Blog
Recent blogs

Auditing ISO 42001: Its Unique Requirements and Key Differences From ISO 27001
Published on
28
August
2026
TRENDING
URM's blog examines how the ISO 42001 management system requirements differ from ISO 27001, and the impact this has on what auditors will expect to see.
Read more
Information Security
Published on
4/10/2024
Implementing and Auditing ‘People Controls’ from ISO 27001:2022TRENDING
URM’s blog explains why ‘people’ warrants its own control theme in ISO 27001 and how to prepare for a people controls audit, offering advice for each control.
Data Protection
Published on
27/9/2024
Data Protection Considerations for Monitoring EmployeesTRENDING
URM’s blog offers key advice and detailed guidance on how to balance your organisation’s needs with GDPR compliance as you perform workplace monitoring.
Information Security
Published on
20/9/2024
ISO 27002, the Unsung HeroTRENDING
URM’s blog explains what ISO 27002 is, how it can benefit your organisation, & how you can use it to support your implementation of an ISO 27001-conformant ISMS
Data Protection
Published on
13/9/2024
How to Conduct a Legitimate Interest Assessment (LIA)TRENDING
URM’s blog discusses the importance of LIAs for maintaining compliance with the GDPR, as well as providing a step-by-step breakdown of how to conduct one.
Information Security
Published on
5/9/2024
Common Questions When Managing Supplier Information Security Risks TRENDING
URM’s blog answers key questions on supplier risk management, with a particular focus on the aspects to consider once a supplier has been selected.
Data Protection
Published on
30/8/2024
The ICO Issues its First Notice of Intention to Fine a Data ProcessorTRENDING
URM’s blog explores the first provisional monetary penalty imposed by the ICO exclusively on a data processor & the lessons that can be learned from the case.
Cyber Security
Published on
22/8/2024
Pitfalls to Avoid in your Penetration Testing ProgrammeTRENDING
URM’s blog explores common pen testing mistakes & how to avoid them, and simple improvements you can immediately implement to enhance your security posture.
Other Standards
Published on
16/8/2024
The EU Artificial Intelligence ActTRENDING
URM’s blog breaks down the EU AI Act and discusses its scope, requirements, how it will be enforced, how it may impact the UK & the rest of the world, and more.
Information Security
Published on
8/8/2024
How to Conduct Effective Supplier Information Security Risk ManagementTRENDING
URM’s blog provides a stage-by-stage breakdown of the key steps you will need to take to conduct effective supplier information security risk management.
Cyber Security
Published on
1/8/2024
10 Most Common Vulnerabilities Found in Pen TestsTRENDING
URM’s blog outlines the top 10 most common vulnerabilities we identify when conducting pen tests, the associated risks, and how they can be fixed/avoided.
URM’s consultants have assisted over 450 organisations achieve and maintain certification to ISO 27001.
Find out more
how URM CAN HELP?
URM CONSULTING services
Do you need assistance managing your DSARs?
URM can offer a host of consultancy services to help you managing DSARs, DPIAs ROPAs, privacy notices, data retention schedules and training programmes.
Read more
URM CONSULTING services
Not sure where to begin with GDPR compliance?
We offer a free, no‑obligation call to help you understand your current data protection position and identify the most practical next steps
Read more
URM CONSULTING services
Unsure how PCI DSS applies to your environment?
You do not need a fully scoped programme to speak with us. We offer a free call to help you understand your PCI DSS obligations, clarify scope, and identify practical next steps. Early insight can significantly reduce complexity and cost
Read more
"
Without URM we would not have achieved our certification goals.
Director, Havas People
contact US
Let us help you
Let us help you in your compliance journey by completing the form and letting us know how we can best support you.
