<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spoiledlunch</title><link>https://072f2ff5.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Fri, 24 Apr 2026 08:20:00 -0400</lastBuildDate><atom:link href="https://072f2ff5.spoiledlunch.pages.dev/topics/grc/" rel="self" type="application/rss+xml"/><item><title>Compliance Gets Better When Regulators Ship Tools Instead of Slogans</title><link>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-24-compliance-gets-better-when-regulators-ship-tools-instead-of-slogans/</link><pubDate>Fri, 24 Apr 2026 08:20:00 -0400</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-24-compliance-gets-better-when-regulators-ship-tools-instead-of-slogans/</guid><description>
&lt;![CDATA[<p><strong>Article</strong> • April 24, 2026 • 2 min read</p><p><strong>Topics:</strong> GRC</p><p>A lot of compliance guidance dies as slideware because it explains principles without changing the operator&rsquo;s daily work. The more interesting recent GRC signal is that standards bodies and …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-24-compliance-gets-better-when-regulators-ship-tools-instead-of-slogans/">Read full analysis →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>compliance</category><category>gdpr</category><category>csf 2.0</category><category>governance</category></item><item><title>Why AI Governance Frameworks Are Security Theater</title><link>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</link><pubDate>Mon, 20 Apr 2026 09:00:00 -0700</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</guid><description>
&lt;![CDATA[<p><strong>Article</strong> • April 20, 2026 • 4 min read</p><p><strong>Topics:</strong> AI, GRC</p><p>Why AI Governance Frameworks Are Security Theater Most enterprise AI governance frameworks are elaborate exercises in checkbox compliance that miss the actual risks. They&rsquo;re designed to satisfy …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/">Read full analysis →</a></p>
]]></description><author>@spoiledlunch</author><category>AI</category><category>GRC</category><category>governance</category><category>risk management</category><category>enterprise AI</category><category>compliance</category></item><item><title>The SOC 2 Compliance Cargo Cult</title><link>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</link><pubDate>Sat, 18 Apr 2026 14:30:00 -0700</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</guid><description>
&lt;![CDATA[<p><strong>Article</strong> • April 18, 2026 • 6 min read</p><p><strong>Topics:</strong> GRC, Security</p><p>The SOC 2 Compliance Cargo Cult SOC 2 compliance has become a cargo cult ritual in enterprise security. Organizations implement the ceremonial controls, follow the prescribed procedures, and wait for …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/">Read full analysis →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>Security</category><category>SOC 2</category><category>compliance</category><category>security controls</category><category>audit</category></item><item><title>EDPB Sharpens Research Guidance and Speeds Up Anonymisation Work</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-16-edpb-brings-clarity-to-data-processing-for-scientific-research-speeds-up-the-finalisation-of-the-anonymisation-guidelines-and-approves-first-european-data-protection-seal-as-a-tool-for-transfers/</link><pubDate>Thu, 16 Apr 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-16-edpb-brings-clarity-to-data-processing-for-scientific-research-speeds-up-the-finalisation-of-the-anonymisation-guidelines-and-approves-first-european-data-protection-seal-as-a-tool-for-transfers/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • April 16, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: EDPB used its April plenary to tighten guidance on scientific-research processing, accelerate anonymisation work, and approve a new …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-16-edpb-brings-clarity-to-data-processing-for-scientific-research-speeds-up-the-finalisation-of-the-anonymisation-guidelines-and-approves-first-european-data-protection-seal-as-a-tool-for-transfers/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>edpb</category><category>research</category><category>anonymisation</category></item><item><title>FTC Targets Noncompete Agreements in Pest Control Enforcement Action</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-15-ftc-takes-action-against-noncompete-agreements-securing-protections-for-workers/</link><pubDate>Wed, 15 Apr 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-15-ftc-takes-action-against-noncompete-agreements-securing-protections-for-workers/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • April 15, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: The FTC ordered Rollins to stop enforcing noncompete agreements against thousands of workers and paired the action with warning letters to …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-15-ftc-takes-action-against-noncompete-agreements-securing-protections-for-workers/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>ftc</category><category>labor</category><category>enforcement</category></item><item><title>FTC Bars Forever Living From Deceptive Earnings Claims</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-14-ftc-order-to-prohibit-forever-living-and-its-operators-from-deceiving-consumers-about-potential-earnings/</link><pubDate>Tue, 14 Apr 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-14-ftc-order-to-prohibit-forever-living-and-its-operators-from-deceiving-consumers-about-potential-earnings/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • April 14, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: The FTC settled with Forever Living and its operators, permanently