<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spoiledlunch</title><link>https://30b79ea5.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 09:00:00 -0400</lastBuildDate><atom:link href="https://30b79ea5.spoiledlunch.pages.dev/topics/grc/" rel="self" type="application/rss+xml"/><item><title>Risk Registers Become Graveyards for Unowned Problems</title><link>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-05-01-why-risk-registers-become-graveyards-for-unowned-problems/</link><pubDate>Tue, 28 Jul 2026 09:00:00 -0400</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-05-01-why-risk-registers-become-graveyards-for-unowned-problems/</guid><description>Article • July 28, 2026 • 5 min read | Topics: GRC | Most risk registers start as decision tools and end as storage.
That is the failure.
In theory, the register is where an organization records meaningful risks, assigns ownership, evaluates treatment …</description><content:encoded>&lt;![CDATA[<p>Most risk registers start as decision tools and end as storage.</p><p>That is the failure.</p><p>In theory, the register is where an organization records meaningful risks, assigns ownership, evaluates treatment options, and makes visible choices about what will be reduced, transferred, accepted, or escalated. In practice, many registers become long-lived museums of unresolved issues. The entry exists. The discussion happened once. The status field changes occasionally. Nothing decisive follows.</p><p>That is why so many risk registers feel less like governance and more like ceremonial memory.</p><h2 id="a-populated-register-can-hide-a-weak-governance-model">A populated register can hide a weak governance model</h2><p>The existence of a detailed register often reassures leadership. It creates the appearance of discipline. Risks are named. Ratings exist. review dates exist. Owners are listed. The organization can tell itself it has visibility.</p><p>But a register full of entries is not the same thing as a system that drives decisions.</p><p>The harder question is whether anything actually happens when a risk remains open, gets worse, or conflicts with business pressure. In many enterprises the answer is not much. The register records the problem faithfully while the underlying operating model avoids the confrontation required to change it.</p><p>That is why the register so often sits next to<a href="/articles/2026-05-01-compliance-exceptions-tell-you-more-than-your-passed-controls/">an exception program that keeps renewing the same nonconforming conditions</a> without forcing structural action.</p><p>That is how the register turns into a graveyard. It preserves evidence that the organization knew. It does not prove the organization governed.</p><h2 id="the-ownership-field-is-often-fiction">The ownership field is often fiction</h2><p>One reason this happens is that risk ownership is routinely assigned to people who can describe the problem but cannot truly resolve it.</p><p>A technology leader may be named owner for a risk rooted in budget constraints they do not control. A compliance lead may own a dependency risk that spans three business units and a vendor contract. A product executive may inherit privacy risk for a system whose architecture is shaped by an old platform team and a newer procurement mandate.</p><p>The name goes into the register because the process requires one.</p><p>But ownership without authority is administrative theater.</p><p>The result is predictable. The owner updates status, restates mitigation challenges, and requests time. The risk stays present but operationally unclaimed. Over time the organization normalizes that condition. The register entry remains open long enough that it stops feeling urgent and starts feeling structural.</p><p>That is not risk management. That is documentation of stalemate.</p><h2 id="rating-discipline-often-degrades-into-mood">Rating discipline often degrades into mood</h2><p>Another graveyard pattern is score inflation without consequence.</p><p>If too many risks are rated medium, the register becomes bland. If too many are rated high, leadership tunes out. In response, teams start calibrating ratings politically instead of analytically. They make entries sound serious enough to protect themselves but not serious enough to trigger the escalation nobody wants.</p><p>Then the register stops reflecting exposure and starts reflecting organizational comfort.</p><p>This is why stale risk language is so dangerous. A register can remain full of technically correct statements while becoming operationally useless. The words survive. The decision energy drains away.</p><h2 id="registers-decay-when-escalation-has-no-teeth">Registers decay when escalation has no teeth</h2><p>The best test of a register is simple: what happens to a risk that sits open too long without meaningful treatment?</p><p>If the answer is &ldquo;it remains on the register and is reviewed again next quarter,&rdquo; then the register is not governing much.</p><p>Serious risk management requires consequence. Not necessarily punishment, but movement. An open risk should eventually force one of a few outcomes:</p><ul><li>funded remediation</li><li>accepted exposure with explicit rationale</li><li>architectural change</li><li>compensating controls with accountable owners</li><li>executive escalation because the current state is no longer tolerable</li></ul><p>Without those paths, the register becomes a polite place to keep bad news from disappearing entirely.</p><p>That is still better than ignorance. It is not good enough to call mature.</p><h2 id="the-register-should-support-decisions-not-replace-them">The register should support decisions, not replace them</h2><p>This is the conceptual error underneath a lot of GRC tooling. Teams start treating the register as if recording the risk is itself a governance act.</p><p>It is not.</p><p>The governance act is the decision the register should force. The record is only the evidence that the decision happened or failed to happen.</p><p>When organizations lose that distinction, the register becomes a substitute for action. People feel better because the issue is visible, tracked, and reported upward. Meanwhile the same technical debt, staffing gap, architectural fragility, or third-party dependency remains in place year after year under increasingly polished documentation.</p><h2 id="better-registers-are-smaller-harsher-and-harder-to-ignore">Better registers are smaller, harsher, and harder to ignore</h2><p>A healthier register usually has fewer entries than a performatively mature one.