<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:spotify="https://www.spotify.com/ns/rss">
  <channel>
    <generator>Fame Host (https://fame.so)</generator>
    <title>Trust Issues</title>
    <link>https://podcasts.fame.so/the-trust-issues</link>
    <itunes:new-feed-url>https://feeds.fame.so/the-trust-issues</itunes:new-feed-url>
    <description>Why do so many businesses have trust issues with security and compliance? We’re here to find out.
Hosted by Brandon Lecoq and Joseph Candelario, Trust Issues is the podcast that makes cybersecurity and compliance a little less boring (and a lot more human). From SOC 2 nightmares to the myths that keep teams stuck in checklist mode, we dig into real stories, ethical dilemmas, and the psychology that fuels bad security habits.
Expect sharp takes, relatable stories, and the occasional existential crisis (nothing that cant be fixed)</description>
    <copyright>BEMO</copyright>
    <language>en</language>
    <pubDate>Fri, 27 Mar 2026 09:27:03 +0000</pubDate>
    <lastBuildDate>Sat, 04 Apr 2026 15:06:36 +0000</lastBuildDate>
    <image>
      <url>https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png</url>
      <title>Trust Issues</title>
      <link>https://podcasts.fame.so/the-trust-issues</link>
      <description>Why do so many businesses have trust issues with security and compliance? We’re here to find out.
Hosted by Brandon Lecoq and Joseph Candelario, Trust Issues is the podcast that makes cybersecurity and compliance a little less boring (and a lot more human). From SOC 2 nightmares to the myths that keep teams stuck in checklist mode, we dig into real stories, ethical dilemmas, and the psychology that fuels bad security habits.
Expect sharp takes, relatable stories, and the occasional existential crisis (nothing that cant be fixed)</description>
    </image>
    <googleplay:author>BEMO</googleplay:author>
    <googleplay:image href="https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png"/>
    <itunes:category text="Technology"/>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <googleplay:summary>Why do so many businesses have trust issues with security and compliance? We’re here to find out.
Hosted by Brandon Lecoq and Joseph Candelario, Trust Issues is the podcast that makes cybersecurity and compliance a little less boring (and a lot more human). From SOC 2 nightmares to the myths that keep teams stuck in checklist mode, we dig into real stories, ethical dilemmas, and the psychology that fuels bad security habits.
Expect sharp takes, relatable stories, and the occasional existential crisis (nothing that cant be fixed)</googleplay:summary>
    <googleplay:explicit>No</googleplay:explicit>
    <googleplay:block>No</googleplay:block>
    <itunes:type>episodic</itunes:type>
    <itunes:author>BEMO</itunes:author>
    <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/f6027f00-2d0a-11f1-b296-35e3858469d3/f6028000-2d0a-11f1-8957-0b83e03f5608.png"/>
    <itunes:summary>Why do so many businesses have trust issues with security and compliance? We’re here to find out.
Hosted by Brandon Lecoq and Joseph Candelario, Trust Issues is the podcast that makes cybersecurity and compliance a little less boring (and a lot more human). From SOC 2 nightmares to the myths that keep teams stuck in checklist mode, we dig into real stories, ethical dilemmas, and the psychology that fuels bad security habits.
Expect sharp takes, relatable stories, and the occasional existential crisis (nothing that cant be fixed)</itunes:summary>
    <itunes:subtitle>Why do so many businesses have trust issues with security and compliance? We’re here to find out.
Hosted by Brandon Lecoq and Joseph Candelario, Trust Issues is the podcast that makes cybersecurity and compliance a little less boring (and a lot more human). From SOC 2 nightmares to the myths that keep teams stuck in checklist mode, we dig into real stories, ethical dilemmas, and the psychology that fuels bad security habits.
