<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://compliancebureau.org/</loc><lastmod>2026-09-15T11:58:18.652Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary</loc><lastmod>2026-08-28T07:22:08.212Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/72-hour-notification-requirement</loc><lastmod>2026-07-05T02:17:20.521Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/ai-management-system-aims</loc><lastmod>2026-07-05T00:19:56.592Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/ansiisa-62443</loc><lastmod>2026-07-04T23:27:32.601Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/access-recertification</loc><lastmod>2026-07-04T21:08:22.015Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/access-review</loc><lastmod>2026-07-04T21:30:36.019Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/accredited-certification-body</loc><lastmod>2026-07-05T01:44:36.754Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/algorithmic-transparency</loc><lastmod>2026-07-05T00:18:16.185Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/approved-scanning-vendor</loc><lastmod>2026-07-05T01:36:12.057Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/article-49-derogations</loc><lastmod>2026-07-05T02:04:43.467Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/attestation-report</loc><lastmod>2026-07-05T01:29:37.233Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/attribute-based-access-control</loc><lastmod>2026-07-04T21:00:01.529Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/authentication-and-authorization</loc><lastmod>2026-07-04T21:32:09.299Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/automated-individual-decision-making-and-profiling</loc><lastmod>2026-07-04T23:14:43.174Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/binding-corporate-rules</loc><lastmod>2026-07-05T01:51:11.937Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/breach-notification</loc><lastmod>2026-07-05T02:15:31.779Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/broad-consent</loc><lastmod>2026-07-04T22:55:24.665Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/business-associate-agreement-baa</loc><lastmod>2026-07-04T23:51:37.673Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/business-continuity-plan</loc><lastmod>2026-07-04T20:55:31.643Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/business-impact-analysis</loc><lastmod>2026-07-05T01:19:51.258Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/cis-critical-security-controls</loc><lastmod>2026-07-04T23:22:46.213Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/cobit</loc><lastmod>2026-07-04T23:25:56.652Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/coso-framework</loc><lastmod>2026-07-05T00:30:28.880Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/csf-core-functions-govern-identify-protect-detect-respond-recover</loc><lastmod>2026-07-04T23:31:01.014Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/chapter-v-transfer-mechanisms</loc><lastmod>2026-07-05T02:03:11.163Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/common-criteria</loc><lastmod>2026-07-05T01:26:29.724Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/computer-security-incident-response-team</loc><lastmod>2026-07-05T02:22:41.139Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/concentration-risk</loc><lastmod>2026-07-05T02:48:22.985Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/conformity-assessment</loc><lastmod>2026-07-05T01:46:18.779Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/conformity-assessment-for-ai</loc><lastmod>2026-07-05T00:23:12.710Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/consent-management-platform</loc><lastmod>2026-07-04T22:58:48.113Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/consent-withdrawal</loc><lastmod>2026-07-04T22:57:10.112Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/containment-eradication-and-recovery</loc><lastmod>2026-07-05T02:25:39.921Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/continuous-monitoring</loc><lastmod>2026-07-05T00:34:32.035Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/control-assessment</loc><lastmod>2026-07-05T01:16:55.380Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/control-environment</loc><lastmod>2026-07-05T00:31:59.173Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/control-objective</loc><lastmod>2026-07-05T00:33:12.495Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/covered-entity</loc><lastmod>2026-07-04T22:18:05.038Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/cryptographic-module-validation-fips-140-3</loc><lastmod>2026-07-04T23:45:17.336Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/cybersecurity-and-infrastructure-security-agency</loc><lastmod>2026-07-04T21:23:01.833Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-breach-register</loc><lastmod>2026-07-05T02:30:59.956Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-classification</loc><lastmod>2026-07-04T22:20:19.359Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-controller</loc><lastmod>2026-07-04T22:16:43.676Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-custodian</loc><lastmod>2026-07-04T22:31:22.913Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-inventory-and-mapping</loc><lastmod>2026-07-04T22:28:10.777Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-lifecycle-management</loc><lastmod>2026-07-04T22:21:53.836Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-lineage</loc><lastmod>2026-07-05T00:37:42.482Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-localization</loc><lastmod>2026-07-05T02:06:20.027Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-loss-prevention</loc><lastmod>2026-07-04T23:47:00.431Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-minimisation</loc><lastmod>2026-07-04T17:23:59.133Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-processing-agreement</loc><lastmod>2026-07-04T23:53:04.337Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-protection-authority</loc><lastmod>2026-07-04T21:34:07.676Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-protection-impact-assessment</loc><lastmod>2026-07-04T22:00:05.557Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-retention-policy</loc><lastmod>2026-07-04T22:25:01.542Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-steward</loc><lastmod>2026-07-04T22:29:39.503Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/data-subject-access-request</loc><lastmod>2026-07-04T23:02:23.695Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/department-of-health-and-human-services-hhs-office-for-civil-rights</loc><lastmod>2026-07-05T00:44:41.414Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/disaster-recovery-plan</loc><lastmod>2026-07-05T02:34:05.748Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/dynamic-consent</loc><lastmod>2026-07-04T22:53:49.580Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/eu-ai-act</loc><lastmod>2026-07-04T23:56:27.260Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/eu-us-data-privacy-framework</loc><lastmod>2026-07-05T01:58:00.625Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/encryption-at-rest</loc><lastmod>2026-07-04T23:34:14.831Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/encryption-in-transit</loc><lastmod>2026-07-04T23:35:38.847Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/end-to-end-encryption</loc><lastmod>2026-07-04T23:41:41.774Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/endpoint-protection</loc><lastmod>2026-07-05T01:01:13.950Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/essentially-equivalent-protection</loc><lastmod>2026-07-05T02:12:54.194Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/european-commission</loc><lastmod>2026-07-04T21:37:54.965Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/european-data-protection-board</loc><lastmod>2026-07-04T21:24:40.091Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/explicit-consent</loc><lastmod>2026-07-04T22:51:34.606Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/fatf-recommendations</loc><lastmod>2026-07-04T17:13:01.542Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/family-educational-rights-and-privacy-act</loc><lastmod>2026-07-04T20:52:28.028Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/fedramp-authorization</loc><lastmod>2026-08-28T07:22:08.212Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/federal-information-security-management-act-fisma</loc><lastmod>2026-07-04T22:43:27.991Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/federal-trade-commission</loc><lastmod>2026-07-05T00:43:17.820Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/firewall-configuration</loc><lastmod>2026-07-05T00:58:13.773Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/forensic-investigation</loc><lastmod>2026-07-05T02:32:29.761Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/fourth-party-risk</loc><lastmod>2026-07-05T02:39:27.872Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/fundamental-rights-impact-assessment</loc><lastmod>2026-07-05T00:15:00.498Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/glba-safeguards-rule</loc><lastmod>2026-07-05T01:48:12.678Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/general-data-protection-regulation</loc><lastmod>2026-07-04T21:14:56.160Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/general-purpose-ai-gpai</loc><lastmod>2026-07-05T00:10:48.201Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/governance-risk-and-compliance-grc</loc><lastmod>2026-07-05T00:27:16.266Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/gramm-leach-bliley-act</loc><lastmod>2026-07-04T22:40:23.731Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/hipaa-privacy-rule</loc><lastmod>2026-07-04T22:05:04.907Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/hipaa-security-rule</loc><lastmod>2026-07-04T22:03:23.944Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/hitrust-csf-certification</loc><lastmod>2026-07-05T01:31:13.593Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/hashing</loc><lastmod>2026-07-05T00:56:08.968Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/health-information-technology-for-economic-and-clinical-health-act</loc><lastmod>2026-07-04T22:37:12.340Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/health-insurance-portability-and-accountability-act</loc><lastmod>2026-07-04T22:01:38.706Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/high-risk-ai-system</loc><lastmod>2026-08-28T07:15:44.320Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/human-oversight</loc><lastmod>2026-07-05T00:24:42.928Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/iso-27001-certification</loc><lastmod>2026-07-05T00:39:22.317Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/iso-31000</loc><lastmod>2026-07-04T17:22:33.085Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/isoiec-27001</loc><lastmod>2026-07-04T21:13:28.820Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/isoiec-27002</loc><lastmod>2026-07-04T23:17:50.479Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/isoiec-42001</loc><lastmod>2026-07-05T00:00:05.149Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/identity-federation</loc><lastmod>2026-07-04T21:19:41.571Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/identity-governance-and-administration</loc><lastmod>2026-08-28T07:18:01.234Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/implementation-tiers</loc><lastmod>2026-07-04T23:32:31.735Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/incident-response-plan</loc><lastmod>2026-07-05T02:19:27.377Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