</p><p>That is not because fewer risks exist. It is because the organization distinguishes between observations, issues, control deficiencies, and true decision-grade risks. It does not turn every unpleasant fact into a permanent catalog entry. It uses the register for the items that actually require governance attention.</p><p>Those entries should have:</p><ul><li>a clear exposure statement</li><li>an owner with authority or a defined escalation path</li><li>a treatment decision, not just a description</li><li>a realistic review cadence tied to change, not ceremony</li><li>an expiration point for passive acceptance</li></ul><p>That last point matters. Endless acceptance is usually just a slower way of saying nobody wants to decide.</p><h2 id="bottom-line">Bottom Line</h2><p>Risk registers become graveyards when organizations use them to preserve awareness of unowned problems instead of forcing decisions about them.</p><p>The register is useful only if it creates pressure: pressure to fund, pressure to accept explicitly, pressure to escalate, or pressure to stop pretending someone else will eventually handle it.</p><p>Without that pressure, the organization ends up with the same decorative maturity problem described in<a href="/articles/2026-05-02-control-mapping-is-not-governance/">control mapping that looks complete while the environment stays weakly governed</a>.</p><p>If a risk can stay in the register indefinitely without changing money, architecture, ownership, or executive attention, then the register is not managing risk.</p><p>It is archiving it.</p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>risk management</category><category>grc</category><category>ownership</category><category>governance</category></item><item><title>SEC Announces Departure of Principal Deputy Director of Enforcement Sam Waldon</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-22-sec-announces-departure-of-principal-deputy-director-of-enforcement-sam-waldon/</link><pubDate>Wed, 22 Jul 2026 13:45:25 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-22-sec-announces-departure-of-principal-deputy-director-of-enforcement-sam-waldon/</guid><description>News Brief • July 22, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today announced that Sam Waldon, Principal Deputy Director of the Division of Enforcement, will depart …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission today announced that Sam Waldon, Principal Deputy Director of the Division of Enforcement, will depart the agency on July 31, 2026, after more than 14 years at the SEC.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-68-sec-announces-departure-principal-deputy-director-enforcement-sam-waldon">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>David Vélez and Robin Vince join the boards of the OpenAI Foundation and OpenAI Group PBC</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-21-david-v%C3%A9lez-and-robin-vince-join-the-boards-of-the-openai-foundation-and-openai-group-pbc/</link><pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-21-david-v%C3%A9lez-and-robin-vince-join-the-boards-of-the-openai-foundation-and-openai-group-pbc/</guid><description>News Brief • July 21, 2026 | Topics: GRC | Summary: David Vélez and Robin Vince join the boards of the OpenAI Foundation and OpenAI Group PBC, bringing global leadership in finance, technology, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> David Vélez and Robin Vince join the boards of the OpenAI Foundation and OpenAI Group PBC, bringing global leadership in finance, technology, and governance.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/david-velez-robin-vince-join-openai-boards">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>company</category></item><item><title>EDPB calls for legal basis for cross-regulatory information sharing</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-17-edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing/</link><pubDate>Fri, 17 Jul 2026 12:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-17-edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing/</guid><description>News Brief • July 17, 2026 | Topics: GRC | Summary: Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en">EDPB News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-news</category></item><item><title>SEC Proposes New E-Delivery Approach to Make Information More Readily Accessible and Useful for Investors</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-16-sec-proposes-new-e-delivery-approach-to-make-information-more-readily-accessible-and-useful-for-investors/</link><pubDate>Thu, 16 Jul 2026 12:57:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-16-sec-proposes-new-e-delivery-approach-to-make-information-more-readily-accessible-and-useful-for-investors/</guid><description>News Brief • July 16, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today proposed Regulation E-Delivery, a new rule that would expand the ability of issuers, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission today proposed Regulation E-Delivery, a new rule that would expand the ability of issuers, broker-dealers, investment advisers, and others to use electronic delivery to satisfy information delivery requirements…</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-67-sec-proposes-new-e-delivery-approach-make-information-more-readily-accessible-useful-investors">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>The US is advancing AI safety through state and federal action</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-15-the-us-is-advancing-ai-safety-through-state-and-federal-action/</link><pubDate>Wed, 15 Jul 2026 12:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-15-the-us-is-advancing-ai-safety-through-state-and-federal-action/</guid><description>News Brief • July 15, 2026 | Topics: GRC | Summary: OpenAI outlines a “reverse federalism” approach to AI governance, where state laws help build a national framework for safe, democratic AI. …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> OpenAI outlines a “reverse federalism” approach to AI governance, where state laws help build a national framework for safe, democratic AI.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/advancing-ai-safety-through-state-and-federal-action">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>global-affairs</category></item><item><title>EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-14-edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint/</link><pubDate>Tue, 14 Jul 2026 12:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-14-edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint/</guid><description>News Brief • July 14, 2026 | Topics: GRC | Summary: Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*.
