<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://media.rss.com/style.xsl"?>
<rss xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom" xml:lang="en" version="2.0">
  <channel>
    <title><![CDATA[GRC Academy]]></title>
    <link>https://grcacademy.io/</link>
    <atom:link href="https://media.rss.com/grcacademy/feed.xml" rel="self" type="application/rss+xml"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <description><![CDATA[Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!]]></description>
    <generator>RSS.com 2026.401.141116</generator>
    <lastBuildDate>Fri, 17 Apr 2026 11:09:57 GMT</lastBuildDate>
    <language>en-us</language>
    <copyright><![CDATA[Copyright GRC Academy]]></copyright>
    <itunes:image href="https://media.rss.com/grcacademy/podcast_cover.png"/>
    <podcast:guid>bbbe44d7-5863-5e6f-943b-ee9c466d950e</podcast:guid>
    <image>
      <url>https://media.rss.com/grcacademy/podcast_cover.png</url>
      <title>GRC Academy</title>
      <link>https://grcacademy.io/</link>
    </image>
    <podcast:locked>yes</podcast:locked>
    <podcast:license>Copyright GRC Academy</podcast:license>
    <itunes:author>Jacob Hill</itunes:author>
    <itunes:owner>
      <itunes:name>Jacob Hill</itunes:name>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:type>episodic</itunes:type>
    <itunes:category text="Technology"/>
    <podcast:medium>podcast</podcast:medium>
    <item>
      <title><![CDATA[Deltek's Journey to FedRAMP Moderate Equivalency]]></title>
      <itunes:title><![CDATA[Deltek's Journey to FedRAMP Moderate Equivalency]]></itunes:title>
      <description><![CDATA[<p>I have a surprise for you --- the last GRC Academy podcast!</p><p>In this last episode, Michael Greenman from Deltek shares the journey to FedRAMP Moderate Equivalency for Deltek Costpoint GovCon Cloud Moderate (GCC-M).</p><p>And let me tell you, it's quite a story: changes in the control baseline, new policy from the DoW, and lessons learned.</p><p>Here are some of the biggest takeaways:</p><ul><li>The real-world implications of DoW's equivalency definition</li><li>How the absence of continuous monitoring shapes the trust model</li><li>How Deltek developed a customer responsibility matrix that reduces friction for their customers</li><li>Should the DoW blow up FedRAMP moderate equivalency?</li></ul><p>We also discussed improvements that can be made by the DoW, the Cyber AB, and more!</p><p>We recorded this months ago, but this conversation is still very relevant.</p><p>On another note, it is kind of surreal to think this is the last episode of the GRC Academy podcast. I hope you've enjoyed listening!!</p><p>What were your biggest takeaways? Let me know in the comments.</p><p>Follow Michael on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/michael-greenman-94952a3/">https://www.linkedin.com/in/michael-greenman-94952a3/</a></p><p>Deltek Costpoint GCC-M: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.deltek.com/en/government-contracting/costpoint/cloud">https://www.deltek.com/en/government-contracting/costpoint/cloud</a></p><p>-----------</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://tekfused.com/marketplace/?utm_source=podcast&amp;utm_medium=s2-12&amp;utm_campaign=marketplace">https://tekfused.com/marketplace/?utm_source=podcast&amp;utm_medium=s2-12&amp;utm_campaign=marketplace</a></p><p>#cmmc</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2333559</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2333559/grcacademy/2025_11_18_03_33_48_2c018bc7-fe22-4032-a90a-bbf8a7e28890.mp3" length="34812409" type="audio/mpeg"/>
      <guid isPermaLink="false">c893a89a-889e-4b3d-a8f3-925d73da9601</guid>
      <itunes:duration>2175</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 18 Nov 2025 13:00:54 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20251118_031122_535e0c8b55a8f32fe55e138c6c553bc5.png"/>
    </item>
    <item>
      <title><![CDATA[What's Next for GRC Academy and Jacob Hill]]></title>
      <itunes:title><![CDATA[What's Next for GRC Academy and Jacob Hill]]></itunes:title>
      <description><![CDATA[<p>I have an incredible announcement to share! 👀</p><p>Before that though, let me share some of my history with you.</p><p>Back in 2016, I started a side-business called TEKFused LLC focused on web design/hosting.</p><p>Fast forward to 2022, I launched GRC Academy, and since then I’ve released 3 CMMC courses, released 50+ podcast episodes, and partnered with some amazing companies.</p><p>Earlier this year, life threw me a curveball when I was laid off from my full-time role.</p><p>Thanks to the incredible support of my AMAZING LinkedIn network, I had new opportunities on the table immediately!</p><p>Within a week, I accepted a role with Summit 7 as Director of Cybersecurity - a company I’ve admired since 2019.</p><p>And here’s the part I NEVER expected:</p><p>👉 Summit 7 has officially acquired GRC Academy!! 🎉🥳🎉</p><p>And guess what?!? I've already completely updated and rerecorded my CMMC training!! And it's even better than it was before!!</p><p>GRC Academy students with active enrollments to my CMMC training will receive access to the new training on Summit 7's platform. It will take some time to get this all together, so keep your eyes open for that announcement.</p><p>I'll be contributing to Summit 7's YouTube channel in the future as well, so subscribe if you haven't already: <a target="_blank" rel="noopener noreferrer nofollow" href="https://youtube.com/@summit7">https://youtube.com/@summit7</a></p><p>I will still be reselling PECB training at my TEKFused LLC website! If you need to get certified in ISO 27001/42001 (and more), be sure to keep me on your list: <a target="_blank" rel="noopener noreferrer nofollow" href="https://tekfused.com/courses/?utm_source=podcast&amp;utm_medium=s2-11&amp;utm_campaign=s7-acquisition-announcement">https://tekfused.com/courses/?utm_source=podcast&amp;utm_medium=s2-11&amp;utm_campaign=s7-acquisition-announcement</a></p><p>On a personal note, I’m very thankful that this transition allows me to spend way more time with my family - while continuing my mission of educating the Defense Industrial Base!</p><p>I learned so much during this chapter of my life. I want to thank all of you for your support - it truly made this possible.</p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2198889</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2198889/grcacademy/2025_09_04_04_16_49_c1be298c-b8dc-4789-85be-e953b166514c.mp3" length="3683973" type="audio/mpeg"/>
      <guid isPermaLink="false">37d9a7ee-9003-4311-87eb-8eb532344bbb</guid>
      <itunes:duration>230</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 04 Sep 2025 14:00:10 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250904_030941_61cad1452411d4ebaf3fc0e6e8aa5099.jpg"/>
    </item>
    <item>
      <title><![CDATA[The Business Case for CMMC - Surviving DOGE]]></title>
      <itunes:title><![CDATA[The Business Case for CMMC - Surviving DOGE]]></itunes:title>
      <description><![CDATA[<p>CMMC certification could be the key to surviving DOGE cuts! 👀</p><p>In this episode, I’m joined by Derek Kernus of Aethon Security to discuss the business case for CMMC!</p><p>This episode was really refreshing to me. Yes, our discussions about deep CMMC topics are important, but learning how to convince your company leadership to make the CMMC investment is even more critical.</p><p>Here are some takeaways:</p><ul><li>How CMMC early adopters can shape contracts and limit competition</li><li>How to frame the CMMC investment to internal leadership</li><li>The impending CMMC bottleneck of doom 👻</li><li>What mock assessments are and how they can help you prepare</li><li>Why choosing the wrong MSP could actually kill your chances at certification</li></ul><p>After being impacted by DOGE myself, I've put a lot of thought into how small businesses will be impacted by DOGE + CMMC.</p><p>Most of my concern is for SMBs that haven't started preparing for CMMC. That costs a lot of money, and if SMBs lose revenue due to DOGE cuts before they prepare for CMMC, I'm not sure they'll be able to survive in the defense contracting space.</p><p>But there is great opportunity for CMMC early adopters to be part a small cadre of CMMC certified companies and operate in a much smaller competitive space.</p><p>It turns out CMMC actually could be your business's savior. Who knew!?!</p><p>I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.</p><p>Follow Derek on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/derekkernus/">https://www.linkedin.com/in/derekkernus/</a></p><p>Aethon Security Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.aethonsecurity.com/">https://www.aethonsecurity.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Get back time to focus on strengthening security and scaling your business.</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-10&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-10&amp;utm_campaign=courses</a></p><p>#cmmc</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2080663</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2080663/grcacademy/2025_06_19_05_55_12_2a010ada-7b9c-49ee-b632-d9cf01ad9ab0.mp3" length="50781208" type="audio/mpeg"/>
      <guid isPermaLink="false">a18a312b-c498-4408-8401-6aacf2ccba08</guid>
      <itunes:duration>3173</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 19 Jun 2025 12:01:07 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250619_050609_cf9d2cad3942c466ca525e883148d16d.png"/>
    </item>
    <item>
      <title><![CDATA[The Compliance Playbook to Cybersecurity]]></title>
      <itunes:title><![CDATA[The Compliance Playbook to Cybersecurity]]></itunes:title>
      <description><![CDATA[<p>"Compliance is the security referee - frameworks are the playbooks."</p><p>In this episode, I’m joined by Tim Golden, Founder of Compliance Scorecard, to unpack the misunderstood, and mission-critical world of cyber GRC.</p><p>Tim shares what he’s learned from decades of hands-on work - from implementing NIST frameworks before “GRC” was even a term, to helping teams understand why writing policies is just as important as patching vulnerabilities.</p><p>Here are some highlights from the episode:</p><ul><li>What GRC actually means - and why governance is the most misunderstood part</li><li>Why people who say "compliance isn't security" are missing the point</li><li>How explaining the "why" of cybersecurity controls aids in acceptance</li><li>Why data retention policies can protect you from major legal headaches</li><li>And yes… a story about how Tim accidentally ransomwared himself 🙃</li></ul><p>This is a must-listen for anyone navigating compliance, cybersecurity, or just trying to understand how it all fits together!</p><p>I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.</p><p>Follow Tim on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/timothygolden/">https://www.linkedin.com/in/timothygolden/</a></p><p>Compliance Scorecard Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://compliancescorecard.com/">https://compliancescorecard.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Get back time to focus on strengthening security and scaling your business.</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e9&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e9&amp;utm_campaign=courses</a></p><p>#cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2059888</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2059888/grcacademy/2025_06_05_04_26_34_9a702233-95cf-4b59-8833-665735992361.mp3" length="30461679" type="audio/mpeg"/>
      <guid isPermaLink="false">3bb28c5f-550a-4e66-95b7-def206ff99fc</guid>
      <itunes:duration>1903</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 05 Jun 2025 12:00:45 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250605_040631_edd9ac5e455f3232ce6ee555bf7bfed3.png"/>
    </item>
    <item>
      <title><![CDATA[How HITRUST Fixes What’s Broken in Cybersecurity Compliance]]></title>
      <itunes:title><![CDATA[How HITRUST Fixes What’s Broken in Cybersecurity Compliance]]></itunes:title>
      <description><![CDATA[<p>Cybersecurity frameworks can learn a lot from HITRUST.</p><p>In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.</p><p>I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.</p><p>Here’s what stood out to me:</p><ul><li>HITRUST reviews its security controls quarterly based on threat intel and control effectiveness</li><li>There are three distinct assessment levels (like CMMC)</li><li>HITRUST itself issues a certification after the 3rd party assessment and running the assessment results through two stages of QA</li><li>Every 3rd assessment gets reviewed. Every. Single. One.</li></ul><p>The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.</p><p>HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.</p><p>I personally think that commercial cybersecurity frameworks should take a look at HITRUST.</p><p>What were your biggest takeaways? Let me know in the comments.</p><p>Follow Ryan on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/ryan-patrick-3699117a/">https://www.linkedin.com/in/ryan-patrick-3699117a/</a></p><p>HITRUST Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://hitrustalliance.net/">https://hitrustalliance.net/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Get back time to focus on strengthening security and scaling your business.</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e8&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e8&amp;utm_campaign=courses</a></p><p>#hitrust</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2046191</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2046191/grcacademy/2025_05_27_02_40_42_51819daa-aaf9-4bc2-adc3-9347d1583627.mp3" length="53553553" type="audio/mpeg"/>
      <guid isPermaLink="false">a528e790-7b5f-499d-be36-aa82567e59e1</guid>
      <itunes:duration>3346</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 27 May 2025 12:01:12 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250527_020539_5f5777d2160b983603259083e722bf17.jpg"/>
    </item>
    <item>
      <title><![CDATA[CUI Masterclass with Ryan Bonner]]></title>
      <itunes:title><![CDATA[CUI Masterclass with Ryan Bonner]]></itunes:title>
      <description><![CDATA[<p>"Outread the others" - that's how Ryan Bonner mastered CUI.</p><p>If you're confused about Controlled Unclassified Information (CUI) - you're not alone. Many defense contractors (not to mention DoD themselves) misunderstand what is CUI, where it comes from, and how to handle it.</p><p>In this episode, Ryan Bonner, CEO of DEFCERT, gives a masterclass in understanding CUI from the actual laws and regulations - not just hearsay.</p><p>👉 Here are the highlights:</p><ul><li>What CUI really is - and what it’s not</li><li>How to use the NARA and DoD CUI registries</li><li>The proprietary paradox</li><li>How to decontrol CUI</li><li>The difference between FCI and CUI</li><li>DoD memo on determining CMMC levels </li></ul><p>This is essential listening for anyone working with the defense industrial base - primes, subs, and especially DoD program managers who want to avoid missteps.</p><p>What were your biggest takeaways? Let me know in the comments.</p><p>Follow Ryan on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/rybonner/">https://www.linkedin.com/in/rybonner/</a></p><p>DEFCERT Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://defcert.com/">https://defcert.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Get back time to focus on strengthening security and scaling your business.</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e7&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e7&amp;utm_campaign=courses</a></p><p>#cui #cmmc</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/2020846</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/2020846/grcacademy/2025_05_09_02_53_59_825c9b6a-e961-4b55-974b-39a8c5c44fd9.mp3" length="49036937" type="audio/mpeg"/>
      <guid isPermaLink="false">26796cba-286d-4867-b4c4-21a46c7181f6</guid>
      <itunes:duration>3064</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 09 May 2025 12:20:18 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250509_120554_54980f8558b9ab1cb8bfeedc65101836.jpg"/>
