<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:spotify="https://www.spotify.com/ns/rss">
  <channel>
    <generator>Fame Host (https://fame.so)</generator>
    <title>Trust Issues</title>
    <link>https://podcasts.fame.so/the-trust-issues</link>
    <itunes:new-feed-url>https://feeds.fame.so/the-trust-issues</itunes:new-feed-url>
    <description>For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins. Produced by BEMO and hosted by Bruno Lecoq, the show pulls back the curtain on what’s actually happening inside the CMMC, GRC, and cybersecurity ecosystem. Each episode brings together auditors, implementers, GRC platforms, and business leaders to unpack CMMC, zero trust, and modern security. 
With every conversation, we decode the “industry drama” and explore what it really takes to build secure, resilient, and audit-ready organizations using Microsoft-centric security and practical GRC frameworks.
Tune in and learn how to turn compliance into a competitive advantage.</description>
    <copyright>BEMO</copyright>
    <language>en</language>
    <pubDate>Fri, 27 Mar 2026 09:27:03 +0000</pubDate>
    <lastBuildDate>Thu, 21 May 2026 13:29:29 +0000</lastBuildDate>
    <image>
      <url>https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png</url>
      <title>Trust Issues</title>
      <link>https://podcasts.fame.so/the-trust-issues</link>
      <description>For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins. Produced by BEMO and hosted by Bruno Lecoq, the show pulls back the curtain on what’s actually happening inside the CMMC, GRC, and cybersecurity ecosystem. Each episode brings together auditors, implementers, GRC platforms, and business leaders to unpack CMMC, zero trust, and modern security. 
With every conversation, we decode the “industry drama” and explore what it really takes to build secure, resilient, and audit-ready organizations using Microsoft-centric security and practical GRC frameworks.
Tune in and learn how to turn compliance into a competitive advantage.</description>
    </image>
    <googleplay:author>BEMO</googleplay:author>
    <googleplay:image href="https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png"/>
    <itunes:category text="Technology"/>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <googleplay:summary>For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins. Produced by BEMO and hosted by Bruno Lecoq, the show pulls back the curtain on what’s actually happening inside the CMMC, GRC, and cybersecurity ecosystem. Each episode brings together auditors, implementers, GRC platforms, and business leaders to unpack CMMC, zero trust, and modern security. 
With every conversation, we decode the “industry drama” and explore what it really takes to build secure, resilient, and audit-ready organizations using Microsoft-centric security and practical GRC frameworks.
Tune in and learn how to turn compliance into a competitive advantage.</googleplay:summary>
    <googleplay:explicit>No</googleplay:explicit>
    <googleplay:block>No</googleplay:block>
    <itunes:type>episodic</itunes:type>
    <itunes:author>BEMO</itunes:author>
    <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png"/>
    <itunes:summary>For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins. Produced by BEMO and hosted by Bruno Lecoq, the show pulls back the curtain on what’s actually happening inside the CMMC, GRC, and cybersecurity ecosystem. Each episode brings together auditors, implementers, GRC platforms, and business leaders to unpack CMMC, zero trust, and modern security. 
With every conversation, we decode the “industry drama” and explore what it really takes to build secure, resilient, and audit-ready organizations using Microsoft-centric security and practical GRC frameworks.
Tune in and learn how to turn compliance into a competitive advantage.</itunes:summary>
    <itunes:subtitle>For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins. Produced by BEMO and hosted by Bruno Lecoq, the show pulls back the curtain on what’s actually happening inside the CMMC, GRC, and cybersecurity ecosystem. Each episode brings together auditors, implementers, GRC platforms, and business leaders to unpack CMMC, zero trust, and modern security. 
With every conversation, we decode the “industry drama” and explore what it really takes to build secure, resilient, and audit-ready organizations using Microsoft-centric security and practical GRC frameworks.
Tune in and learn how to turn compliance into a competitive advantage.</itunes:subtitle>
    <itunes:keywords>cybersecurity podcast, compliance podcast, SOC 2, cybersecurity, compliance, risk management, security frameworks, cybersecurity stories, compliance myths, security culture, CISO insights, SMB cybersecurity,</itunes:keywords>
    <itunes:owner>
      <itunes:name>BEMO</itunes:name>
      <itunes:email>team-bmp@fame.so</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <itunes:block>No</itunes:block>
    <item>
      <title>How BEMO Aced CMMC Level 2</title>
      <link>https://podcasts.fame.so/e/lnqw5q9n</link>
      <itunes:title>How BEMO Aced CMMC Level 2</itunes:title>
      <itunes:episode>8</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81nv3yl1</guid>
      <description>Getting CMMC Level 2 certified isn't about checking a box. It's about fundamentally transforming how your organization operates, and the path to certification is far more rigorous than most companies anticipate. In this episode of Trust Issues, Brandon and Bruno Lecoq share their firsthand experience achieving CMMC Level 2 certification as an MSSP, walking through the mock audit process, the documentation challenges they encountered, and the operational changes required to maintain compliance at scale.</description>
      <content:encoded><![CDATA[<div>Getting CMMC Level 2 certified isn't about checking a box. It's about fundamentally transforming how your organization operates, and the path to certification is far more rigorous than most companies anticipate. In this episode of Trust Issues, Brandon and Bruno Lecoq share their firsthand experience achieving CMMC Level 2 certification as an MSSP, walking through the mock audit process, the documentation challenges they encountered, and the operational changes required to maintain compliance at scale.&nbsp;<br><br></div><div>This is a candid breakdown of what actually happens during a five-day assessment, why the preparation phase matters more than most realize, and how scoping decisions made early can make or break your certification timeline.