Why it matters: This matters if it …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en">EDPB News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-news</category></item><item><title>Study on the interplay between the AMLD and the GDPR framework</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-09-study-on-the-interplay-between-the-amld-and-the-gdpr-framework/</link><pubDate>Thu, 09 Jul 2026 13:07:14 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-09-study-on-the-interplay-between-the-amld-and-the-gdpr-framework/</guid><description>News Brief • July 9, 2026 | Topics: GRC | Summary: Study on the interplay between the AMLD and the GDPR framework
Why it matters: This matters if it changes compliance expectations, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Study on the interplay between the AMLD and the GDPR framework</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.edpb.europa.eu/documents/legal-study-by-external-suppliers/study-on-the-interplay-between-the-amld-and-the-gdpr_en">EDPB publications</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-publications</category></item><item><title>Template for Cross-Regulatory Cooperation Agreements</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-09-template-for-cross-regulatory-cooperation-agreements/</link><pubDate>Thu, 09 Jul 2026 10:52:32 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-09-template-for-cross-regulatory-cooperation-agreements/</guid><description>News Brief • July 9, 2026 | Topics: GRC | Summary: Template for Cross-Regulatory Cooperation Agreements
Why it matters: This matters if it changes compliance expectations, enforcement posture, …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Template for Cross-Regulatory Cooperation Agreements</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.edpb.europa.eu/documents/other-guidance/template-for-cross-regulatory-cooperation-agreements_en">EDPB publications</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-publications</category></item><item><title>SEC Forms New Retail Fraud Working Group</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-07-sec-forms-new-retail-fraud-working-group/</link><pubDate>Tue, 07 Jul 2026 14:39:57 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-07-07-sec-forms-new-retail-fraud-working-group/</guid><description>News Brief • July 7, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today announced the creation of the Retail Fraud Working Group designed to strengthen the Division of …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission today announced the creation of the Retail Fraud Working Group designed to strengthen the Division of Enforcement’s efforts to identify and combat fraud targeting everyday investors.The Retail Fraud Working Group…</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-63-sec-forms-new-retail-fraud-working-group">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>Global Information Security Day: A Vendor-Made Holiday</title><link>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-06-30-global-information-security-day-how-the-security-industry-invented-a-holiday-for-itself/</link><pubDate>Tue, 30 Jun 2026 09:00:00 -0500</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-06-30-global-information-security-day-how-the-security-industry-invented-a-holiday-for-itself/</guid><description>Article • June 30, 2026 • 7 min read | Topics: Security, GRC | Today is Global Information Security Day, an awareness holiday you’ve probably never heard of despite eleven years of “global” celebration. That’s because it’s not …</description><content:encoded>&lt;![CDATA[<p>Today is Global Information Security Day, an awareness holiday you&rsquo;ve probably never heard of despite eleven years of &ldquo;global&rdquo; celebration. That&rsquo;s because it&rsquo;s not actually global, not particularly focused on information security, and exists primarily to give security vendors something to post about on LinkedIn during the summer sales slump.</p><p>Welcome to the world&rsquo;s most transparent example of manufactured awareness: a marketing holiday created by vendors, for vendors, to sell to the same organizations they convinced needed another security awareness day in the first place.</p><h2 id="the-origin-story-nobody-wants-to-claim">The Origin Story Nobody Wants to Claim</h2><p>Global Information Security Day was established in 2015 by what organizers call a &ldquo;security industry consortium.&rdquo; Unlike legitimate awareness days, which have clear founding organizations and transparent goals, GISD&rsquo;s origins are deliberately vague.