barring deceptive earnings claims and reinforcing that consumer-protection …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-14-ftc-order-to-prohibit-forever-living-and-its-operators-from-deceiving-consumers-about-potential-earnings/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>ftc</category><category>enforcement</category><category>consumer-protection</category></item><item><title>EDPB Annual Report 2025 Highlights the Board's Enforcement Priorities</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-09-edpb-annual-report-2025-supporting-stakeholders-through-guidance-and-dialogue/</link><pubDate>Thu, 09 Apr 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-09-edpb-annual-report-2025-supporting-stakeholders-through-guidance-and-dialogue/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • April 9, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: EDPB&rsquo;s 2025 annual report summarizes the board&rsquo;s guidance, coordination, and enforcement priorities, giving privacy teams a …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-04-09-edpb-annual-report-2025-supporting-stakeholders-through-guidance-and-dialogue/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>edpb</category><category>enforcement</category><category>privacy</category></item><item><title>EDPB Publishes One-Stop-Shop Digest on Legitimate Interest</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-26-one-stop-shop-case-digest-on-the-legal-basis-of-legitimate-interest/</link><pubDate>Thu, 26 Mar 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-26-one-stop-shop-case-digest-on-the-legal-basis-of-legitimate-interest/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • March 26, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: EDPB published a digest of one-stop-shop decisions on legitimate interest, giving privacy teams a clearer signal on how regulators are …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-26-one-stop-shop-case-digest-on-the-legal-basis-of-legitimate-interest/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>edpb</category><category>gdpr</category><category>legitimate-interest</category></item><item><title>EDPB conference on cross-regulatory cooperation: what we learned</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-24-edpb-conference-on-cross-regulatory-cooperation-what-we-learned/</link><pubDate>Tue, 24 Mar 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-24-edpb-conference-on-cross-regulatory-cooperation-what-we-learned/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • March 24, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: EDPB used its March conference to press for deeper coordination between privacy regulators and adjacent EU authorities, signaling that …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-24-edpb-conference-on-cross-regulatory-cooperation-what-we-learned/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>edpb</category><category>regulation</category><category>coordination</category></item><item><title>NIST Releases CSF 2.0 Quick-Start Guides for ERM and Informative References</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/</link><pubDate>Mon, 23 Mar 2026 09:00:00 -0400</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • March 23, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: NIST announced two Cybersecurity Framework 2.0 quick-start guide updates on March 23, 2026. The agency released the final SP 1308 guide on …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-23-nist-releases-csf-2-0-quick-start-guides-for-erm-and-informative-references/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>NIST</category><category>CSF 2.0</category><category>ERM</category><category>governance</category></item><item><title>EDPB and EDPS Back Stronger EU Cybersecurity Rules While Guarding Personal Data</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-19-edpb-and-edps-support-strengthening-eu-s-cybersecurity-and-easing-compliance-while-protecting-individuals-personal-data/</link><pubDate>Thu, 19 Mar 2026 12:00:00 +0000</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-19-edpb-and-edps-support-strengthening-eu-s-cybersecurity-and-easing-compliance-while-protecting-individuals-personal-data/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • March 19, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: EDPB and EDPS issued a joint opinion on the Commission&rsquo;s CSA2 and NIS2 proposals, arguing the EU can streamline cybersecurity …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-03-19-edpb-and-edps-support-strengthening-eu-s-cybersecurity-and-easing-compliance-while-protecting-individuals-personal-data/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>grc</category><category>edpb</category><category>cybersecurity</category><category>privacy</category></item><item><title>EDPB Sets a 2026-2027 Programme Focused on Compliance and Regulatory Coordination</title><link>https://072f2ff5.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/</link><pubDate>Thu, 12 Feb 2026 09:00:00 +0100</pubDate><guid>https://072f2ff5.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/</guid><description>
&lt;![CDATA[<p><strong>News Brief</strong> • February 12, 2026</p><p><strong>Topics:</strong> GRC</p><p>Summary: The European Data Protection Board adopted its 2026-2027 work programme on February 12, 2026. The programme emphasizes making GDPR compliance …</p><p><a href="https://072f2ff5.spoiledlunch.pages.dev/news/2026-02-12-edpb-sets-a-2026-2027-programme-focused-on-compliance-and-regulatory-coordination/">Read brief →</a></p>
]]></description><author>@spoiledlunch</author><category>GRC</category><category>EDPB</category><category>GDPR</category><category>privacy</category><category>compliance</category></item></channel></rss>