<br><br></div><div><strong>What You’ll Learn:<br></strong><br></div><ul><li>Why the mock audit is non-negotiable and how to structure your audit team across multiple departments</li><li>The real scope of documentation you'll need and the operational reality of audit weeks</li><li>Why setting your scope boundary correctly in Phase 1 determines everything downstream</li><li>How automation and ticketing discipline transform from "nice to have" to a survival requirement</li><li>The hidden cost of MSSP certification and why "self-tested and compliant" claims should raise red flags</li><li>Why preparation isn't a sprint, but rather a sustained operational shift<br><br></li></ul><div><strong>Episode Chapters:</strong>&nbsp;<br><br></div><div>00:00 Introduction&nbsp;</div><div>00:38 How BEMO Achieves CMMC Level 2 Certification as an MSSP</div><div>01:50 Why the Mock Audit Is Your Only Risk-Free Test Run</div><div>05:17 What Happens During a Five-Day Mock Audit Assessment</div><div>09:18 The 240 Fail-Critical Controls That End Your Certification</div><div>12:40 Building a Cross-Functional Audit Team Beyond IT</div><div>15:13 The 10-Day Window to Fix Mock Audit Findings</div><div>28:22 Why Documentation Prep Takes Months, Not Weeks</div><div>29:36 Scoping as an MSSP: How Your Boundaries Affect Your Customers</div><div>30:58 Why Uncertified MSSPs Fail Your Customer's Audit</div><div>33:45 Most Organizations Are Operating at 30% Maturity While Claiming Readiness</div><div>35:33 Three Layers of Prep Before Your Official Audit</div><div>37:26 Why Artificial Scoping Boundaries Get Rejected at Phase One</div><div>39:08 The Scoping Session: Where Most Organizations Fail</div><div>40:54 Key Takeaways &amp; Closing Thoughts&nbsp;</div><div><strong><em><br>Quotes:<br></em></strong><br></div><div><em>"What I would say to all our customers, you have to do a mock. So what was interesting from a BEMO perspective is we did the mock - it was one week, starting at 7 AM Pacific until 3 PM, every day for five days, very intense. You go through with the assessor, they go through all your controls, and from a people perspective on IT, we had 100% no problem, no control, but we ended up with five documentation issues."<br></em><br></div><div><em>"They cannot tell you how to fix it. They just say you failed; we needed to see that, and we didn't see it, or this was wrong. But now you go fix it - they don't tell you how. So it's not like you come back and hope they like how you fixed or changed it."<br></em><br></div><div><em>"People for sure underestimate the prep. From an IT perspective, if people work with us, we do the IT, but what people don't realize is that at the end, we go with them to their audit, but we are only IT. We are not the HR, we are not the one who represents their company. Their procedure is their procedure. You have to know your procedure and know the policy because it's your policy."<br></em><br></div><div><em>"For me, going through CMMC is a best practice, and I will never run a business without running it the way CMMC does it. Yes, it's more work, but it makes total sense. I have learned a best practice, and now BEMO is following that best practice."<br><br></em><strong>Connect with the team:</strong>&nbsp;<br><br></div><div>👉 Bruno Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a>&nbsp;<br><br></div><div>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a> &nbsp;<br><br></div><div>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a>&nbsp;</div><div><br></div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 19 May 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/8rjn47z8.mp3" length="66222288" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/c41342e0-5376-11f1-a3fc-ef0ba9d4f8b9/c41344d0-5376-11f1-b997-8366494fb856.png"/>
      <itunes:duration>2521</itunes:duration>
      <itunes:summary>Getting CMMC Level 2 certified isn't about checking a box. It's about fundamentally transforming how your organization operates, and the path to certification is far more rigorous than most companies anticipate. In this episode of Trust Issues, Brandon and Bruno Lecoq share their firsthand experience achieving CMMC Level 2 certification as an MSSP, walking through the mock audit process, the documentation challenges they encountered, and the operational changes required to maintain compliance at scale.</itunes:summary>
      <itunes:subtitle>Getting CMMC Level 2 certified isn't about checking a box. It's about fundamentally transforming how your organization operates, and the path to certification is far more rigorous than most companies anticipate. In this episode of Trust Issues, Brandon and Bruno Lecoq share their firsthand experience achieving CMMC Level 2 certification as an MSSP, walking through the mock audit process, the documentation challenges they encountered, and the operational changes required to maintain compliance at scale.</itunes:subtitle>
      <itunes:keywords>CMMC Level 2 certification, CMMC audit process, mock audit preparation, MSSP compliance, CUI data handling, security documentation, SSP (System Security Plan), compliance framework, NIST framework implementation, control assessment, C3 PAO assessment, documentation errors in compliance, policy and procedure alignment, evidence collection for audits, IT control validation, compliance automation, ticketing systems for security, passwordless authentication compliance, baseline policy deployment, cross-control verification,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Security Lessons from a Microsoft Veteran</title>
      <link>https://podcasts.fame.so/e/xn127k48</link>
      <itunes:title>Security Lessons from a Microsoft Veteran</itunes:title>
      <itunes:episode>7</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">703rymp1</guid>
      <description>Dive into the evolving world of cybersecurity and compliance with Bruno Lecoq and Brandon Lecoq. This episode uncovers the reality of securing your organization using a streamlined Microsoft approach and why proper implementation takes dedication. Discover the hidden risks of ignoring basic security protocols and how continuous monitoring can protect your business from unseen threats.</description>
      <content:encoded><![CDATA[<div>Join Bruno and Brandon Lecoq for a detailed conversation on building resilient security programs and navigating the complex world of CMMC and SOC 2 frameworks. Bruno shares the foundational story behind BEMO and his transition from a twenty-year career at Microsoft to creating a cybersecurity powerhouse for SMBs. Throughout this episode, we unpack the sheer volume of daily threats facing organizations and how a dedicated Security Operations Center filters through tens of thousands of logs to identify risks.&nbsp;<br><br></div><div>The discussion explores why a unified Microsoft approach heavily reduces complexity and accelerates your timeline for audit readiness. You will also learn the truth about compliance timelines and why those offering certificates in a few weeks are putting your business in serious danger.&nbsp;<br><br></div><div>From the absolute necessity of enforcing multifactor authentication for admin accounts to understanding why your managed service provider falls under the scope of your external audit, this episode provides a comprehensive roadmap for protecting your business.<br><br></div><div><strong>What You’ll Learn:<br></strong><br></div><ul><li>The benefits of adopting a Microsoft-centric security strategy</li><li>How Microsoft Secure Score acts as an indicator of audit readiness</li><li>The process of filtering thousands of daily security logs through a SOC</li><li>Why implementing MFA is a non-negotiable step for safeguarding accounts</li><li>How to verify your MSP's qualifications for CMMC audits</li></ul><div><strong><br>Episode Chapters:</strong>&nbsp;<br><br></div><div>00:00 Introduction&nbsp;</div><div>01:07 Leaving Microsoft to build BEMO&nbsp;</div><div>05:32 Choosing a Microsoft-centric approach&nbsp;</div><div>13:51 Azure Sentinel and SOC reporting&nbsp;</div><div>16:41 Tracking Microsoft Secure Score&nbsp;</div><div>18:36 Why compliance timelines vary&nbsp;</div><div>20:50 The dangers of cheap compliance&nbsp;</div><div>25:20 Enforcing MFA for administrators&nbsp;</div><div>28:29 Processing daily security logs&nbsp;</div><div>34:38 Building your policy framework&nbsp;</div><div>45:41 Understanding CMMC certifications</div><div><strong><em><br>Quotes:<br></em></strong><br></div><div><em>"I always said I owe my life to Microsoft. I worked 20 years there, and now we are BEMO. We are a Microsoft partner and one of their top 100 cybersecurity partners in the world."<br></em><br></div><div><em>"Half of the company doesn't have an admin with no MFA, and you're like, okay. That's it. So easy to work."<br></em><br></div><div><em>"I welcome the third-party assessor because I want to validate that my system is as good as I can do it. I can never guarantee 100% security, but I know our Secure Score is high, and someone outside checked what we did."<br></em><br></div><div><strong>Connect with the team:</strong>&nbsp;<br><br></div><div>👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/&nbsp;<br>👉 Brandon Lecoq on LinkedIn: https://www.linkedin.com/in/brandon-lecoq&nbsp;<br>👉 BEMO Website: https://www.bemopro.com/<br><br></div><div><br><br></div><div><br><br></div><div><br><br></div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 12 May 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/wqyq5n3w.mp3" length="38161848" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/4d24f760-4e06-11f1-8b5a-451e72d96a34/4d24f900-4e06-11f1-b823-1f59e808f6a9.png"/>
