<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog</title>
    <link>https://risk3sixty.com/blog</link>
    <description>Discover insights on ISO 42001, GRC program management, and the future of cybersecurity through expert perspectives and practical guides on compliance and risk management.</description>
    <language>en-us</language>
    <pubDate>Tue, 25 Aug 2026 15:45:52 GMT</pubDate>
    <dc:date>2026-08-25T15:45:52Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>Determining Your ISO 42001 Role: A Guide for Organizations</title>
      <link>https://risk3sixty.com/blog/determining-your-iso-42001-role-guide</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/determining-your-iso-42001-role-guide" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Determining-Your-ISO-42001-Role-square-1.png" alt="Determining Your ISO 42001 Role: A Guide for Organizations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;As organizations strive to manage risk and innovation in a rapidly changing AI landscape, the adoption of &lt;a href="https://risk3sixty.com/webinars/iso-42001-everything-you-need-to-get-certified"&gt;ISO 42001&lt;/a&gt; becomes increasingly relevant.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/determining-your-iso-42001-role-guide" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Determining-Your-ISO-42001-Role-square-1.png" alt="Determining Your ISO 42001 Role: A Guide for Organizations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;As organizations strive to manage risk and innovation in a rapidly changing AI landscape, the adoption of &lt;a href="https://risk3sixty.com/webinars/iso-42001-everything-you-need-to-get-certified"&gt;ISO 42001&lt;/a&gt; becomes increasingly relevant.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fdetermining-your-iso-42001-role-guide&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>ISO 42001</category>
      <category>EU AI Act</category>
      <pubDate>Thu, 04 Jun 2026 04:00:00 GMT</pubDate>
      <author>philip.brudney@risk3sixty.com (Philip Brudney)</author>
      <guid>https://risk3sixty.com/blog/determining-your-iso-42001-role-guide</guid>
      <dc:date>2026-06-04T04:00:00Z</dc:date>
    </item>
    <item>
      <title>A Practical Guide to CMMC Compliance, Implementation, and Certification</title>
      <link>https://risk3sixty.com/blog/practical-guide-cmmc-compliance-implementation-certification</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/practical-guide-cmmc-compliance-implementation-certification" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Practical-guide-cmmc-implementation-and-certification-1-1.png" alt="A Practical Guide to CMMC Compliance, Implementation, and Certification" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;em&gt;This is a joint effort between &lt;a href="https://www.schellman.com/"&gt;Schellman&lt;/a&gt; and risk3sixty. You can find the original post &lt;a href="https://www.schellman.com/blog/federal-compliance/cmmc-compliance-guide"&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/practical-guide-cmmc-compliance-implementation-certification" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Practical-guide-cmmc-implementation-and-certification-1-1.png" alt="A Practical Guide to CMMC Compliance, Implementation, and Certification" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;em&gt;This is a joint effort between &lt;a href="https://www.schellman.com/"&gt;Schellman&lt;/a&gt; and risk3sixty. You can find the original post &lt;a href="https://www.schellman.com/blog/federal-compliance/cmmc-compliance-guide"&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fpractical-guide-cmmc-compliance-implementation-certification&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>CMMC</category>
      <pubDate>Thu, 21 May 2026 04:00:00 GMT</pubDate>
      <author>andrew.parks@risk3sixty.com (Andrew Parks)</author>
      <guid>https://risk3sixty.com/blog/practical-guide-cmmc-compliance-implementation-certification</guid>
      <dc:date>2026-05-21T04:00:00Z</dc:date>
    </item>
    <item>
      <title>The Future of Control Testing: How AI Is Reshaping Internal Audit, SOC 2, SOX, and Continuous Controls Monitoring</title>
      <link>https://risk3sixty.com/blog/ai-controls-testing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/ai-controls-testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/risk3sixty-Agentic-AI-Controls-Testing-1.png" alt="The Future of Control Testing: How AI Is Reshaping Internal Audit, SOC 2, SOX, and Continuous Controls Monitoring" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Yesterday I spoke with a team that is responsible for testing 1000s of controls a year. They have an entire staff that goes through the process of gathering evidence, documenting results, and reporting them to leadership day after day.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/ai-controls-testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/risk3sixty-Agentic-AI-Controls-Testing-1.png" alt="The Future of Control Testing: How AI Is Reshaping Internal Audit, SOC 2, SOX, and Continuous Controls Monitoring" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Yesterday I spoke with a team that is responsible for testing 1000s of controls a year. They have an entire staff that goes through the process of gathering evidence, documenting results, and reporting them to leadership day after day.&lt;/p&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fai-controls-testing&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Artificial Intelligence</category>
