<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[We Make Sure]]></title><description><![CDATA[<p>Governance, Risk,Welcome to the <b>WeMakeSure Podcast</b> — where cybersecurity, governance, risk, and compliance meet real-world leadership.</p><p>This channel is built for <b>executives, founders, IT leaders, compliance professionals, and security practitioners</b> who want to understand how <b>cybersecurity and risk management actually drive business success</b> — not just pass audits.</p><p>Each episode breaks down complex topics like <b>Cybersecurity, HIPAA, ISO 27001, SOC 2, vendor risk, leadership, and security culture</b> into practical conversations you can apply immediately inside your organization.</p><p>On this channel you’ll find:</p><p>🎙 <b>Video podcast episodes</b> with security and compliance leaders<br />🛡 <b>Cybersecurity insights</b> explained in plain English<br />📊 <b>Risk and compliance strategies</b> for growing companies<br />🏥 <b>Healthcare security &amp; HIPAA guidance</b><br />🏢 <b>Leadership lessons for CISOs, founders, and executives</b><br />⚡ <b>Real-world stories from audits, breaches, and security programs</b></p><p>Whether you're leading a startup, managing IT, running compliance, or sitting in the <b>C-suite</b>, the goal is simple:</p><p><b>Help organizations build trust, reduce risk, and create a culture of security.</b></p><p>Because security isn’t just about controls and checklists.</p><p><b>It’s about making sure the things that matter most are protected.</b></p><p>🔔 <b>Subscribe for weekly conversations on cybersecurity, governance, risk, compliance, and leadership.</b> and Compliance</p>]]></description><link>http://www.wemakesure.com</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Thu, 28 May 2026 11:31:20 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/p9HEzVdY.rss" rel="self" type="application/rss+xml"/><author><![CDATA[David Pahlman and Robert Parker]]></author><pubDate>Mon, 09 Mar 2026 14:26:15 GMT</pubDate><copyright><![CDATA[2026 David Pahlman and Robert Parker]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Business]]></category><category><![CDATA[Technology]]></category><itunes:author>David Pahlman and Robert Parker</itunes:author><itunes:summary>&lt;p&gt;Governance, Risk,Welcome to the &lt;b&gt;WeMakeSure Podcast&lt;/b&gt; — where cybersecurity, governance, risk, and compliance meet real-world leadership.&lt;/p&gt;&lt;p&gt;This channel is built for &lt;b&gt;executives, founders, IT leaders, compliance professionals, and security practitioners&lt;/b&gt; who want to understand how &lt;b&gt;cybersecurity and risk management actually drive business success&lt;/b&gt; — not just pass audits.&lt;/p&gt;&lt;p&gt;Each episode breaks down complex topics like &lt;b&gt;Cybersecurity, HIPAA, ISO 27001, SOC 2, vendor risk, leadership, and security culture&lt;/b&gt; into practical conversations you can apply immediately inside your organization.&lt;/p&gt;&lt;p&gt;On this channel you’ll find:&lt;/p&gt;&lt;p&gt;🎙 &lt;b&gt;Video podcast episodes&lt;/b&gt; with security and compliance leaders&lt;br /&gt;🛡 &lt;b&gt;Cybersecurity insights&lt;/b&gt; explained in plain English&lt;br /&gt;📊 &lt;b&gt;Risk and compliance strategies&lt;/b&gt; for growing companies&lt;br /&gt;🏥 &lt;b&gt;Healthcare security &amp;amp; HIPAA guidance&lt;/b&gt;&lt;br /&gt;🏢 &lt;b&gt;Leadership lessons for CISOs, founders, and executives&lt;/b&gt;&lt;br /&gt;⚡ &lt;b&gt;Real-world stories from audits, breaches, and security programs&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Whether you&apos;re leading a startup, managing IT, running compliance, or sitting in the &lt;b&gt;C-suite&lt;/b&gt;, the goal is simple:&lt;/p&gt;&lt;p&gt;&lt;b&gt;Help organizations build trust, reduce risk, and create a culture of security.