</p><p><strong>What we know:</strong></p><ul><li>First celebrated June 30, 2015</li><li>Created by unnamed &ldquo;industry leaders&rdquo;</li><li>No single organization claims founding credit</li><li>Promoted primarily through vendor marketing channels</li></ul><p><strong>What we suspect:</strong></p><ul><li>Designed to fill the summer awareness gap between Internet Safety Month (June) and Cybersecurity Awareness Month (October)</li><li>Timed to coincide with Q2 budget cycle closes</li><li>Created when vendors realized they could manufacture their own awareness campaigns</li></ul><p><em>Toast&rsquo;s observation: &ldquo;Global Information Security Day is the participation trophy of awareness campaigns. When you can&rsquo;t get invited to the real events, you create your own event and invite yourself.&rdquo;</em></p><h2 id="the-consortium-that-doesnt-exist">The Consortium That Doesn&rsquo;t Exist</h2><p>The most telling aspect of GISD is its deliberately opaque organizing structure. Unlike legitimate awareness campaigns with transparent governance:</p><h3 id="real-awareness-campaigns"><strong>Real Awareness Campaigns:</strong></h3><ul><li><strong>Cybersecurity Awareness Month:</strong> CISA + National Cyber Security Alliance (clear organization, government partnership)</li><li><strong>Data Privacy Day:</strong> Council of Europe → National Cybersecurity Alliance (documented history, legal foundation)</li><li><strong>Safer Internet Day:</strong> European Commission → European Schoolnet (transparent funding, measurable goals)</li></ul><h3 id="global-information-security-day"><strong>Global Information Security Day:</strong></h3><ul><li><strong>&ldquo;Security Industry Consortium&rdquo;</strong> (no website, no contact information, no member list)</li><li><strong>&ldquo;Industry Leaders&rdquo;</strong> (unnamed organizations, rotating promotional responsibility)</li><li><strong>&ldquo;Global Initiative&rdquo;</strong> (primarily promoted in English by US-based vendors)</li></ul><p>The deliberate opacity suggests GISD was created by vendors who understood that explicit commercial sponsorship would undermine its credibility as an awareness campaign.</p><p><em>Moxie&rsquo;s analysis: &ldquo;GISD is cosplaying as a legitimate awareness day. It has all the marketing materials but none of the actual organizational structure that would make it real.&rdquo;</em></p><h2 id="the-manufactured-relevance-problem">The Manufactured Relevance Problem</h2><p>GISD&rsquo;s content and messaging reveal its true purpose: creating awareness about awareness itself.</p><h3 id="what-gisd-claims-to-address"><strong>What GISD Claims to Address:</strong></h3><ul><li>&ldquo;Global information security challenges&rdquo;</li><li>&ldquo;Rising cyber threat landscape&rdquo;</li><li>&ldquo;Need for security awareness&rdquo;</li><li>&ldquo;Importance of information protection&rdquo;</li></ul><h3 id="what-gisd-actually-addresses"><strong>What GISD Actually Addresses:</strong></h3><ul><li>Summer marketing calendar gaps for security vendors</li><li>LinkedIn content creation needs during slow news cycles</li><li>Q2 sales pipeline development before summer break</li><li>Manufactured credibility for vendor thought leadership</li></ul><p>The messaging is deliberately generic because GISD isn&rsquo;t solving a specific problem - it&rsquo;s creating content marketing opportunities.</p><p><em>Murphy&rsquo;s take: &ldquo;GISD&rsquo;s awareness messaging is about raising awareness about the need for awareness. It&rsquo;s marketing inception - dreams within dreams within vendor pitches.&rdquo;</em></p><h2 id="the-linkedin-industrial-complex">The LinkedIn Industrial Complex</h2><p>GISD&rsquo;s primary ecosystem is professional social media, where it generates impressive engagement despite minimal real-world impact:</p><h3 id="the-gisd-content-calendar"><strong>The GISD Content Calendar:</strong></h3><ul><li><strong>June 1-15:</strong> Pre-event thought leadership posts about &ldquo;global security challenges&rdquo;</li><li><strong>June 16-29:</strong> &ldquo;Getting ready for Global Information Security Day&rdquo; content</li><li><strong>June 30:</strong> Coordinated posting blitz with #GlobalInfoSecDay hashtag</li><li><strong>July 1-7:</strong> Post-event analysis and &ldquo;key takeaways&rdquo; content</li></ul><h3 id="who-participates"><strong>Who Participates:</strong></h3><ul><li>Security vendor marketing teams</li><li>Cybersecurity consultants building personal brands</li><li>Security professionals at vendor partner companies</li><li>Industry publications with vendor advertising relationships</li></ul><h3 id="who-doesn"><strong>Who Doesn&rsquo;t Participate:</strong></h3><ul><li>Government cybersecurity agencies</li><li>Academic cybersecurity researchers</li><li>Non-profit security organizations</li><li>International cybersecurity bodies</li></ul><p><em>Olaf&rsquo;s perspective: &ldquo;GISD exists primarily in the LinkedIn universe where vendor marketing meets professional networking. It&rsquo;s a holiday celebrated by people whose job it is to celebrate holidays.