Webinar

11:00 am
|
Wednesday
|
14
October
2026

Alastair Stewart explains how customised approaches, compensating controls and targeted risk analyses can provide flexibility without compromising security or compliance.

Read more
USB stick, Padlock, Keys
Webinar

11:00 am
|
Wednesday
|
21
October
2026

URM and BSI will share practical insights gained from more than 20 years of helping organisations implement, certify, maintain, and continually improve their ISMS.

Read more
USB stick, Padlock, Keys
In-Person Event

What Every Finance Leader Needs to Know

8:30 am
|
Thursday
|
22
October
2026

Join our cyber security breakfast in Reading and discover how finance leaders can understand cyber risk and better protect their business.

Read more
USB stick, Padlock, Keys
Find out more events
George Ryan
|
Consultant at URM
Neil Jones
|
Senior Consultant at URM
Published on
09
October
2026

URM's blog explores the growing use of AI agents and agentic AI, the risks they introduce, and how organisations can govern them responsibly.

Read more
Information Security
Published on
2/10/2026
ISO 27001 Clause 4.2, Understanding the Needs and Expectations of Interested Parties

URM's blog examines ISO 27001:2022 Clause 4.2, covering interested parties, their requirements and how these are addressed through the ISMS.

Information Security
Published on
21/9/2026
ISO 27001 Clause 4.1 - Understanding the Organisation and its Context

URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.

Information Security
Published on
28/8/2026
Auditing ISO 42001: Its Unique Requirements and Key Differences From ISO 27001

URM's blog examines how the ISO 42001 management system requirements differ from ISO 27001, and the impact this has on what auditors will expect to see.

Find out more blogs
Talk Cyber
Season
3
, Episode
6
(
106
)

Building Your Cyber Resilience

In this episode of InfoSec Insider – Talk Cyber, Wayne Armstrong, Senior Consultant at URM, and Mike Emery, Senior Security Consultant at URM, explore how organisations can build greater cyber resilience in the face of an increasingly sophisticated threat landscape. Drawing on practical experience, they examine where organisations are most vulnerable and discuss the steps businesses can take to strengthen their defences and prepare for cyber incidents.

The episode explores:

  • Today’s cyber threat landscape and common organisational weaknesses, including phishing, impersonation and spoofing, malware and ransomware, as well as the risks created by human error, poor access management, unpatched systems and third-party suppliers.
  • Practical approaches to strengthening cyber resilience, from understanding and assessing information assets and cyber risks to improving security awareness, access controls, supplier management, vulnerability management and layered technical protection.
  • How to prepare for and respond effectively to cyber incidents, including developing and testing incident response plans, maintaining effective communications, protecting business continuity and considering the often-overlooked human impact of a cyber breach.

‍

Listen to the episode
Find out more podcasts
|

Test yourself with these 12 questions combining real-world cyber incidents with situations you might encounter at work.

Take the quiz
Find out more quizzes

ISO 27001 FAQs

How long does it take to implement ISO 27001?

There is no straightforward answer to this question as it depends on the size and complexity of your organisation, what systems and processes are already in place and what resources are available.  However, in URM’s experience it typically takes between 6 and 9 months for a small, low complexity organisation to fully implement ISO 27001.  

With larger, more complex environments, 9 to 18 months is closer to the norm for fully establishing an ISMS. This naturally assumes that the appropriate resources are made available to achieve the desired outcomes.

Apart from the existing maturity of operational practices and controls and availability of in-house resource, another key determinant in how long an ISO 27001 implementation will take place will be the support and involvement of senior management.  URM has seen organisations achieve very aggressive timescales in implementing and achieving ISO 27001 certification where Senior Management has prioritised the project, often associated with being awarded a significant client project.

Is there a legal requirement to comply with or be certified to ISO 27001?

There is, generally, no direct legal requirement for compliance as such, indicating why many people choose to use the word conformance rather than compliance.  Organisations choose whether or not to implement the requirements of ISO 27001 based upon the benefits that would be gained by doing so. However, you should pay close attention to any contractual obligations you may have for protecting the information of clients and other stakeholders.  

There is an increasing trend where customers require third party suppliers to implement or certify to ISO 27001, thus making it a legal requirement, by virtue of a contract.

What does ISO 27001 require you to do?

A key requirement of ISO 27001 is that you adopt a risk-based approach when implementing your ISMS.  You are also required to ensure that certain processes are in place to ensure effective and proactive management and continuous improvement.  

These requirements are broken down into 7 major clauses, which deal with context of the organisation, leadership, planning, support, operation, performance evaluation and improvement.  These clauses are consistent with other ISO Management system standards such as ISO 9001 and ISO 22301, and is known as the harmonised structure.

When was ISO 27001 last updated?

The current version of the Standard, ISO/IEC 27001:2022 replaced the 2013 version of the Standard on 25 October 2022.  As of 1 May 2024, all initial and recertification assessments must be conducted against ISO 27001:2022 and, on 31 October 2025, all ISO 27001:2013 certificates will be withdrawn.  Whilst the management system clauses received a relatively minor makeover in order to harmonize ISO 27001 with other standards, the information security controls contained within Annex A were completely restructured with some controls being merged with others as well as 11 new ones being introduced.

Read more
Find out more FAQs
Release date:
17
April
2026

In this document, we outline the key changes to Cyber Essentials and Cyber Essentials Plus scheme and what they mean for you as applicants.

Read more
Find out more white papers
Course type: 
Online
CISMP
DATE:
09
November 2026
-
16
November 2026
Location:

The course provides the information how to manage information and cyber security and address the ever-evolving threats and changes.

Register
USB stick, Padlock, Keys
Course type: 
Online
How to Manage Data Subject Access Requests (DSARs)
DATE:
19
November 2026
-
19
November 2026
Location:

The course provides clear and practical instruction and guidance on dealing with all aspects of a data subject access request (DSAR).

Register
USB stick, Padlock, Keys
Course type: 
Online
CDP
DATE:
01
December 2026
-
04
December 2026
Location:

The course provides a sound grounding and practical interpretation of the key elements of UK data protection law, including the UK GDPR

Register
USB stick, Padlock, Keys
Course type: 
Online
PCIRM
DATE:
07
December 2026
-
14
December 2026
Location:

All you need to know about the information risk management, conducting risk assessments and developing risk treatment plans.

Register
USB stick, Padlock, Keys
Scheduled courses
URM is one of the UK's most trusted training providers in the areas of risk management and business continuity. Check our training program.
Find out more
"
Thank you for an excellent webinar!
Webinar 'Maximising the Benefits from your Penetration Tests'
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.