Expect sharp takes, relatable stories, and the occasional existential crisis (nothing that cant be fixed)</itunes:subtitle>
    <itunes:keywords/>
    <itunes:owner>
      <itunes:name>BEMO</itunes:name>
      <itunes:email>team-bmp@fame.so</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <itunes:block>No</itunes:block>
    <item>
      <title>Your Compliance Report Might Be Worthless</title>
      <link>https://podcasts.fame.so/e/08jyqw9n</link>
      <itunes:title>Your Compliance Report Might Be Worthless</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">41pqxl80</guid>
      <description>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</description>
      <content:encoded><![CDATA[<div>There is a real cost to cutting compliance corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification.<br><br></div><div><strong>What You’ll Learn:&nbsp;</strong></div><ul><li>Why market pressure creates fraud and how to avoid it</li><li>How to spot a fraudulent compliance vendor before engaging</li><li>The real cost of due diligence and why legitimate vendors should demand deeper scrutiny</li><li>Why open-source GRC platforms like GigaChad GRC are disrupting the market</li><li>How to validate compliance readiness without falling into the trap</li><li>The ripple effect of fraudulent reports&nbsp;</li></ul><div><br>Tune in for actionable strategies to position your organization for the growth that 2026 promises to bring.<br><br></div><div><strong>Episode Chapters:&nbsp;</strong></div><div><br></div><div>00:00 Introduction&nbsp;</div><div>00:36 A widespread SOC 2 fraud scheme finally exposed</div><div>02:22 Why market pressure creates compliance shortcuts</div><div>07:37 What happens now?&nbsp;</div><div>12:51 Why open-source GRC platforms are price disruptors</div><div>19:23 Your due diligence = auditor attestation letters</div><div>22:35 Consult peers and advisors before committing to vendors</div><div>24:10 The “too good to be true” test&nbsp;</div><div>24:46 Key takeaways &amp; final thoughts&nbsp;</div><div><br></div><div><strong><em>Quotes:</em></strong></div><div><br></div><ol><li>"I feel like a lot of people in the compliance space have thought that something like this was going on with some companies, and they didn't really know who it was or where it was happening, but it just seemed like there's a lot of, like, a gold rush happening right now."</li></ol><div><br></div><ol><li>“There's a lot of startups who are trying to go mid-market enterprise really, really fast because they have a good product. And in order to do that, they're finding that they have pressure to get something like a SOC two in place. And because there's a strong need on the market for that, there are gonna be people and companies that are going to want to do that."</li></ol><div><br></div><ol><li>"I had one conversation where the guy was spending three times what many other really, really good reputable firms that we work with charge. And the company is literally 20 people, but they're charging three times the amount for the audit for something that does not in any way need to be that thorough."</li></ol><div><br></div><ol><li>“The people that actually care about the space or are passionate about the space will push back on you on certain aspects. You can go find people that would be happy to give their two cents about what your plan is."</li></ol><div><br></div><ol><li>"If it sounds too good to be true, it probably is. It's kind of like a fitness analogy - if you see big signs that you should take a pill, you probably shouldn't take that pill. If you know that your IT is not up to par and something is very fast and very cheap, you should be very skeptical because it's probably not very good."</li></ol><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 14:00:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w53y3zmw.mp3" length="35381712" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/fc58e940-2d0b-11f1-bbcf-4315fd1d11b1/fc58ea40-2d0b-11f1-8e7b-d7521d15d6f5.jpg"/>
      <itunes:duration>1556</itunes:duration>
      <itunes:summary>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</itunes:summary>
      <itunes:subtitle>Reports of a widespread SOC 2 fraud scheme have exposed the dangerous gap between “compliance theater” and REAL security, forcing the industry to reckon with the cost of cutting corners. In the debut episode of the Trust Issues podcast, host Brandon Lecoq welcomes Joseph Candelario, Business Development, Partnerships and Marketing Executive at BEMO, to discuss an emerging fraud scheme involving a compliance automation platform and audit firms rubber-stamping identical SOC 2 reports without verification. Together, they explore why startups are pressured into fast, cheap compliance solutions, how market innovation is both creating and solving problems, and what SMBs should actually do when faced with unrealistic compliance timelines and too-good-to-be-true vendors.</itunes:subtitle>
      <itunes:keywords>SOC 2 fraud, Compliance automation platforms, GRC platforms, Audit firm rubber-stamping, Fraudulent compliance reports, SOC 2 certification, Compliance frameworks, GRC software, Vendor due diligence, Compliance shortcuts, Fast compliance solutions, Evidence collection, Control mapping, policy management, Vendor risk assessment, Open source GRC, Compliance audit process, Compliance implementation timeline,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Trust Issues Trailer</title>
      <link>https://podcasts.fame.so/e/x8y73xk8</link>
      <itunes:title>Trust Issues Trailer</itunes:title>
      <itunes:episode>7</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">l04r53z0</guid>
      <description>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</description>
      <content:encoded><![CDATA[<div>Compliance has a trust problem.<br>Everyone says they can get you certified.<br>Everyone claims to be “security-first.”<br>And yet, breaches still happen, systems fail, and data is lost.<br>So what’s actually going on?<br><br>Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.<br>We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.<br><br>If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.<br><br>🔗 Subscribe and follow to stay ahead.<br><br>#ComplianceMatters #CMMC #Cybersecurity</div><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 10:37:00 +0000</pubDate>
      <author>BEMO</author>
      <enclosure url="https://media.fame.so/w6ljl9mw.mp3" length="1673016" type="audio/mpeg"/>
      <itunes:author>BEMO</itunes:author>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/b5b097d0-2c66-11f1-81c5-2f9d7cfd5c5c/b5b098d0-2c66-11f1-9b84-79109cb3df21.jpg"/>
      <itunes:duration>59</itunes:duration>
      <itunes:summary>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</itunes:summary>
      <itunes:subtitle>Compliance has a trust problem.