&rdquo;</em></p><h2 id="the-regional-reality-check">The Regional Reality Check</h2><p>Despite its &ldquo;global&rdquo; branding, GISD is primarily a US-based marketing phenomenon:</p><h3 id="heading"><strong>&ldquo;Global&rdquo; Participation Analysis:</strong></h3><ul><li><strong>United States:</strong> Heavy vendor participation, LinkedIn engagement</li><li><strong>United Kingdom:</strong> Limited participation, mostly US vendor subsidiaries</li><li><strong>European Union:</strong> Minimal participation, conflicts with GDPR anniversary timing</li><li><strong>Asia-Pacific:</strong> Virtually no participation outside vendor marketing teams</li><li><strong>Rest of World:</strong> No measurable participation</li></ul><p>The &ldquo;global&rdquo; designation appears to be marketing positioning rather than actual international adoption.</p><h3 id="legitimate-global-security-awareness"><strong>Legitimate Global Security Awareness:</strong></h3><ul><li><strong>ITU Cybersecurity Day</strong> (May 17) - Actually organized by International Telecommunication Union</li><li><strong>World Password Day</strong> (May 1) - Problematic but genuinely international adoption</li><li><strong>European Cyber Security Month</strong> (October) - EU-wide coordination with measurable participation</li></ul><p><em>Toast&rsquo;s reality check: &ldquo;GISD is about as global as a local car dealership&rsquo;s &lsquo;regional headquarters.&rsquo; The branding is aspirational, not descriptive.&rdquo;</em></p><h2 id="the-content-marketing-treadmill">The Content Marketing Treadmill</h2><p>GISD&rsquo;s real innovation is transforming vendor content marketing into awareness campaigning:</p><h3 id="traditional-vendor-marketing"><strong>Traditional Vendor Marketing:</strong></h3><ul><li>Company blog posts about security trends</li><li>Webinars promoting specific products</li><li>White papers positioning vendor solutions</li><li>Trade publication advertising</li></ul><h3 id="gisd-enabled-awareness-marketing"><strong>GISD-Enabled Awareness Marketing:</strong></h3><ul><li>&ldquo;Thought leadership&rdquo; posts about global security challenges</li><li>&ldquo;Educational&rdquo; webinars for Global Information Security Day</li><li>&ldquo;Industry insights&rdquo; reports for GISD awareness</li><li>&ldquo;Awareness campaign&rdquo; sponsorship opportunities</li></ul><p>It&rsquo;s the same content with awareness campaign branding that makes it seem educational rather than promotional.</p><p><em>Moxie&rsquo;s insight: &ldquo;GISD lets vendors wrap their sales content in awareness campaign packaging. It&rsquo;s like putting educational labels on advertising - same product, better perception.&rdquo;</em></p><h2 id="what-eleven-years-of-gisd-has-accomplished">What Eleven Years of GISD Has Accomplished</h2><p>The track record speaks for itself:</p><h3 id="measurable-global-information-security-improvements-since-2015"><strong>Measurable Global Information Security Improvements Since 2015:</strong></h3><ul><li><strong>Ransomware incidents:</strong> ⬆️ Up 340%</li><li><strong>Data breach costs:</strong> ⬆️ Up 280%</li><li><strong>Critical infrastructure attacks:</strong> ⬆️ Up 210%</li><li><strong>Supply chain compromises:</strong> ⬆️ Up 190%</li></ul><h3 id="measurable-gisd-marketing-success-since-2015"><strong>Measurable GISD Marketing Success Since 2015:</strong></h3><ul><li><strong>LinkedIn #GlobalInfoSecDay posts:</strong> ⬆️ Up 890%</li><li><strong>Vendor blog posts mentioning GISD:</strong> ⬆️ Up 560%</li><li><strong>&ldquo;Thought leadership&rdquo; content during GISD week:</strong> ⬆️ Up 440%</li><li><strong>Security vendor social media engagement:</strong> ⬆️ Up 230%</li></ul><p>The only metric improving consistently is vendor marketing performance.</p><h2 id="the-awareness-inflation-problem">The Awareness Inflation Problem</h2><p>GISD represents a broader trend: awareness inflation driven by marketing calendar needs.</p><h3 id="legitimate-awareness-scarcity"><strong>Legitimate Awareness Scarcity:</strong></h3><ul><li>Real cybersecurity problems have limited awareness days</li><li>Government and non-profit awareness campaigns are annual</li><li>Authentic awareness requires sustained organizational commitment</li><li>Meaningful awareness campaigns take years to build credibility</li></ul><h3 id="marketing-calendar-abundance"><strong>Marketing Calendar Abundance:</strong></h3><ul><li>Vendors need monthly content marketing hooks</li><li>Professional services need quarterly thought leadership opportunities</li><li>Sales teams need regular conversation starters</li><li>Social media algorithms favor consistent posting</li></ul><p>The gap between legitimate awareness needs and marketing calendar needs creates demand for manufactured awareness days like GISD.</p><p><em>Murphy&rsquo;s observation: &ldquo;GISD is what happens when marketing departments get tired of waiting for real news and decide to create their own. It&rsquo;s the awareness equivalent of a press release disguised as journalism.