      <itunes:duration>1449</itunes:duration>
      <itunes:summary>Dive into the evolving world of cybersecurity and compliance with Bruno Lecoq and Brandon Lecoq. This episode uncovers the reality of securing your organization using a streamlined Microsoft approach and why proper implementation takes dedication. Discover the hidden risks of ignoring basic security protocols and how continuous monitoring can protect your business from unseen threats.</itunes:summary>
      <itunes:subtitle>Dive into the evolving world of cybersecurity and compliance with Bruno Lecoq and Brandon Lecoq. This episode uncovers the reality of securing your organization using a streamlined Microsoft approach and why proper implementation takes dedication. Discover the hidden risks of ignoring basic security protocols and how continuous monitoring can protect your business from unseen threats.</itunes:subtitle>
      <itunes:keywords>CMMC level 2 compliance,  Microsoft 365 security,  SOC 2 compliance, cybersecurity for SMBs,  Azure Sentinel SIEM,  security operations center,  compliance frameworks, DOD contractor security,  managed security services,  Microsoft Defender,  identity and access management,  security incident response, compliance audit, Microsoft licensing for security,  threat detection,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>This CMMC Myth Is Costing You $200K a Year</title>
      <link>https://podcasts.fame.so/e/18p75v9n</link>
      <itunes:title>This CMMC Myth Is Costing You $200K a Year</itunes:title>
      <itunes:episode>6</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">z1r4j3w1</guid>
      <description>What if your CMMC compliance could be built on proven experience rather than guesswork? In this episode of Trust Issues, Brandon sits down with Nicholas Bakewell, Director of Information Security at Acuris Aerospace and Lead CCA at Redwood Cyber Services, to explore what CMMC compliance actually looks like from the inside, how to move from documentation theater to real security, and why the first step isn't buying tools - it's understanding your data. In this conversation, Nicholas shares hard-won insights on navigating assessor discretion, building defensible security programs with Microsoft's ecosystem and the critical mistake most organizations make before they even start. 
Turns out slow, deliberate planning is the way to go because slow is smooth and smooth is fast!</description>
      <content:encoded><![CDATA[<div>What if your CMMC compliance could be built on proven experience rather than guesswork? In this episode of Trust Issues, Brandon sits down with Nicholas Bakewell, Director of Information Security at Acuris Aerospace and Lead CCA at Redwood Cyber Services, to explore what CMMC compliance actually looks like from the inside.&nbsp;<br><br></div><div><strong>What You’ll Learn:&nbsp;<br></strong><br></div><ul><li>How to shift from compliance theater to real security</li><li>Why getting your CCP (or CCA) as an implementer gives you negotiating power</li><li>The data mapping exercise that prevents scope creep and massive rework</li><li>Why "November 1, 2026" doesn't mean what you think it means</li><li>How to build a cohesive security stack without multiplying complexity</li><li>The hard truth about DIB contractors avoiding CMMC</li></ul><div><br>This episode is a reminder that slow, deliberate planning is the way to go because slow is smooth and smooth is fast!<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction &amp; Meeting Nicholas Bakewell&nbsp;</div><div>02:33 From Marine Corps ISSM to Defense Contractor Security Leader</div><div>05:10 Why CMMC Isn't Prescriptive</div><div>09:40 CCP as Your Negotiating Power</div><div>12:30 Redwood Cyber Services and Breaking Through CMMC Myths</div><div>14:00 The CUI Ambiguity Problem &amp; Why Waiting Is a Dangerous Bet</div><div>17:48 DFARS 7012 Has Been Required Since 2017</div><div>18:54 November 2026 Isn't the Real Deadline: The Real June/July Cutoffs</div><div>20:49 Why Niche Suppliers Can't Avoid Compliance</div><div>22:21 Life After Certification: Preparing for NIST 800-171 Revision Three</div><div>24:56 Compliance is Not Security - A Valid Thought?&nbsp;</div><div>27:39 Reduce Complexity, Master Your Tools Deeply</div><div>32:33 Automating Compliance Evidence</div><div>34:10 Start Now: Data Discovery &amp; Mapping</div><div>35:34 Key Takeaways &amp; Closing Thoughts&nbsp;</div><div><br><strong>Connect with the team:</strong>&nbsp;<br><br></div><div>👉 Nicholas Bakewell on LinkedIn: <a href="https://www.linkedin.com/in/nsbakewell/">https://www.linkedin.com/in/nsbakewell/</a> <br>👉 Bruno Lecoq on LinkedIn:<a href="https://www.linkedin.com/in/huffaker"> </a><a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a> <br>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a> <br>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a> &nbsp;</div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 05 May 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/8qyq5658.mp3" length="58339272" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/9349bc50-4880-11f1-8b10-49eba5dd4598/9349be20-4880-11f1-a2ab-bdeb177f5b19.png"/>
      <itunes:duration>2192</itunes:duration>
      <itunes:summary>What if your CMMC compliance could be built on proven experience rather than guesswork? In this episode of Trust Issues, Brandon sits down with Nicholas Bakewell, Director of Information Security at Acuris Aerospace and Lead CCA at Redwood Cyber Services, to explore what CMMC compliance actually looks like from the inside, how to move from documentation theater to real security, and why the first step isn't buying tools - it's understanding your data. In this conversation, Nicholas shares hard-won insights on navigating assessor discretion, building defensible security programs with Microsoft's ecosystem and the critical mistake most organizations make before they even start. 
Turns out slow, deliberate planning is the way to go because slow is smooth and smooth is fast!</itunes:summary>
      <itunes:subtitle>What if your CMMC compliance could be built on proven experience rather than guesswork? In this episode of Trust Issues, Brandon sits down with Nicholas Bakewell, Director of Information Security at Acuris Aerospace and Lead CCA at Redwood Cyber Services, to explore what CMMC compliance actually looks like from the inside, how to move from documentation theater to real security, and why the first step isn't buying tools - it's understanding your data. In this conversation, Nicholas shares hard-won insights on navigating assessor discretion, building defensible security programs with Microsoft's ecosystem and the critical mistake most organizations make before they even start. 