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Because security isn’t just about controls and checklists.&lt;/p&gt;&lt;p&gt;&lt;b&gt;It’s about making sure the things that matter most are protected.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;🔔 &lt;b&gt;Subscribe for weekly conversations on cybersecurity, governance, risk, compliance, and leadership.&lt;/b&gt; and Compliance&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>David Pahlman and Robert Parker</itunes:name><itunes:email>pahlman.david@gmail.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"/><itunes:category text="Technology"/><itunes:image href="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/logos/f0052a11-28c4-4ca3-8081-c3256149260e.jpeg"/><item><title><![CDATA[David Pahlman - Starting the First Risk Assessment]]></title><description><![CDATA[<p>The episode provides a practical guide to conducting a risk assessment, emphasizing simplicity and practicality. It outlines five key steps: defining scope, identifying risks, assessing likelihood and impact, planning response, and documenting the assessment.</p><p></p><p>Takeaways</p><ul><li>Simplicity in risk assessment</li><li>Regular review of risk assessment</li></ul><p></p><p>Chapters</p><ul><li>00:00 The Truth About Risk Assessment</li></ul>]]></description><guid isPermaLink="false">32a2049e-a0a9-4629-9b36-398b8aadf3f1</guid><dc:creator><![CDATA[David Pahlman and Robert Parker]]></dc:creator><pubDate>Tue, 07 Apr 2026 16:47:47 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/2a58bf20196c99bf5e5edeae656ab99a42129759b6913d3c203c10224f3aecce/eyJlcGlzb2RlSWQiOiIzMmEyMDQ5ZS1hMGE5LTQ2MjktOWIzNi0zOThiOGFhZGYzZjEiLCJwb2RjYXN0SWQiOiJiOWJiNTQ0Yi02MjhmLTRlNWEtOGYwZC1iNzJmZWZiY2IxYmEiLCJhY2NvdW50SWQiOiI2OTFmZDRhYzI1YTYzMDA0N2Y4Y2Q3NzIiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlkNTMxNDNiMGI0NGQ4ZjU3OThkMjU5L2Rhdmlkcy1zdHVkaW8tY09QWWUtY29tcG9zZXItMjAyNi00LTdfXzE4LTMwLTU5Lm1wMyJ9.mp3" length="6593036" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/episodes/32a2049e-a0a9-4629-9b36-398b8aadf3f1/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;The episode provides a practical guide to conducting a risk assessment, emphasizing simplicity and practicality. It outlines five key steps: defining scope, identifying risks, assessing likelihood and impact, planning response, and documenting the assessment.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Simplicity in risk assessment&lt;/li&gt;&lt;li&gt;Regular review of risk assessment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Chapters&lt;/p&gt;&lt;ul&gt;&lt;li&gt;00:00 The Truth About Risk Assessment&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:35</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/logos/f0052a11-28c4-4ca3-8081-c3256149260e.jpeg"/><itunes:title>David Pahlman - Starting the First Risk Assessment</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[David Pahlman - Agentic A.I. Governance]]></title><description><![CDATA[<p>Agentic AI is a compliance problem that most businesses aren't ready for. It requires governance, human checkpoints, audit logging, and updated AI policies to address the liability and accountability issues. Businesses need to define the scope and permissions, build human checkpoints, require audit logging, and update AI policies to address the challenges of agentic AI.