<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spoiledlunch</title><link>https://05504994.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Mon, 20 Apr 2026 09:00:00 -0700</lastBuildDate><atom:link href="https://05504994.spoiledlunch.pages.dev/topics/grc/" rel="self" type="application/rss+xml"/><item><title>Why AI Governance Frameworks Are Security Theater</title><link>https://05504994.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</link><pubDate>Mon, 20 Apr 2026 09:00:00 -0700</pubDate><guid>https://05504994.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</guid><description>
&lt;![CDATA[<p><strong>Article</strong> • April 20, 2026 • 4 min read</p><p><strong>Topics:</strong> AI, GRC</p><p>Why AI Governance Frameworks Are Security Theater Most enterprise AI governance frameworks are elaborate exercises in checkbox compliance that miss the actual risks. They&rsquo;re designed to satisfy …</p><p><a href="https://05504994.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/">Read full analysis →</a></p>
]]></description><author>@spoiledlunch</author><category>AI</category><category>GRC</category><category>governance</category><category>risk management</category><category>enterprise AI</category><category>compliance</category></item><item><title>The SOC 2 Compliance Cargo Cult</title><link>https://05504994.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</link><pubDate>Sat, 18 Apr 2026 14:30:00 -0700</pubDate><guid>https://05504994.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</guid><description>
&lt;![CDATA[<p><strong>Article</strong> • April 18, 2026 • 6 min read</p><p><strong>Topics:</strong> GRC, Security</p><p>The SOC 2 Compliance Cargo Cult SOC 2 compliance has become a cargo cult ritual in enterprise security. Organizations implement the ceremonial controls, follow the prescribed procedures, and wait for …</p><p><a href="https://05504994.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/">Read full analysis →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>Security</category><category>SOC 2</category><category>compliance</category><category>security controls</category><category>audit</category></item><item><title>NIST Releases CSF 2.0 Quick-Start Guides for ERM and Informative References</title><link>https://05504994.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/</link><pubDate>Mon, 23 Mar 2026 09:00:00 -0400</pubDate><guid>https://05504994.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • March 23, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: NIST announced two Cybersecurity Framework 2.0 quick-start guide updates on March 23, 2026. The agency released the final SP 1308 guide on …</p><p><a href="https://05504994.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>NIST</category><category>CSF 2.0</category><category>ERM</category><category>governance</category></item><item><title>EDPB Sets a 2026-2027 Programme Focused on Compliance and Regulatory Coordination</title><link>https://05504994.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/</link><pubDate>Thu, 12 Feb 2026 09:00:00 +0100</pubDate><guid>https://05504994.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • February 12, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: The European Data Protection Board adopted its 2026-2027 work programme on February 12, 2026. The programme emphasizes making GDPR compliance …</p><p><a href="https://05504994.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>EDPB</category><category>GDPR</category><category>privacy</category><category>compliance</category></item></channel></rss>