Webinar

A practical look at what AI really means for security teams

11:00 am
|
Wednesday
|
12
August
2026

We'll look at where AI is genuinely useful, where its limitations remain, and how it is affecting penetration testing and cyber defence in practice.

Read more
USB stick, Padlock, Keys
Find out more events
Wayne Armstrong
|
Senior Information Security Consultant and Consultant Manager at URM
|
Published on
07
August
2026

URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.

Read more
Information Security
Published on
30/7/2026
ISO 27001 Clause 7.4: Communication

URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

Information Security
Published on
17/7/2026
The Subtleties of Scheduled Tasks in PCI DSS

URM’s blog explores the nuances and challenges of PCI DSS scheduled activities and practical approaches for improving compliance with periodic requirements.

Information Security
Published on
14/7/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Find out more blogs
InfoSec Insider
Season
2
, Episode
47
(
97
)

PCI DSS Periodic Activities

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

  • Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
  • The common mistakes they see organisations make when defining their own frequencies
  • Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
  • How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
  • How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
  • How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
  • And more.

Listen to the episode
Find out more podcasts
|

By completing the quiz, you will gain a clearer understanding of how organisations prepare for, respond to, and recover from disruption, and why business continuity is a shared responsibility rather than a purely technical or specialist function.

Take the quiz
Find out more quizzes

ISO 27001 FAQs

How long does it take to implement ISO 27001?

There is no straightforward answer to this question as it depends on the size and complexity of your organisation, what systems and processes are already in place and what resources are available.  However, in URM’s experience it typically takes between 6 and 9 months for a small, low complexity organisation to fully implement ISO 27001.  

With larger, more complex environments, 9 to 18 months is closer to the norm for fully establishing an ISMS. This naturally assumes that the appropriate resources are made available to achieve the desired outcomes.

Apart from the existing maturity of operational practices and controls and availability of in-house resource, another key determinant in how long an ISO 27001 implementation will take place will be the support and involvement of senior management.  URM has seen organisations achieve very aggressive timescales in implementing and achieving ISO 27001 certification where Senior Management has prioritised the project, often associated with being awarded a significant client project.

Is there a legal requirement to comply with or be certified to ISO 27001?

There is, generally, no direct legal requirement for compliance as such, indicating why many people choose to use the word conformance rather than compliance.  Organisations choose whether or not to implement the requirements of ISO 27001 based upon the benefits that would be gained by doing so. However, you should pay close attention to any contractual obligations you may have for protecting the information of clients and other stakeholders.  

There is an increasing trend where customers require third party suppliers to implement or certify to ISO 27001, thus making it a legal requirement, by virtue of a contract.

What does ISO 27001 require you to do?

A key requirement of ISO 27001 is that you adopt a risk-based approach when implementing your ISMS.  You are also required to ensure that certain processes are in place to ensure effective and proactive management and continuous improvement.  

These requirements are broken down into 7 major clauses, which deal with context of the organisation, leadership, planning, support, operation, performance evaluation and improvement.  These clauses are consistent with other ISO Management system standards such as ISO 9001 and ISO 22301, and is known as the harmonised structure.

When was ISO 27001 last updated?

The current version of the Standard, ISO/IEC 27001:2022 replaced the 2013 version of the Standard on 25 October 2022.  As of 1 May 2024, all initial and recertification assessments must be conducted against ISO 27001:2022 and, on 31 October 2025, all ISO 27001:2013 certificates will be withdrawn.  Whilst the management system clauses received a relatively minor makeover in order to harmonize ISO 27001 with other standards, the information security controls contained within Annex A were completely restructured with some controls being merged with others as well as 11 new ones being introduced.

Read more
Find out more FAQs
Release date:
17
April
2026

In this document, we outline the key changes to Cyber Essentials and Cyber Essentials Plus scheme and what they mean for you as applicants.

Read more
Find out more white papers
Course type: 
Online
PCIRM
DATE:
14
September 2026
-
21
September 2026
Location:

All you need to know about the information risk management, conducting risk assessments and developing risk treatment plans.

Register
USB stick, Padlock, Keys
Course type: 
Online
CDP
DATE:
01
December 2026
-
04
December 2026
Location:

The course provides a sound grounding and practical interpretation of the key elements of UK data protection law, including the UK GDPR

Register
USB stick, Padlock, Keys
Scheduled courses
URM can offer a range of support services when applying for Cyber Essentials Certification. Check our offer!
Find out more
"
We've been using URM for our PCI DSS assessments for the last 5 years and we are pleased with their service. The assessment is always completed promptly, the price is competitive, and communication is great. We'll keep using them and are happy to recommend URM to anyone.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.