    </item>
    <item>
      <title><![CDATA[Small Business Achieves CMMC Level 2 Certification: Reynolds Construction's DIY Success Story]]></title>
      <itunes:title><![CDATA[Small Business Achieves CMMC Level 2 Certification: Reynolds Construction's DIY Success Story]]></itunes:title>
      <description><![CDATA[<p>HR guy leads his company to CMMC level 2 certification! 👀</p><p>In this episode I’m joined by Eric Fields of Reynolds Construction to learn how he led his business to CMMC level 2 certification!</p><p>I call him "Eric the Great" - you'll see why in a moment.</p><p>Eric's background was in HR and business operations. He had no background in IT or cybersecurity.</p><p>They did it in-house - with just two people and smart choices.</p><p>👉 Here’s how they did it:</p><ul><li>CMMC training from GRC Academy</li><li>Resources and advisory services from Kieri Solutions</li><li>CCP &amp; CCA training</li><li>Meticulous documentation</li></ul><p>This episode is very special to me - Eric's intro to CMMC was through GRC Academy more than 2 years ago, and he was actually the second person to leave a 5-star review on my CMMC training for defense contractors: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/course-reviews/cmmc-overview-training-eric-f-20230127/">https://grcacademy.io/course-reviews/cmmc-overview-training-eric-f-20230127/</a></p><p>This episode is a great reminder that small businesses can achieve CMMC certification without breaking the bank.</p><p>That said, time is no longer a luxury. With CMMC phasing in this summer, small businesses need to move fast - and partnering with a CMMC-focused MSP can help accelerate the process.</p><p>What were your biggest takeaways? Feel free to celebrate with "Eric the Great" in the comments!</p><p>Follow Eric on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/ericfields6/">https://www.linkedin.com/in/ericfields6/</a></p><p>Reynolds Construction Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reynoldscon.com/">https://www.reynoldscon.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Get back time to focus on strengthening security and scaling your business.</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e6&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e6&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1999897</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1999897/grcacademy/2025_04_24_07_02_18_9ecdc094-8702-472d-98e0-83625425dfa6.mp3" length="35042306" type="audio/mpeg"/>
      <guid isPermaLink="false">be076216-08cf-467a-893e-bd626d814fa5</guid>
      <itunes:duration>2189</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 24 Apr 2025 12:00:24 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250424_070416_cd0b35c3ecc2b06128224f867f38693d.jpg"/>
    </item>
    <item>
      <title><![CDATA[The FASTEST Way to CMMC Compliance - CUI Enclaves]]></title>
      <itunes:title><![CDATA[The FASTEST Way to CMMC Compliance - CUI Enclaves]]></itunes:title>
      <description><![CDATA[<p>CMMC rolls out in a few months and there are STILL companies who are JUST getting started!</p><p>In this episode I’m joined by Daniel Akridge of Summit 7 to talk about the real challenges facing the Defense Industrial Base - and the FASTEST path to CMMC certification.</p><p>To CUI Enclave, or not to CUI enclave - that is the question!</p><p>👉 Here are some of the highlights:</p><ul><li>What the big primes are saying about their subs and CMMC</li><li>The biggest CMMC hurdles for defense contractors</li><li>Why MOST DoD contracts could require CMMC Level 2 certification - not just self-attestation</li><li>Deep dive into CUI enclaves and their pros and cons</li></ul><p>I personally like CUI enclaves because it keeps government cybersecurity regulations and incident reporting requirements out of my corporate IT environment...</p><p>However if you are a small business that primarily supports the DoD, CUI enclaves begin to make less sense - even as I try to reason otherwise!</p><p>What were your biggest takeaways? Do you LUV CUI enclaves?? Let me know in the comments!</p><p>Follow Daniel on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/danielakridge/">https://www.linkedin.com/in/danielakridge/</a></p><p>Summit 7 Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.summit7.us/">https://www.summit7.us/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Need continuous visibility into the state of your security controls?</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e4&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e5&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1980987</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1980987/grcacademy/2025_04_10_06_50_21_2b8859a6-9305-48e9-ab2f-4c29cd2a2c26.mp3" length="56019473" type="audio/mpeg"/>
      <guid isPermaLink="false">bb622f59-d06f-4eba-a78e-fd269e4e86a9</guid>
      <itunes:duration>3500</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 10 Apr 2025 12:00:51 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250420_010421_385b84ad0e673cdd69196570f1011785.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Will BREAK Your MSP - Axiom's CMMC Level 2 Journey]]></title>
      <itunes:title><![CDATA[CMMC Will BREAK Your MSP - Axiom's CMMC Level 2 Journey]]></itunes:title>
      <description><![CDATA[<p>“We built a second company from scratch…”</p><p>Is that what it takes for MSPs to get CMMC'd!?! 👀</p><p>In this episode I’m joined by Bobby Guerra and Kaleigh Floyd from Axiom, an IT Managed Service Provider (MSP). They explain exactly what it took to achieve CMMC level 2 certification - after 4 years of effort.</p><p>Most MSPs aren’t ready for CMMC. Many believe it's just another checkbox, but it’s a complete operational shift that requires rethinking your tools, processes, and client relationships!</p><p>Here are some of the highlights:</p><ul><li>How much money they allocated for CMMC (it’s more than you think)</li><li>How to build scalable and repeatable processes to support compliance</li><li>The tools, contracts, and agreements you MUST have in place</li><li>How to prepare for the assessment (and avoid sleepless nights!)</li></ul><p>Bobby Guerra is the CEO of Axiom and has led the MSP for over 22 years. Under his leadership, Axiom became one of the first MSPs in the U.S. to achieve CMMC Level 2 Certification. Bobby now helps guide clients through their own CMMC journeys, focusing on sustainable security and compliance.</p><p>Kaleigh Floyd is the Marketing Director at Axiom and Co-Host of the Climbing Mount CMMC podcast. Raised in the MSP world, she now educates others through Microsoft 365 training and cybersecurity content. Her passion lies in simplifying tech and making a lasting impact in the industry.</p><p>This is a true CMMC for MSPs masterclass! So much great advice packed into this episode!</p><p>What were your biggest takeaways? Let me know in the comments!</p><p>Follow Bobby on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/bobbyguerra/">https://www.linkedin.com/in/bobbyguerra/</a></p><p>Follow Kaleigh on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/kaleigh-floyd-079a52190/">https://www.linkedin.com/in/kaleigh-floyd-079a52190/</a></p><p>Axiom's Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.axiom.tech/">https://www.axiom.tech/</a></p><p>Climbing Mount CMMC Podcast: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.axiom.tech/climbing-mount-cmmc-the-podcast/">https://www.axiom.tech/climbing-mount-cmmc-the-podcast/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Need continuous visibility into the state of your security controls?</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e4&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e4&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1957190</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1957190/grcacademy/2025_03_25_11_38_31_189d16c5-98a9-49e6-bb49-77ec30a5e127.mp3" length="88548817" type="audio/mpeg"/>
      <guid isPermaLink="false">841c40f5-dc5b-4ace-8fe1-310daafdcb06</guid>
      <itunes:duration>5534</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 25 Mar 2025 11:41:44 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250327_020319_e20dd98ee1d6ca4a0fb76f5fc531e2d4.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Level 2 Assessments - What to Expect and How to Avoid Disaster]]></title>
      <itunes:title><![CDATA[CMMC Level 2 Assessments - What to Expect and How to Avoid Disaster]]></itunes:title>
      <description><![CDATA[<p>Preparing for a CMMC assessment, but don't know what to expect?</p><p>Get ready to learn from CMMC Lead Assessor Fernando Machado as he explains EXACTLY what happens in each phase of the CMMC assessment process!</p><p>Fernando is the Managing Principal of Cybersec Investments which is an authorized C3PAO. Fernando has been involved with CMMC starting in 2020 as a member of the Cyber AB's Standards Management Industry Working Group.</p><p>Cybersec Investments has already issued 12 CMMC certifications since CMMC assessments began in January of 2025 and previously participated in nearly 20 Joint Surveillance Voluntary Assessments (JSVAs).</p><p>👉 Here are some highlights:</p><ul><li>What to expect during a CMMC assessment</li><li>The 4-phases of the CMMC Assessment Process (v2.0)</li><li>No self-assessment? No independent assessment</li><li>Common issues that could cause assessment failures</li><li>How to make the assessment easier for your assessor (and you)</li></ul><p>It is overwhelming preparing for a CMMC assessment, but don't go into it without knowing what to expect!</p><p>What were your biggest takeaways? Let me know in the comments!</p><p>Follow Fernando on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/">https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/</a></p><p>Cybersec Investments Website: <a target="_blank" rel="noopener noreferrer nofollow" href="http://cybersecinvestments.com/">https://cybersecinvestments.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Need continuous visibility into the state of your security controls?</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e3&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e3&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1932106</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1932106/grcacademy/2025_03_09_02_45_55_bb8bb139-dba6-45c6-81fc-b524b3f0c503.mp3" length="34312547" type="audio/mpeg"/>
      <guid isPermaLink="false">68a8e8cb-47c5-4813-84c6-2decfb9286e5</guid>
      <itunes:duration>2144</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 11 Mar 2025 12:00:53 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250310_070316_12a03cebadccf5f8bf8e4847a6c8163a.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Mistakes COST Villa-Tech $485,000]]></title>
      <itunes:title><![CDATA[CMMC Mistakes COST Villa-Tech $485,000]]></itunes:title>
      <description><![CDATA[<p>🔥 "I Could Have Saved $300K on CMMC!" 🔥</p><p>Miguel is the founder of Villa-Tech, a small but powerful tech company that is breaking into the defense contracting space.</p><p>Miguel shares a raw and honest look at the costly missteps, lessons learned, and strategies that could save small businesses hundreds of thousands of dollars preparing for CMMC certification!</p><p>👉 Here are some highlights:</p><ul><li>How he could have saved $300k</li><li>Bad advice is expensive - how to hire the right consultants</li><li>Rebuilding their SSP 4 times</li><li>The importance of CMMC education before diving in</li></ul><p>Villa-Tech has built a CUI enclave environment that other defense contractors can leverage! They also have an amazing set of capabilities and just achieved CMMC level 2 certification, so be sure to check out their capabilities statement below.</p><p>Small businesses CAN succeed in CMMC, but the path is filled with pitfalls that can drain your budget.</p><p>Don’t make the same mistakes - learn from someone who’s been through it!</p><p>What were your biggest takeaways? Let me know in the comments!</p><p>Follow Miguel on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/miguel-villarreal-0231286/">https://www.linkedin.com/in/miguel-villarreal-0231286/</a></p><p>Villa-Tech Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.villa-tech.com">https://www.villa-tech.com</a></p><p>Villa-Tech Capabilities: <a target="_blank" rel="noopener noreferrer nofollow" href="https://villa-tech.com/government/capabilities-statement/">https://villa-tech.com/government/capabilities-statement/</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="http://Structura.io">Structura.io</a> Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://structura.io/">https://structura.io/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Need continuous visibility into the state of your security controls?</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e2&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e2&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1910163</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1910163/grcacademy/2025_02_23_02_45_28_82f1322a-ceb7-4853-b29c-bea5283a6ee6.mp3" length="51971544" type="audio/mpeg"/>
      <guid isPermaLink="false">c688dbc0-a60f-47c6-b236-6b495aba8bf5</guid>
      <itunes:duration>3248</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 25 Feb 2025 13:00:50 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250301_080354_7c6d82d5f59c12e6b874ebb3ed949cc9.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Compliance in AWS Cloud Just Got a LOT Easier]]></title>
      <itunes:title><![CDATA[CMMC Compliance in AWS Cloud Just Got a LOT Easier]]></itunes:title>
      <description><![CDATA[<p>CMMC and DFARS compliance is hard - especially in the cloud.</p><p>Got AWS? They've given you tools that make compliance much easier!</p><p>In this episode, I sit down with Travis Goldbach from Amazon Web Services (AWS) to break down the solutions AWS has created to simplify CMMC and DFARS compliance.</p><p>👉 Here are some highlights:</p><ul><li>AWS compliance automation - reducing manual effort and risk</li><li>Shared Responsibility Model - what AWS secures vs. what you manage</li><li>AWS GovCloud vs. Commercial Cloud - choosing the right environment</li><li>Landing Zone Accelerator - your shortcut to a secure, compliant AWS setup</li><li>How AWS is pursuing its own CMMC certification &amp; what that means for you</li></ul><p>I didn't know that AWS was so mature when it came to CMMC and DFARS compliance!</p><p>It was really awesome to learn how they are making compliance easier!</p><p>What were your biggest takeaways? Let me know in the comments!</p><p>Follow Travis on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/travis-goldbach-b446a223/">https://www.linkedin.com/in/travis-goldbach-b446a223/</a></p><p>AWS CMMC website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://aws.amazon.com/compliance/cmmc/">https://aws.amazon.com/compliance/cmmc/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Need continuous visibility into the state of your security controls?</p><p>Discover the new way to GRC here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e1&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s2-e1&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity #aws</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1891185</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1891185/grcacademy/2025_02_11_12_46_13_60e272cb-db68-4384-b392-16e9a7db5190.mp3" length="28617983" type="audio/mpeg"/>
      <guid isPermaLink="false">e68dd47c-4de2-4ea8-bb6c-947e772e8be7</guid>
      <itunes:duration>1756</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 11 Feb 2025 12:49:34 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250211_020219_2eab5c2efd13fc8785d8a1ce9cb5de43.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 Is FINALLY Here - What Happens Next (with Stacy Bostjanick)]]></title>
      <itunes:title><![CDATA[CMMC 2.0 Is FINALLY Here - What Happens Next (with Stacy Bostjanick)]]></itunes:title>
