<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[The GRC Engineering Club's AntiCheckBox Podcast]]></title><description><![CDATA[<p>Compliance became a documentation ritual somewhere along the way. <br /><br />Screenshots, spreadsheets, a scramble every quarter, and a piece of paper at the end that tells you almost nothing about whether the control actually works. That job is getting automated out from under the people doing it, and good riddance.</p><p><br />The AntiCheckbox Podcast is about the other version of this work. Controls as a data and engineering problem. Evidence that generates itself. Governance you can defend to a regulator, a board, or a plaintiff's attorney because the system produces the proof, not because somebody filled in a cell.<br /></p><p>Every week we sit down with the practitioners actually building this way. Auditors who got tired of asking for screenshots and learned to write code. Engineers who got handed a framework and refused to accept that it had to be miserable. The people writing the standards, the people running programs at scale, and the ones who lived through the audit that changed how they think.<br /></p><p>No vendor pitches. No certification worship. No pretending the current model is fine.<br /></p><p>If you work in GRC, security, risk, audit, privacy, or you are trying to get into any of it and cannot get a straight answer from anybody, this is for you.<br /></p><p>The show is the front door to the GRC Engineering Club, a community of practitioners doing this work in the open. Early episodes, the Slack, and The Convergence newsletter live at <a rel="noopener noreferrer nofollow" href="http://patreon.com/c/GRCEngineeringClub" target="_blank">patreon.com/c/GRCEngineeringClub</a>.</p>]]></description><link>https://www.patreon.com/c/GRCEngineeringClub</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Thu, 06 Aug 2026 05:13:22 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/GsHodstG.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Dr. Omar Sangurima]]></author><pubDate>Tue, 28 Jul 2026 10:27:44 GMT</pubDate><copyright><![CDATA[2026 Dr. Omar Sangurima]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Management]]></category><category><![CDATA[Technology]]></category><itunes:author>Dr. Omar Sangurima</itunes:author><itunes:summary>&lt;p&gt;Compliance became a documentation ritual somewhere along the way. &lt;br /&gt;&lt;br /&gt;Screenshots, spreadsheets, a scramble every quarter, and a piece of paper at the end that tells you almost nothing about whether the control actually works. That job is getting automated out from under the people doing it, and good riddance.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The AntiCheckbox Podcast is about the other version of this work. Controls as a data and engineering problem. Evidence that generates itself. Governance you can defend to a regulator, a board, or a plaintiff&apos;s attorney because the system produces the proof, not because somebody filled in a cell.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Every week we sit down with the practitioners actually building this way. Auditors who got tired of asking for screenshots and learned to write code. Engineers who got handed a framework and refused to accept that it had to be miserable. The people writing the standards, the people running programs at scale, and the ones who lived through the audit that changed how they think.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;No vendor pitches. No certification worship. No pretending the current model is fine.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;If you work in GRC, security, risk, audit, privacy, or you are trying to get into any of it and cannot get a straight answer from anybody, this is for you.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The show is the front door to the GRC Engineering Club, a community of practitioners doing this work in the open. Early episodes, the Slack, and The Convergence newsletter live at &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;http://patreon.com/c/GRCEngineeringClub&quot; target=&quot;_blank&quot;&gt;patreon.com/c/GRCEngineeringClub&lt;/a&gt;.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Dr. Omar Sangurima</itunes:name><itunes:email>osangurima1@gmail.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"><itunes:category text="Management"/></itunes:category><itunes:category text="Technology"/><itunes:image href="https://hosting-media.riverside.com/media/podcasts/7d1f7887-ea92-407c-bfaf-bf88ea0aee37/logos/e145917d-56c2-4af5-b7e5-3ce0cc1b2ff6.jpeg"/><item><title><![CDATA[People Don't Scale: Tamelia Hutchinson on the 40 Year "Fad" of GRC Engineering]]></title><description><![CDATA[<p>We asked Tamelia Hutchinson whether GRC engineering is a fad or here to stay. She answered with a question of her own: what is your definition of GRC engineering? Everything after that was worth the price of admission.<br /><br />Tamelia has spent about twenty years in security and compliance, accidentally at first and then on purpose. In this one she splits GRC engineering into its process side and its technical side, argues neither one is going anywhere, and lands on a phrase that is going to live in our head for a while: it has been a fad for forty years, so it is a fad in the geological sense.