Everyone says they can get you certified.
Everyone claims to be “security-first.”
And yet, breaches still happen, systems fail, and data is lost.
So what’s actually going on?
Trust Issues is the podcast where we unpack what real security looks like, beyond the checkboxes, buzzwords, and sales pitches.
We sit down with auditors, implementers, GRC platforms, and industry leaders to explore what’s really happening inside compliance, especially in the world of CMMC and government contracting.
If you’re a Head of IT, CISO, or business leader navigating compliance, this is where the real conversations happen.
🔗 Subscribe and follow to stay ahead.
#ComplianceMatters #CMMC #Cybersecurity</itunes:subtitle>
      <itunes:keywords>cybersecurity compliance, CMMC compliance, information security, GRC platforms, data protection strategies, risk management cybersecurity, security audits, government contracting security, cybersecurity podcast, compliance best practices,</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Why CMMC Matters: A Deep Dive into Security Standards</title>
      <link>https://podcasts.fame.so/e/lnqw6ypn</link>
      <itunes:title>Why CMMC Matters: A Deep Dive into Security Standards</itunes:title>
      <itunes:episode>6</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81nvq581</guid>
      <description>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</description>
      <content:encoded><![CDATA[<p><strong>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade?</strong> 😅<br></p><p>We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.</p><p>We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.</p><p>Plus, we get into what contractors should actually do next:<br>➡️ How to identify your real security gap<br>➡️ Why compliance automation tools will be essential<br>➡️ What budgeting realistically looks like<br>➡️ Why taking small steps today saves massive stress later</p><p>If you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.</p><p>Follow BEMO for more practical breakdowns on compliance, security, and modernization:<br>🔗 <strong>Website:</strong> <a href="https://www.bemopro.com" target="_new" rel="noopener">https://www.bemopro.com</a><br>🔗 <strong>LinkedIn:</strong> <a href="https://www.linkedin.com/company/bemopro" target="_new" rel="noopener">https://www.linkedin.com/company/bemopro</a></p><p></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2025 15:26:14 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/8vykyq3w.mp3" length="39581987" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1d5b0830-29bf-11f1-95b8-015b6fe91892/1d5b03e0-29bf-11f1-9508-edc5d09b513e.jpg"/>
      <itunes:duration>2473</itunes:duration>
      <itunes:summary>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</itunes:summary>
      <itunes:subtitle>Why are so many DoD contractors shocked by CMMC… when the security requirements have been around for almost a decade? 😅We break down what’s actually driving the panic: companies realizing they’ve skipped years of basic security work. No MFA. No Intune. Still on GoDaddy. Still on Microsoft Business Basic. Still trusting that “nobody will check.” And now that third-party audits are here, the bill is due.We also talk about the bigger picture: how CMMC is less about “new rules” and more about catching up on modernization. From outdated IT setups to security questionnaires with… let’s call them “creative” answers, this episode shows why CMMC matters and why the organizations who invest early will be the ones who stay competitive.Plus, we get into what contractors should actually do next:➡️ How to identify your real security gap➡️ Why compliance automation tools will be essential➡️ What budgeting realistically looks like➡️ Why taking small steps today saves massive stress laterIf you want a grounded, no-BS explanation of where CMMC came from, why it’s sticking around, and what it means for the future of the defense industrial base, this episode is for you.Follow BEMO for more practical breakdowns on compliance, security, and modernization:🔗 Website: https://www.bemopro.com🔗 LinkedIn: https://www.linkedin.com/company/bemopro</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Outsourcing Compliance: When and Why It Makes Sense</title>
      <link>https://podcasts.fame.so/e/mn4lqz9n</link>
      <itunes:title>Outsourcing Compliance: When and Why It Makes Sense</itunes:title>
      <itunes:episode>5</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">x06r2xm0</guid>