      <description><![CDATA[<p>It’s been a long and wild ride on this #cmmc ship! ⛵</p><p>In this episode, I speak with Stacy Bostjanick who is the Director of the CMMC program at DoD CIO!</p><p>Here are some highlights from the episode:</p><ul><li>Expectations for the initial phase in of CMMC</li><li>Who determines CMMC levels for contracts?</li><li>How will CMMC waivers work?</li><li>Criteria for CMMC level 2 self-assessments and CMMC level 3</li><li>Early use of NIST 800-171 r3</li><li>And so much more!</li></ul><p>First mentioned in 2019, CMMC 1.0 was released in 2020 under the Trump administration.</p><p>CMMC 1.0 was reviewed during the Biden administration, they released CMMC 2.0 in late 2021, and then… There was a great silence.</p><p>If you threw a small rock, you’d hit ten people who thought CMMC was going away.</p><p>All this time though, the DoD was quietly marching on.</p><p>They released the proposed CMMC program rule in December 2023 and released the final CMMC program rule in October 2024 - which is now EFFECTIVE.</p><p>After all of that, CMMC will FINALLY begin to phase into DoD solicitations and contracts by this summer.</p><p>CMMC has been a LONG time coming, and it was an honor to hear the back story and why certain decisions were made!</p><p>What were your biggest takeaways? Let me know in the comments!</p><p>Follow Stacy on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/stacy-bostjanick-a3b67173/">https://www.linkedin.com/in/stacy-bostjanick-a3b67173/</a></p><p>DoD CIO CMMC website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://dodcio.defense.gov/CMMC/">https://dodcio.defense.gov/CMMC/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e42&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e43&amp;utm_campaign=courses</a></p><p>#cmmc #nist #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1836080</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1836080/grcacademy/2025_01_07_13_31_18_e94f0130-72ae-49a7-8d0f-3f25bdba5bd9.mp3" length="65093323" type="audio/mpeg"/>
      <guid isPermaLink="false">5b90213d-d88a-4197-b5cf-2aeea43f5233</guid>
      <itunes:duration>4068</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>43</itunes:episode>
      <podcast:episode>43</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 07 Jan 2025 13:31:42 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250107_010151_96f5c1e4c7ab888961287d1c4a626c1e.png"/>
    </item>
    <item>
      <title><![CDATA[CMMC Disaster: What MSPs Aren't Telling You]]></title>
      <itunes:title><![CDATA[CMMC Disaster: What MSPs Aren't Telling You]]></itunes:title>
      <description><![CDATA[<p>Your MSP could be a CMMC disaster. 💥💣💥</p><p>I wish I was joking.</p><p>In this episode I speak with Joy Beland about the critical role IT Managed Service Providers (MSPs) play in the CMMC space and why so many of them will cause their clients to fail their CMMC assessments.</p><p>Here are some of the highlights:</p><ul><li>The NEW critical CMMC requirement for MSPs</li><li>Why so many MSPs will cause their clients to fail CMMC assessments</li><li>Why MSPs SHOULD still get CMMC certified</li><li>Questions to ask your MSP to gauge their CMMC readiness</li></ul><p>Joy is the Vice President of Cybersecurity Compliance at Summit 7 and brings over 20 years of experience as a former MSP owner. Summit 7 is a specialized MSP exclusively supporting defense contractors.</p><p>If you use an MSP, don't just assume that everything is OK and your MSP has it all covered.</p><p>It's highly likely that they do NOT and you'll FAIL your CMMC assessment because of them.</p><p>There are some great CMMC-focused MSPs out there, but the majority of MSPs have NO BUSINESS supporting defense contractors.</p><p>Choose wisely!</p><p>What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!</p><p>Follow Joy on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/joy-belinda-beland/">https://www.linkedin.com/in/joy-belinda-beland/</a></p><p>Summit 7 website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.summit7.us/">https://www.summit7.us/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e42&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e42&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1808432</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1808432/grcacademy/2024_12_19_04_47_34_b6e17a94-ab0b-4012-8be8-c1141e5f1cf9.mp3" length="45580340" type="audio/mpeg"/>
      <guid isPermaLink="false">f6672edc-68e0-41cc-8613-36cbf24ad143</guid>
      <itunes:duration>2848</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>42</itunes:episode>
      <podcast:episode>42</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 19 Dec 2024 13:30:18 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241219_041215_1acaec039c027c26b41b9ca0413bda99.png"/>
    </item>
    <item>
      <title><![CDATA[Healthcare Cybersecurity: Lives are at Stake]]></title>
      <itunes:title><![CDATA[Healthcare Cybersecurity: Lives are at Stake]]></itunes:title>
      <description><![CDATA[<p>Should you NEVER pay after a ransomware attack?</p><p>In this episode I speak with Frank Riccardi about cybersecurity in healthcare and the event that triggered much more cyber accountability for the C-suite.</p><p>Here are some of the highlights:</p><ul><li>Why healthcare workers are prone to social engineering attacks</li><li>Reasons you SHOULD and should NOT pay after ransomware attacks</li><li>Managing shadow IT after acquisitions/mergers</li><li>Why every member of the C-suite must understand cyber</li><li>The importance of a culture of reporting</li></ul><p>Frank is a former C-level executive with 25 years of experience developing compliance and privacy programs for large healthcare systems comprised of hospitals, physician practice groups, urgent care centers, and other healthcare organizations.</p><p>I really enjoyed Frank's description of shadow IT! I always thought of an employee who is using an unauthorized application, but I never thought of it from the standpoint of an acquisition/merger.</p><p>What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!</p><p>Follow Frank on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/frank-riccardi-261831b1/">https://www.linkedin.com/in/frank-riccardi-261831b1/</a></p><p>Frank's Book (Mobilizing the C-Suite: Waging War Against Cyberattacks): <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.amazon.com/Mobilizing-C-Suite-Waging-Against-Cyberattacks/dp/1637424248/">https://www.amazon.com/Mobilizing-C-Suite-Waging-Against-Cyberattacks/dp/1637424248/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e41&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e41&amp;utm_campaign=courses</a></p><p>#cybersecurity #healthcare #hospital #informationtechnology</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1799917</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1799917/grcacademy/2024_12_13_02_52_56_2d8f2bbf-ff8e-4cd3-b37d-a255ab767c9d.mp3" length="33420179" type="audio/mpeg"/>
      <guid isPermaLink="false">0c412381-ceef-44f3-8314-ce220b6259c0</guid>
      <itunes:duration>2088</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>41</itunes:episode>
      <podcast:episode>41</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 13 Dec 2024 13:00:45 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241213_021241_0be499bb0cd22bb7705895637d9ea9f0.png"/>
    </item>
    <item>
      <title><![CDATA[My MSP Was Hacked - Should I Fire Them?]]></title>
      <itunes:title><![CDATA[My MSP Was Hacked - Should I Fire Them?]]></itunes:title>
      <description><![CDATA[<p>Should you fire your MSP?!? 🔥🔥🔥</p><p>In this episode, I speak with cybersecurity attorney Sarah Anderson about how to evaluate IT Managed Service Providers and how businesses can protect themselves when relying on them.</p><p>Here are some of the highlights:</p><ul><li>How you should evaluate MSPs</li><li>What to do after your MSP is hacked</li><li>Managing the cyber incident</li><li>Cyber insurance pitfalls</li><li>Should you fire your hacked MSP?</li></ul><p>Sarah is the owner of SWA Law LLC and also serves in U.S. Army Reserves as a Lieutenant Colonel.</p><p>She has been involved in more than 100 cyber incident responses throughout her career and also represents public and private entities in regulatory compliance, cybersecurity practices, and technology contract negotiations.</p><p>If you are relying on an MSP to manage your IT and security, you won’t want to miss this!</p><p>As Sarah said, not all MSPs are created equally. Many MSPs have such poor security practices they WILL get you hacked.</p><p>Encourage your MSP to join MSPCyberX! It's a nonprofit focused on elevating the security of MSPs: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.mspcyberx.com/">https://www.mspcyberx.com/</a></p><p>Follow Sarah on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sarah-anderson-lacyberlawblog123/">https://www.linkedin.com/in/sarah-anderson-lacyberlawblog123/</a></p><p>Legally Cyber website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.legallycyber.com/">https://www.legallycyber.com/</a></p><p>Sarah's cybersecurity course for lawyers: <a target="_blank" rel="noopener noreferrer nofollow" href="https://courses.sprouteducation.com/item/cybersecurity-basics-lawyers-653403">https://courses.sprouteducation.com/item/cybersecurity-basics-lawyers-653403</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e40&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e40&amp;utm_campaign=courses</a></p><p>#msp #informationtechnology #cybersecurity #cmmc</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1785574</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1785574/grcacademy/2024_12_04_14_06_17_570eb860-ca02-4687-b963-80c1d820fe69.mp3" length="50679422" type="audio/mpeg"/>
      <guid isPermaLink="false">d34f19e6-8cdf-4233-a2cd-0b63d468a359</guid>
      <itunes:duration>3167</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>40</itunes:episode>
      <podcast:episode>40</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Wed, 04 Dec 2024 14:13:19 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241204_021252_b7beb827cb10c525ec69fe091391c568.png"/>
    </item>
    <item>
      <title><![CDATA[SOC 2 Compliance: ALL The Essentials Simplified]]></title>
      <itunes:title><![CDATA[SOC 2 Compliance: ALL The Essentials Simplified]]></itunes:title>
      <description><![CDATA[<p>SOC 2 isn't the only SOC out there! 🧦</p><p>In this episode Cera Adams breaks down these SOC reports and what to expect in a SOC audit!</p><p>Here are a few highlights from this episode:</p><ul><li>Why CPAs are involved</li><li>What SOC 1 / SOC 2 / SOC 3 reports mean to providers and consumers</li><li>Difference between SOC 2 Type 1 and Type 2 reports</li><li>How SOC scoping and audits work</li><li>SOC consulting/audit independence requirements</li></ul><p>Cera is the Director of IT Assurance Services and leads OCD Tech's SOC 2 and IT Audit Practices. She has more than 20 years of experience in information security!</p><p>I've spent most of my career working in the NIST cybersecurity space, so this was very interesting to me!</p><p>I thought that the SOC 3 report was interesting, especially since many other frameworks don't have an equivalent.</p><p>What were your takeaways? What is your best SOC pun? Let me know in the comments!</p><p>Follow Cera on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/ceraadams/">https://www.linkedin.com/in/ceraadams/</a></p><p>OCD Tech Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://ocd-tech.com/">https://ocd-tech.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e39&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e39&amp;utm_campaign=courses</a></p><p>#soc2 #cybersecurity #informationsecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1771743</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1771743/grcacademy/2024_11_26_01_08_37_9c95f4e6-c9cf-488b-a645-6cc081214f21.mp3" length="21388153" type="audio/mpeg"/>
      <guid isPermaLink="false">c8acc20d-74f3-4498-ac05-74627a316b0f</guid>
      <itunes:duration>1336</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>39</itunes:episode>
      <podcast:episode>39</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 26 Nov 2024 13:00:25 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241126_011153_518df4028b2927c79e02f25081ca5d4e.png"/>
    </item>
    <item>
      <title><![CDATA[Android Security Masterclass: What Every Cyber GRC Team Must Know]]></title>
      <itunes:title><![CDATA[Android Security Masterclass: What Every Cyber GRC Team Must Know]]></itunes:title>
      <description><![CDATA[<p>Do you use Android at work, but don't really understand it?</p><p>In this episode Hahna Kane Latonick teaches an Android cybersecurity masterclass for cyber GRC teams:</p><p>Here are a few highlights from this episode:</p><ul><li>How the Android project is managed</li><li>How Android devices are compromised</li><li>The many steps to update Android devices</li><li>Most important steps to secure Android devices</li><li>Is Apple more secure than Android?</li></ul><p>Hahna is the Director of Security Research at Dark Wolf Solutions. Some of her focuses include Android reverse engineering and exploit development. She has been featured on national media outlets including Fox Business News, ABC News, and many others!</p><p>Too often companies integrate mobile devices at work without truly understanding how they work and the risks involved.</p><p>Hahna explained these concepts so well! And of course, we had some back and forth on what is more secure, Android or Apple.</p><p>I really enjoyed this episode and learned more about Android myself! What were your takeaways?</p><p>Follow Hahna on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/hahnakane/">https://www.linkedin.com/in/hahnakane/</a></p><p>Dark Wolf Solutions Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://darkwolfsolutions.com/">https://darkwolfsolutions.com/</a></p><p>Android Security Research Playbook: <a target="_blank" rel="noopener noreferrer nofollow" href="https://asrp.darkwolf.io/">https://asrp.darkwolf.io/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e38&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e38&amp;utm_campaign=courses</a></p><p>#android #cybersecurity #informationsecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1758388</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1758388/grcacademy/2024_11_17_17_55_37_ff7e0de5-daf2-42c0-a158-0ec670e2b9fe.mp3" length="77695876" type="audio/mpeg"/>
      <guid isPermaLink="false">b36c91da-c486-4ae7-bd9e-e09b991722fb</guid>
      <itunes:duration>4855</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>38</itunes:episode>
      <podcast:episode>38</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 19 Nov 2024 13:00:33 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241117_051101_47e6c0fbb9c136b2d0e1391f14539fb6.jpg"/>
    </item>
    <item>
      <title><![CDATA[Penn State Cybersecurity False Claims Scandal: Meet the Whistleblower]]></title>
      <itunes:title><![CDATA[Penn State Cybersecurity False Claims Scandal: Meet the Whistleblower]]></itunes:title>