<br /><br />We get into the thing nobody warns you about, which is that if you automate a bad process, you are just automating your demise. You get to the cliff faster. Tamelia walks through why software led transformation stalls when the people on the receiving end were never brought along, what she does when there is no internal proof of concept to point at, and the specific question she asks to get a stakeholder to imagine a different way of working instead of defending the current one.<br /><br />She also breaks down how she actually learned to talk to leadership, which was not from a book. It was from sitting in rooms with people who were better at it than she was, listening for what connected, and then adapting it rather than copying it. Her line on that: copying someone else's delivery is like wearing somebody else's pants who says they are going to fit you.<br /><br />And then there is the part we did not see coming. Leadership asked her how they would know the investment in compliance and security had paid off. Her answer was that they would know when they could let her go. When the maturity is high enough and the toil is reduced enough that her position is not needed. Her reasoning is the whole thesis of this show compressed into three words: people don't scale.<br /><br />The GRC Engineering Club is a community of practitioners treating governance, risk, and compliance as an engineering discipline instead of a documentation ritual. <br /><br />Subscribe for new episodes of the AntiCheckbox Podcast every week.<br /><br />#GRC #GRCEngineering #Cybersecurity #Compliance #RiskManagement #SecurityLeadership #DevSecOps #Automation<br /><br />---<br /><br />Learn GRC Engineering:<br />- GRC Engineering 101: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-engineering-101" target="_blank">https://grcengclub.com/learn/grc-engineering-101</a><br />- How to Break Into GRC Engineering: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/how-to-break-into-grc-engineering" target="_blank">https://grcengclub.com/learn/how-to-break-into-grc-engineering</a><br />- GRC Engineer Salary Guide: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-engineering-salary" target="_blank">https://grcengclub.com/learn/grc-engineering-salary</a><br />- GRC vs Traditional GRC: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-vs-traditional-grc" target="_blank">https://grcengclub.com/learn/grc-vs-traditional-grc</a><br /><br />Website: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com" target="_blank">https://grcengclub.com</a><br />Merch: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/merch" target="_blank">https://grcengclub.com/merch</a><br />Patreon: <a rel="noopener noreferrer nofollow" href="https://www.patreon.com/cw/GRCEngineeringClub" target="_blank">https://www.patreon.com/cw/GRCEngineeringClub</a><br />LinkedIn: <a rel="noopener noreferrer nofollow" href="https://www.linkedin.com/company/grc-engineering-club/" target="_blank">https://www.linkedin.com/company/grc-engineering-club/</a></p>]]></description><guid isPermaLink="false">ae62d57e-4205-448a-b5ad-99e8788414e3</guid><dc:creator><![CDATA[Dr. Omar Sangurima]]></dc:creator><pubDate>Sat, 01 Aug 2026 13:15:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/92acd05e7e46d0bd5cd52fad07b830c062c2228cab5f4682478afb0fc4b6437b/eyJlcGlzb2RlSWQiOiJhZTYyZDU3ZS00MjA1LTQ0OGEtYjVhZC05OWU4Nzg4NDE0ZTMiLCJwb2RjYXN0SWQiOiI3ZDFmNzg4Ny1lYTkyLTQwN2MtYmZhZi1iZjg4ZWEwYWVlMzciLCJhY2NvdW50SWQiOiI2NWJmYTM3OThjMzlmNGVkMjFmNDkyZmUiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1M2ViZWMzZDIxOTY0MzJiN2U5YzlhL29tYXItc2FuZ3VyaW1hcy1zdHVkaW8tY29tcG9zZXItMjAyNi03LTEyX18yMS0zMy0wLm1wMyJ9.mp3" length="79404869" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/7d1f7887-ea92-407c-bfaf-bf88ea0aee37/episodes/ae62d57e-4205-448a-b5ad-99e8788414e3/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;We asked Tamelia Hutchinson whether GRC engineering is a fad or here to stay. She answered with a question of her own: what is your definition of GRC engineering? Everything after that was worth the price of admission.&lt;br /&gt;&lt;br /&gt;Tamelia has spent about twenty years in security and compliance, accidentally at first and then on purpose. In this one she splits GRC engineering into its process side and its technical side, argues neither one is going anywhere, and lands on a phrase that is going to live in our head for a while: it has been a fad for forty years, so it is a fad in the geological sense.&lt;br /&gt;&lt;br /&gt;We get into the thing nobody warns you about, which is that if you automate a bad process, you are just automating your demise. You get to the cliff faster. Tamelia walks through why software led transformation stalls when the people on the receiving end were never brought along, what she does when there is no internal proof of concept to point at, and the specific question she asks to get a stakeholder to imagine a different way of working instead of defending the current one.&lt;br /&gt;&lt;br /&gt;She also breaks down how she actually learned to talk to leadership, which was not from a book. It was from sitting in rooms with people who were better at it than she was, listening for what connected, and then adapting it rather than copying it. Her line on that: copying someone else&apos;s delivery is like wearing somebody else&apos;s pants who says they are going to fit you.