/incident-triage</loc><lastmod>2026-07-05T02:24:15.982Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/information-security-management-system</loc><lastmod>2026-07-04T23:29:04.584Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/inherent-risk</loc><lastmod>2026-07-05T01:14:56.302Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/internal-controls-over-financial-reporting</loc><lastmod>2026-07-05T00:28:42.707Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/intrusion-detection-system</loc><lastmod>2026-07-05T00:53:04.072Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/just-in-time-access</loc><lastmod>2026-07-04T21:29:12.647Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/key-management</loc><lastmod>2026-07-04T23:38:26.080Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/lawful-basis-for-processing</loc><lastmod>2026-07-04T22:10:23.416Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/legal-hold</loc><lastmod>2026-07-04T22:34:22.379Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/legitimate-interest</loc><lastmod>2026-07-04T22:15:16.900Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/master-data-management</loc><lastmod>2026-07-04T22:32:49.688Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/model-explainability</loc><lastmod>2026-07-05T00:21:28.742Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/money-laundering-reporting-officer</loc><lastmod>2026-07-04T17:25:29.185Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/multi-factor-authentication</loc><lastmod>2026-07-04T20:56:55.896Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nist-ai-risk-management-framework</loc><lastmod>2026-07-04T23:58:11.558Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nist-cybersecurity-framework-csf-20</loc><lastmod>2026-07-04T23:16:24.597Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nist-risk-management-framework</loc><lastmod>2026-07-05T01:03:18.724Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nist-sp-800-171</loc><lastmod>2026-07-04T23:21:11.671Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nist-sp-800-53</loc><lastmod>2026-07-04T23:19:26.078Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nydfs-cybersecurity-regulation</loc><lastmod>2026-07-04T22:46:47.436Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/national-institute-of-standards-and-technology</loc><lastmod>2026-07-04T21:21:16.302Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/network-segmentation</loc><lastmod>2026-07-04T23:43:53.036Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/nonpublic-personal-information</loc><lastmod>2026-07-04T21:52:50.726Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/north-american-electric-reliability-corporation-critical-infrastructure-protection</loc><lastmod>2026-07-04T22:48:31.241Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/onward-transfer</loc><lastmod>2026-07-05T02:07:46.004Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/organizational-profile</loc><lastmod>2026-07-05T00:06:33.331Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/pci-security-standards-council</loc><lastmod>2026-07-05T00:49:57.676Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/personal-data</loc><lastmod>2026-07-04T21:43:15.655Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/personal-data-breach</loc><lastmod>2026-07-04T23:00:37.576Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/personally-identifiable-information</loc><lastmod>2026-07-04T21:41:50.988Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/points-of-focus</loc><lastmod>2026-07-05T01:27:57.781Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/post-incident-review</loc><lastmod>2026-07-05T02:27:10.412Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/principle-of-least-privilege</loc><lastmod>2026-07-04T21:01:24.686Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/privacy-notice</loc><lastmod>2026-07-04T21:51:08.092Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/privacy-by-design-and-by-default</loc><lastmod>2026-07-04T21:58:23.274Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/privileged-access-management</loc><lastmod>2026-07-04T21:04:20.990Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/prohibited-ai-practices</loc><lastmod>2026-07-05T00:13:04.487Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/protected-health-information</loc><lastmod>2026-07-04T21:49:41.836Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/provisioning-and-deprovisioning</loc><lastmod>2026-07-04T21:18:11.713Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/pseudonymization</loc><lastmod>2026-07-04T21:54:17.600Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/public-key-infrastructure</loc><lastmod>2026-07-05T00:54:38.673Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/purpose-limitation</loc><lastmod>2026-07-04T22:06:55.505Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/qualified-opinion</loc><lastmod>2026-07-05T01:42:10.653Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/qualified-security-assessor</loc><lastmod>2026-07-05T01:32:49.486Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/records-retention-schedule</loc><lastmod>2026-07-04T22:23:25.578Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/records-of-processing-activities</loc><lastmod>2026-07-04T22:26:39.354Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/residual-risk</loc><lastmod>2026-07-04T17:26:49.501Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-of-access</loc><lastmod>2026-07-04T22:50:02.398Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-data-portability</loc><lastmod>2026-07-04T23:06:38.807Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-erasure</loc><lastmod>2026-07-04T23:03:53.492Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-object</loc><lastmod>2026-07-04T23:09:50.789Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-rectification</loc><lastmod>2026-07-04T23:05:15.283Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-restriction-of-processing</loc><lastmod>2026-07-04T23:08:16.590Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-be-informed</loc><lastmod>2026-07-04T23:11:18.543Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/right-to-audit-clause</loc><lastmod>2026-07-05T02:44:24.679Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-acceptance</loc><lastmod>2026-07-05T01:18:19.712Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-appetite</loc><lastmod>2026-07-05T01:06:44.734Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-register</loc><lastmod>2026-07-05T01:04:59.660Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-tolerance</loc><lastmod>2026-07-05T01:08:21.405Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-treatment</loc><lastmod>2026-07-05T01:13:14.467Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/risk-based-approach</loc><lastmod>2026-07-04T17:28:22.258Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/role-based-access-control</loc><lastmod>2026-07-04T20:58:24.677Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/soc-1</loc><lastmod>2026-07-05T01:21:37.007Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/soc-2-type-i</loc><lastmod>2026-07-04T21:46:18.034Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/soc-2-type-ii</loc><lastmod>2026-07-04T21:44:45.042Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/soc-3</loc><lastmod>2026-07-05T01:23:31.067Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/sarbanes-oxley-act</loc><lastmod>2026-07-04T22:41:55.557Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/schrems-ii</loc><lastmod>2026-07-05T01:59:39.307Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/security-incident</loc><lastmod>2026-07-05T02:20:56.517Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/segregation-of-duties</loc><lastmod>2026-07-05T00:36:12.318Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/service-level-agreement</loc><lastmod>2026-07-05T02:41:09.448Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/simplified-due-diligence</loc><lastmod>2026-07-04T17:11:13.004Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/special-categories-of-personal-data</loc><lastmod>2026-07-04T21:47:56.964Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/standard-contractual-clauses</loc><lastmod>2026-07-05T01:49:41.992Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/statement-of-applicability</loc><lastmod>2026-07-05T00:41:37.623Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/storage-limitation</loc><lastmod>2026-07-04T22:08:28.258Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/sub-processor</loc><lastmod>2026-07-05T02:36:31.154Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/supply-chain-risk-management</loc><lastmod>2026-07-04T23:54:48.868Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/third-country-transfer</loc><lastmod>2026-07-05T02:11:09.861Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/third-party-risk-management</loc><lastmod>2026-07-04T23:48:37.081Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/threat-modeling</loc><lastmod>2026-07-05T01:09:54.521Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/tokenization</loc><lastmod>2026-07-04T23:40:01.078Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/transfer-impact-assessment</loc><lastmod>2026-07-05T01:54:25.328Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/trust-services-criteria</loc><lastmod>2026-07-05T01:24:55.698Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/trustworthy-ai</loc><lastmod>2026-07-05T00:16:49.143Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/usa-patriot-act</loc><lastmod>2026-07-04T17:14:34.762Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/vendor-due-diligence</loc><lastmod>2026-07-05T02:38:00.995Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/vendor-risk-assessment</loc><lastmod>2026-07-04T23:50:06.210Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/vendor-security-questionnaire</loc><lastmod>2026-07-05T02:42:48.504Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/vulnerability-assessment</loc><lastmod>2026-07-05T01:11:50.196Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/vulnerability-scanning</loc><lastmod>2026-07-05T00:59:38.970Z</lastmod></url>