</p><p></p><p>Takeaways</p><ul><li>Agentic AI requires governance</li><li>Human checkpoints are essential for agentic AI</li><li>Audit logging is necessary for every action of an AI agent</li><li>Updated AI policies are crucial for addressing the challenges of agentic AI</li></ul><p></p><p>Chapters</p><ul><li>00:00 Introduction to Agentic AI</li></ul>]]></description><guid isPermaLink="false">f5571728-59fe-4db0-ac82-d99dea827d5c</guid><dc:creator><![CDATA[David Pahlman and Robert Parker]]></dc:creator><pubDate>Mon, 06 Apr 2026 13:01:18 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/cfd7557a12a8ad895ee5a45b51678165e96e83738d2fa4bb5841ccffd79a9d5b/eyJlcGlzb2RlSWQiOiJmNTU3MTcyOC01OWZlLTRkYjAtYWM4Mi1kOTlkZWE4MjdkNWMiLCJwb2RjYXN0SWQiOiJiOWJiNTQ0Yi02MjhmLTRlNWEtOGYwZC1iNzJmZWZiY2IxYmEiLCJhY2NvdW50SWQiOiI2OTFmZDRhYzI1YTYzMDA0N2Y4Y2Q3NzIiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlkM2FjYTMyYWI0MDBlZDE1NDc0ZjAyL2Rhdmlkcy1zdHVkaW8tY09QWWUtY29tcG9zZXItMjAyNi00LTZfXzE0LTUyLTUxLm1wMyJ9.mp3" length="5327873" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/episodes/f5571728-59fe-4db0-ac82-d99dea827d5c/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Agentic AI is a compliance problem that most businesses aren&apos;t ready for. It requires governance, human checkpoints, audit logging, and updated AI policies to address the liability and accountability issues. Businesses need to define the scope and permissions, build human checkpoints, require audit logging, and update AI policies to address the challenges of agentic AI.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Agentic AI requires governance&lt;/li&gt;&lt;li&gt;Human checkpoints are essential for agentic AI&lt;/li&gt;&lt;li&gt;Audit logging is necessary for every action of an AI agent&lt;/li&gt;&lt;li&gt;Updated AI policies are crucial for addressing the challenges of agentic AI&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Chapters&lt;/p&gt;&lt;ul&gt;&lt;li&gt;00:00 Introduction to Agentic AI&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:03:42</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/logos/f0052a11-28c4-4ca3-8081-c3256149260e.jpeg"/><itunes:title>David Pahlman - Agentic A.I. Governance</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[David Pahlman - Compliance As Code]]></title><description><![CDATA[<p>Compliance as Code vs Real Compliance | HIPAA, ISO 27001, and NIST 800-53 Explained<br /><br />Everyone is talking about Compliance as Code—automating controls, enforcing policies in CI/CD, and letting tools monitor security posture in real time. But can automation really handle the full scope of compliance frameworks like HIPAA, ISO 27001, and NIST 800-53?<br /><br />In this episode of the We Make Sure Podcast, David Pahlman breaks down where Compliance as Code works incredibly well—and where it falls short.<br /><br />You’ll learn why automation can enforce technical controls, but frameworks like HIPAA and ISO demand something deeper: governance, leadership involvement, risk-based decisions, and documented intent.<br /><br />If you're a CISO, security leader, compliance professional, or executive, this episode will help you understand how to balance automation with real-world compliance strategy.<br /><br />In this episode we discuss:<br />• What Compliance as Code actually is<br />• Where automation strengthens security programs<br />• Why HIPAA compliance is mostly administrative<br />• Why ISO 27001 requires intentional governance<br />• The limits of automation in NIST 800-53<br />• The difference between proving a control exists and proving why it exists<br /><br />Compliance as Code is powerful—but real compliance still requires people, judgment, and leadership.<br /><br />Subscribe for more conversations on:<br />Cybersecurity • Governance • Risk Management • Compliance • Leadership<br /><br />About the We Make Sure Podcast<br /><br />The We Make Sure Podcast explores the intersection of cybersecurity, governance, risk management, and leadership. Each episode breaks down complex security and compliance topics into practical insights that executives and security professionals can actually use.