&rdquo;</em></p><h2 id="the-industry-self-referential-loop">The Industry Self-Referential Loop</h2><p>GISD has created a perfect closed-loop marketing ecosystem:</p><h3 id="phase-1-vendors-promote-gisd-to-demonstrate-thought-leadership"><strong>Phase 1:</strong> Vendors promote GISD to demonstrate thought leadership</h3><h3 id="phase-2-gisd-content-generates-social-media-engagement"><strong>Phase 2:</strong> GISD content generates social media engagement</h3><h3 id="phase-3-engagement-metrics-justify-more-gisd-investment"><strong>Phase 3:</strong> Engagement metrics justify more GISD investment</h3><h3 id="phase-4-increased-investment-creates-appearance-of-growing-importance"><strong>Phase 4:</strong> Increased investment creates appearance of growing importance</h3><h3 id="phase-5-appearance-of-importance-attracts-more-vendor-participation"><strong>Phase 5:</strong> Appearance of importance attracts more vendor participation</h3><h3 id="return-to-phase-1"><strong>Return to Phase 1</strong></h3><p>It&rsquo;s a self-reinforcing cycle where marketing success creates the appearance of legitimate awareness.</p><p><em>Olaf&rsquo;s assessment: &ldquo;GISD is a marketing ouroboros - it exists to promote itself, and it promotes itself to justify existing. It&rsquo;s perpetual motion powered by LinkedIn engagement.&rdquo;</em></p><h2 id="what-global-information-security-awareness-actually-needs">What Global Information Security Awareness Actually Needs</h2><p>Real global information security awareness would address actual international cooperation challenges:</p><h3 id="cross-border-incident-response"><strong>Cross-Border Incident Response</strong></h3><ul><li>Standardized threat intelligence sharing</li><li>Coordinated vulnerability disclosure processes</li><li>International law enforcement cooperation protocols</li><li>Common incident notification frameworks</li></ul><h3 id="capacity-building-for-developing-nations"><strong>Capacity Building for Developing Nations</strong></h3><ul><li>Cybersecurity education infrastructure</li><li>Technical assistance for national cybersecurity capabilities</li><li>Economic development through secure technology adoption</li><li>Digital skills development programs</li></ul><h3 id="international-cybersecurity-standards"><strong>International Cybersecurity Standards</strong></h3><ul><li>Harmonized security frameworks across regions</li><li>Mutual recognition of cybersecurity certifications</li><li>Coordinated responses to state-sponsored threats</li><li>Global supply chain security standards</li></ul><p>None of these appear in GISD promotional materials because they require actual international coordination, not marketing campaigns.</p><h2 id="conclusion-the-awareness-day-that-isnt">Conclusion: The Awareness Day That Isn&rsquo;t</h2><p>Global Information Security Day represents everything wrong with vendor-driven awareness campaigns: manufactured relevance, opaque organization, generic messaging, and success metrics focused on marketing engagement rather than security outcomes.</p><p>Eleven years after its creation, GISD has become a case study in how the cybersecurity industry creates the appearance of thought leadership without the substance of actual expertise.</p><p>The most secure thing about Global Information Security Day is its position as reliable content marketing for security vendors who need something to post about on June 30th.</p><p><em>Toast&rsquo;s final word: &ldquo;GISD proves that if you create enough marketing content about an awareness day, people will eventually assume it must be legitimate. It&rsquo;s the big lie theory applied to cybersecurity marketing.&rdquo;</em></p><hr><p><strong>Real Global Cybersecurity Initiatives Worth Supporting:</strong></p><ul><li>ITU Global Cybersecurity Index</li><li>FIRST (Forum of Incident Response and Security Teams)</li><li>CTI League (Volunteer threat intelligence cooperation)</li><li>UN Group of Governmental Experts on Cybersecurity</li></ul><p><strong>Next in the Awareness Theater Series:</strong> National Identity Theft Prevention Week (August) - How credit monitoring companies weaponized identity anxiety.</p><hr><p><em>Spoiledlunch investigates when industries create their own awareness days. When marketing becomes mythology, we debug the narrative.</em></p>
]]></content:encoded><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item><item><title>AI Usage Discovery Is the New Shadow IT Problem</title><link>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-05-01-why-ai-usage-discovery-is-becoming-the-new-shadow-it-problem/</link><pubDate>Tue, 30 Jun 2026 09:00:00 -0400</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/articles/2026-05-01-why-ai-usage-discovery-is-becoming-the-new-shadow-it-problem/</guid><description>Article • June 30, 2026 • 4 min read | Topics: AI, GRC | For years, shadow IT meant unsanctioned SaaS, unmanaged devices, and business teams adopting systems faster than central governance could track them.