      <description>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</description>
      <content:encoded><![CDATA[<p>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.</p><p>In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</p><p><br></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 21 Nov 2025 13:26:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/wj090k4w.mp3" length="38809181" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1e26fbb0-29bf-11f1-9a32-33716d4fb600/1e26f7c0-29bf-11f1-8d07-13da7c3b4459.jpg"/>
      <itunes:duration>2425</itunes:duration>
      <itunes:summary>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</itunes:summary>
      <itunes:subtitle>If you’ve ever wondered whether you should handle compliance in-house or call in experts, this episode gives you the honest, behind-the-scenes breakdown.In this episode, Brandon and Joseph break down the real reasons companies decide to outsource compliance—and why it’s often the smartest move you can make when revenue, timelines, and focus are on the line.</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Smart Compliance Tip 2: Know When to Outsource</title>
      <link>https://podcasts.fame.so/e/q80vrk48</link>
      <itunes:title>Smart Compliance Tip 2: Know When to Outsource</itunes:title>
      <itunes:episode>4</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">p0knq9m1</guid>
      <description>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </description>
      <content:encoded><![CDATA[<p>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2025 06:57:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/w95r5m6w.mp3" length="22693928" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1e969000-29bf-11f1-bbd8-5d957f3f53a5/1e968b20-29bf-11f1-8155-6f758533d556.jpg"/>
      <itunes:duration>1418</itunes:duration>
      <itunes:summary>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </itunes:summary>
      <itunes:subtitle>Compliance doesn’t have to drain your time (or sanity). One of the biggest challenges for growing teams is knowing when to outsource compliance.If your internal team is stretched thin, or you’re just starting to think about frameworks like SOC 2 or ISO 27001, outsourcing to a Managed Security and Compliance Provider (MSSP) or consultant might be your best move. </itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>Smart Compliance Tip 1: Understand Business Impact</title>
      <link>https://podcasts.fame.so/e/p8m7v4v8</link>
      <itunes:title>Smart Compliance Tip 1: Understand Business Impact</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">70v53m31</guid>
      <description>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</description>
      <content:encoded><![CDATA[<p>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2025 08:09:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/84v2vyr8.mp3" length="27194931" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1f11e420-29bf-11f1-99a9-d7dd3ca0b346/1f11e1f0-29bf-11f1-a29b-1bed260c3434.jpg"/>
      <itunes:duration>1699</itunes:duration>
      <itunes:summary>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</itunes:summary>
      <itunes:subtitle>We kick off our Smart Compliance Tips series with an important mindset shift: understanding your business impact.Too often, IT managers and tech staff are handed compliance tasks simply because leadership assumes “it’s an IT thing.” But compliance is a business-wide responsibility — one that affects revenue, ROI, and company growth.When you start thinking in business terms — metrics, risk, and outcomes — you can better advocate for the tools, staff, and resources you need to do compliance right.Connect with Us:🌐 Website: https://www.bemopro.com</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>The Compliance Checklist Mentality - A Growing Problem</title>
      <link>https://podcasts.fame.so/e/28xzryq8</link>
      <itunes:title>The Compliance Checklist Mentality - A Growing Problem</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">60mkq930</guid>
      <description>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</description>