      <description><![CDATA[<p>Introducing the Penn State Whistleblower.</p><p>In this episode, the whistleblower explains how he tried to stop Penn State from misrepresenting their NIST 800-171 compliance to the DoD and what he has faced since he blew the whistle!</p><p>Whistleblower attorney Julie Bracker also shares what the media got wrong in this case and the latest on the Georgia Tech FCA case!</p><p>Here are a few highlights from this episode:</p><p>- Hear directly from the whistleblower in this False Claims Act case</p><p>- What the media got wrong</p><p>- Recommendations to universities</p><p>- Advice for other whistleblowers</p><p>Matthew Decker was the Chief Information Officer at the Applied Research Laboratory at Penn State from 2015 until 2023 and the interim Vice Provost and CIO responsible for all of Penn State from January 2016 until September 2016. Matthew currently serves as the Chief Data and Information Officer at NASA’s Jet Propulsion Laboratory since 2023.</p><p>It was fascinating to learn that the university assumed compliance with their own AD95 security policy meant they were automatically compliant (at least to some measure) with NIST 800-171. This is a great reminder that the details always matter!</p><p>Special thanks to Matt for sharing his story with us, and to Julie Bracker for coordinating this interview!</p><p>Follow Julie on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/juliekeetonbracker/">https://www.linkedin.com/in/juliekeetonbracker/</a></p><p>Bracker &amp; Marcus LLC Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.fcacounsel.com/">https://www.fcacounsel.com/</a></p><p>Connect with Matt on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/matt-decker-cio/">https://www.linkedin.com/in/matt-decker-cio/</a></p><p>Whistleblower's Handbook: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.amazon.com/New-Whistleblowers-Handbook-Step-Step/dp/1493028812/">https://www.amazon.com/New-Whistleblowers-Handbook-Step-Step/dp/1493028812/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e37&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e37&amp;utm_campaign=courses</a></p><p>#whistleblower #cmmc #cybersecurity</p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1747078</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1747078/grcacademy/2024_11_11_20_22_49_6fda5072-11f6-4802-ad87-10bac53aa195.mp3" length="42631535" type="audio/mpeg"/>
      <guid isPermaLink="false">d3ead623-25aa-4f10-b966-9789c20330da</guid>
      <itunes:duration>2664</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>37</itunes:episode>
      <podcast:episode>37</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Mon, 11 Nov 2024 20:29:59 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241111_081129_7796e5d732b5154f2f81f8d26ea75f88.jpg"/>
    </item>
    <item>
      <title><![CDATA[Microsoft 365 GCC High: The Inside Story with Richard Wakeman]]></title>
      <itunes:title><![CDATA[Microsoft 365 GCC High: The Inside Story with Richard Wakeman]]></itunes:title>
      <description><![CDATA[<p>Confused about Microsoft 365 and DFARS/CMMC compliance?</p><p>In this episode, I speak with Richard Wakeman, Chief Architect for cybersecurity of Aerospace &amp; Defense @ Microsoft!</p><p>We discuss the history of the government clouds, the need behind GCC and GCC High, and much more!</p><p>Here are some highlights:</p><ul><li>The origins of the Microsoft clouds</li><li>Which clouds support DFARS 7012 compliance</li><li>When will GCC High be FedRAMP authorized?</li><li>CUI enclave considerations</li></ul><p>Richard is a wealth of knowledge, and I have personally benefited from his compliance blog articles since at least 2020!</p><p>If you are currently operating in the Microsoft cloud or are trying to decide which Microsoft cloud to buy, you won't want to miss this!</p><p>Were you aware that GCC High isn't FedRAMP authorized yet? What about Microsoft 365 commercial not being compliant with DFARS 7012?</p><p>Whatever your thoughts are, let me know!</p><p>Follow Richard on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/wakeman/">https://www.linkedin.com/in/wakeman/</a></p><p>Microsoft Cloud compliance article: <a target="_blank" rel="noopener noreferrer nofollow" href="https://aka.ms/MSGovCompliance">https://aka.ms/MSGovCompliance</a></p><p>Microsoft 365 Roadmap: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.microsoft.com/en-us/microsoft-365/roadmap">https://www.microsoft.com/en-us/microsoft-365/roadmap</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e36&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e36&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1737475</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1737475/grcacademy/2024_11_05_08_13_47_24c8a3bb-0a47-46b9-87d2-70d5be1b6525.mp3" length="59615718" type="audio/mpeg"/>
      <guid isPermaLink="false">d0ed71e5-1da7-4166-92a4-9b2bd0fd227c</guid>
      <itunes:duration>3725</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>36</itunes:episode>
      <podcast:episode>36</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 05 Nov 2024 13:00:44 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241105_071107_10cf386ce9f84863c46afdaa65a35e9e.jpg"/>
    </item>
    <item>
      <title><![CDATA[MSP Cyber Exchange: Shield Your MSP from Hackers (MSPCyberX)]]></title>
      <itunes:title><![CDATA[MSP Cyber Exchange: Shield Your MSP from Hackers (MSPCyberX)]]></itunes:title>
      <description><![CDATA[<p>Is your MSP a cybersecurity liability?</p><p>In this episode, I speak with Brian Hubbard, President of Evolved Cyber Solutions and the MSP Cybersecurity Exchange!</p><p>We discuss the state of MSP cybersecurity and how MSPCyberX is elevating the security posture of MSPs everywhere!</p><p>Here are some highlights:</p><ul><li>Why MSPs are so critical to our nation's security</li><li>The inevitable regulations that will target MSPs</li><li>MSPs involvement during CMMC assessments</li><li>How MSPCyberX can help</li></ul><p>GRC Academy partnered with MSPCyberX early on to provide CMMC training to its members at a discount! It was great to hear about MSPCyberX's origin story!</p><p>If your MSP is not a member of MSPCyberX, it is in your best interest that they join!</p><p>Follow Brian on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/brian-scott-hubbard/">https://www.linkedin.com/in/brian-scott-hubbard/</a></p><p>Follow MSPCyberX on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/company/mspcyberx/">https://www.linkedin.com/company/mspcyberx/</a></p><p>MSPCyberX Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.mspcyberx.com/">https://www.mspcyberx.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e35&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e35&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1731340</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1731340/grcacademy/2024_11_01_02_50_58_aedc3ac8-c8b1-4a52-a969-4f46d63bc1e0.mp3" length="15020934" type="audio/mpeg"/>
      <guid isPermaLink="false">3a7c40f5-ad7c-4ba7-a8b1-c2bb8310d11a</guid>
      <itunes:duration>938</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>35</itunes:episode>
      <podcast:episode>35</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 01 Nov 2024 12:00:39 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241101_021150_8fbe746a890e394c8493dfb6165af823.png"/>
    </item>
    <item>
      <title><![CDATA[FREE CMMC Cybersecurity Services You NEED to Know About!]]></title>
      <itunes:title><![CDATA[FREE CMMC Cybersecurity Services You NEED to Know About!]]></itunes:title>
      <description><![CDATA[<p>FREE CMMC gap assessments!! FREE penetration tests!! FREE SOC &amp; incident response!!</p><p>This is a hidden CMMC treasure that no one's talking about!</p><p>In this episode, I speak with Darren Mott about the FREE cybersecurity services offered to the DIB by the National Cybersecurity Operations Center!</p><p>Here are some of the FREE services they offer:</p><ul><li>CMMC gap assessments</li><li>Penetration testing</li><li>SOC &amp; Incident response</li><li>Forensic analysis</li><li>Threat intelligence</li></ul><p>I had no idea the National CSOC existed! This is an AMAZING opportunity that small defense contractors should take advantage of quickly before they reach capacity!</p><p>On another note, I actually listened to Darren's podcast when it first came out. I never thought I'd actually host a podcast let alone speak with him!</p><p>Follow Darren on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/darrenmott/">https://www.linkedin.com/in/darrenmott/</a></p><p>The CyBUr Guy Podcast: <a target="_blank" rel="noopener noreferrer nofollow" href="https://podcasts.apple.com/us/podcast/the-cybur-guy-podcast/id1526491250">https://podcasts.apple.com/us/podcast/the-cybur-guy-podcast/id1526491250</a></p><p>National CSOC Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://nationalcsoc.com/">https://nationalcsoc.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Experience questionnaire automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e34&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e34&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1679807</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1679807/grcacademy/2024_10_01_01_54_30_025fff8e-1ccf-4a9e-ada6-7f71457edbab.mp3" length="17012592" type="audio/mpeg"/>
      <guid isPermaLink="false">8506a172-ddbe-41cc-8ad5-457d6e317978</guid>
      <itunes:duration>1063</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>34</itunes:episode>
      <podcast:episode>34</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 01 Oct 2024 12:00:59 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20241001_011022_95bfe1856e02c881359429a41c17a26c.png"/>
    </item>
    <item>
      <title><![CDATA[Mastering GRC - What I Learned from Big Tech! (with Kenneth Moras)]]></title>
      <itunes:title><![CDATA[Mastering GRC - What I Learned from Big Tech! (with Kenneth Moras)]]></itunes:title>
      <description><![CDATA[<p>Want a high paying job in GRC? Want to build a powerful GRC team?</p><p>In this episode, I spoke with Kenneth Moras, Security GRC Lead at Plaid.</p><p>Kenneth has worked in critical GRC roles in big tech companies like Adobe and Meta! He was heavily involved in the cyber response to international regulators after severe breaches.</p><p>Here are some highlights:</p><ul><li>What you need to do and know to get a job in GRC</li><li>How to master GRC</li><li>3 critical skillsets you need in your cyber GRC team</li><li>How regulatory incident response differs from traditional cyber incident response</li></ul><p>Kenneth is a true GRC master! His advice for folks wanting to get into GRC is the best I've heard! His tips on building successful GRC teams were excellent as well!</p><p>What were your biggest takeaway? Do you agree that GRC teams need technical knowledge? Looking forward to your thoughts!</p><p>Follow Kenneth on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/kennethmoras/">https://www.linkedin.com/in/kennethmoras/</a></p><p>Plaid Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://plaid.com/">https://plaid.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e33&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e33&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1667810</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1667810/grcacademy/2024_09_23_01_50_56_b80a92e6-188a-4b47-8872-997357978b41.mp3" length="29918851" type="audio/mpeg"/>
      <guid isPermaLink="false">68bbd390-1236-433d-8ada-b595583b2a49</guid>
      <itunes:duration>1869</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>33</itunes:episode>
      <podcast:episode>33</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 24 Sep 2024 12:00:56 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240923_010943_4678b2e083192b2ad33133c1fc399c22.png"/>
    </item>
    <item>
      <title><![CDATA[Digital Identity Wallets: How They Work and What Big Tech Is Hiding]]></title>
      <itunes:title><![CDATA[Digital Identity Wallets: How They Work and What Big Tech Is Hiding]]></itunes:title>
      <description><![CDATA[<p>Throw away your plastic driver's license - digital IDs have entered the chat!</p><p>In this episode, I spoke with Dr. Paul Ashley, the CTO of Anonyome Labs.</p><p>Paul explains how widespread online surveillance is, the evolution of digital identity from centralized to decentralized models, how digital wallets work, and what big tech doesn't want you to know!</p><p>Here are a few highlights from this episode:</p><ul><li>Big tech's surveillance economy</li><li>Evolution of digital identity</li><li>Decentralized Identity</li><li>Global adoption of digital ID wallets - including in the USA!</li></ul><p>I had no idea this was happening. More than 20 states in the USA are adopting digital driver's licenses!</p><p>It's fascinating to think of how digital IDs could be used personally and at work!</p><p>It's also scary to think of how some governments could abuse this technology.</p><p>Whatever you think, I'm looking forward to hearing your thoughts!</p><p>Follow Paul on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/drpaulashley/">https://www.linkedin.com/in/drpaulashley/</a></p><p>Anonyome Labs Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://anonyome.com/">https://anonyome.com/</a></p><p>My Sudo App: <a target="_blank" rel="noopener noreferrer nofollow" href="https://mysudo.com/">https://mysudo.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e32&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e32&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1659712</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1659712/grcacademy/2024_09_17_12_05_38_652a41d0-43d0-49ef-8c94-5f9060049bf9.mp3" length="24944341" type="audio/mpeg"/>
      <guid isPermaLink="false">03bba8a8-66b6-4274-9567-2cefe40ca36a</guid>
      <itunes:duration>1558</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>32</itunes:episode>
      <podcast:episode>32</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 17 Sep 2024 12:09:20 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240917_120925_3de0b31abffceb9cafc1353ba8c1dd79.png"/>
    </item>
    <item>
      <title><![CDATA[Georgia Tech Cybersecurity False Claims Scandal: Meet the Whistleblowers]]></title>
      <itunes:title><![CDATA[Georgia Tech Cybersecurity False Claims Scandal: Meet the Whistleblowers]]></itunes:title>
      <description><![CDATA[<p>Introducing the Georgia Tech Whistleblowers.</p><p>In this episode, the whistleblowers explain how they tried to stop Georgia Tech from allegedly LYING to the government about their NIST 800-171 compliance and what they have faced since they blew the whistle!</p><p>Whistleblower attorney Julie Bracker also shares what could come next and how much Georgia Tech may have to pay out!</p><p>Here are a few highlights from this episode:</p><ul><li>Hear directly from the whistleblowers in this False Claims Act case</li><li>Details on the "Fictitious" NIST 800-171 SPRS Score</li><li>How much money Georgia Tech might have to pay</li><li>Recommendations to universities</li><li>Advice for other whistleblowers</li></ul><p>Both of the whistleblowers have a long history with Georgia Tech and truly care for the institution.</p><p>Christopher Craig has worked at Georgia Tech for more than 20 years. He was the Associate Director of Cybersecurity where he managed all central cyber security personnel and built the GRC team until Georgia Tech demoted him to an Enterprise Security Architect.</p><p>Kyle Koza worked at Georgia Tech for more than 15 years until he left his role as a Principal Information Security Engineer in 2022. He got his bachelor’s and master's degrees from Georgia Tech and also co-wrote and still teaches a security incident response master's degree course at the university.</p><p>I thought Christopher's recommendation (24:37) for universities to centralize their labs was excellent!</p><p>How can a university expect to maintain its NIST / CMMC compliance if multiple labs are built and managed by different teams who may not even be familiar with the NIST 800-171 security controls?</p><p>I also loved hearing Chris tell us about the support he has received from the cyber community (38:00)! Who in cyber doesn't want to do the right thing? I would like to think those with bad intent are an extremely small percentage.</p><p>Special thanks to Christopher and Kyle for sharing their stories with us, and to Julie Bracker for coordinating this interview!</p><p>Follow Julie on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/juliekeetonbracker/">https://www.linkedin.com/in/juliekeetonbracker/</a></p><p>Bracker &amp; Marcus LLC Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.fcacounsel.com/">https://www.fcacounsel.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's upcoming webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e31&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e31&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1647232</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1647232/grcacademy/2024_09_09_02_24_13_f3f02bd3-b35b-4829-a562-bec7b0f72872.mp3" length="39937630" type="audio/mpeg"/>
      <guid isPermaLink="false">794a29e1-116b-404a-9dd7-1e5f6c773811</guid>
      <itunes:duration>2495</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>31</itunes:episode>