Turns out slow, deliberate planning is the way to go because slow is smooth and smooth is fast!</itunes:subtitle>
      <itunes:keywords>CMMC compliance,  CMMC level 2 certification, defense industrial base security, NIST 800-171, cybersecurity controls implementation, federal contractor compliance, CUI protection, DFARS 7012, CMMC assessment process, C3PAO audits, lead CCA certification, information security program design, compliance documentation, security baseline configuration, data mapping and discovery, compliance frameworks for contractors,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>The CMMC Myth That's Costing SMBs Millions</title>
      <link>https://podcasts.fame.so/e/4n9m33qn</link>
      <itunes:title>The CMMC Myth That's Costing SMBs Millions</itunes:title>
      <itunes:episode>5</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">v07r2271</guid>
      <description>The CMMC journey is a lot harder than people think it is, and we’re unpacking the truth on this episode of Trust Issues. Tune in as hosts Brandon and Bruno Lecoq sit down with Raymond King, Senior Customer Success Manager at BEMO, to unpack the real CMMC compliance journey - from the initial self-assessment through final audit. Raymond reveals why most companies dramatically underestimate the work involved, how culture determines success or failure faster than any tool ever will and why self-attested compliance is essentially meaningless until a third party verifies it. Turns out CMMC really isn't a checkbox - it's a foundational shift in how your entire organization operates.</description>
      <content:encoded><![CDATA[<div>The CMMC journey is a lot harder than people think it is, and we’re unpacking the truth on this episode of Trust Issues. Tune in as hosts Brandon and Bruno Lecoq sit down with Raymond King, Senior Customer Success Manager at BEMO, to unpack the real CMMC compliance journey - from the initial self-assessment through final audit.</div><div><strong><br>What You’ll Learn:&nbsp;<br></strong><br></div><ul><li>Why self-attestation is a false confidence play</li><li>How CMMC sprawls across your entire organization, not just IT</li><li>The culture-first truth separates six-month timelines from eighteen-month struggles</li><li>SOC 2 compliance is trivially easy compared to CMMC's rigor</li><li>The GRC platform paradox - why buying Drata or Vanta doesn't make you compliant</li><li>Why only 1,000 companies hold CMMC Level 2 certification today</li></ul><div><br>Turns out CMMC really isn't a checkbox - it's a foundational shift in how your entire organization operates.&nbsp;<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction</div><div>01:39 From Microsoft Government Specialist to CMMC Reality Check</div><div>04:54 Three Types of CMMC Customers: Who Moves Fast and Who Stalls</div><div>11:50 The 18-Month Journey: What a Real CMMC Level 2 Audit Actually Looks Like</div><div>14:54 GFE Users Aren't Out of Scope - Your Biggest Security Gap</div><div>16:21 SOC 2 vs. CMMC: Why Level 2 Is Exponentially Harder</div><div>20:26 SPRS Scores and the Illusion of Self-Attestation</div><div>24:35 Why External Verification Is Non-Negotiable</div><div>28:50 The November Deadline: Self-Attestation Window Is Closing</div><div>34:10 Security Culture Beats Infrastructure: Why Some Teams Succeed 6–12 Months Faster</div><div>37:19 The GRC Platform Graveyard: Why Buying Tools Doesn't Equal Compliance</div><div>40:18 The 60/40 Decision: When Government Contracts Aren't Worth the Effort</div><div>42:44 GCC vs. Enclaves vs. Two Tenants: Architecture Decisions That Impact Audit</div><div>44:55 Why Complexity Creates Evidence Burden</div><div>46:26 CMMC Is Coming for Everyone: DFARS Expansion and What's Next</div><div>46:53 Key Takeaways: Start Now, Build Culture, Verify Externally</div><div><br><strong><em>Quotes:<br><br></em></strong>"It's really that mindset of, are we just turning it on to meet the controls, or is this a core priority for our company? And is this part of our culture? And it makes a huge difference when it's part of the culture."</div><div><br>"A lot of the time, I think customers will go, and they'll buy a solution. So they'll say we bought E5, Microsoft 365 E5. We're compliant. They didn't go and turn everything on. They didn't connect everything. They didn't actually watch what's happening, and they just said, well, we purchased it and that makes us compliant."<br><br>"SOC is easy by comparison. With CMMC, we're going to be meeting with customers every month. We're going to be reviewing their stances. We're going to be reviewing if a control fell out of compliance and what happened. We are on top of all of their policies in a way that we don't have to have that level of detail with SOC."<br><br>"When I was at Microsoft, and we were analyzing the market size, 70% of businesses that were impacted fell into the small and medium space. And we were estimating around 320,000 companies that had to become CMMC compliant. So, yeah, if you get it done now, you've got a serious advantage."</div><div><br><strong>Connect with the team:</strong>&nbsp;<br><br></div><div>👉 Raymond King on LinkedIn: <a href="https://www.linkedin.com/in/raymondkingmsft/">https://www.linkedin.com/in/raymondkingmsft/</a>&nbsp; <br>👉 Bruno Lecoq on LinkedIn:<a href="https://www.linkedin.com/in/huffaker"> </a><a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a> <br>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a> <br>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a> &nbsp;</div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 28 Apr 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w3lz1j68.mp3" length="76121640" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/c6ec22f0-42fe-11f1-8510-db0afd6e4e69/c6ec2410-42fe-11f1-a5cc-a12ef68e4fca.png"/>
      <itunes:duration>2857</itunes:duration>
      <itunes:summary>The CMMC journey is a lot harder than people think it is, and we’re unpacking the truth on this episode of Trust Issues. Tune in as hosts Brandon and Bruno Lecoq sit down with Raymond King, Senior Customer Success Manager at BEMO, to unpack the real CMMC compliance journey - from the initial self-assessment through final audit. Raymond reveals why most companies dramatically underestimate the work involved, how culture determines success or failure faster than any tool ever will and why self-attested compliance is essentially meaningless until a third party verifies it. Turns out CMMC really isn't a checkbox - it's a foundational shift in how your entire organization operates.</itunes:summary>
      <itunes:subtitle>The CMMC journey is a lot harder than people think it is, and we’re unpacking the truth on this episode of Trust Issues. Tune in as hosts Brandon and Bruno Lecoq sit down with Raymond King, Senior Customer Success Manager at BEMO, to unpack the real CMMC compliance journey - from the initial self-assessment through final audit. Raymond reveals why most companies dramatically underestimate the work involved, how culture determines success or failure faster than any tool ever will and why self-attested compliance is essentially meaningless until a third party verifies it. Turns out CMMC really isn't a checkbox - it's a foundational shift in how your entire organization operates.</itunes:subtitle>
      <itunes:keywords>CMMC compliance, CMMC level 2 audit, DoD contractor compliance, cybersecurity for contractors, federal compliance, DFARS compliance, compliance certification, security framework, government contracts, compliance assessment, self assessment, compliance audit, GRC platform, Drata, Vanta, Microsoft 365 Government, security training, compliance gaps, compliance maintenance, internal assessment, audit prep, compliance monitoring,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>The CMMC Trap: Why Certification Isn’t Compliance</title>
      <link>https://podcasts.fame.so/e/1np73zw8</link>
      <itunes:title>The CMMC Trap: Why Certification Isn’t Compliance</itunes:title>
      <itunes:episode>4</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">z0r4xm20</guid>
      <description>Discipline is the difference between winning and losing - even in the world of security and compliance. In this episode of Trust Issues, hosts Brandon and Bruno Lecoq welcome Cindy Oliveto, Senior Director of Operations at BEMO, to break down why government contractors struggle with certification, how to avoid the "checkbox trap,” and why automation and clear ownership are non-negotiable for real compliance success. This episode serves as a critical reminder that you can have all the certifications in the world, but without operational discipline, they amount to naught.</description>