      <category>Christian Hyatt</category>
      <category>GRC Tool</category>
      <pubDate>Tue, 05 May 2026 04:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/ai-controls-testing</guid>
      <dc:date>2026-05-05T04:00:00Z</dc:date>
    </item>
    <item>
      <title>Georgia Tech Students Are Showing Us the Future of Cybersecurity Work</title>
      <link>https://risk3sixty.com/blog/georgia-tech-students-risk3sixty-and-the-future-of-cybersecurity-work</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/georgia-tech-students-risk3sixty-and-the-future-of-cybersecurity-work" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Capstone-Team-scaled-1.jpg" alt="Georgia Tech Students Are Showing Us the Future of Cybersecurity Work" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I am blown away by what Georgia Tech students are building right now.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/georgia-tech-students-risk3sixty-and-the-future-of-cybersecurity-work" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Capstone-Team-scaled-1.jpg" alt="Georgia Tech Students Are Showing Us the Future of Cybersecurity Work" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I am blown away by what Georgia Tech students are building right now.&lt;/p&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fgeorgia-tech-students-risk3sixty-and-the-future-of-cybersecurity-work&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity</category>
      <category>Artificial Intelligence</category>
      <category>Christian Hyatt</category>
      <pubDate>Tue, 21 Apr 2026 04:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/georgia-tech-students-risk3sixty-and-the-future-of-cybersecurity-work</guid>
      <dc:date>2026-04-21T04:00:00Z</dc:date>
    </item>
    <item>
      <title>Introducing the risk3sixty Ecosystem</title>
      <link>https://risk3sixty.com/blog/introducing-the-risk3sixty-ecosystem</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/introducing-the-risk3sixty-ecosystem" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/the-risk3sixty-ecosystem-v1-1.png" alt="Introducing the risk3sixty Ecosystem" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;risk3sixty was founded 10 years ago because Christian Hyatt and Christian White wanted to build a business aligned to their personal values. &lt;strong&gt;That meant creating something special.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/introducing-the-risk3sixty-ecosystem" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/the-risk3sixty-ecosystem-v1-1.png" alt="Introducing the risk3sixty Ecosystem" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;risk3sixty was founded 10 years ago because Christian Hyatt and Christian White wanted to build a business aligned to their personal values. &lt;strong&gt;That meant creating something special.&lt;/strong&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fintroducing-the-risk3sixty-ecosystem&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Cybersecurity</category>
      <category>Information Security</category>
      <category>Risk Management</category>
      <pubDate>Mon, 20 Apr 2026 04:00:00 GMT</pubDate>
      <author>sawyer.miller@risk3sixty.com (Sawyer Miller)</author>
      <guid>https://risk3sixty.com/blog/introducing-the-risk3sixty-ecosystem</guid>
      <dc:date>2026-04-20T04:00:00Z</dc:date>
    </item>
    <item>
      <title>The Future of GRC: Why Compliance Professionals Must Become Program Architects</title>
      <link>https://risk3sixty.com/blog/grc-program-architect</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/grc-program-architect" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Rise-of-the-GRC-Architect-risk3sixty-1.png" alt="The Future of GRC: Why Compliance Professionals Must Become Program Architects" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For years, too many talented people entered GRC expecting to do meaningful, high-impact work only to find themselves stuck chasing screenshots, organizing evidence folders, and repeatedly following up with engineers for audit artifacts.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/grc-program-architect" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Rise-of-the-GRC-Architect-risk3sixty-1.png" alt="The Future of GRC: Why Compliance Professionals Must Become Program Architects" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For years, too many talented people entered GRC expecting to do meaningful, high-impact work only to find themselves stuck chasing screenshots, organizing evidence folders, and repeatedly following up with engineers for audit artifacts.&lt;/p&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fgrc-program-architect&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity</category>
      <category>Compliance</category>
      <category>Christian Hyatt</category>
      <pubDate>Thu, 16 Apr 2026 04:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/grc-program-architect</guid>
      <dc:date>2026-04-16T04:00:00Z</dc:date>
    </item>
    <item>
      <title>Why GRC Teams Spend More Time Managing Tools Than Managing Risk</title>