      <podcast:episode>31</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 10 Sep 2024 12:00:46 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240910_010956_1c6b497f286c805fa3c99e354c1cf9a5.png"/>
    </item>
    <item>
      <title><![CDATA[Zero Trust - It's Way Easier Than You Think with John Kindervag]]></title>
      <itunes:title><![CDATA[Zero Trust - It's Way Easier Than You Think with John Kindervag]]></itunes:title>
      <description><![CDATA[<p>Zero Trust is NOT complicated!</p><p>Don't believe me? Let me introduce you to its creator!</p><p>In this episode, Jacob speaks with John Kindervag, the creator of Zero Trust.</p><p>John is the Chief Evangelist at Illumio where he accelerates awareness and adoption of Zero Trust Segmentation.</p><p>In the episode he shares the origin story of Zero Trust starting with his time at Forrester Research. He explains the fundamental principles of Zero Trust, debunks common misconceptions, and how you can implement Zero Trust using a 5-step model.</p><p>Here are a few highlights from this episode:</p><ul><li>The broken trust model that has allowed the largest data breaches</li><li>Defining Zero Trust and misconceptions about it</li><li>How to implement zero trust in 5 steps</li><li>"Things Run Amok" poem - if Dr. Seuss wrote about the Internet of Things</li></ul><p>John's elevator pitch for Zero Trust is a masterclass in itself.</p><p>If you want to convince business leaders to invest in cybersecurity, you have to focus on how that investment will benefit the business. John does exactly that here and we should all take note.</p><p>Illumio is a Zero Trust Segmentation company that prevents breaches and ransomware from spreading across hybrid environments. Their platform visualizes traffic flows, automatically sets granular segmentation policies, and isolates critical assets and compromised systems. Founded in 2013, Illumio protects organizations of all sizes, from Fortune 100 to small businesses.</p><p>Follow John on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/john-kindervag-40572b1/">https://www.linkedin.com/in/john-kindervag-40572b1/</a></p><p>Illumio Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.illumio.com/">https://www.illumio.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's upcoming webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e30&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e30&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1630249</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1630249/grcacademy/2024_09_01_21_13_08_f1990aa3-3010-4b51-a65e-8c4f7ae21eba.mp3" length="30497803" type="audio/mpeg"/>
      <guid isPermaLink="false">ac57ecd1-b85f-42c6-b883-e32cb59df418</guid>
      <itunes:duration>1905</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>30</itunes:episode>
      <podcast:episode>30</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 03 Sep 2024 12:30:18 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20250317_120312_a9072cd0a827a3887409a599b8c99591.jpg"/>
    </item>
    <item>
      <title><![CDATA[The Cisco Whistleblower - The First Settled Cybersecurity False Claims Act (FCA) Lawsuit]]></title>
      <itunes:title><![CDATA[The Cisco Whistleblower - The First Settled Cybersecurity False Claims Act (FCA) Lawsuit]]></itunes:title>
      <description><![CDATA[<p>Introducing the Cisco Whistleblower.</p><p>In this episode, Jacob speaks with lawyer Hamsa Mahendranathan about the FIRST cybersecurity False Claims Act (FCA) lawsuit that reached a settlement!</p><p>This goes all the way back to 2008 believe it or not… The lawsuit was FINALLY settled in 2019!</p><p>As we all know, the DoJ has intervened in the Georgia Tech NIST 800-171 FCA whistleblower complaint.</p><p>Wonder what the whistleblowers may be dealing with? Maybe you want to blow the whistle yourself and don't know what to expect?</p><p>Here are a few highlights from this episode:</p><ul><li>How Hamsa's client unwittingly became a whistleblower</li><li>The fallout he experienced for doing the right thing</li><li>Mitigations for career consequences of blowing the whistle</li><li>The complexity of working with federal, state, and local False Claim Act laws</li></ul><p>And so much more!</p><p>If you are interested in the False Claims Act and cyber compliance, you won't want to miss this one! This episode is truly one for the history books!</p><p>Read the whistleblower complaint: <a target="_blank" rel="noopener noreferrer nofollow" href="https://cdn.grcacademy.io/web/20240824091900/us-ex-rel-glenn-vs-cisco-fca-complaint.pdf">https://cdn.grcacademy.io/web/20240824091900/us-ex-rel-glenn-vs-cisco-fca-complaint.pdf</a></p><p>Follow Hamsa on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/hamsa-mahendranathan/">https://www.linkedin.com/in/hamsa-mahendranathan/</a></p><p>Whistleblower Partners Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whistleblower.law/">https://www.whistleblower.law/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's upcoming webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e29&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e29&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1625183</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1625183/grcacademy/2024_08_24_12_44_12_871fb524-9526-4ec0-a069-975747c2aadf.mp3" length="25444663" type="audio/mpeg"/>
      <guid isPermaLink="false">68f05c63-76b9-474e-a7e8-9f8ce415670b</guid>
      <itunes:duration>1590</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>29</itunes:episode>
      <podcast:episode>29</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Sat, 24 Aug 2024 12:44:40 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240824_020844_dfe5be102f585b8b945421006e4b65fc.png"/>
    </item>
    <item>
      <title><![CDATA[CMMC and Manufacturing with Daniel Stark]]></title>
      <itunes:title><![CDATA[CMMC and Manufacturing with Daniel Stark]]></itunes:title>
      <description><![CDATA[<p>Think your users are resistant to CMMC? You ain't seen nothin' yet!</p><p>In this episode, Jacob speaks with Daniel Stark of Meerkat Cyber about the unique CMMC compliance challenges in a manufacturing environment.</p><p>Here are some highlights:</p><ul><li>Daniel's experience running IT in a family-owned manufacturing shop</li><li>How Controlled Unclassified Information (CUI) flows on the shop floor</li><li>Physical and environmental security constraints unique to manufacturing</li><li>How ISO 9001 / AS9100 can help get the buy in for CMMC</li><li>Advice for manufacturing IT staff dealing with CMMC compliance</li><li>Tips on hiring the right CMMC consultant and assessor</li></ul><p>I really enjoyed learning more about how machine shops operate and the unique challenges they have when it comes to CMMC compliance!</p><p>It's awesome that there are folks in the CMMC ecosystem that are familiar with manufacturers!</p><p>Manufacturing is an extremely different type of environment and in my opinion "normal" office IT assessment experience won't cut it. Hire wisely, folks!</p><p>Follow Daniel on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/daniel-stark-a85694222/">https://www.linkedin.com/in/daniel-stark-a85694222/</a></p><p>Meerkcat Cyber Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://meerkatcyber.com/">https://meerkatcyber.com/</a></p><p>-----------</p><p>Thanks to our sponsor Vanta!</p><p>Want to save time filling out security questionnaires?</p><p>Register for Vanta's upcoming webinar on Questionnaire Automation here: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vanta.com/grcacademy">https://vanta.com/grcacademy</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e28&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e28&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1619326</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1619326/grcacademy/2024_08_20_01_25_26_cb5e9a82-6aea-46c2-a3ba-8da4a8934a95.mp3" length="24689805" type="audio/mpeg"/>
      <guid isPermaLink="false">9825799d-acbc-4a1f-a3a5-e97dfffe3831</guid>
      <itunes:duration>1543</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>28</itunes:episode>
      <podcast:episode>28</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 20 Aug 2024 12:01:14 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240820_010812_0dae7bc7a10daf50ce7fac74876e4a15.png"/>
    </item>
    <item>
      <title><![CDATA[Insights on NIST 800-171 Joint Surveillance Voluntary Assessments (JSVA) from IntelliGRC]]></title>
      <itunes:title><![CDATA[Insights on NIST 800-171 Joint Surveillance Voluntary Assessments (JSVA) from IntelliGRC]]></itunes:title>
      <description><![CDATA[<p>So… How do I get a CMMC’d early?</p><p>In this episode, Jacob speaks with Steven Molter of IntelliGRC about his experiences helping IntelliGRC clients complete NIST 800-171 Joint Surveillance Voluntary Assessments (JSVAs).</p><p>Here are some highlights:</p><ul><li>The JSVA process &amp; how to request one</li><li>The different teams within DIBCAC</li><li>The challenge of subjectivity during assessments</li><li>Advice for companies preparing for JSVAs</li><li>How a company convinced DIBCAC to "upgrade" from a traditional DIBCAC high assessment to a JSVA</li></ul><p>According to the proposed CMMC program rule, JSVAs are eligible to convert to CMMC level 2 certifications once the CMMC program goes live assuming certain conditions are met:</p><ul><li>Perfect assessment score</li><li>No open assessment POA&amp;Ms</li></ul><p>Steve shared some great lessons for those preparing for JSVAs and CMMC assessments. If you're prepping for either, you won’t want to miss this episode!</p><p>Also, just in case you didn’t know, IntelliGRC customers receive my DIB-focused CMMC Overview Training! No other GRC platform that I'm aware of today provides comprehensive foundational CMMC training to their customers!</p><p>If you are looking for a GRC platform to manage your CMMC compliance program, check out IntelliGRC!</p><p>Follow Steve on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/steven-molter-apologeticz/">https://www.linkedin.com/in/steven-molter-apologeticz/</a></p><p>Follow IntelliGRC on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/company/intelligrc/">https://www.linkedin.com/company/intelligrc/</a></p><p>IntelliGRC Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.intelligrc.com/">https://www.intelligrc.com/</a></p><p>IntelliGRC YouTube Channel: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.youtube.com/@intelligrc">https://www.youtube.com/@intelligrc</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e27&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e27&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1593995</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1593995/grcacademy/2024_08_01_13_54_30_d931ef4e-1b0d-46b4-9581-f2d7489f8487.mp3" length="26571503" type="audio/mpeg"/>
      <guid isPermaLink="false">18109e69-c32b-4fad-86b8-2371bd6ec1ac</guid>
      <itunes:duration>1660</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>27</itunes:episode>
      <podcast:episode>27</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 01 Aug 2024 13:56:42 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240801_010812_606e55ceb1e98bf8e9b08ad7799179be.png"/>
    </item>
    <item>
      <title><![CDATA[Hypori Halo: Redefining Mobile Device Security with Brian Kovalski]]></title>
      <itunes:title><![CDATA[Hypori Halo: Redefining Mobile Device Security with Brian Kovalski]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with Brian Kowalski, Senior Vice President of Federal at Hypori.</p><p>In the episode they discuss Hypori's origin story and its innovations in the mobile security space.</p><p>Here are some highlights from the episode:</p><ul><li>Hypori's origin story and its roots starting as an NSA Commercial Solutions for Classified Program (CSfC) product</li><li>How it is different from traditional Mobile Device Management (MDM)</li><li>How it works, its certifications, and its deployment options</li><li>How Hypori can help achieve CMMC compliance</li></ul><p>We don't think about it much, but mobile devices really are a huge risk - just think of how much information is on your phone!</p><p>If you work in cybersecurity, you should know about this unique option to provide secure mobile access!</p><p>Follow Brian on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/brian-kovalski-057b8a7/">https://www.linkedin.com/in/brian-kovalski-057b8a7/</a></p><p>Hypori Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.hypori.com/">https://www.hypori.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e26&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e26&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1562601</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1562601/grcacademy/2024_07_10_03_47_58_7c927e4e-ffbb-4efc-8d1e-c7a05985ccc4.mp3" length="11503188" type="audio/mpeg"/>
      <guid isPermaLink="false">082c9124-3731-48d7-a2fb-bc9a319c820c</guid>
      <itunes:duration>718</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 16 Jul 2024 12:01:29 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240710_030751_b391a013fee296b1d8bbaf5df10b8870.png"/>
    </item>
    <item>
      <title><![CDATA[The Business Case for Information Security with Mark Nicholls]]></title>
      <itunes:title><![CDATA[The Business Case for Information Security with Mark Nicholls]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with Mr. Mark Nicholls!</p><p>Mark is the CEO of Information Professionals Group and has over 30 years of experience!</p><p>In the episode they discuss the business case for information security, and how cybersecurity professionals can effectively communicate with the C-suite and other business leaders!</p><p>Here are some highlights from the episode:</p><ul><li>The Importance of information security in business</li><li>The Importance of securing data</li><li>How cyber professionals should engage with business leaders</li><li>Roleplaying exercise - bad/good examples of a cyber pro trying to convince a CEO</li><li>How active listening can help you make a difference</li></ul><p>Follow Mark on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/markdnicholls/">https://www.linkedin.com/in/markdnicholls/</a></p><p>Information Professionals Group Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.informpros.com.au/">https://www.informpros.com.au/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e25&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e25&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1529471</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1529471/grcacademy/2024_06_18_04_09_59_3bdb1e68-0057-42b5-9356-42d8254af75e.mp3" length="27379017" type="audio/mpeg"/>
      <guid isPermaLink="false">714823e7-293e-4278-b814-169fd0723e4a</guid>
      <itunes:duration>1711</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>25</itunes:episode>
      <podcast:episode>25</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 18 Jun 2024 12:01:25 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240618_040643_925118e1d1b678e82034b66748f68270.png"/>
    </item>
    <item>
      <title><![CDATA[How To Stop Social Engineering in Its Tracks with Chris Silvers]]></title>
      <itunes:title><![CDATA[How To Stop Social Engineering in Its Tracks with Chris Silvers]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with Penetration Tester &amp; Social Engineer Chris Silvers!</p><p>Chris Silvers is the founder of CG Silvers Consulting! Chris has a vast amount of experience ranging from CMMC assessments to penetration testing. He even won the prestigious DEF CON black badge during the DEF CON 24 Social Engineering Capture the Flag (SECTF)!</p><p>In this episode they focus on how organizations can defend against social engineering attacks!</p><p>Here are some highlights from the episode:</p><ul><li>Winning the DEF CON SECTF black badge</li><li>Social engineering tactics and tools</li><li>CEO impersonation / fraud attacks</li><li>How can GRC help defend against social engineering?</li><li>Why businesses shouldn't start with a penetration test</li></ul><p>Follow Chris on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/cgsilvers/">https://www.linkedin.com/in/cgsilvers/</a></p><p>Chris's Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cgsilvers.com/">https://www.cgsilvers.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e24&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e24&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1493691</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1493691/grcacademy/2024_05_26_02_35_13_5ca52dcf-7355-49a9-9273-4c3217302f55.mp3" length="29834860" type="audio/mpeg"/>
