<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spoiledlunch</title><link>https://511d98a7.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Tue, 12 May 2026 00:00:00 -0500</lastBuildDate><atom:link href="https://511d98a7.spoiledlunch.pages.dev/topics/security/" rel="self" type="application/rss+xml"/><item><title>International Anti-Ransomware Day: Who Really Profits from the Fear Campaign?</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-12-international-anti-ransomware-day-who-profits-from-fear/</link><pubDate>Tue, 12 May 2026 00:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-12-international-anti-ransomware-day-who-profits-from-fear/</guid><description>Article • May 12, 2026 • 6 min read | Topics: Security, GRC | It’s International Anti-Ransomware Day. Time to be very, very afraid of ransomware. And conveniently, very, very ready to buy solutions.
What started as a legitimate effort to raise awareness …</description><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item><item><title>World Password Day: Intel's Marketing Legacy Thirteen Years Later</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-07-world-password-day-intels-marketing-legacy-thirteen-years-later/</link><pubDate>Thu, 07 May 2026 17:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-07-world-password-day-intels-marketing-legacy-thirteen-years-later/</guid><description>Article • May 7, 2026 • 6 min read | Topics: Security, GRC | World Password Day just ended, and with it, another week of password managers explaining why your passwords aren’t complex enough, MFA vendors explaining why passwords are fundamentally broken, …</description><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item><item><title>Why Dashboard Metrics Collapse During Real Incidents</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-why-dashboard-metrics-collapse-during-real-incidents/</link><pubDate>Tue, 05 May 2026 09:00:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-why-dashboard-metrics-collapse-during-real-incidents/</guid><description>Article • May 5, 2026 • 1 min read | Topics: Security | Most security dashboards are built to reassure leadership, not to help responders make decisions under pressure. That tradeoff usually stays hidden until a real incident forces the dashboard to answer …</description><author>Spoiledlunch</author><category>Security</category><category>incident response</category><category>dashboards</category><category>operations</category></item><item><title>World Password Day: How Security Hygiene Became Subscription Revenue</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-02-world-password-day-how-security-hygiene-became-subscription-revenue/</link><pubDate>Sat, 02 May 2026 09:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-02-world-password-day-how-security-hygiene-became-subscription-revenue/</guid><description>Article • May 2, 2026 • 6 min read | Topics: Security, Privacy | Today is World Password Day, which means it’s time to feel bad about your password habits and grateful for the password manager subscriptions that will save you from your own human limitations. …</description><author>Spoiledlunch</author><category>Security</category><category>Privacy</category></item><item><title>Why Vulnerability Management Breaks Long Before Patching Does</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-28-why-vulnerability-management-breaks-long-before-patching-does/</link><pubDate>Tue, 28 Apr 2026 17:05:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-28-why-vulnerability-management-breaks-long-before-patching-does/</guid><description>Article • April 28, 2026 • 7 min read | Topics: Security | When leaders say their vulnerability program is struggling because patching is too slow, they are usually describing the last visible failure, not the first one.
Patching is where the program becomes …</description><author>Spoiledlunch</author><category>Security</category><category>vulnerability management</category><category>patching</category><category>asset inventory</category><category>prioritization</category></item><item><title>Why Visibility Is Becoming a Hardware Security Problem</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-why-visibility-is-becoming-a-hardware-security-problem/</link><pubDate>Fri, 24 Apr 2026 08:10:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-why-visibility-is-becoming-a-hardware-security-problem/</guid><description>Article • April 24, 2026 • 2 min read | Topics: Security | Security teams still talk about hardware trust like it is a procurement checkbox, but recent NIST guidance points to a more embarrassing reality: many organizations are defending systems they cannot …</description><author>Spoiledlunch</author><category>Security</category><category>hardware security</category><category>firmware</category><category>monitoring</category><category>nist</category></item><item><title>The SOC 2 Compliance Cargo Cult</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</link><pubDate>Sat, 18 Apr 2026 14:30:00 -0700</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</guid><description>Article • April 18, 2026 • 7 min read | Topics: GRC, Security | SOC 2 compliance has become a cargo cult ritual in enterprise security. Organizations implement the ceremonial controls, follow the prescribed procedures, and wait for security to magically appear. …</description><author>Spoiledlunch</author><category>GRC</category><category>Security</category><category>SOC 2</category><category>compliance</category><category>security controls</category><category>audit</category></item><item><title>When Zero Trust Meets Reality</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-15-zero-trust-meets-reality/</link><pubDate>Wed, 15 Apr 2026 11:15:00 -0700</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-15-zero-trust-meets-reality/</guid><description>Article • April 15, 2026 • 7 min read | Topics: Security | Zero Trust promises to solve network security by eliminating trust assumptions. The marketing pitch is compelling: assume breach, verify everything, trust nothing. In practice, most Zero Trust …</description><author>Spoiledlunch</author><category>Security</category><category>zero trust</category><category>network security</category><category>architecture</category><category>implementation</category></item><item><title>NIST Publishes Hardware Security White Paper on Firmware-Based Monitoring</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-15-nist-publishes-hardware-security-white-paper-on-firmware-based-monitoring/</link><pubDate>Wed, 15 Apr 2026 09:00:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-15-nist-publishes-hardware-security-white-paper-on-firmware-based-monitoring/</guid><description>News Brief • April 15, 2026 | Topics: Security | Summary: NIST published Cybersecurity White Paper 52, “Firmware-Based Monitoring for Bus-Based Computer Systems,” on April 15, 2026. The …</description><author>Spoiledlunch</author><category>Security</category><category>NIST</category><category>hardware security</category><category>firmware</category><category>forensics</category></item><item><title>NIST Updates NVD Operations to Address Record CVE Growth</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-15-nist-updates-nvd-operations-to-address-record-cve-growth/</link><pubDate>Wed, 15 Apr 2026 12:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-15-nist-updates-nvd-operations-to-address-record-cve-growth/</guid><description>News Brief • April 15, 2026 | Topics: Security | Summary: NIST is changing NVD operations to keep up with record CVE volume, signaling that vulnerability teams should expect continued prioritization …</description><author>Spoiledlunch</author><category>Security</category><category>security</category><category>nist</category><category>nvd</category><category>vulnerabilities</category></item><item><title>NIST Finalizes Revision 3 of Its DNS Deployment Guide</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-03-19-nist-finalizes-revision-3-of-its-dns-deployment-guide/</link><pubDate>Thu, 19 Mar 2026 09:00:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-03-19-nist-finalizes-revision-3-of-its-dns-deployment-guide/</guid><description>News Brief • March 19, 2026 | Topics: Security | Summary: NIST published the final version of SP 800-81 Revision 3, “Secure Domain Name System (DNS) Deployment Guide,” on March 19, 2026. …</description><author>Spoiledlunch</author><category>Security</category><category>NIST</category><category>DNS</category><category>DNSSEC</category><category>zero trust</category></item><item><title>Data Privacy Week: How a Single Day Became a Marketing Event</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/data-privacy-week-investigation/</link><pubDate>Mon, 26 Jan 2026 09:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/data-privacy-week-investigation/</guid><description>Article • January 26, 2026 • 3 min read | Topics: Security, GRC | It’s Data Privacy Week. Or is it Data Privacy Day? The confusion isn’t accidental.
What started as a legitimate European observance on January 28 has expanded into a week-long American …</description><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item></channel></rss>