      <content:encoded><![CDATA[<p>Still treating compliance like a checklist? 😬 It’s time to break the habit. </p><p>In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. </p><p><br></p><p>Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.</p><p><br></p><p>Want to go deeper? Read our blogs on:</p><p><a href="https://www.bemopro.com/cybersecurity-blog/soc-2-compliance-matters" target="_blank" rel="noopener noreferer">- Why SOC 2 compliance really matters 👉 </a></p><p><a href="https://www.bemopro.com/cybersecurity-blog/what-to-do-the-first-time-you-face-soc-2-compliance" target="_blank" rel="noopener noreferer">- What to Do the First Time You&#39;re Tackling SOC 2 Compliance </a></p><p><a href="https://www.bemopro.com/cybersecurity-blog/rushing-soc-2-compliance-can-cost-you-a-major-deal-what-to-do-instead" target="_blank" rel="noopener noreferer">- Rushing SOC 2 Compliance Can Cost You a Major Deal </a></p><p><br></p><p>🔗 Learn More About <a href="https://www.bemopro.com/compliance" target="_blank" rel="noopener noreferer">BEMO</a></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2025 18:30:00 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/w0vlvq9w.mp3" length="26768612" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/20cdeb70-29bf-11f1-996e-df6b82771d8e/20cde940-29bf-11f1-8e08-930a4fe4bc4a.jpg"/>
      <itunes:duration>1673</itunes:duration>
      <itunes:summary>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</itunes:summary>
      <itunes:subtitle>Still treating compliance like a checklist? 😬 It’s time to break the habit. In this episode of Trust Issues, Joseph and Brandon tackle the growing concerns surrounding compliance in the tech industry, particularly focusing on the checklist mentality that&amp;#39;s infiltrating the SOC 2 certification process. We explore how this approach, pressures auditing firms and companies alike to cut corners and prioritize speed over thoroughness. Join us as we unpack the complexities of SOC 2, the role of GRC platform reps, and the need for a shift in how we approach compliance to ensure genuine security and trust.Want to go deeper? Read our blogs on:- Why SOC 2 compliance really matters 👉 - What to Do the First Time You&amp;#39;re Tackling SOC 2 Compliance - Rushing SOC 2 Compliance Can Cost You a Major Deal 🔗 Learn More About BEMO</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
    <item>
      <title>You Bought a GRC Platform...Now What?</title>
      <link>https://podcasts.fame.so/e/v85j4p6n</link>
      <itunes:title>You Bought a GRC Platform...Now What?</itunes:title>
      <itunes:episode>1</itunes:episode>
      <itunes:block>No</itunes:block>
      <googleplay:block>No</googleplay:block>
      <guid isPermaLink="false">81q3xpv1</guid>
      <description>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</description>
      <content:encoded><![CDATA[<p>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About <a href="https://www.bemopro.com/compliance">⁠BEMO⁠</a></p><div>Trust Issues is handcrafted by our friends over at: <a href="https://www.fame.so/?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=masters-of-community-with-david-spinks?utm_medium=podcast&amp;utm_source=bcast&amp;utm_campaign=fame-client">fame.so</a></div>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2025 16:23:58 +0000</pubDate>
      <author/>
      <enclosure url="https://media.fame.so/8rjnjpj8.mp3" length="15956844" type="audio/mpeg"/>
      <itunes:author/>
      <itunes:image href="https://content.fameapp.so/uploads/4jq4k571/1fcbba30-29bf-11f1-b9d7-69919e6c1b6b/1fcbb820-29bf-11f1-8e76-572886b1b235.jpg"/>
      <itunes:duration>997</itunes:duration>
      <itunes:summary>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</itunes:summary>
      <itunes:subtitle>Getting compliant takes more than just buying a tool. In this episode of Trust Issues, Joseph and Brandon break down a major misconception in the compliance world: thinking a GRC platform will HANDLE compliance for you. Spoiler alert: it won’t. They discuss why GRC software is just the starting point, not the finish line. It helps you understand where you stand, but it won’t implement controls, write policies, or build the ongoing structure your organization needs to stay compliant. You’ll also hear why delegating compliance to an IT manager or developer can lead to major gaps, and why successful companies invest in a dedicated, well-funded compliance team, or a trusted managed compliance partner to do it right.🔗 Learn More About ⁠BEMO⁠</itunes:subtitle>
      <itunes:keywords/>
      <itunes:explicit>No</itunes:explicit>
      <googleplay:explicit>No</googleplay:explicit>
    </item>
  </channel>
</rss>
