security training may provide a useful baseline, but often fails to address the different risks faced by specific roles, teams and sectors How tailored training can make cyber security more relevant to employees, encourage behavioural change and help organisations develop a stronger security culture How the growing use of AI is creating new security risks and training requirements, as well as new opportunities to make cyber security awareness more effective And more. If there's a GRC or cyber security related issue you'd like us to explore, share it with us here here: https://urmconsulting.com/podcasts/cyber-security-training-awareness-and-benefits-of-tailored-training We use listener questions to guide future discussions and ensure our episodes tackle the challenges that matter most to organisations like yours. You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             Brought to you by URM, the UK’s leading information and cyber security specialists.

  2. Sep 10

    PCI DSS Compensating Controls vs. Customized Approach

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, examine one of the most frequently misunderstood areas of PCI DSS: the difference between compensating controls and the customised approach. Drawing on their extensive PCI DSS assessment experience, they discuss: The key differences between compensating controls and customised approaches, and the specific scenarios where each can be used Why compensating controls are not a “get out of jail free” card for non-compliance and the strict conditions that must be met before they can be applied The legal, regulatory, technical, and financial constraints that may justify the use of compensating controls How customised approaches were introduced in PCI DSS v4.0 to support innovative and non-traditional methods of meeting security objectives Why customised validations require significant planning, documentation, evidence collection, and assessor involvement before they can be approved And more. If there's a PCI DSS related issue you'd like us to explore, share it with us here here: https://urmconsulting.com/podcasts/pci-dss-compensating-controls-vs-customized-approach We use listener questions to guide future discussions and ensure our episodes tackle the challenges that matter most to organisations like yours. You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts              Brought to you by URM, the UK’s leading information and cyber security specialists.

  3. Aug 6

    PCI DSS Periodic Activities

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:   Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls The common mistakes they see organisations make when defining their own frequencies Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms And more. Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities   If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider            You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts             Connect with us on LinkedIn     Brought to you by URM, the UK’s leading information and cyber security specialists.

About

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy. 

You Might Also Like