      <content:encoded><![CDATA[<div>Discipline is the difference between winning and losing - even in the world of security and compliance. In this episode of Trust Issues, hosts Brandon and Bruno Lecoq welcome Cindy Oliveto, Senior Director of Operations at BEMO, to break down why operational discipline is the key to winning the security game:&nbsp;</div><div><strong><br>What You’ll Learn:&nbsp;<br></strong><br></div><ul><li>Why repeatable processes and consistent operational rigor across every department are the key to compliance&nbsp;</li><li>How SOC 2, ISO 27001, and CMMC differ strategically</li><li>The "post-certification cliff" you can't ignore and why compliance isn’t a one-time project</li><li>How to build an unstoppable compliance infrastructure</li><li>Why your policies must match your actual business operations</li><li>The hidden prerequisite before deploying AI responsibly</li></ul><div><br>This episode serves as a critical reminder that you can have all the certifications in the world, but without operational discipline, they amount to naught.<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction&nbsp;</div><div>01:46 From Entrepreneurship to BEMO: Lessons Learnt&nbsp;</div><div>02:36 Building Repeatable Systems with Clear Ownership</div><div>05:48 SOC 2 vs. ISO 27001 vs. CMMC: Framework Breakdown</div><div>10:20 What to Expect from CMMC Level 2 Audits</div><div>15:17 Automating Evidence Capture Across 60 Log Sources</div><div>18:38 Why Data Cleansing Must Come Before Deploying AI</div><div>23:49 ISO 42001: Why BEMO is Going After this Certification</div><div>28:10 The Shadow AI Problem &amp; Stopping Unauthorized Data Exposure</div><div>33:42 Why it Should be Team First, Tools Second, Automation Third</div><div>36:25 Key Takeaways: Building Sustainable Compliance</div><div><br></div><div><strong><em>Quotes:</em></strong></div><div><br>"I think looking at the entire operating model across an organization is important. So developing that dependable rhythm across teams, those are the key things that I think build team dependencies, customer trust, and deliver good outcomes."</div><div><br>"It requires a lot of discipline, and companies really aren't sure what or how to implement that discipline. So the scoping required, the ability to track, and the ability to monitor evidence - the challenges really aren't the tools or the security. It is documentation, operational rigor, cadence, and they're just not prepared to embrace that across all of their departments."</div><div><br>"Before you can even start thinking that your agent can have accurate boundaries within how you want it to operate, you need group policies and access privileges in place across your organization."</div><div><br>"Identify your core team that is gonna drive this initiative - who's in charge of it, and who's owning it, and what are the players?"</div><div>“We ensure customers know what it takes to manage the security, and manage it from a business standpoint. We give them templates so that it helps them come up to speed real quickly around what those policies and what the controls mean.”&nbsp;</div><div><br><strong>Connect with the team:</strong>&nbsp;<br><br></div><div>👉 Cindy Oliveto on LinkedIn: <a href="https://www.linkedin.com/in/cindyoliveto/">https://www.linkedin.com/in/cindyoliveto/</a>&nbsp;</div><div>👉 Bruno Lecoq on LinkedIn:<a href="https://www.linkedin.com/in/huffaker"> </a><a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a> <br>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a>&nbsp;</div><div>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a> &nbsp;</div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 21 Apr 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w53yvzjw.mp3" length="61732512" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/5a0bfbf0-3d83-11f1-a580-fd24d2c3e394/5a0bfcf0-3d83-11f1-81ce-7f9aa14cf952.png"/>
      <itunes:duration>2297</itunes:duration>
      <itunes:summary>Discipline is the difference between winning and losing - even in the world of security and compliance. In this episode of Trust Issues, hosts Brandon and Bruno Lecoq welcome Cindy Oliveto, Senior Director of Operations at BEMO, to break down why government contractors struggle with certification, how to avoid the "checkbox trap,” and why automation and clear ownership are non-negotiable for real compliance success. This episode serves as a critical reminder that you can have all the certifications in the world, but without operational discipline, they amount to naught.</itunes:summary>
      <itunes:subtitle>Discipline is the difference between winning and losing - even in the world of security and compliance. In this episode of Trust Issues, hosts Brandon and Bruno Lecoq welcome Cindy Oliveto, Senior Director of Operations at BEMO, to break down why government contractors struggle with certification, how to avoid the "checkbox trap,” and why automation and clear ownership are non-negotiable for real compliance success. This episode serves as a critical reminder that you can have all the certifications in the world, but without operational discipline, they amount to naught.</itunes:subtitle>
      <itunes:keywords>CMMC compliance, CMMC level two certification, SOC 2 compliance, ISO 27001 certification, compliance frameworks, defense contractor compliance, GRC platform, security compliance, operational excellence, compliance automation, compliance audit process, evidence collection, compliance documentation, control management, risk management, vendor management, nonconformity tracking, internal audit,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Why Security Complacency is the CEO's Greatest Mistake</title>
      <link>https://podcasts.fame.so/e/vn5j49z8</link>
      <itunes:title>Why Security Complacency is the CEO's Greatest Mistake</itunes:title>
      <itunes:episode>3</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">80q3xlk0</guid>
      <description>You wouldn’t drive a car without insurance, would you? Then why run a company without giving security the utmost thought? In this episode of Trust Issues, Brandon Lecoq and Bruno Lecoq, CEO/CISO at BEMO, confront the uncomfortable truth about cybersecurity in SMBs: size doesn't determine risk, security hygiene does. Drawing on real-world attacks from BEMO's 478-client base, Bruno shares critical Microsoft security data, insider threat case studies, and the deceptively simple attack methods that catch most organizations off guard. The conversation leaves the noise behind, focusing on what actually stops attackers and why so many SMBs remain dangerously unprepared.</description>
      <content:encoded><![CDATA[<div>You wouldn’t drive a car without insurance, would you? Then why run a company without giving security the utmost thought? In this episode of Trust Issues, Brandon Lecoq and Bruno Lecoq, CEO/CISO at BEMO, confront the uncomfortable truth about cybersecurity in SMBs: <strong>size doesn't determine risk, security hygiene does.<br></strong><br></div><div><strong>What You’ll Learn:&nbsp;</strong></div><ul><li>Why the "we're too small to be targeted" myth costs you everything</li><li>How to recognize when employees unknowingly hand attackers the keys</li><li>The three-move attack sequence that works on most SMBs</li><li>How to interpret fake phishing test results as a leading indicator</li><li>The ROI calculation that justifies investing in Microsoft 365 E5&nbsp;</li><li>Why "we've never been attacked" is a dangerous approach to security&nbsp;</li></ul><div><br>This conversation leaves the noise behind, focusing on what actually stops attackers and why so many SMBs remain dangerously unprepared.<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:47 The "Too Small to Target" Myth</div><div>01:36 Why Org Size Doesn't Determine Risk</div><div>03:09 The MFA Social Engineering Attack</div><div>07:28 Why Microsoft 365 E5 Matters</div><div>11:30 Phishing Remains the #1 Attack Vector</div><div>16:13 42% Click-Through Rate on the First Phishing Test</div><div>18:52 How MFA and Anti-Phishing Stop 99% of Automated Attacks</div><div>21:40 Key Takeaways &amp; Closing Thoughts&nbsp;</div><div><br></div><div><strong><em>Quotes:</em></strong></div><div><br>"I just came back from a Microsoft conference, and they told us 48% of admin accounts on Office 365 don't have MFA. If you take that number, it's about 2,500,000 company accounts with no MFA. I can be by the beach in Rio and give you a nice run somewhere and you will pay me a thousand bucks to give you the key, I just need to do 10 a day, and I have a very nice retirement."