<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blog on 0xwolfe</title><link>https://0xwolfe.com/blog/</link><description>Recent content in Blog on 0xwolfe</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://0xwolfe.com/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Read the policy before you sign it</title><link>https://0xwolfe.com/blog/read-the-policy-before-you-sign-it/</link><pubDate>Fri, 02 Oct 2026 00:00:00 -0400</pubDate><guid>https://0xwolfe.com/blog/read-the-policy-before-you-sign-it/</guid><description>&lt;p&gt;A company needs a security program, usually because a big customer sent over a questionnaire or sales promised a SOC 2 report by the end of the year. They bring in a virtual CISO, and a few weeks later a folder shows up with twenty or so polished policies: access control, change management, incident response, vendor management, encryption, acceptable use. Leadership looks them over in one meeting and approves them. A few months later the audit starts, and the auditor tests the company against those documents line by line.&lt;/p&gt;</description></item><item><title>Hello, world</title><link>https://0xwolfe.com/blog/hello-world/</link><pubDate>Wed, 30 Sep 2026 00:00:00 -0400</pubDate><guid>https://0xwolfe.com/blog/hello-world/</guid><description>&lt;p&gt;Every security person eventually builds a personal site, and this is mine.&lt;/p&gt;&#10;&lt;p&gt;I&amp;rsquo;ll mostly write about building governance, risk, and compliance programs: what works, what falls apart in the first audit, and how to keep the program useful once the certificate is on the wall. I&amp;rsquo;ll also write some about operations, because that&amp;rsquo;s where most security programs live or die.&lt;/p&gt;&#10;&lt;p&gt;Some posts will have nothing to do with work. Expect some astrophotography and Pokémon cards.&lt;/p&gt;</description></item></channel></rss>