      <link>https://risk3sixty.com/blog/grc-teams-spend-more-time-managing-tools-than-risk</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/grc-teams-spend-more-time-managing-tools-than-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/managing-grc-risk-1.jpg" alt="Why GRC Teams Spend More Time Managing Tools Than Managing Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most GRC leaders didn’t buy a GRC platform because they were chasing shiny objects or trying to impress the board with new software.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/grc-teams-spend-more-time-managing-tools-than-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/managing-grc-risk-1.jpg" alt="Why GRC Teams Spend More Time Managing Tools Than Managing Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most GRC leaders didn’t buy a GRC platform because they were chasing shiny objects or trying to impress the board with new software.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fgrc-teams-spend-more-time-managing-tools-than-risk&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Risk Management</category>
      <category>GRC Tool</category>
      <pubDate>Wed, 04 Mar 2026 05:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/grc-teams-spend-more-time-managing-tools-than-risk</guid>
      <dc:date>2026-03-04T05:00:00Z</dc:date>
    </item>
    <item>
      <title>The Hidden Work No One Accounts for in SOC 2, ISO 27001, and PCI Programs</title>
      <link>https://risk3sixty.com/blog/hidden-work-soc-2-iso-27001-pci-dss</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/hidden-work-soc-2-iso-27001-pci-dss" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/hidden-work-in-soc-2-iso-27001-pci-1.jpg" alt="The Hidden Work No One Accounts for in SOC 2, ISO 27001, and PCI Programs" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/hidden-work-soc-2-iso-27001-pci-dss" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/hidden-work-in-soc-2-iso-27001-pci-1.jpg" alt="The Hidden Work No One Accounts for in SOC 2, ISO 27001, and PCI Programs" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fhidden-work-soc-2-iso-27001-pci-dss&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>ISO 27001</category>
      <category>ISO 27001 Compliance</category>
      <category>SOC 2</category>
      <category>SOC Reporting</category>
      <category>PCI DSS</category>
      <pubDate>Wed, 25 Feb 2026 05:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/hidden-work-soc-2-iso-27001-pci-dss</guid>
      <dc:date>2026-02-25T05:00:00Z</dc:date>
    </item>
    <item>
      <title>Leaders Must Balance Peace and Urgency</title>
      <link>https://risk3sixty.com/blog/peace-and-urgency</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/peace-and-urgency" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Peace-and-Urgency-at-risk3sixty-1.png" alt="Leaders Must Balance Peace and Urgency" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I’ve always been restless. I don’t sit still well. My mind tends to run ahead of me, constantly generating new ideas like services we could launch, improvements we could make, markets we could explore. There is always something else we could do, and if I’m not careful, I can convince myself that we should do all of it.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/peace-and-urgency" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/Peace-and-Urgency-at-risk3sixty-1.png" alt="Leaders Must Balance Peace and Urgency" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I’ve always been restless. I don’t sit still well. My mind tends to run ahead of me, constantly generating new ideas like services we could launch, improvements we could make, markets we could explore. There is always something else we could do, and if I’m not careful, I can convince myself that we should do all of it.&lt;/p&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fpeace-and-urgency&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Leadership</category>
      <category>Business</category>
      <category>Christian Hyatt</category>
      <pubDate>Mon, 23 Feb 2026 05:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/peace-and-urgency</guid>
      <dc:date>2026-02-23T05:00:00Z</dc:date>
    </item>
    <item>
      <title>What It Actually Takes to Run a GRC Program (And Why Most People Get It Wrong)</title>
      <link>https://risk3sixty.com/blog/what-it-actually-takes-to-run-grc-program</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/what-it-actually-takes-to-run-grc-program" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/What-it-takes-to-run-grc-program-blog-1.jpg" alt="What It Actually Takes to Run a GRC Program (And Why Most People Get It Wrong)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most people think running a GRC program is about getting ready for audits.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://risk3sixty.com/blog/what-it-actually-takes-to-run-grc-program" title="" class="hs-featured-image-link"&gt; &lt;img src="https://risk3sixty.com/hubfs/Imported_Blog_Media/What-it-takes-to-run-grc-program-blog-1.jpg" alt="What It Actually Takes to Run a GRC Program (And Why Most People Get It Wrong)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most people think running a GRC program is about getting ready for audits.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3338278&amp;amp;k=14&amp;amp;r=https%3A%2F%2Frisk3sixty.com%2Fblog%2Fwhat-it-actually-takes-to-run-grc-program&amp;amp;bu=https%253A%252F%252Frisk3sixty.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity</category>
      <pubDate>Wed, 18 Feb 2026 05:00:00 GMT</pubDate>
      <author>christian.hyatt@risk3sixty.com (Christian Hyatt)</author>
      <guid>https://risk3sixty.com/blog/what-it-actually-takes-to-run-grc-program</guid>
      <dc:date>2026-02-18T05:00:00Z</dc:date>
    </item>
  </channel>
</rss>