</div><div><br>"Across our 478 customer base, the attack volume has no correlation with company size. The only correlation is security hygiene, what matters is your secure score.”</div><div><br>"The number one attack we see is phishing links, finding a way for you to click. If you click, it's game over, especially if you don't have MFA. Even if they click, it's about how fast the hacker can come in and what they can access with those credentials."</div><div><br>"One amazing stat from a conference I attended was that 42% of global admins don't have MFA. For me, this was a shocking number. There are 5,700,000 small businesses in the US, and roughly 2,500,000 company accounts may have a global admin with no MFA. That's a nice target, and of course, hackers are happy about it."</div><div><br>“For all the companies we deploy awareness training to, our average is 42% of people clicking on the first phishing test. It's basically half your company clicking - done. That's why we tell all companies the goal should be below 3%, and if you have three clicks, you're in trouble with HR because we cannot take that risk."</div><div><br><strong>Connect with the team:</strong>&nbsp;</div><div><br>👉 Bruno Lecoq on LinkedIn:<a href="https://www.linkedin.com/in/huffaker"> </a><a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a> <br><br>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a>&nbsp;<br><br></div><div>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a> &nbsp;</div><div><br><br></div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 14 Apr 2026 13:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/84v27798.mp3" length="30278424" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/78d31ff0-3805-11f1-8322-293e997cadff/78d320f0-3805-11f1-be33-09194c5e28df.png"/>
      <itunes:duration>1342</itunes:duration>
      <itunes:summary>You wouldn’t drive a car without insurance, would you? Then why run a company without giving security the utmost thought? In this episode of Trust Issues, Brandon Lecoq and Bruno Lecoq, CEO/CISO at BEMO, confront the uncomfortable truth about cybersecurity in SMBs: size doesn't determine risk, security hygiene does. Drawing on real-world attacks from BEMO's 478-client base, Bruno shares critical Microsoft security data, insider threat case studies, and the deceptively simple attack methods that catch most organizations off guard. The conversation leaves the noise behind, focusing on what actually stops attackers and why so many SMBs remain dangerously unprepared.</itunes:summary>
      <itunes:subtitle>You wouldn’t drive a car without insurance, would you? Then why run a company without giving security the utmost thought? In this episode of Trust Issues, Brandon Lecoq and Bruno Lecoq, CEO/CISO at BEMO, confront the uncomfortable truth about cybersecurity in SMBs: size doesn't determine risk, security hygiene does. Drawing on real-world attacks from BEMO's 478-client base, Bruno shares critical Microsoft security data, insider threat case studies, and the deceptively simple attack methods that catch most organizations off guard. The conversation leaves the noise behind, focusing on what actually stops attackers and why so many SMBs remain dangerously unprepared.</itunes:subtitle>
      <itunes:keywords>Microsoft 365 security, MFA implementation, Phishing attacks, Cyber attack prevention, SMB cybersecurity, Admin account security, Office 365 security, Password attacks, Brute force attacks, Insider risk management, Security awareness training, Microsoft Defender, GCC compliance, Conditional access policies, Device management, Intune MDM, Identity and access management, Fake phishing testing,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>BEMO’s Blueprint for the CMMC Revolution</title>
      <link>https://podcasts.fame.so/e/vnwp2148</link>
      <itunes:title>BEMO’s Blueprint for the CMMC Revolution</itunes:title>
      <itunes:episode>2</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81x23m71</guid>
      <description>Security may never be 100% foolproof, but that’s no reason to stop striving for it. In this episode of *Trust Issues* by BEMO, hosts Bruno Lecoq, CEO and CISO, and Brandon Lecoq, Head of Sales, team up for an eye-opening conversation that cuts through the noise of compliance and security. Together, they tackle why checking compliance boxes isn’t the same as being secure, how a Microsoft-centric architecture can simplify CMMC implementation, and why true compliance takes time—but is always worth the effort.

This episode is packed with actionable insights, real talk, and a refreshing dose of clarity on building security that lasts. You’ll also discover why shortcuts in compliance often cost more in the long run and how to approach security with a strategy that works. Don’t miss this dynamic discussion that proves simplicity and strategy are the keys to compliance success. Tune in now for a masterclass in doing security the right way!</description>
      <content:encoded><![CDATA[<div>Security is never 100% foolproof, but that doesn’t mean you should stop striving for it. In this episode of *Trust Issues* by BEMO, hosts Bruno Lecoq, CEO and CISO, and Brandon Lecoq, Head of Sales, dive into how organizations can master the real game of security and compliance—and come out on top.<br><br></div><div><strong>What You’ll Learn:&nbsp;<br></strong><br></div><ul><li>How to build a Microsoft 365–centric security stack without complexity</li><li>Why your Microsoft Secure Score is a leading indicator of compliance readiness</li><li>The real cost of "quick" compliance. Hint: it’s more than you think</li><li>How to leverage your SOC and SIEM to generate continuous compliance evidence</li><li>Why your MSP matters more than you think</li><li>The non-negotiable baseline: MFA on all admin accounts</li></ul><div><br>This episode drives home a simple yet profound point: no organization can <em>afford </em>to ignore security and compliance in today’s environment!&nbsp;<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction&nbsp;</div><div>01:05 Why Bruno Left Microsoft to Build BEMO</div><div>05:36 The Microsoft-Centric Approach of Simplicity</div><div>09:53 Why Complexity Slows Compliance&nbsp;</div><div>13:26 Azure Sentinel Reporting: Ins and Outs</div><div>16:59 Microsoft Secure Score: Your Compliance Readiness Thermometer</div><div>20:18 Why True Compliance Takes 6-12 Months, Not 3 Weeks</div><div>25:08 How MFA on Admin Accounts Eliminates 99% of Breach Risk</div><div>31:21 The Strategies to Automate Compliance Evidence</div><div>34:38 Building Your Policy Framework</div><div>36:55 Documentation as Your Competitive Advantage</div><div>39:06 Only Work With Companies That Care About Security</div><div>41:20 Compliance as a Business Legitimacy Signal</div><div>44:01 Monitor What You Allow, Don't Block It</div><div>45:07 Verify Your MSP's CMMC Credentials on CyberAB.org</div><div>49:43 Key Takeaways &amp; Closing Thoughts <br><strong><br>Connect with the team:</strong>&nbsp;</div><div><br>👉 Bruno Lecoq on LinkedIn:<a href="https://www.linkedin.com/in/huffaker"> </a><a href="https://www.linkedin.com/in/brunolecoq/">https://www.linkedin.com/in/brunolecoq/</a> <br>👉 Brandon Lecoq on LinkedIn: <a href="https://www.linkedin.com/in/brandon-lecoq">https://www.linkedin.com/in/brandon-lecoq</a>&nbsp;</div><div>👉 BEMO Website: <a href="https://www.bemopro.com/">https://www.bemopro.com/</a> &nbsp;<br><br></div><div><br><br></div><div><br><br></div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 07 Apr 2026 14:39:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/wyqyqz5w.mp3" length="77832960" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/e66e4320-328f-11f1-b4fd-4d57c69cc5b4/e66e4420-328f-11f1-b31b-a1f579d2d4be.png"/>
      <itunes:duration>3085</itunes:duration>
      <itunes:summary>Security may never be 100% foolproof, but that’s no reason to stop striving for it. In this episode of *Trust Issues* by BEMO, hosts Bruno Lecoq, CEO and CISO, and Brandon Lecoq, Head of Sales, team up for an eye-opening conversation that cuts through the noise of compliance and security. Together, they tackle why checking compliance boxes isn’t the same as being secure, how a Microsoft-centric architecture can simplify CMMC implementation, and why true compliance takes time—but is always worth the effort.