      <guid isPermaLink="false">2463ac8c-97b6-4386-a9b0-5e6f8dcb2ccb</guid>
      <itunes:duration>1864</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>24</itunes:episode>
      <podcast:episode>24</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 07 Jun 2024 12:00:32 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240526_020557_2474f0ecb8caf9283b8fc98c4016baa8.png"/>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Essentials with Aron Lange]]></title>
      <itunes:title><![CDATA[ISO 27001 Essentials with Aron Lange]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with ISO 27001 expert Aron Lange!</p><p>Aron is the founder of the GRC Lab, and a Udemy instructor with more than 11,000 students! He is an experienced auditor for management systems based on ISO 27001, ISO 9001, ISO 27018 and ISO 22301.</p><p>In this episode they discuss the essentials of ISO 27001 including the history of the standard and the changes in the latest revision, but also the significance of the organizations involved and the danger of ISO “certification paper mills.”</p><p>Here are some highlights from the episode:</p><ul><li>The history of ISO 27001</li><li>Changes in ISO 27001:2022</li><li>Who are the IAF, accreditation bodies, and certification bodies?</li><li>The importance of hiring an IAF affiliated certification body</li><li>ISO scoping</li><li>Maintaining an ISO certification</li><li>Best practices for internal audits</li></ul><p>Follow Aron on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/aronlange/">https://www.linkedin.com/in/aronlange/</a></p><p>Aron’s Udemy courses: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.udemy.com/user/aron-lange/">https://www.udemy.com/user/aron-lange/</a></p><p>Aron’s Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.aronlange.com/">https://www.aronlange.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e23&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e23&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1467915</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1467915/grcacademy/2024_05_06_21_28_13_43ae333a-15b1-456d-b9f9-82909d901603.mp3" length="26904154" type="audio/mpeg"/>
      <guid isPermaLink="false">ea3de8a5-db09-4c22-8ea6-f150143a0608</guid>
      <itunes:duration>1681</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Mon, 06 May 2024 21:28:30 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240506_090557_8fdda05f74fd053744251da6a5bda01a.png"/>
    </item>
    <item>
      <title><![CDATA[Why Threat Intel is Essential for Vulnerability Management with Patrick Garrity]]></title>
      <itunes:title><![CDATA[Why Threat Intel is Essential for Vulnerability Management with Patrick Garrity]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with cybersecurity researcher Patrick Garrity!</p><p>Patrick Garrity is a seasoned security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors.</p><p>In this episode they discuss the importance of integrating threat intelligence into vulnerability management using the Exploit Prediction Scoring System (EPSS), CISA Known Exploited Vulnerabilities Catalog, and the changes in CVSS 4.0!</p><p>Here are some highlights from the episode:</p><ul><li>How Exploit Prediction Scoring System (EPSS) can predict exploitation</li><li>How vulnerability scanners integrate EPSS</li><li>CISA's Known Exploited Vulnerabilities (KEV) Catalog</li><li>The national security implications of vulnerability management</li></ul><p>Follow Patrick on LinkedIn: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/patrickmgarrity/">https://www.linkedin.com/in/patrickmgarrity/</a></p><p>VulnCheck Website: <a target="_blank" rel="noopener noreferrer nofollow" href="https://vulncheck.com/">https://vulncheck.com/</a></p><p>Thanks to our sponsor Keeper Security!</p><p>Need a FedRAMP authorized Password Manager? See how Keeper can help you comply with CMMC: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.keepersecurity.com/cmmc/?utm_source=grcacademy&amp;utm_medium=display&amp;utm_campaign=cmmc_video">https://www.keepersecurity.com/cmmc/?utm_source=grcacademy&amp;utm_medium=display&amp;utm_campaign=cmmc_video</a></p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e22&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e22&amp;utm_campaign=courses</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1458444</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1458444/grcacademy/2024_04_30_01_56_43_cfce1d32-e7cf-4030-a804-21c34dc35f41.mp3" length="26042330" type="audio/mpeg"/>
      <guid isPermaLink="false">b92b81db-6495-405b-8d2c-9ade6c362c01</guid>
      <itunes:duration>1627</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 30 Apr 2024 12:00:53 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240430_010432_8d2f063641c8a7617e94124965afe01e.png"/>
    </item>
    <item>
      <title><![CDATA[The False Claims Act and The DOJ's Civil Cyber Fraud Initiative with Julie Bracker]]></title>
      <itunes:title><![CDATA[The False Claims Act and The DOJ's Civil Cyber Fraud Initiative with Julie Bracker]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with attorney Julie Bracker!</p><p>Julie is the whistleblower attorney for both the Penn State University and Georgia Tech University FCA complaints. These complaints essentially allege the defendants misrepresented their compliance with NIST 800-171!</p><p>They discuss the False Claims Act and the DOJ's Civil Cyber Fraud Initiative, and what federal contractors can do to avoid being the subject of a whistleblower complaint!</p><p>Here are some highlights from the episode:</p><ul><li>What is the False Claims Act?</li><li>What is the DoJ's Civil Cyber Fraud Initiative?</li><li>What are the risks and rewards for whistleblowers?</li><li>Who are the targets of the initiative?</li><li>Can companies blindly rely on their MSP and be safe?</li><li>How to quantify damages of cyber noncompliance fraud</li><li>DoJ Civil Cyber Fraud settled lawsuits so far</li><li>Georgia Tech and Penn State FCA cases</li></ul><p>Follow Julie on LinkedIn: <a href="https://www.linkedin.com/in/juliekeetonbracker/">https://www.linkedin.com/in/juliekeetonbracker/</a></p><p>Bracker & Marcus LLP Website: <a href="https://www.fcacounsel.com/">https://www.fcacounsel.com/</a></p><p>Penn State FCA Complaint: <a href="https://cdn.grcacademy.io/web/20240325204912/penn-state-university-false-claims-act-complaint.pdf">https://cdn.grcacademy.io/web/20240325204912/penn-state-university-false-claims-act-complaint.pdf</a></p><p>Georgia Tech FCA Complaint: <a href="https://cdn.grcacademy.io/web/20240325204909/georgia-tech-university-false-claims-act-complaint.pdf">https://cdn.grcacademy.io/web/20240325204909/georgia-tech-university-false-claims-act-complaint.pdf</a></p><p>2023 DoJ Report of FCA settlements (more than $2.68 billion): <a href="https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-268-billion-fiscal-year-2023">https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-268-billion-fiscal-year-2023</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e21&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e21&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1407448</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1407448/grcacademy/2024_03_26_01_13_59_a371b169-c330-4ab6-97be-33a6d60e02de.mp3" length="39277474" type="audio/mpeg"/>
      <guid isPermaLink="false">8c013361-a1b5-4b43-884b-1c8d9fa5584d</guid>
      <itunes:duration>2454</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 26 Mar 2024 12:01:16 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240326_010339_6dbdf32936aa747d6cdd3ad4c97e5070.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC and Security Compliance in Higher Education]]></title>
      <itunes:title><![CDATA[CMMC and Security Compliance in Higher Education]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob speaks with a panel of information security experts from universities about CMMC and their experience preparing for it!</p><p>They discuss security and compliance challenges at universities, the Penn State NIST 800-171 False Claims Act lawsuit, and much more!</p><p>Here are some highlights from the episode:</p><ul><li>How universities are different from other types of organizations</li><li>Different compliance requirements for universities</li><li>Who is involved in the execution of a government contract?</li><li>The drivers of cybersecurity compliance at universities</li><li>Thoughts on the Penn State False Claims Act lawsuit</li><li>How to drive positive cybersecurity change at a university</li><li>CUI enclaves at universities</li><li>Areas of CMMC that need clarification</li></ul><p>Here are the panelists:</p><ul><li>Jay Gallman - Duke University (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/jay-gallman/">https://www.linkedin.com/in/jay-gallman/</a>)</li><li>Kolin Hodgson - Notre Dame (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/kolin-hodgson-cisa-cissp-4bbb9a/">https://www.linkedin.com/in/kolin-hodgson-cisa-cissp-4bbb9a/</a>)</li><li>Melissa Kimble - University of Maine (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/melissa-kimble/">https://www.linkedin.com/in/melissa-kimble/</a>)</li><li>Wendy Epley - University of Arizona (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/wendyepley/">https://www.linkedin.com/in/wendyepley/</a>)</li></ul><p>Thanks to our sponsor Keeper Security!</p><p>Need a secure file sharing solution? Register for a webinar showing how Defense Contractors can share sensitive information using Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/webinar-cmmc-file-sharing-april-2024/">https://grcacademy.io/ref/keeper/webinar-cmmc-file-sharing-april-2024/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e20&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e20&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1390921</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1390921/grcacademy/2024_03_15_01_53_52_a49b1beb-65f7-406f-8e52-f7577837d30f.mp3" length="72899299" type="audio/mpeg"/>
      <guid isPermaLink="false">128fc9da-4b14-4818-bd36-e1bd48e5a9ce</guid>
      <itunes:duration>4556</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>20</itunes:episode>
      <podcast:episode>20</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Wed, 20 Mar 2024 12:00:48 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240315_010308_3fa1c930808d79e2e59fd71d38532bf8.jpg"/>
    </item>
    <item>
      <title><![CDATA[AI's Impact on Cybersecurity Risk with Dr. Raghuram Srinivas of MetricStream]]></title>
      <itunes:title><![CDATA[AI's Impact on Cybersecurity Risk with Dr. Raghuram Srinivas of MetricStream]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob talks to Dr. Raghuram Srinivas from MetricStream!</p><p>They discuss the beginnings of AI, how it has evolved over time, and the risks and opportunities it presents to companies around the world!</p><p>Raghuram is the Senior Vice President of Product Management at MetricStream. He is an AI expert and has worked in AI-focused roles at JPM Chase, KPMG, as well as the Watson Group at IBM.</p><p>Here are some highlights from the episode:</p><ul><li>The history of AI</li><li>How do large language models (LLMs) work?</li><li>AI for GRC & GRC for AI</li><li>Using AI in cyber operations</li><li>The future of cyber risk</li></ul><p>Follow Ragu on LinkedIn: <a href="https://www.linkedin.com/in/raghuramsrinivas/">https://www.linkedin.com/in/raghuramsrinivas/</a></p><p>MetricStream website: <a href="https://www.metricstream.com/">https://www.metricstream.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online cyber GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e19&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e19&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1368842</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1368842/grcacademy/2024_03_01_04_01_53_1cb4a920-117d-4fe2-9953-1fe33dc9f9c7.mp3" length="16474129" type="audio/mpeg"/>
      <guid isPermaLink="false">ce5bc7ab-5841-4d2c-ad04-08bc77ecd628</guid>
      <itunes:duration>1019</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>19</itunes:episode>
      <podcast:episode>19</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 01 Mar 2024 13:01:20 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240301_020311_21ad75a954cdc0fd52104cb46292628c.png"/>
      <podcast:transcript url="https://transcripts.rss.com/230061/1368842/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[Zscaler on FedRAMP and Zero Trust with Patrick Perry]]></title>
      <itunes:title><![CDATA[Zscaler on FedRAMP and Zero Trust with Patrick Perry]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jacob talks to Patrick Perry from Zscaler. They discuss Zscaler's experiences navigating the FedRAMP and DoD Impact Level processes as well as Zero Trust!</p><p>Pat is a cybersecurity expert with over 20 years of experience. He currently works at Zscaler as Field CTO and is responsible for the alignment of Zscaler capabilities to the DoD and IC mission sets in order to provide dynamic, mission-focused, innovative approaches to enable transformation and zero trust to warfighter organizations.</p><p>Zscaler U.S. Government Solutions enables the U.S government and their strategic partners to securely transform their networks and applications for a mobile and cloud-first world. Zscaler's FedRAMP Moderate/High/DoD IL5-authorized solutions ensure fast, secure connections between users and applications, regardless of device, location, or network.</p><p>Here are some highlights from the episode:</p><ul><li>Zscaler's Approach to FedRAMP, DoD Impact Levels, and CMMC</li><li>Shared Responsibility Between Cloud Service Providers and Users</li><li>What Zero Trust is and how it relates to CMMC</li><li>Zero Trust Pillars</li><li>Thoughts on Federal Approach to Zero Trust</li></ul><p>Follow Patrick on LinkedIn: <a href="https://www.linkedin.com/in/perrypn2019/">https://www.linkedin.com/in/perrypn2019/</a></p><p>Zscaler website: <a href="https://www.zscaler.com/">https://www.zscaler.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e18&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e18&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1251604</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1251604/grcacademy/2023_12_05_02_28_53_58fc35f0-a5e6-491b-ba2a-c95c7d242d24.mp3" length="27195228" type="audio/mpeg"/>
      <guid isPermaLink="false">27b04393-2da3-4bfc-a5b4-241920979d8a</guid>
      <itunes:duration>1699</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 05 Dec 2023 22:47:59 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231205_021252_76fe7d1a7b9113a64c91609d637e6ce3.jpg"/>
    </item>
    <item>
      <title><![CDATA[Cyber Security Questionnaire Essentials with Derrich Phillips of Aspire Cyber]]></title>
      <itunes:title><![CDATA[Cyber Security Questionnaire Essentials with Derrich Phillips of Aspire Cyber]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Derrich Phillips from Aspire Cyber about best practices and tips when filling out cybersecurity questionnaires.</p><p>Derrich Phillips is a cybersecurity expert with over 20 years of experience in the field. He started his career in the Army's security operations center, defending networks against cyber attacks. As the founder of Aspire Cyber, he focuses on helping small companies prove their cybersecurity readiness to handle information for enterprise customers.</p><p>Here are some highlights from the episode:</p><ul><li>How Derrich get into cybersecurity</li><li>The what and why of security questionnaires</li><li>How to save time and money while filling out a security questionnaires</li><li>When to push back on overly burdensome requirements</li></ul><p>Check out this video where Derrich and I discuss how ChatGPT can be used in information security compliance: <a href="https://youtu.be/IAAJPJLBeaY">https://youtu.be/IAAJPJLBeaY</a></p><p>Follow Derrich on LinkedIn: <a href="https://www.linkedin.com/in/derrichphillips/">https://www.linkedin.com/in/derrichphillips/</a></p><p>Aspire Cyber website: <a href="https://www.aspirecyber.com/">https://www.aspirecyber.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e17&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e17&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1219448</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1219448/grcacademy/2023_11_13_13_38_17_78ce7bfb-1062-4808-b224-4eb014fd228a.mp3" length="12174953" type="audio/mpeg"/>