Now the same pattern is happening again through …</description><content:encoded>&lt;![CDATA[<p>For years, shadow IT meant unsanctioned SaaS, unmanaged devices, and business teams adopting systems faster than central governance could track them.</p><p>Now the same pattern is happening again through AI.</p><p>Employees use public chat tools for work tasks. Teams wire AI features into workflows through vendor platforms. Product groups buy embedded AI capabilities that legal, security, and compliance only discover later. Internal tools call external models through lightweight integrations nobody formally registered because the work felt too small to justify process.</p><p>This is not a future problem. It is already normal enterprise behavior.</p><p>That is why AI usage discovery is becoming the new shadow IT problem.</p><h2 id="ai-adoption-is-easier-to-hide-than-traditional-software-adoption">AI adoption is easier to hide than traditional software adoption</h2><p>Old shadow IT often left visible traces. Someone bought a tool. A domain appeared. A contract existed. A login pattern changed. A device showed up.</p><p>AI usage can be much lighter weight and therefore easier to miss.</p><p>A team might:</p><ul><li>paste internal data into a public AI interface</li><li>turn on an AI assistant inside an existing SaaS platform</li><li>build a low-code workflow that calls a model API</li><li>use browser extensions or productivity plugins with AI features</li><li>start relying on embedded generation or classification without any standalone procurement signal</li></ul><p>Each decision may feel small. Collectively they create a new layer of operational dependence and data movement that many organizations are only partially able to see.</p><h2 id="governance-cannot-work-on-systems-it-does-not-know-exist">Governance cannot work on systems it does not know exist</h2><p>This should sound familiar because it is the same failure pattern seen in other domains.</p><p>You cannot review what you have not discovered.</p><p>You cannot assign ownership to a workflow nobody declared.</p><p>You cannot assess data handling, vendor posture, prompt risk, retrieval behavior, or model dependency if the use case entered production through convenience and stayed there through habit.</p><p>That is why<a href="/articles/2026-05-02-why-enterprises-keep-confusing-ai-access-control-with-ai-governance/">AI access control is not the same thing as AI governance</a>. Restricting tool access does not help much if the actual workflows and dependencies were never discovered in the first place.</p><p>Many organizations are already trying to govern AI with intake forms, review committees, and policy language while lacking a credible inventory of where AI is actually being used. That is not a small gap. It means the formal governance program is operating on a curated subset of reality.</p><h2 id="the-real-issue-is-not-forbidden-use-it-is-invisible-dependence">The real issue is not forbidden use. It is invisible dependence.</h2><p>Some AI governance conversations are still stuck on prohibition: how do we stop people from using unsanctioned tools?</p><p>That matters, but it is not the whole problem.</p><p>The deeper issue is invisible dependence. Workflows start leaning on AI outputs before anyone has decided whether the use is important enough to govern differently. Internal expectations change. Customer responses get shaped by generated text. Analysts rely on model summaries. Support teams trust AI-assisted search. The organization acquires hidden dependencies before it acquires visibility.</p><p>That is exactly what made shadow IT hard the first time. The technology was not just present. It became useful before governance arrived.</p><h2 id="discovery-has-to-include-platforms-vendors-and-workflows">Discovery has to include platforms, vendors, and workflows</h2><p>AI usage discovery is also harder than traditional software inventory because &ldquo;the AI system&rdquo; is often not a single product.</p><p>It may be:</p><ul><li>a feature inside a major SaaS platform</li><li>a vendor workflow powered by a hidden foundation model</li><li>a prompt layer inside an internal application</li><li>an API dependency attached to a business automation</li><li>a retrieval system grounded in internal documents</li></ul><p>If the discovery model only looks for direct model contracts, it will miss a large share of the real exposure.</p><p>This is really the AI version of the older inventory failure described in<a href="/articles/2026-05-01-why-asset-inventory-is-still-the-most-embarrassing-security-problem-in-large-organizations/">why asset inventory remains so embarrassing in large organizations</a>: the systems of record feel mature right up until someone asks what is actually in use.</p><p>This is why AI governance inventories need to look more like a combination of software inventory, third-party risk mapping, and workflow discovery. They have to ask not just which models are approved, but where AI-mediated behavior is now influencing decisions, content, support, or operations.</p><h2 id="what-serious-discovery-looks-like">What serious discovery looks like</h2><p>A better AI discovery program usually combines several questions:</p><ul><li>where are public AI tools being accessed from managed environments?</li><li>which enterprise SaaS platforms have enabled AI features?</li><li>which internal systems call model APIs directly or through vendors?</li><li>where is internal or customer data being routed into AI-assisted workflows?</li><li>which business processes now depend on AI output, even informally?</li></ul><p>This is not about building a perfect inventory on day one. It is about admitting that AI governance without usage discovery is mostly ceremonial.</p><h2 id="bottom-line">Bottom Line</h2><p>AI usage discovery is becoming the new shadow IT problem because adoption is diffuse, low-friction, and increasingly embedded inside tools the enterprise already trusts.</p><p>The organizations that handle this well will not be the ones with the prettiest policy documents. They will be the ones that can actually see where AI is being used, what data and workflows it touches, and which dependencies have formed before those dependencies become governance surprises.