<br /><br />If you work in security, compliance, healthcare technology, or executive leadership, this channel is built for you.<br /><br />#CyberSecurity #Compliance #ISO27001 #HIPAA #NIST #GRC #DevSecOps #InformationSecurity #WeMakeSure</p>]]></description><guid isPermaLink="false">290c11b7-23b8-47fe-b3a7-c8934b83b35a</guid><dc:creator><![CDATA[David Pahlman and Robert Parker]]></dc:creator><pubDate>Tue, 10 Mar 2026 15:23:30 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0faa816e90cc198cadbcb5985f590af1ab64f1a9cd3b32c498ffbdbdf8037fe9/eyJlcGlzb2RlSWQiOiIyOTBjMTFiNy0yM2I4LTQ3ZmUtYjNhNy1jODkzNGI4M2IzNWEiLCJwb2RjYXN0SWQiOiJiOWJiNTQ0Yi02MjhmLTRlNWEtOGYwZC1iNzJmZWZiY2IxYmEiLCJhY2NvdW50SWQiOiI2OTFmZDRhYzI1YTYzMDA0N2Y4Y2Q3NzIiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlhZjM2MmUwNmUwNjlmM2Y4OWIyODRkL2Rhdmlkcy1zdHVkaW8tY09QWWUtY29tcG9zZXItMjAyNi0zLTlfXzIyLTUtNTAubXAzIn0=.mp3" length="15568291" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/episodes/290c11b7-23b8-47fe-b3a7-c8934b83b35a/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Compliance as Code vs Real Compliance | HIPAA, ISO 27001, and NIST 800-53 Explained&lt;br /&gt;&lt;br /&gt;Everyone is talking about Compliance as Code—automating controls, enforcing policies in CI/CD, and letting tools monitor security posture in real time. But can automation really handle the full scope of compliance frameworks like HIPAA, ISO 27001, and NIST 800-53?&lt;br /&gt;&lt;br /&gt;In this episode of the We Make Sure Podcast, David Pahlman breaks down where Compliance as Code works incredibly well—and where it falls short.&lt;br /&gt;&lt;br /&gt;You’ll learn why automation can enforce technical controls, but frameworks like HIPAA and ISO demand something deeper: governance, leadership involvement, risk-based decisions, and documented intent.&lt;br /&gt;&lt;br /&gt;If you&apos;re a CISO, security leader, compliance professional, or executive, this episode will help you understand how to balance automation with real-world compliance strategy.&lt;br /&gt;&lt;br /&gt;In this episode we discuss:&lt;br /&gt;• What Compliance as Code actually is&lt;br /&gt;• Where automation strengthens security programs&lt;br /&gt;• Why HIPAA compliance is mostly administrative&lt;br /&gt;• Why ISO 27001 requires intentional governance&lt;br /&gt;• The limits of automation in NIST 800-53&lt;br /&gt;• The difference between proving a control exists and proving why it exists&lt;br /&gt;&lt;br /&gt;Compliance as Code is powerful—but real compliance still requires people, judgment, and leadership.&lt;br /&gt;&lt;br /&gt;Subscribe for more conversations on:&lt;br /&gt;Cybersecurity • Governance • Risk Management • Compliance • Leadership&lt;br /&gt;&lt;br /&gt;About the We Make Sure Podcast&lt;br /&gt;&lt;br /&gt;The We Make Sure Podcast explores the intersection of cybersecurity, governance, risk management, and leadership. Each episode breaks down complex security and compliance topics into practical insights that executives and security professionals can actually use.&lt;br /&gt;&lt;br /&gt;If you work in security, compliance, healthcare technology, or executive leadership, this channel is built for you.&lt;br /&gt;&lt;br /&gt;#CyberSecurity #Compliance #ISO27001 #HIPAA #NIST #GRC #DevSecOps #InformationSecurity #WeMakeSure&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:10:49</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/b9bb544b-628f-4e5a-8f0d-b72fefbcb1ba/episodes/290c11b7-23b8-47fe-b3a7-c8934b83b35a/images/87f576e7-2f06-40f2-9f40-7e2a3ed0e5a6.png"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:title>David Pahlman - Compliance As Code</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>