This episode is packed with actionable insights, real talk, and a refreshing dose of clarity on building security that lasts. You’ll also discover why shortcuts in compliance often cost more in the long run and how to approach security with a strategy that works. Don’t miss this dynamic discussion that proves simplicity and strategy are the keys to compliance success. Tune in now for a masterclass in doing security the right way!</itunes:summary>
      <itunes:subtitle>Security may never be 100% foolproof, but that’s no reason to stop striving for it. In this episode of *Trust Issues* by BEMO, hosts Bruno Lecoq, CEO and CISO, and Brandon Lecoq, Head of Sales, team up for an eye-opening conversation that cuts through the noise of compliance and security. Together, they tackle why checking compliance boxes isn’t the same as being secure, how a Microsoft-centric architecture can simplify CMMC implementation, and why true compliance takes time—but is always worth the effort.

This episode is packed with actionable insights, real talk, and a refreshing dose of clarity on building security that lasts. You’ll also discover why shortcuts in compliance often cost more in the long run and how to approach security with a strategy that works. Don’t miss this dynamic discussion that proves simplicity and strategy are the keys to compliance success. Tune in now for a masterclass in doing security the right way!</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Your Compliance Report Might Be Worthless</title>
      <link>https://podcasts.fame.so/e/08jyqw9n</link>
      <itunes:title>Your Compliance Report Might Be Worthless</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">41pqxl80</guid>
      <description>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</description>
      <content:encoded><![CDATA[<div>There is a real cost to cutting compliance corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification.<br><br></div><div><strong>What You’ll Learn:&nbsp;</strong></div><ul><li>Why market pressure creates fraud and how to avoid it</li><li>How to spot a fraudulent compliance vendor before engaging</li><li>The real cost of due diligence and why legitimate vendors should demand deeper scrutiny</li><li>Why open-source GRC platforms like GigaChad GRC are disrupting the market</li><li>How to validate compliance readiness without falling into the trap</li><li>The ripple effect of fraudulent reports&nbsp;</li></ul><div><br>Tune in for actionable strategies to position your organization for the growth that 2026 promises to bring.<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction&nbsp;</div><div>00:36 A widespread SOC 2 fraud scheme finally exposed</div><div>02:22 Why market pressure creates compliance shortcuts</div><div>07:37 What happens now?&nbsp;</div><div>12:51 Why open-source GRC platforms are price disruptors</div><div>19:23 Your due diligence = auditor attestation letters</div><div>22:35 Consult peers and advisors before committing to vendors</div><div>24:10 The “too good to be true” test&nbsp;</div><div>24:46 Key takeaways &amp; final thoughts&nbsp;</div><div><br></div><div><strong><em>Quotes:</em></strong></div><div><br></div><ol><li>"I feel like a lot of people in the compliance space have thought that something like this was going on with some companies, and they didn't really know who it was or where it was happening, but it just seemed like there's a lot of, like, a gold rush happening right now."</li></ol><div><br></div><ol><li>“There's a lot of startups who are trying to go mid-market enterprise really, really fast because they have a good product. And in order to do that, they're finding that they have pressure to get something like a SOC two in place. And because there's a strong need on the market for that, there are gonna be people and companies that are going to want to do that."</li></ol><div><br></div><ol><li>"I had one conversation where the guy was spending three times what many other really, really good reputable firms that we work with charge. And the company is literally 20 people, but they're charging three times the amount for the audit for something that does not in any way need to be that thorough."</li></ol><div><br></div><ol><li>“The people that actually care about the space or are passionate about the space will push back on you on certain aspects. You can go find people that would be happy to give their two cents about what your plan is."</li></ol><div><br></div><ol><li>"If it sounds too good to be true, it probably is. It's kind of like a fitness analogy - if you see big signs that you should take a pill, you probably shouldn't take that pill. If you know that your IT is not up to par and something is very fast and very cheap, you should be very skeptical because it's probably not very good."</li></ol><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 14:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w53y3zmw.mp3" length="35381712" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/fc58e940-2d0b-11f1-bbcf-4315fd1d11b1/fc58ea40-2d0b-11f1-8e7b-d7521d15d6f5.jpg"/>
      <itunes:duration>1556</itunes:duration>
      <itunes:summary>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</itunes:summary>
      <itunes:subtitle>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</itunes:subtitle>
      <itunes:keywords>SOC 2 fraud, Compliance automation platforms, GRC platforms, Audit firm rubber-stamping, Fraudulent compliance reports, SOC 2 certification, Compliance frameworks, GRC software, Vendor due diligence, Compliance shortcuts, Fast compliance solutions, Evidence collection, Control mapping, policy management, Vendor risk assessment, Open source GRC, Compliance audit process, Compliance implementation timeline,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Trust Issues Trailer</title>
      <link>https://podcasts.fame.so/e/x8y73xk8</link>
      <itunes:title>Trust Issues Trailer</itunes:title>
      <itunes:episode>7</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">l04r53z0</guid>
      <description>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</description>
      <content:encoded><![CDATA[<div>Compliance has a trust problem.<br>Everyone says they can get you certified.<br>Everyone claims to be “security-first.”<br>And yet, breaches still happen, systems fail, and data is lost.<br>So what’s actually going on?<br><br>Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.<br>We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.<br><br>If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.<br><br>🔗 Subscribe and follow to stay ahead.<br><br>#ComplianceMatters #CMMC #Cybersecurity</div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 10:37:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w6ljl9mw.mp3" length="1673016" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/b5b097d0-2c66-11f1-81c5-2f9d7cfd5c5c/b5b098d0-2c66-11f1-9b84-79109cb3df21.jpg"/>
      <itunes:duration>59</itunes:duration>
      <itunes:summary>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</itunes:summary>
      <itunes:subtitle>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</itunes:subtitle>
      <itunes:keywords>cybersecurity compliance, CMMC compliance, information security, GRC platforms, data protection strategies, risk management cybersecurity, security audits, government contracting security, cybersecurity podcast, compliance best practices,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Why CMMC Matters: A Deep Dive into Security Standards</title>
