Experts in Information
Security

TRUSTED SERVICES
CREST LogoPen Test LogoOVS Mobile LogoOVS Apps LogoCyber Essentials Certification
PCI DSS CertificationBSI CertificationBSI Certification

ISO 27001
Consultancy
and Auditing

Guaranteed ISO 27001 certification
Tailored ISMS implementation
Highly skilled auditors
Find out more

GDPR Consultancy
and Training Specialist

Pragmatic and tailored
approach to GDPR compliance
Find out more

Leading PCI QSA
Company

Pragmatic and tailored
approach to PCI DSS
compliance
Find out more

Trusted and
Accredited
Penetration Testing

Maximising the benefits from your pen testing. Assessment tailored to your organisation’s needs. Free retest of high or critical vulnerabilities.
Find out more

URM makes
Cyber Essentials
certification easy

Achieve Cyber Essentials and Cyber Essentials Plus certification with our team of qualified experts.
Find out more

Team of Experienced
SOC 2 Consultants

If you need to comply, attest, or prepare for
a SOC 2 report (be that Type 1 or Type 2)
URM provides a full range of services.
Find out more

URM Consulting Services (URM)

URM Consulting Services (URM) is dedicated to providing high quality, cost-effective and tailored consultancy and training in the areas of information and cyber security, data protection, business continuity and risk management.

URM's mission, through its consultancy, cyber testing, auditing and training services, along with risk management software (Abriska), is to assist you achieve the levels of information security, data protection and business continuity which are commensurate with the objectives and culture of your organisation, and which also meet international standards, regulations/legislation and recognised best practice.

Having assisted over 400 organisations achieve ISO 27001 certification, URM is ideally placed to help you certify your information security management system against the Standard or transition from the 2013 version of the Standard to the 2022 version.

Find out more

URM's services include conducting data protection impact assessments (DPIAs), developing records of processing activities (ROPAs) and conducting data subject access request (DSAR) redactions.

Find out more

URM’s qualified security assessors (QSAs) pride themselves on their pragmatic approach to both compliance and assessments and will work with you to find the most appropriate and sensible way for you to meet the requirements of the Standard, including v4.0.

Find out more

As an accredited Cyber Advisor (Cyber Essentials) and Certification Body, URM is ideally placed to provide you with reliable and cost effective cyber security advice and help you achieve Cyber Essentials and Cyber Essentials Plus certification.

Find out more

As a CREST-accredited organisation, URM is able to provide penetration testing services against all assets associated with your organisation, location or service, e.g., external and internal networks, cloud environments, web or mobile applications.

Find out more

If you’re looking to understand whether SOC 2 is the right approach for you, what efforts are required to comply or attest, or prepare for a SOC 2 report (be that Type 1 or Type 2), URM can provide you with a full range of services.

Find out more

Bollin Group

URM provided Bollin Group with comprehensive support in strengthening its cyber and information security posture. This included providing expert guidance in relation to governance, risk management, and compliance, helping Bollin Group achieve Cyber Essentials certification and ISO 27001 certification. URM's consultants took a pragmatic, risk-based approach, ensuring that security measures were embedded seamlessly into business operations at a sustainable pace. Their tailored advice, combined with the two organisations’ shared values of integrity and corporate responsibility, fostered a strong partnership which enabled Bollin Group to enhance its resilience against cyber threats while maintaining operational efficiency.

Read more
Our experts are the ones to trust
when it comes to your cyber security
CREST LogoPen Test LogoOVS Mobile LogoOVS Apps Logo
PCI DSS CertificationCyber Essentials CertificationBSI CertificationBSI Certification
Webinar

Business Continuity Exercising

How to Develop and Deliver Effective BC Exercises

11:00 am
,
Wednesday
30
April
2025

Will draw upon our extensive experience in the development and delivery of effective BC exercises to offer key advice and guidance on planning (scenario development), delivering and evaluating BC exercises.

Read more
USB stick, Padlock, Keys
Webinar

How to Achieve ISO 27001 Certification

11:00 am
,
Wednesday
21
May
2025

URM and BSI will be drawing upon their experiences (from both a consultancy and certification perspective) with literally hundreds of organisations that have successfully achieved and maintained certification to ISO 27001.

Read more
USB stick, Padlock, Keys
Webinar

The SME Cyber Security Journey

11:00 am
,
Wednesday
28
May
2025

URM offers key advice on effective and appropriate steps for SMEs to take in developing a robust cyber security strategy, from the earliest and most fundamental stages to the implementation of advanced security measures and achievement of internationally recognised certifications.

Read more
USB stick, Padlock, Keys

Cyber Security and Resilience Bill Policy Statement – What to Expect

George Ryan
|
Consultant at URM
Published
17
April
2025

URM’s blog explains the measures the Bill will introduce, the entities it will bring into regulatory scope & what the Bill could mean for your organisation.

Read more
Thumbnail of the Blog Illustration
Information Security
Published
16/4/2025
ISO 27001:2022 - A.5 Organisational Controls (Supplier Management)

URM’s blog explains the importance of the 5 supplier management controls in ISO 27001 & provides practical guidance on how to implement each control.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published
3/4/2025
Privacy Policies Explained: Ensuring Transparency Under the GDPR

URM’s blog explains the GDPR’s requirements for privacy policies, the common mistakes organisations make with these policies & how to avoid them.

Read more
Thumbnail of the Blog Illustration
Information Security
Published
27/3/2025
ISO 27001:2022 Annex A Physical Controls

URM’s blog offers key advice on implementing the physical controls in Annex A of ISO 27001 and preparing for a successful physical controls audit.

Read more
"
URM have quickly become a trusted partner who we can rely on for expertise. They've provided a great service since the first day we started working with them and their staff are really knowledgeable, friendly and helpful.