&lt;br /&gt;&lt;br /&gt;And then there is the part we did not see coming. Leadership asked her how they would know the investment in compliance and security had paid off. Her answer was that they would know when they could let her go. When the maturity is high enough and the toil is reduced enough that her position is not needed. Her reasoning is the whole thesis of this show compressed into three words: people don&apos;t scale.&lt;br /&gt;&lt;br /&gt;The GRC Engineering Club is a community of practitioners treating governance, risk, and compliance as an engineering discipline instead of a documentation ritual. &lt;br /&gt;&lt;br /&gt;Subscribe for new episodes of the AntiCheckbox Podcast every week.&lt;br /&gt;&lt;br /&gt;#GRC #GRCEngineering #Cybersecurity #Compliance #RiskManagement #SecurityLeadership #DevSecOps #Automation&lt;br /&gt;&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;Learn GRC Engineering:&lt;br /&gt;- GRC Engineering 101: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-engineering-101&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-engineering-101&lt;/a&gt;&lt;br /&gt;- How to Break Into GRC Engineering: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/how-to-break-into-grc-engineering&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/how-to-break-into-grc-engineering&lt;/a&gt;&lt;br /&gt;- GRC Engineer Salary Guide: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-engineering-salary&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-engineering-salary&lt;/a&gt;&lt;br /&gt;- GRC vs Traditional GRC: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-vs-traditional-grc&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-vs-traditional-grc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Website: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com&lt;/a&gt;&lt;br /&gt;Merch: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/merch&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/merch&lt;/a&gt;&lt;br /&gt;Patreon: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.patreon.com/cw/GRCEngineeringClub&quot; target=&quot;_blank&quot;&gt;https://www.patreon.com/cw/GRCEngineeringClub&lt;/a&gt;&lt;br /&gt;LinkedIn: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.linkedin.com/company/grc-engineering-club/&quot; target=&quot;_blank&quot;&gt;https://www.linkedin.com/company/grc-engineering-club/&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:41:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/7d1f7887-ea92-407c-bfaf-bf88ea0aee37/logos/e145917d-56c2-4af5-b7e5-3ce0cc1b2ff6.jpeg"/><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><itunes:title>People Don&apos;t Scale: Tamelia Hutchinson on the 40 Year &quot;Fad&quot; of GRC Engineering</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran from Locktivity]]></title><description><![CDATA[<p>"We have this weird model where it's like hand me a SOC 2 or answer a questionnaire, tell me everything's good, let's shake hands and move on. And then we forgot to enable 2FA..."  <br /><br />In this episode of the Anti Checkbox Podcast, O sits down with Rachel Curran to dismantle the current state of Third-Party Risk Management (TPRM). Rachel brings a brutally honest perspective to the industry, explaining why the traditional reliance on massive questionnaires and point-in-time compliance frameworks is nothing more than "security theater."  <br /><br />We discuss why small 10-to-12 person startups are being sold a false narrative that they need a SOC 2 or ISO certification just to do business. Instead, Rachel argues for a return to first principles: focusing on continuous monitoring of core security hygiene, like Multi-Factor Authentication (MFA), which can stop the vast majority of breaches. We also explore how a transparent, right-sized security program acts as a "trust marketplace" that can actually help companies close six-figure deals.  <br /><br />Key Takeaways:<br /><br />Security Theater: Why passing around massive questionnaires and point-in-time SOC 2 reports completely fails to stop actual breaches.  <br /><br />The MFA Mandate: Why prioritizing basic hygiene like MFA and encryption is infinitely more valuable than completing 250-point compliance checklists.  <br /><br />Advice for Startups: Why tiny companies should avoid the trap of pursuing expensive SOC 2 certifications and instead invest in a few hours of expert consulting to nail down core business risks.  <br /><br />Selling with Security: How treating third-party risk as a competitive differentiator can get you budget, build trust, and help your company close major enterprise deals.  <br /><br /><br />Learn GRC Engineering:<br />- GRC Engineering 101: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-engineering-101" target="_blank">https://grcengclub.com/learn/grc-engineering-101</a><br />- How to Break Into GRC Engineering: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/how-to-break-into-grc-engineering" target="_blank">https://grcengclub.com/learn/how-to-break-into-grc-engineering</a><br />- GRC Engineer Salary Guide: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-engineering-salary" target="_blank">https://grcengclub.com/learn/grc-engineering-salary</a><br />- GRC vs Traditional GRC: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/learn/grc-vs-traditional-grc" target="_blank">https://grcengclub.com/learn/grc-vs-traditional-grc</a><br /><br />Website: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com" target="_blank">https://grcengclub.com</a><br />Merch: <a rel="noopener noreferrer nofollow" href="https://grcengclub.com/merch" target="_blank">https://grcengclub.com/merch</a><br />Patreon: <a rel="noopener noreferrer nofollow" href="https://www.patreon.com/cw/GRCEngineeringClub" target="_blank">https://www.patreon.com/cw/GRCEngineeringClub</a><br />LinkedIn: <a rel="noopener noreferrer nofollow" href="https://www.linkedin.com/company/grc-engineering-club/" target="_blank">https://www.linkedin.com/company/grc-engineering-club/</a></p>]]></description><guid isPermaLink="false">29d66140-eb98-4710-9862-2d546ecb0316</guid><dc:creator><![CDATA[Dr. Omar Sangurima]]></dc:creator><pubDate>Tue, 28 Jul 2026 22:24:49 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/63fa13d94a2b90594076380310057c99cb5caabe8b97c52211264a6e4b891771/eyJlcGlzb2RlSWQiOiIyOWQ2NjE0MC1lYjk4LTQ3MTAtOTg2Mi0yZDU0NmVjYjAzMTYiLCJwb2RjYXN0SWQiOiI3ZDFmNzg4Ny1lYTkyLTQwN2MtYmZhZi1iZjg4ZWEwYWVlMzciLCJhY2NvdW50SWQiOiI2NWJmYTM3OThjMzlmNGVkMjFmNDkyZmUiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1YWNhZjE3NjYyMzU3OTMzY2M5Zjc1L29tYXItc2FuZ3VyaW1hcy1zdHVkaW8tY29tcG9zZXItMjAyNi03LTE4X18yLTM4LTkubXAzIn0=.mp3" length="91310855" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/7d1f7887-ea92-407c-bfaf-bf88ea0aee37/episodes/29d66140-eb98-4710-9862-2d546ecb0316/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;&quot;We have this weird model where it&apos;s like hand me a SOC 2 or answer a questionnaire, tell me everything&apos;s good, let&apos;s shake hands and move on. And then we forgot to enable 2FA...&quot;  &lt;br /&gt;&lt;br /&gt;In this episode of the Anti Checkbox Podcast, O sits down with Rachel Curran to dismantle the current state of Third-Party Risk Management (TPRM). Rachel brings a brutally honest perspective to the industry, explaining why the traditional reliance on massive questionnaires and point-in-time compliance frameworks is nothing more than &quot;security theater.&quot;  &lt;br /&gt;&lt;br /&gt;We discuss why small 10-to-12 person startups are being sold a false narrative that they need a SOC 2 or ISO certification just to do business. Instead, Rachel argues for a return to first principles: focusing on continuous monitoring of core security hygiene, like Multi-Factor Authentication (MFA), which can stop the vast majority of breaches. We also explore how a transparent, right-sized security program acts as a &quot;trust marketplace&quot; that can actually help companies close six-figure deals.  &lt;br /&gt;&lt;br /&gt;Key Takeaways:&lt;br /&gt;&lt;br /&gt;Security Theater: Why passing around massive questionnaires and point-in-time SOC 2 reports completely fails to stop actual breaches.  &lt;br /&gt;&lt;br /&gt;The MFA Mandate: Why prioritizing basic hygiene like MFA and encryption is infinitely more valuable than completing 250-point compliance checklists.  &lt;br /&gt;&lt;br /&gt;Advice for Startups: Why tiny companies should avoid the trap of pursuing expensive SOC 2 certifications and instead invest in a few hours of expert consulting to nail down core business risks.  &lt;br /&gt;&lt;br /&gt;Selling with Security: How treating third-party risk as a competitive differentiator can get you budget, build trust, and help your company close major enterprise deals.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Learn GRC Engineering:&lt;br /&gt;- GRC Engineering 101: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-engineering-101&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-engineering-101&lt;/a&gt;&lt;br /&gt;- How to Break Into GRC Engineering: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/how-to-break-into-grc-engineering&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/how-to-break-into-grc-engineering&lt;/a&gt;&lt;br /&gt;- GRC Engineer Salary Guide: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-engineering-salary&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-engineering-salary&lt;/a&gt;&lt;br /&gt;- GRC vs Traditional GRC: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/learn/grc-vs-traditional-grc&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/learn/grc-vs-traditional-grc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Website: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com&lt;/a&gt;&lt;br /&gt;Merch: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://grcengclub.com/merch&quot; target=&quot;_blank&quot;&gt;https://grcengclub.com/merch&lt;/a&gt;&lt;br /&gt;Patreon: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.patreon.com/cw/GRCEngineeringClub&quot; target=&quot;_blank&quot;&gt;https://www.patreon.com/cw/GRCEngineeringClub&lt;/a&gt;&lt;br /&gt;LinkedIn: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.linkedin.com/company/grc-engineering-club/&quot; target=&quot;_blank&quot;&gt;https://www.linkedin.com/company/grc-engineering-club/&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:33</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/7d1f7887-ea92-407c-bfaf-bf88ea0aee37/logos/e145917d-56c2-4af5-b7e5-3ce0cc1b2ff6.jpeg"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:title>The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran from Locktivity</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>