      <guid isPermaLink="false">6ca601f8-aefa-43b9-b337-351940e0b5af</guid>
      <itunes:duration>743</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 28 Nov 2023 13:00:33 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231115_031104_436d05e91db0a04f6999cec42e3bcc63.jpg"/>
    </item>
    <item>
      <title><![CDATA[Behind the Curtain of Federal Rulemaking with Shauna Weatherly of FedSubK.com]]></title>
      <itunes:title><![CDATA[Behind the Curtain of Federal Rulemaking with Shauna Weatherly of FedSubK.com]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Shauna Weatherly from <a href="http://FedSubK.com">FedSubK.com</a>.</p><p>Shauna recently retired from the federal government after serving more than 35 years in the federal acquisition / contracting space! During her career she served as chief of contracting, contracting officer representative, and as an advisor to the Civilian Agency Acquisition Council (CAAC).</p><p>She even has direct experience in the federal rulemaking process, and contributed to FAR case 2017-016, also known as the FAR CUI rule, which will contractually require the implementation of NIST SP 800-171 on federal contracts.</p><p>Join us as we pull back the curtain on the federal rulemaking process and more!</p><p>Here are some highlights from the episode:</p><ul><li>Shauna’s background</li><li>Steps and roles involved in the federal rulemaking process</li><li>What is a FAR case?</li><li>What is OIRA’s role?</li><li>The relationship between the FAR and DFARS</li><li>How to provide effective public comments on regulations</li><li>Impacts of FAR case 2017-16 - CUI rule</li><li>Impacts of FAR case 2021-17 - Cyber Threat and Incident Reporting and Information Sharing regulation</li><li>Impacts of FAR case 2021-019 - Standardizing Cybersecurity Requirements for Unclassified Information Systems</li></ul><p>Follow Shauna on LinkedIn: <a href="https://www.linkedin.com/in/shauna-weatherly/">https://www.linkedin.com/in/shauna-weatherly/</a></p><p>FedSubK website: <a href="https://www.fedsubk.com/">https://www.fedsubk.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e16&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e16&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1227010</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1227010/grcacademy/2023_11_17_15_11_58_7e4d9c7f-1c0e-4118-819d-1401278eb5b2.mp3" length="27907670" type="audio/mpeg"/>
      <guid isPermaLink="false">778dc149-2256-40a5-a75e-082ec5600d9a</guid>
      <itunes:duration>1713</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>16</itunes:episode>
      <podcast:episode>16</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Sat, 18 Nov 2023 15:24:20 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231117_031156_22fc5397bbb680f886cb675a0afc73a4.jpg"/>
    </item>
    <item>
      <title><![CDATA[Cloud Security & DFARS 7012 Compliance with Michael Greenman from Deltek]]></title>
      <itunes:title><![CDATA[Cloud Security & DFARS 7012 Compliance with Michael Greenman from Deltek]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Michael Greenman from Deltek.</p><p>Michael has worked in government and cloud-based technology for over 20 years, and currently works at Deltek in the Product Strategy group and is the evangelist for cybersecurity compliance and cloud services!</p><p>Michael shares Deltek's perspective on security and compliance as a cloud service provider.</p><p>Here are some highlights from the episode:</p><ul><li>How Michael got into cybersecurity</li><li>Deltek's government clouds</li><li>DFARS 252.204-7012's C - G incident reporting requirements</li><li>How cloud providers can demonstrate FedRAMP moderate equivalency</li><li>What is a shared responsibility matrix</li><li>The need for a defense focused CSP / ESP / MSP marketplace</li></ul><p>Follow Michael on LinkedIn: <a href="https://www.linkedin.com/in/michael-greenman-94952a3/">https://www.linkedin.com/in/michael-greenman-94952a3/</a></p><p>Deltek website: <a href="https://www.deltek.com/">https://www.deltek.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e15&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e15&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1193819</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1193819/grcacademy/2023_11_02_00_30_37_e4175c8f-5b45-497f-84c5-3cb13fe206f3.mp3" length="13723953" type="audio/mpeg"/>
      <guid isPermaLink="false">ab2ac53c-64bb-4ee0-bd71-92457f9110e6</guid>
      <itunes:duration>839</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 02 Nov 2023 10:30:16 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231029_121049_fa47fe5c0b4dc76ce6138307cb569018.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Insights with Redspin Assessor Thomas Graham]]></title>
      <itunes:title><![CDATA[CMMC Insights with Redspin Assessor Thomas Graham]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Dr. Thomas Graham who is a CMMC assessor.</p><p>Thomas is the Vice President and CISO at Redspin, and Redspin is the first CMMC Third Party Assessor Organization (C3PAO)!</p><p>This episode has a lot of great information for the defense industrial base!Here are some highlights from the episode:</p><ul><li>Redspins' experience becoming the first C3PAO</li><li>Notable changes in NIST 800-171 r3</li><li>CMMC challenges and misconceptions</li><li>Tips for selecting the right CMMC consultant and assessor</li><li>Other countries interested in CMMC</li><li>Each phase of the CMMC assessment process</li><li>What CMMC practices can be POA&M'd according to current guidance</li><li>And more!</li></ul><p>Follow Thomas on LinkedIn: <a href="https://www.linkedin.com/in/tgrahamphd/">https://www.linkedin.com/in/tgrahamphd/</a></p><p>Redspin website: <a href="https://www.redspin.com">https://www.redspin.com</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e14&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e14&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1183297</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1183297/grcacademy/2023_10_21_16_25_15_6c7013f1-f1bd-4bc7-ab19-203fb4a0464a.mp3" length="33589230" type="audio/mpeg"/>
      <guid isPermaLink="false">4c69daad-66e2-4d5c-b2f3-d4ad8f5a9c8f</guid>
      <itunes:duration>2092</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Mon, 23 Oct 2023 12:00:41 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041014_9e974fea5bcb58634600b369e7c8b9e7.jpg"/>
    </item>
    <item>
      <title><![CDATA[CMMC Rulemaking with Jacob Horne]]></title>
      <itunes:title><![CDATA[CMMC Rulemaking with Jacob Horne]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob Hill talks with Jacob Horne from Summit 7!</p><p>Jacob Horne is Summit 7's Chief Security Evangelist, and has a unique genetic superpower that allows him to delve into NIST publications & government regulations without experiencing even a hint of boredom!</p><p>In the episode Jacob Horne explains the history leading up to the CMMC program, when CMMC may be required, and the significance of the FAR CUI rule!</p><p>Here are some key topics we discussed:</p><ul><li>How he started in cybersecurity</li><li>The history leading up to CMMC</li><li>What is rulemaking</li><li>The two CMMC rules we are waiting on</li><li>When CMMC may appear in contracts</li><li>The FAR CUI rule and its importance</li><li>Why DHS and VA regulations were silent on NIST 800-171</li><li>When will the FAR CUI rule drop?</li></ul><p>Follow Jacob on LinkedIn: <a href="https://www.linkedin.com/in/jacob-evan-horne/">https://www.linkedin.com/in/jacob-evan-horne/</a></p><p>Summit 7 website: <a href="https://www.summit7.us/">https://www.summit7.us/</a></p><p>Jacob Horne's Deep dive on CMMC rulemaking timeline: <a href="https://www.youtube.com/watch?v=qyLDQxo-YPg">https://www.youtube.com/watch?v=qyLDQxo-YPg</a></p><p>Federal Rulemaking book: <a href="https://www.amazon.com/Rulemaking-Government-Agencies-Write-Policy/dp/1483352811/">https://www.amazon.com/Rulemaking-Government-Agencies-Write-Policy/dp/1483352811/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e13&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e13&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139205</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139205/grcacademy/2023_09_24_00_45_43_5af72621-a1f7-45d9-9911-786282d111b0.mp3" length="28047949" type="audio/mpeg"/>
      <guid isPermaLink="false">DD2C3D67088005586B282E2E38975202B7759B5A076A73F59F859329B0657DDD</guid>
      <itunes:duration>1745</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 22 Sep 2023 20:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041043_6df340d1dcbb6435d1fd3ca199e416e9.jpg"/>
    </item>
    <item>
      <title><![CDATA[Talking Cybersecurity with Dr Ron Ross of NIST]]></title>
      <itunes:title><![CDATA[Talking Cybersecurity with Dr Ron Ross of NIST]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob talks with Dr. Ron Ross from NIST! This is the final of a three-part series with Dr. Ross.</p><p>In the episode Dr. Ross shares his thoughts on topics like ChatGPT, zero trust, his top 5 security controls, advice to folks new to cybersecurity, and much more!</p><p>Here are some key topics we discussed:</p><ul><li>Top challenges in federal cybersecurity compliance</li><li>How to enable positive cybersecurity culture</li><li>The missing strategic view in cybersecurity</li><li>Zero Trust</li><li>LLMs like ChatGPT</li><li>The importance of managing complexity</li><li>Dr. Ross's top 5 critical security controls</li><li>Career advice to folks new to cybersecurity</li></ul><p>Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more!</p><p>Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure.</p><p>He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors.</p><p>Follow Ron on LinkedIn: <a href="https://www.linkedin.com/in/ronrossecure/">https://www.linkedin.com/in/ronrossecure/</a></p><p>NIST CSRC Website: <a href="https://csrc.nist.gov/">https://csrc.nist.gov/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e12&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e12&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139204</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139204/grcacademy/2023_09_24_00_45_50_43707846-ac61-45aa-9dfe-73d751863e66.mp3" length="29433502" type="audio/mpeg"/>
      <guid isPermaLink="false">BF2C88CDB5CF5600649BFFE2226EA803A6E0BAC8D4C6F49C09E419E9800B71C2</guid>
      <itunes:duration>1831</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 01 Sep 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041017_e3915b54897259804f48841d63dc2cab.jpg"/>
    </item>
    <item>
      <title><![CDATA[NIST 800-171 r3 August 2023 Status Update with Dr Ron Ross]]></title>
      <itunes:title><![CDATA[NIST 800-171 r3 August 2023 Status Update with Dr Ron Ross]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 2nd of a three-part series with Dr. Ross.</p><p>In the episode Dr. Ross shares a status update on NIST 800-171 revision 3. At the time of this recording, NIST has released the 1st initial draft, and the 1st public comment period has closed.</p><p>Here are some key topics we discussed:</p><ul><li>Notable changes in NIST 800-171 r3</li><li>Thoughts on public comments</li><li>Strategy on the ODPs</li><li>Encryption (FIPS 140) control ODP</li><li>Independent Assessment control</li><li>Security Protection Assets</li><li>Implementation examples</li></ul><p>Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more!</p><p>Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure.</p><p>He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors.</p><p>Follow Ron on LinkedIn: <a href="https://www.linkedin.com/in/ronrossecure/">https://www.linkedin.com/in/ronrossecure/</a></p><p>NIST CSRC Website: <a href="https://csrc.nist.gov/">https://csrc.nist.gov/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e11&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e11&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139203</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139203/grcacademy/2023_09_24_00_45_52_a0a31563-66b1-42be-828a-64ec87932115.mp3" length="25286949" type="audio/mpeg"/>
      <guid isPermaLink="false">2A1A3E58D134BB7AA885F546665C1D0FF1177FFE5926C918FAC37F1FC93FB087</guid>
      <itunes:duration>1572</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Mon, 14 Aug 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041027_3404bd47584739fe2f3c0d035a378a7e.jpg"/>
    </item>
    <item>
      <title><![CDATA[NIST Cybersecurity History with Dr Ron Ross]]></title>
      <itunes:title><![CDATA[NIST Cybersecurity History with Dr Ron Ross]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 1st of a three-part series with Dr. Ross.</p><p>In the episode Dr. Ross shares the fascinating history of NISTs involvement in cyber security!</p><p>Here are some key topics we discussed:</p><ul><li>How he started at NIST and the projects he has worked on</li><li>NIST's and the Joint Task Force's Mission</li><li>How he convinced the DoD to transition from DIACAP to RMF</li><li>The history of continuous monitoring program</li><li>The origins of NIST 800-171</li><li>Why NIST did not adopt ISO 27001</li><li>The goal of NIST 800-160</li></ul><p>Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more!</p><p>Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure.</p><p>He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors.</p><p>Follow Ron on LinkedIn: <a href="https://www.linkedin.com/in/ronrossecure/">https://www.linkedin.com/in/ronrossecure/</a></p><p>NIST CSRC Website: <a href="https://csrc.nist.gov/">https://csrc.nist.gov/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e10&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e10&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139202</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139202/grcacademy/2023_09_24_00_45_41_287466f5-8596-4a51-976b-369cc84e98be.mp3" length="28884033" type="audio/mpeg"/>
      <guid isPermaLink="false">56FB4CB40A3B380FD15847C3627B41C1DB466FB789EA883A28009723EC30836B</guid>
      <itunes:duration>1805</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 11 Aug 2023 10:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041041_7e0ae9ff56ceff127f8099bc53f6d870.jpg"/>
    </item>
    <item>
      <title><![CDATA[Securing the Oil and Gas Industry with Industrial OT Cybersecurity Expert Joseph Loomis]]></title>
      <itunes:title><![CDATA[Securing the Oil and Gas Industry with Industrial OT Cybersecurity Expert Joseph Loomis]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob talks with operational technology (OT) cybersecurity expert Joseph Loomis!</p><p>Joseph is the President of Secrabus Inc where he performs cybersecurity assessments on Oil & Gas companies to help elevate their security posture and protect their critical assets.</p><p>Joseph shares his experiences after more than 15 years in the Oil & Gas industrial control system (ICS) and OT cybersecurity space.</p><p>Here are some key topics we discussed:</p><ul><li>How he started in cybersecurity</li><li>The just in time deliverability aspect of Oil & Gas</li><li>IT and OT convergence</li><li>Defense in depth architecture</li><li>GRC Standards that apply to the Oil & Gas industry</li><li>Purdue Model for ICS Security</li><li>His risk assessment methodology</li><li>Interesting stories</li><li>And more!</li></ul><p>Follow Joseph on LinkedIn: <a href="https://www.linkedin.com/in/josephloomis/">https://www.linkedin.com/in/josephloomis/</a></p><p>Secrabus Inc's Website: <a href="https://secrabus.com/">https://secrabus.com/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e9&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e9&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139201</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139201/grcacademy/2023_09_24_00_45_32_20d964df-e9e3-4d20-8a18-5efd50cc48f4.mp3" length="18408850" type="audio/mpeg"/>
