Podcasts

InfoSec Insider
Talk Cyber
Season
3
, Episode
6

Building Your Cyber Resilience

Published on
08 Oct 2026

In this episode of InfoSec Insider – Talk Cyber, Wayne Armstrong, Senior Consultant at URM, and Mike Emery, Senior Security Consultant at URM, explore how organisations can build greater cyber resilience in the face of an increasingly sophisticated threat landscape. Drawing on practical experience, they examine where organisations are most vulnerable and discuss the steps businesses can take to strengthen their defences and prepare for cyber incidents.

The episode explores:

  • Today’s cyber threat landscape and common organisational weaknesses, including phishing, impersonation and spoofing, malware and ransomware, as well as the risks created by human error, poor access management, unpatched systems and third-party suppliers.
  • Practical approaches to strengthening cyber resilience, from understanding and assessing information assets and cyber risks to improving security awareness, access controls, supplier management, vulnerability management and layered technical protection.
  • How to prepare for and respond effectively to cyber incidents, including developing and testing incident response plans, maintaining effective communications, protecting business continuity and considering the often-overlooked human impact of a cyber breach.

‍

Learn more about this topic

About the InfoSec Insider

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more.  In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA).  Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

More episodes

Contact the InfoSec Experts Today

Having assisted over 500 organisations to implement an ISMS and then achieve ISO 27001 certification since the Standard was first published in 2005, we at URM are the ideal partners to help you certify.  With our fully-tailored approach, our specialists can support you through each stage of the ISO 27001 management system lifecycle, offering guidance specific to your organisation’s unique requirements.  
‍
Get in touch with our information security experts today to find out more.

‍

Contact Us

InfoSec Solutions & Products

One the key requirements of ISO 27001 is the need for a robust risk assessment process which can produce repeatable and comparable results.  With its proven, best practice methodology, URM’s information security risk management software, Abriska 27001, enables you to meet this requirement.   We can also assist you to raise and maintain awareness among your staff with our expertly designed and engaging learning management system (LMS), Alurna.

View Products

InfoSec Training Courses

Our information security and risk management training courses can help you learn how to effectively manage information security.  Our Certificate in Information Security Management Principles (CISMP) and Practitioner Certificate in Information Risk Management  (PCIRM) training courses will prepare you to take the BCS (Chartered Institute for IT) administered exams, enabling you to gain industry-recognised qualifications.

View Training Courses

Webinars & Events

URM has gained a reputation as the preeminent UK provider of live webinars, aimed at delivering valuable and practical insights to organisations  looking to improve their information security, risk management, data protection etc. The webinars  are delivered by our senior consultants who share hints and tips on topics such as certifying to ISO 27001 and Cyber Essentials, complying with the GDPR.  All of our webinars are completely free to attend, and include an opportunity to ask questions at the end.

In-Person EventCyber Risk and Financial Resilience

Join our cyber security breakfast in Reading and discover how finance leaders can understand cyber risk and better protect their business.

Read more
Listen to recording
USB stick, Padlock, Keys
WebinarAchieving and Maintaining ISO 27001 Certification: Practical Lessons from Supporting 500 Organisations

URM and BSI will share practical insights gained from more than 20 years of helping organisations implement, certify, maintain, and continually improve ISMS.

Read more
Listen to recording
USB stick, Padlock, Keys
WebinarMaking PCI DSS Work for Your Business: Understanding Flexibility in PCI DSS v4.0

We explain how customised approaches, compensating controls and targeted risk analyses can provide flexibility without compromising security or compliance

Read more
Listen to recording
USB stick, Padlock, Keys

Information Security FAQs

What are 4 types of information security?

If we look to guidance from Annex A of ISO 27001, then the answer is organisational, people, physical and technological.  The International Standard groups information security into these 4 categories.  The ‘organisational’ category requires the creation of policies, roles and responsibilities and day-to-day business activities.  The ‘people’ category ensures that the most appropriate staff are employed, and that they understand what is expected of them in relation to the business’ approach to infosec.  ‘Physical’ controls relate to the security of business premises, clear desk policies etc, whilst, ‘technological’ controls relate to measures that may be adopted by organisations to assist in securing information through the use of technology such as capacity management, configuration management, change management, network security, firewalls, cryptography etc.

What are the 3 principles of information security?

The three aspects that information security (infosec) seeks to protect are ‘confidentiality’, ‘integrity’ and ‘availability’. Confidentiality ensures that information is not made available or disclosed to unauthorised entities.  Integrity protects the accuracy and completeness of assets, whilst Availability ensures that information is accessible and usable on demand by authorised individuals.tc.

What are information security examples?

Examples of information security include encryption, firewalls, antivirus software, multi-factor authentication (MFA), vetting of individuals, controlling access to premises / information and providing staff awareness training.

What are 5 information security policies?

Policies provide direction on your organisation’s approach to different aspects of information security management. Policies may relate to the classification of data, password management, acceptable use of assets, authentication procedures and incident response - these are five examples, but your organisation  may choose to formulate a policy relating to any aspect of information security (infosec) management.

Read more
Information Security FAQ

ISO 27001 Clause 4.2, Understanding the Needs and Expectations of Interested Parties

Published on
2/10/2026

URM's blog examines ISO 27001:2022 Clause 4.2, covering interested parties, their requirements and how these are addressed through the ISMS.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
21/9/2026
ISO 27001 Clause 4.1 - Understanding the Organisation and its Context

URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
28/8/2026
Auditing ISO 42001: Its Unique Requirements and Key Differences From ISO 27001

URM's blog examines how the ISO 42001 management system requirements differ from ISO 27001, and the impact this has on what auditors will expect to see.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
13/8/2026
ISO 27001 Clause 9.1: Monitoring, Measurement, Analysis and Evaluation Explained

URM’s blog explores ISO 27001 Clause 9.1, what it requires and practical guidance on how to implement this Clause in full conformance with the Standard.

Read more
"
We were incredibly impressed with our consultant’s attention to detail during the reworking of many documents and the in-year assessment last month. He stood up and had his finger on the pulse and was a great help. He is liked by our team, and we look forward to a long working relationship with him.