Jun 4, 2026 · 35 min · 7 segments
In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a…
Chris HeighesGuest
Wayne ArmstrongGuestAnnieHost
I think the first thing to mention is that organisations might might tend to look more towards what they can do to implement controls and look for where their IT is weak and what all the threats are that are being discussed out there in the big wide world and start implementing things without actually understanding whether those things are required.

Because there are some controls that are obvious, that you don't need risk management to determine whether or not they're required.

So if you are operating on Windows and you're exposed to the internet, then you're going to have to have some kind of antivirus in place.

But I think the thing that a lot of organizations might miss is that they need to understand what it is they're trying to protect in the first place.

So what are the business objectives? What are they trying to achieve? What are the most important information assets, for example, that they want to protect and guard against compromise and determine if those things were compromised, what kind of impact would that cause for the organization? How much would it hurt? And then by doing that, you can concentrate your efforts on protecting those assets in the most appropriate way.

And that's where you put your resources rather than a blanket approach across the organisation.

think a good example of that is one of the new controls that came in with ISO 27001-2022, the data leakage prevention control.

um i think when this was was first mooted a lot of organizations immediately assumed that means we need to get a dlp tool in place um and still quite often when we we go into organizations to do audits or to do risk assessments when we get to the point of talking about about this particular control, data leakage prevention, people straight away say, oh, we're quite weak in there.

And you always want to take a step back and say, well, for this control, what is your risk? What are you actually looking to protect? If you're an organisation that isn't handling very much PII, personal information.

You need to be looking and understanding what data leakages could occur and what would the actual impact of those be.

So rather than, as Wayne was saying, rather than immediately bolting for sort of the technical solution that's going to be all singing and all dancing, you need to look and you need to understand what business risk have you actually got there? What are you actually looking to protect? And also, importantly, understanding what protection you already actually have in place.

I think the first thing to mention is that organisations might might tend to look more towards what they can do to implement controls and look for where their IT is weak and what all the threats are that are being discussed out there in the big wide world and start implementing things without actually understanding whether those things are required.

Because there are some controls that are obvious, that you don't need risk management to determine whether or not they're required.

So if you are operating on Windows and you're exposed to the internet, then you're going to have to have some kind of antivirus in place.

But I think the thing that a lot of organizations might miss is that they need to understand what it is they're trying to protect in the first place.

So what are the business objectives? What are they trying to achieve? What are the most important information assets, for example, that they want to protect and guard against compromise and determine if those things were compromised, what kind of impact would that cause for the organization? How much would it hurt? And then by doing that, you can concentrate your efforts on protecting those assets in the most appropriate way.

And that's where you put your resources rather than a blanket approach across the organisation.

think a good example of that is one of the new controls that came in with ISO 27001-2022, the data leakage prevention control.

um i think when this was was first mooted a lot of organizations immediately assumed that means we need to get a dlp tool in place um and still quite often when we we go into organizations to do audits or to do risk assessments when we get to the point of talking about about this particular control, data leakage prevention, people straight away say, oh, we're quite weak in there.

And you always want to take a step back and say, well, for this control, what is your risk? What are you actually looking to protect? If you're an organisation that isn't handling very much PII, personal information.

You need to be looking and understanding what data leakages could occur and what would the actual impact of those be.

So rather than, as Wayne was saying, rather than immediately bolting for sort of the technical solution that's going to be all singing and all dancing, you need to look and you need to understand what business risk have you actually got there? What are you actually looking to protect? And also, importantly, understanding what protection you already actually have in place.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.