      <guid isPermaLink="false">1DDA1E56FA5CE0205F688F72CE4D05E14C4FC93BB0E217A45028B7BB95B4086A</guid>
      <itunes:duration>1150</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Sat, 22 Jul 2023 18:30:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041025_efbeaeef11c0485265eb2df1b19adbf5.jpg"/>
    </item>
    <item>
      <title><![CDATA[From Aircraft Maintenance to GRC and Cybersecurity with Jonathan Fisher]]></title>
      <itunes:title><![CDATA[From Aircraft Maintenance to GRC and Cybersecurity with Jonathan Fisher]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob talks with GRC professional Jonathan Fisher.</p><p>Jonathan shifted into the GRC field after 20 years in the military supporting aircraft maintenance, and explains how others can do the same!</p><p>Here are some key topics we discussed:</p><ul><li>What GRC is</li><li>How he transitioned into GRC and cybersecurity</li><li>How nontechnical folks can transition into cybersecurity by starting in a GRC role</li><li>How most folks already have transferrable experience</li><li>What GRC frameworks to focus on</li><li>How to use LinkedIn to boost your career</li></ul><p>Follow Jonathan on LinkedIn: <a href="https://www.linkedin.com/in/jonfisher11/">https://www.linkedin.com/in/jonfisher11/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e8&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e8&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139200</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139200/grcacademy/2023_09_24_00_45_20_15af90c5-8dd7-466c-9e89-3bc4388b0d5b.mp3" length="17883974" type="audio/mpeg"/>
      <guid isPermaLink="false">BD18ECF3B60CBF4AE246696067C324F054C7D07AE6FCADFF0DE0FADDEA3F9483</guid>
      <itunes:duration>1110</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Thu, 22 Jun 2023 18:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_041003_f28849d9ce7e0df7358451ef8ba209a6.jpg"/>
    </item>
    <item>
      <title><![CDATA[Privacy Laws and GRC with Attorney Donata Stroink-Skillrud]]></title>
      <itunes:title><![CDATA[Privacy Laws and GRC with Attorney Donata Stroink-Skillrud]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with privacy attorney Donata Stroink-Skillrud. Donata is the chair of the American Bar Association’s ePrivacy committee, and has an excellent understanding of privacy laws in the US and the EU.</p><p>She shares the impact of US and EU privacy laws on businesses, how they can plan to comply, and much more!</p><p>Here are some key topics we discussed:</p><ul><li>The importance of privacy laws</li><li>Differences between EU and US approaches to privacy</li><li>The impact of GDPR and why many consider it to be the gold standard in privacy laws</li><li>Current and emerging state-level privacy laws in the US</li><li>Implications of privacy laws for small businesses</li><li>The importance of only collecting the information you need</li><li>The status of the US's federal privacy law and how it compares to the GDPR</li><li>How GRC compliance frameworks like NIST’s Privacy Framework and ISO 27001 can help comply</li></ul><p>Donata's website: <a href="https://termageddon.com">https://termageddon.com</a></p><p>Follow Donata on LinkedIn: <a href="https://www.linkedin.com/in/donata-stroink-skillrud/">https://www.linkedin.com/in/donata-stroink-skillrud/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e7&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e7&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139199</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139199/grcacademy/2023_09_24_00_45_19_c2048b13-3d58-4f2f-b1a9-520f28cde671.mp3" length="28581893" type="audio/mpeg"/>
      <guid isPermaLink="false">E830E8D5D08ED30094DCAEADCC4AB9F11038EA46BD8E26DDFF179AE3FAC2F101</guid>
      <itunes:duration>1778</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Wed, 14 Jun 2023 18:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031050_cd516b14053e5a73dd380c439ea7c96e.jpg"/>
    </item>
    <item>
      <title><![CDATA[Insights from CMMC Consultant and Assessor Koren Wise]]></title>
      <itunes:title><![CDATA[Insights from CMMC Consultant and Assessor Koren Wise]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Koren Wise who is a highly experienced CMMC consultant, assessor, and instructor. Koren offers insights from her experience helping companies prepare for CMMC, and gives advice on hiring the right CMMC consultant and assessor for your business - and much more!.</p><p>Here are some of the topics we discussed:</p><ul><li>How she got to where she is today</li><li>Common misconceptions businesses have about CMMC</li><li>Who should take the CMMC Certified Professional (CCP) course</li><li>Real world problems and solutions</li><li>What is a CUI enclave?</li><li>Addressing CUI data sprawl in a business</li><li>Joint Surveillance Assessments</li><li>Managing CMMC compliance like a project</li><li>Hiring the right CMMC consultant</li><li>Hiring the right CMMC assessor</li></ul><p>Follow Koren on LinkedIn: <a href="https://www.linkedin.com/in/koren-wise/">https://www.linkedin.com/in/koren-wise/</a></p><p>Koren's website: <a href="https://www.wtinetworks.com">https://www.wtinetworks.com</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e6&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e6&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139198</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139198/grcacademy/2023_09_24_00_45_16_37e28dc9-2937-4057-918d-9ba55514b9aa.mp3" length="26041119" type="audio/mpeg"/>
      <guid isPermaLink="false">25B60EB6F4DE938FB715564FF4735681502FAFC9A1ACEBF1B93AC26D7C7A51D0</guid>
      <itunes:duration>1619</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 09 Jun 2023 17:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031052_0102442c61246b15c15b1e6b542235df.jpg"/>
    </item>
    <item>
      <title><![CDATA[Cyber Insurance 101 for Government Contractors with Rick Rosenberry]]></title>
      <itunes:title><![CDATA[Cyber Insurance 101 for Government Contractors with Rick Rosenberry]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Rick Rosenberry about Cyber Insurance in the context of DoD and government contracting.</p><p>Rick is an insurance broker and a CMMC Registered Practitioner, and he explains that not all cyber insurance policies are equal and the importance of working with an insurance broker that understands cybersecurity and your regulatory environment.</p><p>Here are a few of the topics we discussed:</p><ul><li>Overview of cyber insurance fundamentals</li><li>Key roles in the cyber insurance process</li><li>How underwriters assess a business's cyber risk</li><li>Critical security controls underwriters want in place</li><li>Benefits of compliance frameworks like NIST 800-171 and ISO 27001</li><li>False Claims Act cyber insurance claim scenarios</li><li>Getting the right coverage to support DFARS 252-204-7012 incident reporting</li></ul><p>Follow Rick on LinkedIn: <a href="https://www.linkedin.com/in/rick-rosenberry/">https://www.linkedin.com/in/rick-rosenberry/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e5&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e5&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139197</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139197/grcacademy/2023_09_24_00_45_13_e409c28b-08bc-40ce-a704-4fd7988a8dbf.mp3" length="13151438" type="audio/mpeg"/>
      <guid isPermaLink="false">7E1C42D88D029F95D4A279AB899054162D49B2069D518A6A70FB853E82BE6927</guid>
      <itunes:duration>814</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 02 Jun 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031025_fb648c7b444bebedc1b0aea3ecf22047.jpg"/>
    </item>
    <item>
      <title><![CDATA[Preparing North Carolina for CMMC with Laura Rodgers]]></title>
      <itunes:title><![CDATA[Preparing North Carolina for CMMC with Laura Rodgers]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Laura Rodgers about her work helping to prepare North Carolina businesses for the DoD's Cybersecurity Maturity Model Certification (CMMC).</p><p>Laura has established an excellent training program that guides North Carolina businesses in the creation of cybersecurity programs. The effort is in collaboration with the North Carolina Military Business Center, North Carolina State University, and other strategic partners.</p><p>Here are a few of the topics we discussed:</p><ul><li>Unique challenges faced by small businesses</li><li>Concerns the government is not properly marking or is overmarking documents as CUI</li><li>Importance of collaboration between technical and compliance teams</li><li>Challenges that incident response presents to small businesses.</li></ul><p>Follow Laura on LinkedIn: <a href="https://www.linkedin.com/in/lauradrodgers/">https://www.linkedin.com/in/lauradrodgers/</a></p><p>Cyber NC website: <a href="https://www.cybernc.us/">https://www.cybernc.us/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e4&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e4&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139196</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139196/grcacademy/2023_09_24_00_45_11_712e10e7-27b1-40ac-b18f-af61e8e2e463.mp3" length="15297390" type="audio/mpeg"/>
      <guid isPermaLink="false">E14A776E9209FF6EE1C872DB0A3F6A227442F28E4D4519DDAF608EB14A04DDA7</guid>
      <itunes:duration>953</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Wed, 12 Apr 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031014_88281dc06781397105033280d29b434d.jpg"/>
    </item>
    <item>
      <title><![CDATA[Power Grid Cyber Security with Jon Watkins]]></title>
      <itunes:title><![CDATA[Power Grid Cyber Security with Jon Watkins]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Jon Watkins about power grid security. Jon is a cybersecurity expert and the founder of the Rural Electric Cyber Advancement Program (RECAP)!</p><p>RECAP enables peer cybersecurity assessments among electric utility cooperatives. Jon has conducted multiple RECAP assessments for co-ops throughout the US.</p><p>Jon tells us about how he started in cybersecurity, the history of electric cooperatives, how power grid cybersecurity is different, how OT and SCADA are used to enhance the reliability of the grid, notable power grid cyber incidents, and RECAP.</p><p>Follow Jon on LinkedIn: <a href="https://www.linkedin.com/in/jonrwatkins/">https://www.linkedin.com/in/jonrwatkins/</a></p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e3&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e3&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139195</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139195/grcacademy/2023_09_24_00_45_09_afba3f17-d790-48f3-b100-1c7c05ae7363.mp3" length="14917749" type="audio/mpeg"/>
      <guid isPermaLink="false">FA06EDDDD9F3E44A80E46F78D0E25AC30D695C1BDEA5E53C79505226F2BAA81C</guid>
      <itunes:duration>930</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Wed, 29 Mar 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031005_87c9dcdee2f44dc2eeca24ad28bd480c.jpg"/>
    </item>
    <item>
      <title><![CDATA[Master Certified Ethical Hacker Eric Reed]]></title>
      <itunes:title><![CDATA[Master Certified Ethical Hacker Eric Reed]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with master Certified Ethical Hacker instructor Eric Reed about his background, how he started teaching, and several scenarios explaining how hackers compromise business networks.</p><p>Eric's website: <a href="https://ericreedlive.com/?utm_source=grcacademy-podcast&utm_medium=grcacademy-podcast&utm_campaign=grcacademy-podcast">https://ericreedlive.com/</a></p><p>Follow Eric on LinkedIn: <a href="https://www.linkedin.com/in/ericreedlive/">https://www.linkedin.com/in/ericreedlive/</a></p><p>Eric Reed is a master cybersecurity instructor with more than 30 years of IT experience! He has been teaching since 2005 and is a master at his craft.</p><p>Eric specializes in instructor led cybersecurity training for the following certifications:</p><ul><li>Certified Ethical Hacker (CEH)</li><li>Computer Hacking Forensic Investigator (CHFI)</li><li>Certified Security Analyst Certification</li><li>Certified Network Defender</li><li>CompTIA’s Security+</li><li>Certified Information Systems Security Professional (CISSP)</li></ul><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a href="https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e2&utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e2&utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139194</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139194/grcacademy/2023_09_24_00_45_08_2a309254-6509-4eef-88a6-77964c27250f.mp3" length="53859542" type="audio/mpeg"/>
      <guid isPermaLink="false">28C525A8C16AC80F9E2751CEE1742F7893F4E863767EA2891ECDA5C96A7559C3</guid>
      <itunes:duration>3363</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Tue, 14 Mar 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20231021_031034_ef5c51ff78044bb47d5abd9c88b1c8d8.jpg"/>
    </item>
    <item>
      <title><![CDATA[NIST Cybersecurity Professional Training Program with Rick Lemieux]]></title>
      <itunes:title><![CDATA[NIST Cybersecurity Professional Training Program with Rick Lemieux]]></itunes:title>
      <description><![CDATA[<p>In this episode Jacob speaks with Rick Lemieux of the DVMS Institute about the NIST Cybersecurity Professional training program, how it started, the government and private organizations that have adopted it, and its courses.</p><p>The NIST Cybersecurity Professional Program is designed to help organizations create a culture-driven, adaptive, cyber-resilient enterprise capable of creating, protecting, delivering digital business value, and how the NIST CSF can be used to help manage digital business risks and ensure improved governance.</p><p>Accredited through APMG International, assured through the UK’s National Cyber Security Centre (NCSC), and listed as qualified cyber training by Cybersecurity and Infrastructure Security Agency (CISA) in the USA, the NIST Cybersecurity Professional training program teaches individuals and organizations how to engineer, operationalize and continually improve a NIST CSF Program.</p><p>-----------</p><p>Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!</p><p>Online GRC Training: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e1&amp;utm_campaign=courses">https://grcacademy.io/courses/?utm_source=podcast&amp;utm_medium=s1-e1&amp;utm_campaign=courses</a></p><p>Need a FedRAMP authorized Password Manager?</p><p>Start a free 14-day trial of Keeper: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/b2b-trial/">https://grcacademy.io/ref/keeper/b2b-trial/</a></p><p>See the CMMC controls that Keeper meets: <a target="_blank" rel="noopener noreferrer nofollow" href="https://grcacademy.io/ref/keeper/cmmc-controls-sheet/">https://grcacademy.io/ref/keeper/cmmc-controls-sheet/</a></p>]]></description>
      <link>https://rss.com/podcasts/grcacademy/1139193</link>
      <enclosure url="https://mgln.ai/e/p778189/https://pscrb.fm/rss/p/content.rss.com/episodes/230061/1139193/grcacademy/2023_09_24_00_45_02_60097931-1d9a-4fdf-99e0-a6f3e7ef13d6.mp3" length="20068535" type="audio/mpeg"/>
      <guid isPermaLink="false">6728AB774B12144F6B71995F1B91F128335294F43A1B263438AA743A789D91D9</guid>
      <itunes:duration>1251</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:explicit>false</itunes:explicit>
      <pubDate>Fri, 10 Mar 2023 13:00:00 GMT</pubDate>
      <itunes:image href="https://media.rss.com/grcacademy/ep_cover_20240206_020244_e76172b31c6723712e11968285db0cb7.png"/>
    </item>
  </channel>
</rss>