      <link>https://podcasts.fame.so/e/lnqw6ypn</link>
      <itunes:title>Why CMMC Matters: A Deep Dive into Security Standards</itunes:title>
      <itunes:episode>6</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81nvq581</guid>
      <description>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</description>
      <content:encoded><![CDATA[<p><strong>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade?</strong> 😅<br></p><p>We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.</p><p>We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.</p><p>Plus, we get into what contractors should actually do next:<br>➡️ How to identify your real security gap<br>➡️ Why compliance automation tools will be essential<br>➡️ What budgeting realistically looks like<br>➡️ Why taking small steps today saves massive stress later</p><p>If you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.</p><p>Follow BEMO for more practical breakdowns on compliance, security, and modernization:<br>🔗 <strong>Website:</strong> <a href="https://www.bemopro.com" target="_new" rel="noopener">https://www.bemopro.com</a><br>🔗 <strong>LinkedIn:</strong> <a href="https://www.linkedin.com/company/bemopro" target="_new" rel="noopener">https://www.linkedin.com/company/bemopro</a></p><p></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2025 15:26:14 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/8vykyq3w.mp3" length="39581987" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1d5b0830-29bf-11f1-95b8-015b6fe91892/1d5b03e0-29bf-11f1-9508-edc5d09b513e.jpg"/>
      <itunes:duration>2473</itunes:duration>
      <itunes:summary>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</itunes:summary>
      <itunes:subtitle>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Outsourcing Compliance: When and Why It Makes Sense</title>
      <link>https://podcasts.fame.so/e/mn4lqz9n</link>
      <itunes:title>Outsourcing Compliance: When and Why It Makes Sense</itunes:title>
      <itunes:episode>5</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">x06r2xm0</guid>
      <description>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</description>
      <content:encoded><![CDATA[<p>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.</p><p>In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</p><p><br></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 21 Nov 2025 13:26:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/wj090k4w.mp3" length="38809181" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1e26fbb0-29bf-11f1-9a32-33716d4fb600/1e26f7c0-29bf-11f1-8d07-13da7c3b4459.jpg"/>
      <itunes:duration>2425</itunes:duration>
      <itunes:summary>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</itunes:summary>
      <itunes:subtitle>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Smart Compliance Tip 2: Know When to Outsource</title>
      <link>https://podcasts.fame.so/e/q80vrk48</link>
      <itunes:title>Smart Compliance Tip 2: Know When to Outsource</itunes:title>
      <itunes:episode>4</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">p0knq9m1</guid>
      <description>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </description>
      <content:encoded><![CDATA[<p>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2025 06:57:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/w95r5m6w.mp3" length="22693928" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1e969000-29bf-11f1-bbd8-5d957f3f53a5/1e968b20-29bf-11f1-8155-6f758533d556.jpg"/>
      <itunes:duration>1418</itunes:duration>
      <itunes:summary>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </itunes:summary>
      <itunes:subtitle>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Smart Compliance Tip 1: Understand Business Impact</title>
      <link>https://podcasts.fame.so/e/p8m7v4v8</link>
      <itunes:title>Smart Compliance Tip 1: Understand Business Impact</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">70v53m31</guid>
      <description>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</description>
      <content:encoded><![CDATA[<p>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2025 08:09:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/84v2vyr8.mp3" length="27194931" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1f11e420-29bf-11f1-99a9-d7dd3ca0b346/1f11e1f0-29bf-11f1-a29b-1bed260c3434.jpg"/>
      <itunes:duration>1699</itunes:duration>
      <itunes:summary>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</itunes:summary>
      <itunes:subtitle>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>The Compliance Checklist Mentality - A Growing Problem</title>
      <link>https://podcasts.fame.so/e/28xzryq8</link>
      <itunes:title>The Compliance Checklist Mentality - A Growing Problem</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">60mkq930</guid>
      <description>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</description>
      <content:encoded><![CDATA[<p>Still treating compliance like a checklist? 😬 It’s time to break the habit. </p><p>In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. </p><p><br></p><p>Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.</p><p><br></p><p>Want to go deeper? Read our blogs on:</p><p><a href="https://www.bemopro.com/cybersecurity-blog/soc-2-compliance-matters" target="_blank" rel="noopener noreferer">- Why SOC 2 compliance really matters 👉 </a></p><p><a href="https://www.bemopro.com/cybersecurity-blog/what-to-do-the-first-time-you-face-soc-2-compliance" target="_blank" rel="noopener noreferer">- What to Do the First Time You&#39;re Tackling SOC 2 Compliance </a></p><p><a href="https://www.bemopro.com/cybersecurity-blog/rushing-soc-2-compliance-can-cost-you-a-major-deal-what-to-do-instead" target="_blank" rel="noopener noreferer">- Rushing SOC 2 Compliance Can Cost You a Major Deal </a></p><p><br></p><p>🔗 Learn More About <a href="https://www.bemopro.com/compliance" target="_blank" rel="noopener noreferer">BEMO</a></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2025 18:30:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/w0vlvq9w.mp3" length="26768612" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/20cdeb70-29bf-11f1-996e-df6b82771d8e/20cde940-29bf-11f1-8e08-930a4fe4bc4a.jpg"/>
      <itunes:duration>1673</itunes:duration>
      <itunes:summary>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</itunes:summary>
      <itunes:subtitle>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>You Bought a GRC Platform...Now What?</title>
      <link>https://podcasts.fame.so/e/v85j4p6n</link>
      <itunes:title>You Bought a GRC Platform...Now What?</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81q3xpv1</guid>
      <description>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</description>
      <content:encoded><![CDATA[<p>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About <a href="https://www.bemopro.com/compliance">⁠BEMO⁠</a></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2025 16:23:58 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/8rjnjpj8.mp3" length="15956844" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1fcbba30-29bf-11f1-b9d7-69919e6c1b6b/1fcbb820-29bf-11f1-8e76-572886b1b235.jpg"/>
      <itunes:duration>997</itunes:duration>
      <itunes:summary>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</itunes:summary>
      <itunes:subtitle>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
  </channel>
</rss>