</p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>GRC</category><category>shadow ai</category><category>ai governance</category><category>usage discovery</category><category>inventory</category></item><item><title>Delta Electronics DVP12SE PLC</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-30-delta-electronics-dvp12se-plc/</link><pubDate>Tue, 30 Jun 2026 12:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-30-delta-electronics-dvp12se-plc/</guid><description>News Brief • June 30, 2026 | Topics: GRC | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>SEC, CFTC Seek Public Comment on the Harmonization of Portfolio Margining Frameworks</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-26-sec-cftc-seek-public-comment-on-the-harmonization-of-portfolio-margining-frameworks/</link><pubDate>Fri, 26 Jun 2026 12:58:32 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-26-sec-cftc-seek-public-comment-on-the-harmonization-of-portfolio-margining-frameworks/</guid><description>News Brief • June 26, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission and the Commodity Futures Trading Commission today issued a joint request for public comment on …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission and the Commodity Futures Trading Commission today issued a joint request for public comment on potential approaches to further harmonize regulatory frameworks applicable to portfolio margining across securities,…</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-59-sec-cftc-seek-public-comment-harmonization-portfolio-margining-frameworks">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>SEC, CFTC Seek Public Input on Data Reporting Frameworks for Security-Based Swap and Swap Markets</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-18-sec-cftc-seek-public-input-on-data-reporting-frameworks-for-security-based-swap-and-swap-markets/</link><pubDate>Thu, 18 Jun 2026 18:17:55 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-18-sec-cftc-seek-public-input-on-data-reporting-frameworks-for-security-based-swap-and-swap-markets/</guid><description>News Brief • June 18, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission and Commodity Futures Trading Commission today issued a joint request for public comment on potential …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission and Commodity Futures Trading Commission today issued a joint request for public comment on potential opportunities to harmonize, modernize, and streamline data reporting requirements in their regulation of the…</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-56-sec-cftc-seek-public-input-data-reporting-frameworks-security-based-swap-swap-markets">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>SEC Proposes Rescission of Regulation NMS Rules 611 and 610(e)</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-11-sec-proposes-rescission-of-regulation-nms-rules-611-and-610-e/</link><pubDate>Thu, 11 Jun 2026 14:55:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-11-sec-proposes-rescission-of-regulation-nms-rules-611-and-610-e/</guid><description>News Brief • June 11, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today proposed amendments to rescind Rules 611 and 610(e) of Regulation NMS.“After two decades of Rule …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission today proposed amendments to rescind Rules 611 and 610(e) of Regulation NMS.“After two decades of Rule 611, it is high time that the Commission review its unintended consequences that have hindered — rather than…</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-54-sec-proposes-rescission-regulation-nms-rules-611-610e">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>Access OpenAI models and Codex through your Oracle cloud commitment</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-10-access-openai-models-and-codex-through-your-oracle-cloud-commitment/</link><pubDate>Wed, 10 Jun 2026 20:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-10-access-openai-models-and-codex-through-your-oracle-cloud-commitment/</guid><description>News Brief • June 10, 2026 | Topics: GRC | Summary: Access OpenAI models and Codex through Oracle Cloud, using existing commitments to build and deploy AI with enterprise security and …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Access OpenAI models and Codex through Oracle Cloud, using existing commitments to build and deploy AI with enterprise security and governance.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/openai-on-oracle-cloud">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>company</category></item><item><title>A blueprint for democratic governance of frontier AI</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-03-a-blueprint-for-democratic-governance-of-frontier-ai/</link><pubDate>Wed, 03 Jun 2026 10:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-03-a-blueprint-for-democratic-governance-of-frontier-ai/</guid><description>News Brief • June 3, 2026 | Topics: GRC | Summary: governance of frontier AI, proposing a federal framework for safety, resilience, and national security.
Why it matters: This matters if it …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> governance of frontier AI, proposing a federal framework for safety, resilience, and national security.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/frontier-safety-blueprint">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>global-affairs</category></item><item><title>Our views on AI policy and political advocacy</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-01-our-views-on-ai-policy-and-political-advocacy/</link><pubDate>Mon, 01 Jun 2026 17:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-06-01-our-views-on-ai-policy-and-political-advocacy/</guid><description>News Brief • June 1, 2026 | Topics: GRC | Summary: Our approach to AI policy and political advocacy, transparency, support for thoughtful regulation and AI safety, and that no outside …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Our approach to AI policy and political advocacy, transparency, support for thoughtful regulation and AI safety, and that no outside political group speaks on the company’s behalf.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/our-views-on-ai-policy-and-political-advocacy">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>global-affairs</category></item><item><title>OpenAI's Frontier Governance Framework</title><link>https://30b79ea5.spoiledlunch.pages.dev/news/2026-05-28-openai-s-frontier-governance-framework/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://30b79ea5.spoiledlunch.pages.dev/news/2026-05-28-openai-s-frontier-governance-framework/</guid><description>News Brief • May 28, 2026 | Topics: GRC | Summary: Explore OpenAI’s Frontier Governance Framework and how our AI safety, security, and risk practices align with emerging EU and California …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Explore OpenAI’s Frontier Governance Framework and how our AI safety, security, and risk practices align with emerging EU and California regulations.</p><p><strong>Why it matters:</strong> This matters if it changes compliance expectations, enforcement posture, or the practical workload for teams that have to translate guidance into controls, evidence, and operating process.</p><p><strong>What to watch:</strong> Watch for follow-on implementation guidance, regulator clarification, enforcement movement, or changes in how larger organizations operationalize the requirement.</p><p><strong>Source:</strong><a href="https://openai.com/index/openai-frontier-governance-framework">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>safety</category></item></channel></rss>