We explain IASME’s clarification of the term ‘point-in-time’ regarding the date that certification is based on.

Watch the video

We discuss perhaps the most brodly impactful change to Cyber Essentials Plus of this year: the new second sampling requirement for update management non-compliances.

Watch the video

We provide an overview of the changes to Cyber Essentials Plus, the scheme’s audited qualification.

Watch the video

We explain the new Cyber Essentials Plus rule banning major non-compliances in the VSA, how it differs from before, and the likely practical impact.

Watch the video

We explore the importance of backups in strengthening their cyber resilience.

Watch the video

We discuss the shift in focus regarding user access control and passwordless authentication options.

Watch the video

We discuss the updates to the guidance for web applications, now titled ‘Application Development’.

Watch the video

We explain the various changes to scoping criteria and how the requirements around scoping have tightened.

Watch the video

We discuss the questions that have been reclassified as ‘automatic failure questions’ in the new Danzell Question Set.

Watch the video

We break down the updates to Cyber Essentials requirements for multi-factor authentication (MFA).

Watch the video

We explain the new formal definition of a ‘cloud service’ that IASME has provided this year.

Watch the video

We provide a high-level overview of the changes to the scheme, from the new Danzell Question Set to the updated Requirements for IT Infrastructure document.

Watch the video

We share the key benefits of implementing ISO 27001 reported by organisations that have achieved certification to the Standard.

Watch the video

We share the key benefits of implementing ISO 27001 reported by organisations that have achieved certification to the Standard.

Watch the video

We break down the structure of ISO 27001, including its ‘Harmonized Structure’ used by other ISO management system standards.

Watch the video

We give a high-level overview of what ISO 27001 is, the background and intention of the Standard, and explain the concept of ISMS

Watch the video

We share the best practices that will allow you to maintain Cyber Essentials and Cyber Essentials Plus certification

Watch the video

This overview gives you a clear picture of today’s cyber risk landscape and what you can do to stay ahead.

Watch the video

This overview gives you a clear picture of today’s cyber risk landscape and what you can do to stay ahead.

Watch the video

This overview gives you a clear picture of today’s cyber risk landscape and what you can do to stay ahead.

Watch the video

This overview gives you a clear picture of today’s cyber risk landscape and what you can do to stay ahead.

Watch the video
Information Security
Published on
30/7/2026
ISO 27001 Clause 7.4: Communication

URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

Information Security
Published on
17/7/2026
The Subtleties of Scheduled Tasks in PCI DSS

URM’s blog explores the nuances and challenges of PCI DSS scheduled activities and practical approaches for improving compliance with periodic requirements.

Information Security
Published on
14/7/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the requirements of ISO 27001 Clause 8.1 and why it matters, as well as sharing key insights on how to properly implement it in practice.

Information Security
Published on
3/7/2026
ISO 27001 Clause 8.1: Effective ISMS operational planning and control

URM’s blog explains the requirements of ISO 27001 Clause 8.1 and why it matters, as well as sharing key insights on how to properly implement it in practice.

Information Security
Published on
26/6/2026
How Organisations Fall Into PCI DSS Scope Without Realising It

URM’s blog explains how organisations can unintentionally and without realising fall into scope of the PCI DSS, despite not directly handling card data.

Information Security
Published on
17/6/2026
ISO 27001 Clause 10.2: Nonconformity and corrective action

URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more

Business Continuity
Published on
12/6/2026
The Essential Must-Dos of Business Continuity

URM’s blog breaks down the foundational ‘must-dos’ that underpin effective business continuity, highlighting key success criteria and common pitfalls for each.

Artificial Intelligence
Published on
5/6/2026
Implementing and Certifying to ISO 42001

URM’s blog breaks down how to effectively implement ISO 42001, where it differs from other ISO standards, and the common certification pitfalls to avoid

Cyber Security
Published on
21/5/2026
Understanding Defence Cyber Certification (DCC)

URM’s blog explains how the DCC works, who needs it, the benefits of certification, with clear guidance on how to approach compliance and avoid common mistakes.

Cyber Security
Published on
21/5/2026
Cyber Security and the Board: The UK Cyber Resilience Pledge in Focus

URM’s blog explains the purpose, structure and content of the Government’s new Cyber Resilience Pledge, and what it means for organisations across the UK.

Artificial Intelligence
Published on
8/5/2026
Artificial Intelligence Frameworks and Regulations: ISO 42001, the NIST AI RMF and the EU AI Act

URM’s blog explores 3 leading AI governance frameworks and regulations, how they complement and differ & what they mean for organisations working with AI.

Information Security
Published on
6/5/2026
Certifying to ISO 27001: Key Tips for Success and Common Pitfalls to Avoid

URM’s blog outlines practical tips for a successful ISO 27001 implementation, and the common mistakes to avoid throughout the certification process.

URM regularly holds FREE webinars on GDPR
Find out more
"
I am pleased to recognise the work of the URM internal auditor we have worked. Throughout all the audits carried out, he has consistently demonstrated professionalism, diligence, and a commitment to excellence in every task undertaken. Thanks to his efforts, we have achieved a very successful first stage ISO 27001:2022 certification audit, with zero findings noted, which has positioned us on track for the second stage audit and for long-term success.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.