  <url><loc>https://compliancebureau.org/glossary/zero-trust-architecture</loc><lastmod>2026-07-04T21:27:44.572Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog</loc><lastmod>2026-09-15T06:09:37.389Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/health-app-breach-rules-five-myths-costing-you-compliance</loc><lastmod>2026-09-15T06:09:37.389Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/personal-device-breach-costs-florida-dmv-what-auditors-must-verify-now</loc><lastmod>2026-09-14T06:09:38.461Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-exposes-727-000-records-what-went-wrong</loc><lastmod>2026-09-13T06:09:27.023Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/extia-s-300k-fine-how-199-ignored-erasure-requests-triggered-gdpr-enforcement</loc><lastmod>2026-09-12T06:09:35.172Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/automated-decisions-that-cost-you-millions</loc><lastmod>2026-09-11T06:09:49.886Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-for-breach-notification-or-breach-prevention</loc><lastmod>2026-09-10T06:09:37.346Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/your-quantum-migration-can-wait</loc><lastmod>2026-09-09T06:09:38.490Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-use-consumer-data-to-set-prices</loc><lastmod>2026-09-08T06:09:45.142Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/court-vendor-breach-exposes-12-states-risk-signals-you-missed</loc><lastmod>2026-09-07T06:11:37.786Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sonicwall-s-chained-zero-day-attack-what-went-wrong</loc><lastmod>2026-09-06T06:07:28.551Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/quantum-threats-aren-t-theoretical-5-myths-blocking-your-crypto-migration</loc><lastmod>2026-09-05T06:13:29.401Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sar-confidentiality-under-the-bsa-what-you-can-tell-customers</loc><lastmod>2026-09-05T06:11:26.633Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-payment-processors-act-as-fraud-police</loc><lastmod>2026-09-05T06:09:26.725Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-incident-response-checklist-for-healthcare-cisos</loc><lastmod>2026-09-04T06:11:57.031Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/compliance-teams-are-guessing-wrong-about-the-national-fraud-enforcement-division</loc><lastmod>2026-09-04T06:09:34.739Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/paper-records-real-penalties-645-000-fine-for-unsecured-medical-files</loc><lastmod>2026-09-04T06:07:29.168Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-to-settlement-checklist-what-to-verify-before-ransomware-hits</loc><lastmod>2026-09-03T06:37:38.940Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pay-or-rebuild-your-ransomware-response-decision</loc><lastmod>2026-09-03T06:35:46.945Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-refusal-five-myths-about-not-paying</loc><lastmod>2026-09-03T06:32:18.458Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-telecom-goes-dark-lessons-from-cisa-s-crisis-communication-framework</loc><lastmod>2026-09-03T06:27:23.649Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/security-awareness-training-won-t-stop-this-attack</loc><lastmod>2026-09-03T06:25:58.599Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/secure-your-paper-records-before-regulators-show-up</loc><lastmod>2026-09-03T06:23:33.325Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/paper-records-retention-policy-template</loc><lastmod>2026-09-03T06:21:55.482Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/medtech-breach-response-what-cisos-ask-after-an-incident</loc><lastmod>2026-09-03T06:17:49.950Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/meta-s-18-billion-settlement-what-failed-and-what-you-fix-today</loc><lastmod>2026-09-03T06:15:43.605Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/why-your-patch-everything-strategy-is-failing</loc><lastmod>2026-09-03T06:12:18.689Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-response-your-72-hour-checklist</loc><lastmod>2026-09-03T06:09:59.218Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-self-host-or-outsource-healthcare-data-storage</loc><lastmod>2026-09-03T06:07:46.399Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-in-healthcare-five-myths-blocking-better-governance</loc><lastmod>2026-09-02T06:45:41.970Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-patients-sue-what-sutter-health-s-ai-consent-failure-reveals-about-hipaa-compliance</loc><lastmod>2026-09-02T06:43:38.580Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/routers-don-t-need-hardening-6-myths-blocking-your-infrastructure-defense</loc><lastmod>2026-09-02T06:40:25.038Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-2-type-ii-to-fedramp-class-a-your-90-day-onboarding-plan</loc><lastmod>2026-09-02T06:31:52.555Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/two-papercut-flaws-show-why-federal-risk-prioritization-works-for-you</loc><lastmod>2026-09-02T06:28:23.109Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-call-it-a-forensic-audit-or-not</loc><lastmod>2026-09-02T06:25:15.323Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/crypto-treasury-move-gone-wrong-what-the-balance-sheet-revealed</loc><lastmod>2026-09-02T06:23:29.756Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/test-your-ir-plan-or-watch-it-fail-which-path-fits-your-organization</loc><lastmod>2026-09-02T06:21:43.256Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-ransomware-response-what-the-davita-case-teaches-security-teams</loc><lastmod>2026-09-02T06:19:40.676Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-driven-cyber-threats-what-financial-security-teams-are-actually-asking</loc><lastmod>2026-09-02T06:17:41.076Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-risk-your-healthcare-breach-prevention-checklist</loc><lastmod>2026-09-02T06:15:33.816Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/u-k-s-streamlined-data-law-mistakes-that-ll-cost-you-compliance</loc><lastmod>2026-09-02T06:08:02.794Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/securing-internet-exposed-ot-a-step-by-step-field-implementation</loc><lastmod>2026-09-01T06:39:43.114Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-your-ai-governance-survive-a-show-cause-order</loc><lastmod>2026-09-01T06:37:25.360Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iam-identity-center-myths-keeping-your-aws-governance-reactive</loc><lastmod>2026-09-01T06:35:31.546Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-ot-systems-ever-touch-the-internet</loc><lastmod>2026-09-01T06:33:32.245Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sanctions-and-aml-after-the-cjeu-italian-rulings</loc><lastmod>2026-09-01T06:31:42.623Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kyc-customer-onboarding-script-for-high-risk-clients</loc><lastmod>2026-09-01T06:29:46.449Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-access-controls-that-fail-under-pressure</loc><lastmod>2026-09-01T06:26:23.835Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-no-pay-policy-build-your-response-without-negotiation</loc><lastmod>2026-09-01T06:23:41.626Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/back-online-or-breach-free-your-recovery-decision-framework</loc><lastmod>2026-08-29T06:41:25.403Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/culture-program-audit-14-checks-that-reveal-if-yours-actually-works</loc><lastmod>2026-08-29T06:39:36.794Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-your-systems-are-up-but-your-adversary-isn-t-out</loc><lastmod>2026-08-29T06:37:08.460Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/quantum-readiness-isn-t-a-tech-problem</loc><lastmod>2026-08-29T06:35:15.462Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-won-t-replace-your-tprm-team-stop-acting-like-it-will</loc><lastmod>2026-08-29T06:33:33.940Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-data-breach-settlements-what-your-legal-team-needs-you-to-know</loc><lastmod>2026-08-29T06:31:41.176Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-centralize-patient-record-requests-or-keep-them-local</loc><lastmod>2026-08-29T06:29:24.030Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hipaa-security-rule-implementation-engineer-s-desk-reference</loc><lastmod>2026-08-28T06:45:46.852Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-enforcement-silence-puts-you-in-the-hot-seat</loc><lastmod>2026-08-28T06:43:31.000Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/data-theft-at-organ-registry-shows-third-party-risk-is-patient-risk</loc><lastmod>2026-08-28T06:41:36.881Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/transplant-coordination-outage-playbook</loc><lastmod>2026-08-28T06:39:40.443Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/why-auxiliary-systems-keep-getting-breached</loc><lastmod>2026-08-28T06:37:58.894Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stop-treating-cisa-s-kev-catalog-like-a-checklist</loc><lastmod>2026-08-28T06:35:35.672Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/shell-company-screening-what-compliance-teams-actually-ask</loc><lastmod>2026-08-28T06:33:32.490Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/foreign-power-equipment-bans-don-t-fix-supply-chain-risk</loc><lastmod>2026-08-28T06:30:23.918Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/audit-third-party-trackers-before-they-audit-you</loc><lastmod>2026-08-28T06:27:58.185Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/why-your-patch-queue-doesn-t-match-your-risk-profile</loc><lastmod>2026-08-27T08:01:55.464Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/harden-third-party-apps-before-extortion-groups-do</loc><lastmod>2026-08-27T07:59:50.943Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/water-system-ot-security-checklist-8-steps-to-lock-down-internet-exposed-controllers</loc><lastmod>2026-08-27T06:45:55.351Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/july-water-attacks-100-systems-hit-through-cellular-modems</loc><lastmod>2026-08-27T06:43:43.168Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/boi-reporting-is-gone-your-boi-obligations-aren-t</loc><lastmod>2026-08-27T06:41:44.467Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-basic-flaws-outpace-advanced-threats</loc><lastmod>2026-08-27T06:39:37.293Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/banks-or-platforms-who-pays-for-cross-boundary-scams</loc><lastmod>2026-08-27T06:37:50.139Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-compliance-traps-in-split-liability-scam-frameworks</loc><lastmod>2026-08-27T06:35:54.913Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/eu-anti-corruption-directive-compliance-checklist</loc><lastmod>2026-08-27T06:32:21.762Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/rca-after-a-breach-what-actually-happens-next</loc><lastmod>2026-08-26T06:45:48.557Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-detection-readiness-12-checks-before-your-next-red-team</loc><lastmod>2026-08-26T06:43:55.154Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/compliance-readiness-evidence-what-to-measure-beyond-course-completion</loc><lastmod>2026-08-26T06:41:40.210Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ism-assessment-readiness-in-weeks-not-months</loc><lastmod>2026-08-26T06:39:39.056Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-additions-what-they-signal-for-your-patch-queue</loc><lastmod>2026-08-26T06:37:41.652Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/oracle-weblogic-zero-day-what-happens-when-patch-management-is-optional</loc><lastmod>2026-08-26T06:35:58.691Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-patch-management-failures-that-let-nation-state-actors-in</loc><lastmod>2026-08-26T06:32:22.308Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/secret-vendor-bans-what-uk-powers-tell-us-about-supply-chain-compliance</loc><lastmod>2026-08-26T06:29:42.342Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-notification-playbook-60-days-to-compliance</loc><lastmod>2026-08-26T06:27:49.732Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/subtractive-hardening-checklist-for-healthcare-it</loc><lastmod>2026-08-25T06:41:58.615Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/biometric-authentication-under-siege-engineering-controls-beyond-the-fingerprint</loc><lastmod>2026-08-25T06:39:33.098Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/self-assessment-fraud-controls-don-t-protect-customers</loc><lastmod>2026-08-25T06:37:45.184Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fingerprint-spoofing-via-3d-printing-what-bsi-s-warning-reveals-about-authentication-controls</loc><lastmod>2026-08-25T06:35:37.732Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-report-activity-or-effectiveness-to-your-board</loc><lastmod>2026-08-25T06:33:21.749Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-notification-template-what-to-say-when-patient-data-gets-stolen</loc><lastmod>2026-08-25T06:31:56.561Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-for-data-access-or-protect-trade-secrets</loc><lastmod>2026-08-25T06:29:28.011Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-actually-patch-this-before-it-s-exploited</loc><lastmod>2026-08-25T06:27:39.953Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/state-privacy-laws-now-cover-half-the-u-s-what-changed-for-compliance-teams</loc><lastmod>2026-08-24T06:37:25.376Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/federal-agency-continuity-template-maintaining-operations-when-your-vendor-loses-a-third-of-its-staff</loc><lastmod>2026-08-23T06:54:26.654Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cryptography-asset-inventory-pre-quantum-field-guide</loc><lastmod>2026-08-23T06:43:48.946Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/quantum-safe-crypto-five-myths-blocking-your-migration</loc><lastmod>2026-08-23T06:41:25.305Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-don-t-need-service-accounts</loc><lastmod>2026-08-23T06:39:29.154Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agent-identity-checklist-12-controls-before-your-next-deployment</loc><lastmod>2026-08-23T06:37:30.424Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ocr-investigation-response-a-48-hour-playbook-for-covered-entities</loc><lastmod>2026-08-23T06:35:43.433Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cve-2026-73570-when-a-single-command-injection-becomes-total-system-compromise</loc><lastmod>2026-08-23T06:33:53.489Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-block-third-party-oauth-or-accept-the-risk</loc><lastmod>2026-08-23T06:29:37.078Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/oauth-phishing-beats-mfa-what-russia-s-campaigns-reveal</loc><lastmod>2026-08-23T06:27:27.156Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sickkids-data-breach-third-party-software-failure</loc><lastmod>2026-08-22T06:53:28.958Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/who-actually-owns-ai-when-it-fails</loc><lastmod>2026-08-22T06:45:20.614Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-scripts-just-rewrote-the-ot-threat-model</loc><lastmod>2026-08-22T06:43:39.381Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-won-t-breach-your-ot-complacency-will</loc><lastmod>2026-08-22T06:41:31.329Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dll-side-loading-detection-your-pre-incident-checklist</loc><lastmod>2026-08-22T06:39:32.011Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nist-tried-to-build-a-better-ai-eval-here-s-how-it-got-weaponized</loc><lastmod>2026-08-22T06:37:16.632Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dll-side-loading-is-breaking-your-edr-five-mistakes-security-teams-make</loc><lastmod>2026-08-22T06:35:50.410Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-patch-or-segment-first-mlflow-cve-2026-64849-response</loc><lastmod>2026-08-22T06:33:33.267Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-a-healthcare-breach-response-program-that-survives-legal-scrutiny</loc><lastmod>2026-08-22T06:29:31.177Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aws-breach-notification-template-for-hipaa-covered-entities</loc><lastmod>2026-08-21T06:46:22.147Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/3-8m-records-lost-in-aws-what-carecloud-s-breach-reveals-about-shared-responsibility</loc><lastmod>2026-08-21T06:43:28.903Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/the-cta-rollback-five-myths-compliance-officers-believe</loc><lastmod>2026-08-21T06:41:30.719Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/federal-agencies-issue-plc-security-checklist-after-ai-threat</loc><lastmod>2026-08-21T06:39:23.637Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-treat-ai-as-a-tool-or-a-decision-maker</loc><lastmod>2026-08-21T06:37:38.783Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/risk-based-vulnerability-management-for-non-federal-organizations</loc><lastmod>2026-08-21T06:35:25.642Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hardening-access-paths-against-raas-operators-a-30-day-playbook</loc><lastmod>2026-08-21T06:32:23.971Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/memory-dumps-or-credential-theft-your-ics-audit-priority</loc><lastmod>2026-08-21T06:29:50.481Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-cloud-breaches-hit-3-7m-records-five-controls-that-failed</loc><lastmod>2026-08-21T06:27:19.544Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ot-quantum-myths-your-board-believes</loc><lastmod>2026-08-20T06:45:43.878Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fedramp-s-poa-m-shift-an-incident-waiting-to-happen</loc><lastmod>2026-08-20T06:43:27.479Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-generated-plc-exploit-script-template-detection-and-defense-configuration</loc><lastmod>2026-08-20T06:41:38.328Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/patch-before-they-pounce-five-mistakes-slowing-your-vulnerability-response</loc><lastmod>2026-08-20T06:39:47.843Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/bacs-cybersecurity-checklist-15-steps-to-protect-your-building-control-systems</loc><lastmod>2026-08-20T06:37:56.966Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-we-patch-this-8-kev-questions-your-team-s-actually-asking</loc><lastmod>2026-08-20T06:34:28.883Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/personalized-pricing-controls-ftc-compliance-playbook</loc><lastmod>2026-08-20T06:31:37.712Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/who-s-liable-when-a-vendor-breach-hits-your-agency</loc><lastmod>2026-08-20T06:29:42.120Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/post-breach-security-overhaul-build-or-buy</loc><lastmod>2026-08-20T06:27:44.766Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/patch-to-breach-60-days-to-secure-third-party-plm</loc><lastmod>2026-08-19T06:57:45.724Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-integration-your-12-point-checklist</loc><lastmod>2026-08-19T06:55:47.584Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-prioritize-digital-or-physical-data-controls</loc><lastmod>2026-08-19T06:53:58.173Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-admt-myths-that-will-wreck-your-2027-compliance-plan</loc><lastmod>2026-08-19T06:44:26.517Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-breach-response-template</loc><lastmod>2026-08-19T06:41:54.166Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/doxo-s-2-1m-ftc-settlement-compliance-breakdown</loc><lastmod>2026-08-19T06:35:47.458Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-cloud-breaches-five-mistakes-that-put-734-000-records-at-risk</loc><lastmod>2026-08-19T06:34:02.146Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-your-company-join-a-federal-offensive-cyber-program</loc><lastmod>2026-08-19T06:31:46.981Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-reply-to-that-review-hipaa-q-a</loc><lastmod>2026-08-19T06:29:39.714Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ot-security-in-hyperscale-data-centers</loc><lastmod>2026-08-18T06:47:45.676Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/securing-data-center-ot-in-90-days</loc><lastmod>2026-08-18T06:41:47.601Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-team-onboarding-script-human-centered-questions-that-predict-burnout</loc><lastmod>2026-08-18T06:39:42.668Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/three-healthcare-breaches-three-failures-what-your-hipaa-program-is-missing</loc><lastmod>2026-08-18T06:37:45.589Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gipa-compliance-checklist-before-your-genetic-data-becomes-a-liability</loc><lastmod>2026-08-18T06:35:44.467Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/a-46m-kickback-settlement-what-the-compliance-failures-reveal</loc><lastmod>2026-08-18T06:33:40.439Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ftc-consent-decrees-cost-more-than-the-fine</loc><lastmod>2026-08-18T06:31:22.240Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-myths-that-put-patient-data-at-risk</loc><lastmod>2026-08-18T06:29:36.357Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aml-program-failures-that-cost-125-million</loc><lastmod>2026-08-18T06:28:01.329Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/social-engineering-loss-data-budget-allocation-field-guide</loc><lastmod>2026-08-17T06:49:58.411Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/you-don-t-need-a-new-identity-framework-for-ai</loc><lastmod>2026-08-17T06:46:27.086Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hospital-doors-that-won-t-lock-a-ransomware-teardown</loc><lastmod>2026-08-17T06:43:45.219Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-bet-on-mfa-or-behavioral-analytics</loc><lastmod>2026-08-17T06:41:41.022Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/continuous-identity-trust-for-healthcare-a-90-day-implementation-plan</loc><lastmod>2026-08-17T06:38:25.700Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-deepfakes-can-t-beat-your-identity-program-five-myths-financial-institutions-believe</loc><lastmod>2026-08-17T06:35:55.481Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/social-engineering-hit-85-of-cyber-losses-what-claims-data-teaches-about-ai-risk</loc><lastmod>2026-08-17T06:33:41.175Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-need-identity-governance-not-just-access-control</loc><lastmod>2026-08-17T06:31:47.410Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/continuous-identity-trust-checklist-for-federal-systems</loc><lastmod>2026-08-17T06:29:47.796Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-welcome-or-fear-the-end-of-boi-reporting</loc><lastmod>2026-08-16T07:05:43.867Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-in-your-erp-questions-security-teams-are-actually-asking</loc><lastmod>2026-08-16T06:59:44.911Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agent-runs-amok-in-your-erp-what-58-of-teams-learned-too-late</loc><lastmod>2026-08-16T06:49:46.794Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-output-audit-12-controls-before-board-review</loc><lastmod>2026-08-16T06:46:23.202Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-business-associate-mistakes-that-turn-vendor-breaches-into-hipaa-nightmares</loc><lastmod>2026-08-16T06:42:01.100Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-incident-response-for-healthcare-a-72-hour-playbook</loc><lastmod>2026-08-16T06:39:49.466Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sanctions-compliance-isn-t-just-paperwork</loc><lastmod>2026-08-16T06:37:30.839Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/you-re-solving-the-wrong-problem-after-a-breach</loc><lastmod>2026-08-16T06:35:33.870Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/post-breach-credit-monitoring-when-it-s-enough-and-when-it-isn-t</loc><lastmod>2026-08-16T06:31:59.277Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/service-account-entitlement-review-template</loc><lastmod>2026-08-15T06:45:39.875Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/board-risk-oversight-is-broken-what-internal-audit-can-do</loc><lastmod>2026-08-15T06:43:31.160Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/3-000-crypto-firms-shut-out-what-the-eu-authorization-collapse-reveals</loc><lastmod>2026-08-15T06:41:34.295Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-a-breach-proof-phi-environment-90-day-technical-hardening-plan</loc><lastmod>2026-08-15T06:39:48.618Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-breach-myths-hipaa-regulated-entities-still-believe</loc><lastmod>2026-08-15T06:37:40.237Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/singapore-s-aml-gap-isn-t-a-tech-problem</loc><lastmod>2026-08-15T06:35:33.105Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/agentic-ai-compliance-gdpr-readiness-checklist</loc><lastmod>2026-08-15T06:33:50.638Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-hipaa-compliance-gaps-that-turn-breaches-into-settlements</loc><lastmod>2026-08-15T06:30:25.078Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/3-5m-settlement-what-zoll-medical-s-breach-response-reveals-about-hipaa-defense-strategies</loc><lastmod>2026-08-15T06:27:34.642Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-compliance-officers-own-ai-governance</loc><lastmod>2026-08-14T06:43:25.274Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nvd-modernization-rfi-what-nist-s-ai-push-reveals-about-your-vulnerability-program</loc><lastmod>2026-08-14T06:41:37.093Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iam-role-automation-when-to-use-aws-role-manager-vs-manual-configuration</loc><lastmod>2026-08-14T06:39:31.160Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-notification-template-for-small-healthcare-practices</loc><lastmod>2026-08-14T06:37:56.011Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/state-sponsored-attacks-need-a-different-patch-cadence</loc><lastmod>2026-08-14T06:35:31.542Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/litigation-discovery-under-lock-and-key-air-gapped-data-handling-for-breach-cases</loc><lastmod>2026-08-14T06:33:47.853Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hospital-doors-won-t-lock-ot-security-questions-you-re-actually-asking</loc><lastmod>2026-08-14T06:31:53.126Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/alerts-go-unread-patches-never-applied-what-acro-teaches-about-accountability-gaps</loc><lastmod>2026-08-14T06:29:52.539Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-a-defensible-phi-security-program-before-the-lawsuit-arrives</loc><lastmod>2026-08-14T06:27:46.216Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fraud-controls-in-telecoms-five-myths-auditors-believe</loc><lastmod>2026-08-13T06:59:44.812Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/post-quantum-migration-it-track-or-ot-track</loc><lastmod>2026-08-13T06:45:45.764Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/interview-hesitation-patterns-that-signal-hidden-risk</loc><lastmod>2026-08-13T06:43:17.508Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-drop-disparate-impact-from-your-compliance-program</loc><lastmod>2026-08-13T06:41:24.573Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/social-engineering-incident-response-checklist</loc><lastmod>2026-08-13T06:38:42.993Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/three-kev-additions-expose-a-common-patch-management-failure</loc><lastmod>2026-08-13T06:35:32.854Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/biomarker-data-under-illinois-gipa-what-changed-and-why-it-matters</loc><lastmod>2026-08-13T06:33:36.542Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-defenses-for-healthcare-a-90-day-hardening-plan</loc><lastmod>2026-08-13T06:29:50.151Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-groups-are-weaponizing-your-social-channels</loc><lastmod>2026-08-13T06:27:43.649Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/state-youth-privacy-laws-now-cover-ages-13-18-what-changed-in-2025</loc><lastmod>2026-08-12T06:57:46.114Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-actually-fire-someone-based-on-this-data</loc><lastmod>2026-08-12T06:54:29.639Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stolen-data-in-litigation-6-mistakes-that-turn-discovery-into-a-second-breach</loc><lastmod>2026-08-12T06:50:33.781Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/readiness-checklist-non-hipaa-health-data-under-the-reform-act</loc><lastmod>2026-08-12T06:46:29.946Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/audit-your-private-cellular-networks-before-attackers-do</loc><lastmod>2026-08-12T06:43:36.973Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-litigation-dictates-your-security-controls</loc><lastmod>2026-08-12T06:42:13.111Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gunra-raas-what-a-federal-advisory-reveals-about-modern-ransomware-defense</loc><lastmod>2026-08-12T06:36:41.481Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-platforms-in-clinical-research-build-a-third-party-risk-program-that-works</loc><lastmod>2026-08-12T06:32:28.182Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fortinet-firewall-exploits-jump-12-as-gunra-pivots-to-raas</loc><lastmod>2026-08-12T06:28:34.687Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-ai-block-a-threat-without-my-approval</loc><lastmod>2026-08-09T06:40:28.145Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/automated-s3-remediation-won-t-save-you</loc><lastmod>2026-08-09T06:37:37.747Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/patching-isn-t-enough-5-mistakes-that-sabotage-federal-vulnerability-programs</loc><lastmod>2026-08-09T06:35:34.624Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/3-8m-patient-records-the-data-center-breach-that-shows-why-hipaa-s-ba-rules-exist</loc><lastmod>2026-08-09T06:33:47.619Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/3-8-million-records-what-the-unlimited-technology-systems-breach-reveals-about-third-party-risk</loc><lastmod>2026-08-09T06:31:57.070Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/audit-quality-myths-that-cost-firms-millions</loc><lastmod>2026-08-09T06:29:52.033Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-incident-sharing-won-t-fix-what-you-think-it-will</loc><lastmod>2026-08-08T07:07:39.433Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-treat-ai-identities-like-user-accounts</loc><lastmod>2026-08-08T06:45:43.973Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-identity-controls-for-ai-first-or-later</loc><lastmod>2026-08-08T06:43:43.438Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-identities-don-t-fit-your-iam-program-fix-it</loc><lastmod>2026-08-08T06:41:46.410Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-need-credentials-how-to-secure-non-human-identities</loc><lastmod>2026-08-08T06:39:48.637Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-break-your-access-review-model</loc><lastmod>2026-08-08T06:37:53.187Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/do-sboms-actually-get-used-faq-from-the-field</loc><lastmod>2026-08-08T06:34:34.028Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agent-goes-rogue-when-intent-deviation-breaks-identity-controls</loc><lastmod>2026-08-08T06:31:52.205Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/8-4m-settlement-shows-acquirers-inherit-cmmc-failures</loc><lastmod>2026-08-08T06:29:21.100Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sboms-are-compliance-theater-until-you-fix-these-five-mistakes</loc><lastmod>2026-08-07T06:46:01.237Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/apac-central-banks-build-ai-governance-ahead-of-the-curve</loc><lastmod>2026-08-07T06:43:48.857Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sbom-request-template-what-to-ask-vendors-before-you-sign</loc><lastmod>2026-08-07T06:41:44.410Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/subscriber-identity-controls-a-security-engineer-s-reference</loc><lastmod>2026-08-07T06:39:52.994Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agent-incident-response-in-30-days</loc><lastmod>2026-08-07T06:36:27.784Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sar-filing-delays-what-your-team-needs-to-know</loc><lastmod>2026-08-07T06:33:46.220Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/settling-breach-lawsuits-won-t-fix-your-controls</loc><lastmod>2026-08-07T06:31:53.856Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/mayo-clinic-whistleblower-case-when-ai-deployment-bypasses-irb-controls</loc><lastmod>2026-08-07T06:29:56.175Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ports-go-manual-what-nc-s-cyber-incident-reveals-about-ot-risk</loc><lastmod>2026-08-07T06:27:45.952Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-breaches-keep-hitting-retailers-here-s-why-you-re-still-vulnerable</loc><lastmod>2026-08-06T07:24:27.317Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/telecom-identity-security-five-myths-blocking-progress</loc><lastmod>2026-08-06T06:47:50.513Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-draw-a-tight-or-loose-fedramp-authorization-boundary</loc><lastmod>2026-08-06T06:45:39.495Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/rethinking-hipaa-risk-assessments-a-technical-challenge</loc><lastmod>2026-08-06T06:42:28.536Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-cyber-risk-programs-build-what-regulators-expect</loc><lastmod>2026-08-06T06:39:50.110Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/risk-based-aml-supervision-malta-s-enforcement-model</loc><lastmod>2026-08-06T06:37:48.561Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/air-gapping-ot-won-t-save-water-utilities</loc><lastmod>2026-08-06T06:35:43.819Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-questions-your-patch-team-is-already-asking</loc><lastmod>2026-08-06T06:32:27.169Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/bsa-compliance-myths-that-lead-to-125m-penalties</loc><lastmod>2026-08-06T06:27:51.691Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-integration-template-risk-based-patching-for-non-federal-teams</loc><lastmod>2026-08-05T07:18:33.067Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-access-gone-wrong-5-mistakes-that-led-to-abka-s-breach</loc><lastmod>2026-08-05T07:14:26.583Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hipaa-risk-assessment-checklist-beyond-ephi</loc><lastmod>2026-08-05T06:45:53.586Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pwc-s-ai-report-failures-what-broke-and-how-to-fix-it</loc><lastmod>2026-08-05T06:43:42.327Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/non-hipaa-health-data-your-90-day-compliance-build</loc><lastmod>2026-08-05T06:42:02.108Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/senate-bill-targets-wearables-and-ai-health-data</loc><lastmod>2026-08-05T06:39:43.514Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-anonymize-data-contextually-or-universally</loc><lastmod>2026-08-05T06:37:38.417Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/attributing-state-sponsored-attacks-on-water-systems</loc><lastmod>2026-08-05T06:31:50.699Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-own-cloud-security-or-trust-your-provider</loc><lastmod>2026-08-04T07:13:42.674Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-inference-footprint-audit-checklist-for-unmeasured-risk</loc><lastmod>2026-08-04T06:45:40.907Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-cloud-breaches-5-mistakes-that-cost-you-data</loc><lastmod>2026-08-04T06:42:27.693Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aws-breach-at-345-000-records-your-cloud-security-checklist</loc><lastmod>2026-08-04T06:37:57.337Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-cloud-breaches-cost-more-than-you-think</loc><lastmod>2026-08-04T06:35:31.709Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/securing-cloud-storage-in-90-days-a-ciso-s-field-manual</loc><lastmod>2026-08-04T06:33:46.989Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/bod-26-04-isn-t-mandatory-for-you-and-other-kev-myths</loc><lastmod>2026-08-04T06:31:36.644Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/public-registries-aren-t-your-security-problem</loc><lastmod>2026-08-04T06:29:34.308Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-embed-tracking-pixels-or-build-a-consent-layer-first</loc><lastmod>2026-08-04T06:27:40.352Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-in-cybersecurity-6-questions-your-board-will-ask</loc><lastmod>2026-08-03T06:45:49.245Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/firmware-patch-checklist-for-ics-environments</loc><lastmod>2026-08-03T06:43:39.518Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/privacy-officers-stuck-playing-whack-a-mole-what-hhs-got-right-in-2011</loc><lastmod>2026-08-03T06:40:30.529Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/vpn-breach-patterns-what-wyden-s-federal-purge-reveals-about-perimeter-security</loc><lastmod>2026-08-03T06:37:32.309Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/whistleblower-retaliation-six-myths-your-program-can-t-afford</loc><lastmod>2026-08-03T06:35:46.089Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sbom-minimums-just-changed-5-updates-that-affect-your-risk-program</loc><lastmod>2026-08-03T06:33:36.504Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/internal-or-external-hipaa-audit-which-should-you-run-first</loc><lastmod>2026-08-03T06:31:45.064Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/doj-self-disclosure-five-mistakes-that-cost-you-leniency</loc><lastmod>2026-08-03T06:29:39.602Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-internal-audit-report-to-the-cfo-or-the-board</loc><lastmod>2026-08-03T06:27:36.512Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/open-source-risk-assessment-with-the-c4-framework</loc><lastmod>2026-08-02T06:43:36.114Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aws-hipaa-guidance-released-what-it-reveals-about-your-cloud-safeguards</loc><lastmod>2026-08-02T06:41:21.878Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cra-compliance-five-myths-that-could-derail-your-product-strategy</loc><lastmod>2026-08-02T06:39:35.914Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/replacing-legacy-edge-devices-with-zero-trust-a-federal-implementation-roadmap</loc><lastmod>2026-08-02T06:37:42.254Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cra-compliance-does-your-product-need-a-full-reset</loc><lastmod>2026-08-02T06:35:29.346Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/federal-zero-trust-mandate-what-wyden-s-2028-deadline-means-for-your-program</loc><lastmod>2026-08-02T06:33:28.900Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-medical-billing-breaches-five-mistakes-that-cost-you-patients-and-lawsuits</loc><lastmod>2026-08-02T06:31:55.740Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/data-sharing-controls-your-pre-publication-checklist</loc><lastmod>2026-08-02T06:29:45.119Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/faq-what-the-mcbs-breach-tells-us-about-third-party-risk</loc><lastmod>2026-08-02T06:27:51.194Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-banks-protect-transaction-systems-or-identity-data-first</loc><lastmod>2026-08-01T06:43:25.928Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/locking-down-ai-platform-sharing-a-technical-playbook</loc><lastmod>2026-08-01T06:41:52.423Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/risk-functions-don-t-need-ai-tools-they-need-a-new-operating-model</loc><lastmod>2026-08-01T06:39:20.917Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/minors-privacy-compliance-tracker-template-for-multi-jurisdiction-monitoring</loc><lastmod>2026-08-01T06:37:40.860Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/minnesota-water-attacks-expose-ot-security-gaps</loc><lastmod>2026-08-01T06:35:36.917Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/waiting-for-cisa-won-t-fix-your-ot-security-problem</loc><lastmod>2026-08-01T06:33:39.967Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-iam-failures-that-let-attackers-walk-through-the-front-door</loc><lastmod>2026-08-01T06:32:00.198Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sc-age-design-code-audit-checklist-for-july-1-deadline</loc><lastmod>2026-08-01T06:30:03.385Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/securing-water-utility-ot-remove-internet-exposed-plcs-in-72-hours</loc><lastmod>2026-08-01T06:27:35.040Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-an-ot-incident-response-plan-or-retrofit-your-it-plan</loc><lastmod>2026-07-31T06:49:54.767Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/what-actually-happens-during-a-hipaa-investigation</loc><lastmod>2026-07-31T06:47:43.964Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/api-privileges-outlive-user-permissions-mikrotik-session-flaw</loc><lastmod>2026-07-31T06:45:59.974Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/incident-response-runbook-data-extortion-without-encryption</loc><lastmod>2026-07-31T06:42:33.549Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/your-subscription-compliance-program-is-solving-the-wrong-problem</loc><lastmod>2026-07-31T06:39:35.181Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/plcs-exposed-to-the-internet-a-security-audit-checklist</loc><lastmod>2026-07-31T06:37:48.474Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/supreme-court-rulings-don-t-rewrite-your-compliance-program</loc><lastmod>2026-07-31T06:35:47.189Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/incident-response-failures-that-turn-breaches-into-disasters</loc><lastmod>2026-07-31T06:32:23.530Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/552-250-penalty-what-osf-healthcare-s-risk-analysis-failures-teach-internal-auditors</loc><lastmod>2026-07-31T06:29:40.712Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ot-incident-response-8-questions-teams-ask-after-a-water-system-attack</loc><lastmod>2026-07-30T06:46:26.210Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dpdp-act-compliance-for-u-s-financial-firms-90-day-playbook</loc><lastmod>2026-07-30T06:44:00.722Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/waiting-for-the-attorney-general-won-t-save-you</loc><lastmod>2026-07-30T06:41:33.674Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hims-hers-ftc-complaint-privacy-promises-vs-tracking-pixels</loc><lastmod>2026-07-30T06:39:37.035Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/data-breach-costs-hit-4-96m-four-security-gaps-you-can-t-ignore</loc><lastmod>2026-07-30T06:37:38.423Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-follow-cisa-s-kev-catalog-if-you-re-not-a-federal-agency</loc><lastmod>2026-07-30T06:35:46.287Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-incident-contain-or-negotiate</loc><lastmod>2026-07-30T06:32:22.697Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/website-tracking-consent-script-for-patient-portals</loc><lastmod>2026-07-30T06:29:38.913Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/telehealth-privacy-myths-that-lead-to-ftc-action</loc><lastmod>2026-07-30T06:27:44.452Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/operationalizing-cisa-s-kev-catalog-a-step-by-step-patch-prioritization-workflow</loc><lastmod>2026-07-29T06:47:46.040Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/banks-still-treat-identity-data-like-a-second-class-asset</loc><lastmod>2026-07-29T06:44:25.538Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/edpb-anonymisation-assessment-your-12-point-compliance-checklist</loc><lastmod>2026-07-29T06:41:56.033Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-settle-or-fight-the-dpa-calculation-every-compliance-team-faces</loc><lastmod>2026-07-29T06:39:40.202Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stop-treating-rate-limiting-like-a-checkbox</loc><lastmod>2026-07-29T06:37:39.699Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-isolate-now-or-wait-critical-infrastructure-segmentation</loc><lastmod>2026-07-29T06:35:52.553Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breaches-5-myths-blocking-better-defense</loc><lastmod>2026-07-29T06:33:55.732Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/unpatchable-vulnerabilities-managing-legacy-systems-when-software-fixes-aren-t-an-option</loc><lastmod>2026-07-29T06:31:41.820Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/email-compromise-still-breaks-banks</loc><lastmod>2026-07-29T06:28:24.953Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-privilege-enforcement-the-containment-checklist</loc><lastmod>2026-07-28T06:39:46.534Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-containment-is-broken-new-data-on-the-72-minute-window</loc><lastmod>2026-07-28T06:37:36.759Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fcc-oig-s-cross-program-risk-model-a-funding-recipient-s-reckoning</loc><lastmod>2026-07-28T06:35:28.355Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/four-breaches-one-pattern-faq-on-detection-lags</loc><lastmod>2026-07-28T06:33:46.018Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/mcbs-breach-3-tb-stolen-in-72-hours</loc><lastmod>2026-07-28T06:31:41.479Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/incident-or-plan-routing-your-cyber-reporting</loc><lastmod>2026-07-28T06:29:34.072Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-governments-hide-behind-borders-when-they-hack</loc><lastmod>2026-07-28T06:27:33.069Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-ways-teams-break-federated-learning-privacy</loc><lastmod>2026-07-27T07:01:53.333Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/deploying-nist-csf-2-0-in-non-english-markets-a-translation-first-implementation-guide</loc><lastmod>2026-07-27T06:58:01.159Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/skills-based-hiring-audit-nice-framework-1-0-0-implementation</loc><lastmod>2026-07-27T06:41:35.386Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/mdl-integration-for-cip-kyc-reference-architecture-for-financial-institutions</loc><lastmod>2026-07-27T06:39:59.359Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-actually-use-csf-2-0-across-borders</loc><lastmod>2026-07-27T06:37:34.445Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/differential-privacy-in-federated-learning-four-findings-that-change-your-risk-calculus</loc><lastmod>2026-07-27T06:35:21.858Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/privacy-first-security-awareness-template-scripts-that-work</loc><lastmod>2026-07-27T06:34:01.460Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-vdc-integration-mistakes-that-will-cost-you-credibility</loc><lastmod>2026-07-27T06:28:22.809Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/shadow-ai-myths-that-ll-cost-you-an-sec-filing</loc><lastmod>2026-07-26T06:45:31.296Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-enhanced-sase-readiness-12-point-implementation-checklist</loc><lastmod>2026-07-26T06:43:34.364Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/blind-spots-kill-compliance-programs</loc><lastmod>2026-07-26T06:41:41.397Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iot-product-security-implementing-nist-ir-8259-before-the-revision-drops</loc><lastmod>2026-07-26T06:39:34.660Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cisa-2015-extension-clears-house-216-212</loc><lastmod>2026-07-26T06:37:27.379Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cisa-sharing-law-extension-your-questions-answered</loc><lastmod>2026-07-26T06:35:36.716Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-data-breach-response-kit-template-and-checklist</loc><lastmod>2026-07-26T06:33:45.715Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/post-breach-encryption-monitoring-or-segmentation-first</loc><lastmod>2026-07-26T06:31:49.319Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/brazil-s-anpd-just-grew-teeth-six-mistakes-that-will-cost-you</loc><lastmod>2026-07-26T06:28:24.190Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/map-pci-dss-to-nist-csf-or-keep-them-separate</loc><lastmod>2026-07-25T06:57:29.143Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/independent-investigations-when-to-bring-in-outside-counsel</loc><lastmod>2026-07-25T06:45:44.690Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/insider-threat-detection-build-a-monitoring-program-that-actually-works</loc><lastmod>2026-07-25T06:43:35.539Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/exposed-plcs-your-audit-checklist</loc><lastmod>2026-07-25T06:39:34.363Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/exposed-plcs-five-myths-blocking-real-protection</loc><lastmod>2026-07-25T06:37:40.779Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pick-your-state-privacy-compliance-model</loc><lastmod>2026-07-25T06:35:42.492Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-scraping-missteps-that-turn-ai-projects-into-gdpr-liabilities</loc><lastmod>2026-07-25T06:33:35.336Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sanctions-screening-what-your-team-actually-asks</loc><lastmod>2026-07-25T06:31:40.519Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-outsource-breach-response-or-build-in-house</loc><lastmod>2026-07-25T06:29:28.496Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/which-framework-fits-your-energy-sector-breach-response</loc><lastmod>2026-07-24T06:59:38.485Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hardening-internet-facing-plcs-a-step-by-step-defense-plan</loc><lastmod>2026-07-24T06:45:52.387Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/two-kev-additions-show-why-federal-vulnerability-rules-should-apply-to-your-team</loc><lastmod>2026-07-24T06:43:35.471Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-won-t-fix-your-cyber-defense-unless-you-bust-these-myths-first</loc><lastmod>2026-07-24T06:41:48.315Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cisa-2015-reauthorization-stalled-what-your-threat-intel-program-needs-now</loc><lastmod>2026-07-24T06:38:32.220Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/incentive-risk-assessment-template-for-compliance-officers</loc><lastmod>2026-07-24T06:35:52.338Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-data-breach-readiness-14-point-checklist</loc><lastmod>2026-07-24T06:33:42.662Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-15-million-records-leak-what-your-ir-team-asks-first</loc><lastmod>2026-07-24T06:31:51.725Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/phishing-breach-detection-a-476-day-gap-field-guide</loc><lastmod>2026-07-24T06:29:49.854Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/four-cves-one-directive-what-cisa-s-latest-kev-update-reveals-about-vulnerability-triage</loc><lastmod>2026-07-23T06:55:35.383Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cmmc-scoping-for-service-providers-a-decision-framework</loc><lastmod>2026-07-23T06:44:23.334Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-won-t-save-you-six-myths-about-us-privacy-compliance</loc><lastmod>2026-07-23T06:41:59.527Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/patch-now-or-mitigate-first-what-the-siemens-iam-flaw-tells-you-about-ics-vulnerability-response</loc><lastmod>2026-07-23T06:37:27.408Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/jwt-bypass-in-factorytalk-what-changed-in-ics-authentication</loc><lastmod>2026-07-23T06:35:39.870Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-centralize-or-distribute-your-sanctions-compliance-program</loc><lastmod>2026-07-23T06:33:52.337Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-services-group-breach-3m-settlement-reveals-four-critical-control-gaps</loc><lastmod>2026-07-23T06:31:41.716Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-actually-stop-healthcare-breaches</loc><lastmod>2026-07-23T06:29:44.996Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-breach-response-what-23andme-s-2-4m-fine-teaches-security-teams</loc><lastmod>2026-07-23T06:27:38.284Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/shadow-ai-response-build-your-incident-plan-before-discovery</loc><lastmod>2026-07-22T07:01:57.515Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/lab-breach-faq-what-542k-records-teach-dpos</loc><lastmod>2026-07-22T06:59:43.908Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gpc-compliance-checklist-test-your-opt-out-system</loc><lastmod>2026-07-22T06:45:35.290Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-breached-hugging-face-what-your-ir-plan-misses</loc><lastmod>2026-07-22T06:41:43.281Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-your-forensics-team-use-open-weight-ai-models</loc><lastmod>2026-07-22T06:39:37.252Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/romania-s-land-registry-attack-a-vulnerability-management-failure</loc><lastmod>2026-07-22T06:37:45.869Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hhs-2026-agenda-your-hipaa-and-health-it-readiness-checklist</loc><lastmod>2026-07-22T06:34:29.130Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/mfa-wouldn-t-have-saved-23andme</loc><lastmod>2026-07-22T06:29:32.285Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/4m-ransomware-settlement-what-apollomd-s-breach-teaches-cisos</loc><lastmod>2026-07-22T06:27:42.100Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/federated-learning-myths-that-put-your-model-at-risk</loc><lastmod>2026-07-21T06:45:33.850Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/federated-learning-across-borders-a-privacy-engineer-s-implementation-guide</loc><lastmod>2026-07-21T06:43:50.039Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-risk-questions-your-framework-team-is-already-asking</loc><lastmod>2026-07-21T06:41:48.083Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nist-ir-8259-revision-why-risk-assessment-came-first-this-time</loc><lastmod>2026-07-21T06:39:37.384Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pci-pts-hsm-v5-0-rfc-your-review-checklist</loc><lastmod>2026-07-21T06:36:24.825Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/mpoc-vendor-verification-checklist-what-to-audit-before-your-lab-submission</loc><lastmod>2026-07-21T06:33:34.605Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/two-credential-standards-one-verification-problem</loc><lastmod>2026-07-21T06:31:35.089Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-your-rfc-response-a-field-guide-to-shaping-pci-kmo-v1-0</loc><lastmod>2026-07-21T06:29:29.381Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/which-iot-security-framework-fits-your-environment</loc><lastmod>2026-07-21T06:27:38.450Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ids-deployment-what-security-engineers-actually-need-to-know</loc><lastmod>2026-07-20T15:04:33.217Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-processors-don-t-make-you-pci-compliant</loc><lastmod>2026-07-20T06:43:37.810Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-mistakes-auditors-make-during-card-production-reviews</loc><lastmod>2026-07-20T06:41:52.466Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-risk-in-your-csf-what-nist-s-draft-profile-means-for-you</loc><lastmod>2026-07-20T06:39:46.717Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pci-dss-and-soc-2-six-myths-that-cost-you-time</loc><lastmod>2026-07-20T06:37:42.997Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/south-africa-s-ai-policy-reveals-what-sector-regulators-will-ask</loc><lastmod>2026-07-20T06:35:37.426Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-collect-that-data-a-privacy-decision-tree-for-loyalty-programs</loc><lastmod>2026-07-20T06:33:39.543Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/credential-issuance-standards-what-to-check-before-you-trust-an-mdl</loc><lastmod>2026-07-20T06:31:43.687Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-your-ciso-be-the-cmmc-affirming-official</loc><lastmod>2026-07-20T06:29:36.066Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/crypto-compliance-tracker-template-for-monitoring-cross-border-regulatory-changes</loc><lastmod>2026-07-20T06:27:31.764Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agent-malware-hits-36-what-failed-and-what-to-fix</loc><lastmod>2026-07-19T06:45:32.340Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-in-your-supply-chain-are-breaking-your-defenses</loc><lastmod>2026-07-19T06:43:31.117Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/privacy-regulation-myths-that-keep-your-ai-risk-unmanaged</loc><lastmod>2026-07-19T06:41:30.105Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ace-hardware-s-5-000-consent-banner-became-a-ucl-liability</loc><lastmod>2026-07-19T06:39:19.923Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/why-isn-t-your-sandbox-patched-yet</loc><lastmod>2026-07-19T06:37:32.207Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/network-adjacent-device-patching-a-fortisandbox-field-guide</loc><lastmod>2026-07-19T06:35:32.695Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/vpn-compromise-and-ransomware-two-breaches-show-where-healthcare-security-breaks</loc><lastmod>2026-07-19T06:33:33.287Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-your-dpa-share-what-it-knows-the-missing-link-in-gdpr-enforcement</loc><lastmod>2026-07-19T06:30:21.727Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-you-seize-emails-without-a-warrant-cjeu-says-yes</loc><lastmod>2026-07-19T06:27:34.360Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-integration-your-risk-based-patching-checklist</loc><lastmod>2026-07-18T06:51:34.684Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-ai-agent-iam-mistakes-that-erase-your-audit-trail</loc><lastmod>2026-07-18T06:43:36.981Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/1-8m-records-lost-what-summit-pathology-s-breach-reveals-about-clia-s-cyber-gaps</loc><lastmod>2026-07-18T06:41:33.873Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-economics-five-myths-blocking-your-recovery-plan</loc><lastmod>2026-07-18T06:39:50.975Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-notifications-what-teams-actually-ask-after-an-incident</loc><lastmod>2026-07-18T06:37:42.571Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/critical-infrastructure-defense-against-organized-cybercrime-groups</loc><lastmod>2026-07-18T06:35:34.977Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/clia-modernization-preparing-your-clinical-lab-for-ai-and-cyber-requirements</loc><lastmod>2026-07-18T06:32:01.277Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/vision-care-breaches-what-525-000-in-settlements-reveals-about-hipaa-technical-safeguards</loc><lastmod>2026-07-18T06:29:30.561Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/age-assurance-policy-template-moving-beyond-inference-models</loc><lastmod>2026-07-18T06:27:52.500Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-run-your-own-cvd-program-or-route-through-cisa</loc><lastmod>2026-07-17T06:47:39.735Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/export-controls-to-china-six-mistakes-that-invite-enforcement</loc><lastmod>2026-07-17T06:45:37.139Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-in-healthcare-your-data-governance-checklist</loc><lastmod>2026-07-17T06:43:50.639Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-in-healthcare-data-governance-what-your-team-s-actually-asking</loc><lastmod>2026-07-17T06:40:31.887Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cisa-kev-catalog-the-field-guide-your-vulnerability-management-program-needs</loc><lastmod>2026-07-17T06:35:44.242Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-board-governance-becomes-a-compliance-liability</loc><lastmod>2026-07-17T06:33:47.853Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breach-costs-hit-5-000-per-patient</loc><lastmod>2026-07-17T06:31:43.655Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-a-72-hour-breach-detection-program-that-actually-works</loc><lastmod>2026-07-17T06:29:42.570Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-myths-about-genetic-data-protection-that-cost-23andme-18-million</loc><lastmod>2026-07-17T06:27:51.649Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cmmc-enclave-scoping-template-define-your-boundaries-before-you-pay</loc><lastmod>2026-07-16T06:59:37.529Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/build-your-cryptographic-asset-inventory-before-march-2027</loc><lastmod>2026-07-16T06:57:34.823Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-in-your-secure-software-lifecycle-choose-your-compliance-path</loc><lastmod>2026-07-16T06:46:30.168Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-router-hardening-mistakes-that-let-nation-state-actors-in</loc><lastmod>2026-07-16T06:43:42.435Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/russian-fsb-hackers-exploited-cisco-smart-install-a-network-hardening-failure</loc><lastmod>2026-07-16T06:41:29.784Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stop-deleting-keys-based-on-last-use-timestamps</loc><lastmod>2026-07-16T06:37:26.757Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cbom-readiness-what-to-inventory-before-federal-guidance-arrives</loc><lastmod>2026-07-16T06:33:51.429Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-we-start-fedramp-20x-or-finish-rev5</loc><lastmod>2026-07-16T06:30:34.714Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hacking-drives-88-5-of-healthcare-breaches-audit-priorities</loc><lastmod>2026-07-16T06:27:22.754Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-access-build-a-control-framework-that-works</loc><lastmod>2026-07-15T06:45:50.786Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-remediation-script-automate-your-cisa-vulnerability-response</loc><lastmod>2026-07-15T06:43:44.431Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sharepoint-patching-isn-t-enough-5-myths-about-server-hardening</loc><lastmod>2026-07-15T06:41:40.816Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/phishing-to-settlement-a-field-guide-to-post-breach-response</loc><lastmod>2026-07-15T06:39:45.670Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/missing-authentication-in-ics-patch-segment-or-retire</loc><lastmod>2026-07-15T06:37:39.699Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cookie-banner-complaints-what-the-edpb-vrt-decision-means-for-your-dpa-strategy</loc><lastmod>2026-07-15T06:35:43.647Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/accelerated-rulemaking-five-compliance-traps-to-avoid</loc><lastmod>2026-07-15T06:32:27.940Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/vastaamo-breach-how-33-000-patient-records-led-to-finland-s-largest-criminal-case</loc><lastmod>2026-07-15T06:29:41.252Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/defense-contractors-your-cmmc-compliance-playbook-after-the-phase-ii-suspension</loc><lastmod>2026-07-15T06:27:50.253Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/scoping-your-esp-boundary-a-cmmc-checklist-for-msps</loc><lastmod>2026-07-14T06:43:52.895Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nist-s-new-triage-model-one-team-s-shift-from-federal-scores-to-risk-ownership</loc><lastmod>2026-07-14T06:41:30.677Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/passkey-enrollment-script-for-microsoft-entra-id</loc><lastmod>2026-07-14T06:39:49.713Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/coordinated-cyber-sanctions-what-security-engineers-need-to-know</loc><lastmod>2026-07-14T06:37:37.762Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-we-care-about-cisa-s-kev-catalog</loc><lastmod>2026-07-14T06:35:42.297Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-hire-external-forensics-for-every-breach</loc><lastmod>2026-07-14T06:33:37.010Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/router-configs-that-get-you-breached-5-fixes</loc><lastmod>2026-07-14T06:31:52.834Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-enforcement-gaps-what-regulators-won-t-tell-you</loc><lastmod>2026-07-14T06:29:31.509Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/eurodac-supervision-shifts-to-csc-what-it-reveals-about-multinational-data-governance</loc><lastmod>2026-07-13T06:45:27.763Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/don-t-treat-data-as-property-a-privacy-officer-s-audit</loc><lastmod>2026-07-13T06:43:46.572Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iso-iec-27001-clause-structure-a-security-engineer-s-field-guide</loc><lastmod>2026-07-13T06:40:30.239Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aws-egress-control-template-block-unauthorized-data-flows</loc><lastmod>2026-07-13T06:37:40.299Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nist-s-iot-guidance-pivot-from-policy-to-practice</loc><lastmod>2026-07-13T06:35:40.426Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-extensions-see-my-keystrokes-8-questions-about-ai-themed-browser-threats</loc><lastmod>2026-07-13T06:33:58.680Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iam-hardening-for-state-level-threats-a-security-engineer-s-playbook</loc><lastmod>2026-07-13T06:31:50.246Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/rotating-your-cryptographic-keys-won-t-save-you</loc><lastmod>2026-07-13T06:29:23.309Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/digital-credentials-5-mistakes-that-stall-your-implementation</loc><lastmod>2026-07-13T06:27:54.942Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/crypto-agility-in-a-quantum-threat-window</loc><lastmod>2026-07-12T06:43:59.368Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/soc-2-audits-now-take-half-the-time-what-zero-trust-teams-report</loc><lastmod>2026-07-12T06:41:34.694Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ftc-policy-statement-teardown-when-ai-accuracy-claims-meet-section-5</loc><lastmod>2026-07-12T06:39:27.254Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pqc-migration-myths-that-will-derail-your-program</loc><lastmod>2026-07-12T06:37:26.515Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pqc-migration-at-scale-120-000-tasks-and-what-they-teach-about-scope</loc><lastmod>2026-07-12T06:35:23.843Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/security-risk-analysis-template-for-small-healthcare-practices</loc><lastmod>2026-07-12T06:33:35.622Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-compliance-governance-your-readiness-checklist</loc><lastmod>2026-07-12T06:31:27.892Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/manual-operations-won-t-save-your-water-utility</loc><lastmod>2026-07-12T06:29:21.655Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/water-utilities-fail-the-offline-test</loc><lastmod>2026-07-12T06:27:35.506Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/csam-scanning-rules-5-myths-compliance-teams-believe</loc><lastmod>2026-07-11T07:07:30.089Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aws-oversight-and-third-party-risk-mistakes-that-cost-financial-firms</loc><lastmod>2026-07-11T06:57:43.914Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/social-engineering-defense-build-controls-before-the-call-comes</loc><lastmod>2026-07-11T06:43:35.940Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-your-aml-tool-or-buy-one</loc><lastmod>2026-07-11T06:41:24.127Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/irish-ncsc-shows-what-board-cyber-oversight-actually-means</loc><lastmod>2026-07-11T06:39:32.668Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/email-breach-response-checklist-first-72-hours</loc><lastmod>2026-07-11T06:37:40.449Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/insider-threat-audit-third-party-negotiators</loc><lastmod>2026-07-11T06:35:48.875Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/two-file-upload-flaws-join-cisa-s-kev-what-your-patch-process-misses</loc><lastmod>2026-07-11T06:33:38.725Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sanctions-screening-in-house-or-third-party</loc><lastmod>2026-07-11T06:31:42.059Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/anchor-ci-myths-what-risk-managers-get-wrong-about-liability</loc><lastmod>2026-07-10T06:53:56.234Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nis2-fines-are-here-5-mistakes-that-got-countries-sued</loc><lastmod>2026-07-10T06:41:52.978Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/nis2-and-dora-what-the-court-referrals-mean-for-your-program</loc><lastmod>2026-07-10T06:39:58.582Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-data-breach-response-the-180-day-field-guide</loc><lastmod>2026-07-10T06:38:02.053Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ransomware-settlement-549-000-and-seven-months-too-late</loc><lastmod>2026-07-10T06:35:48.154Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/rentgrow-pays-2-25m-where-accuracy-controls-broke-down</loc><lastmod>2026-07-10T06:33:42.198Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/penalties-won-t-fix-nis2-transposition-delays</loc><lastmod>2026-07-10T06:31:45.988Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-response-myths-that-put-your-clients-at-risk</loc><lastmod>2026-07-10T06:29:51.551Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-ai-compliance-mistakes-your-audit-program-isn-t-catching</loc><lastmod>2026-07-10T06:28:00.736Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/enforcement-volatility-after-trump-v-slaughter</loc><lastmod>2026-07-09T06:57:59.973Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-your-hotline-promises-protection-the-law-won-t-deliver</loc><lastmod>2026-07-09T06:43:31.239Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/26-of-firms-have-ai-governance-in-place-your-audit-checklist</loc><lastmod>2026-07-09T06:41:55.028Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pqc-migration-timelines-what-12-nations-reveal-about-your-risk</loc><lastmod>2026-07-09T06:39:34.895Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-steer-ai-outputs-for-state-law-compliance</loc><lastmod>2026-07-09T06:37:39.529Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/firmware-backdoor-response-a-network-security-playbook</loc><lastmod>2026-07-09T06:35:52.034Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hipaa-security-rule-myths-that-ll-cost-you-in-2027</loc><lastmod>2026-07-09T06:31:54.488Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/web-scraping-for-ai-training-what-went-wrong</loc><lastmod>2026-07-09T06:29:46.449Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cash-app-paid-45m-what-your-fintech-needs-to-learn</loc><lastmod>2026-07-09T06:27:59.365Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fci-or-cui-copy-this-classification-script-before-your-next-dod-bid</loc><lastmod>2026-07-08T19:21:49.631Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/who-answers-to-ocr-when-hipaa-fails</loc><lastmod>2026-07-08T19:19:51.503Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/forcing-zero-retention-doesn-t-mean-zero-risk</loc><lastmod>2026-07-08T19:17:35.708Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-block-shadow-it-or-build-around-it</loc><lastmod>2026-07-08T19:15:54.724Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dod-privacy-training-rule-build-your-program-before-the-comment-period-ends</loc><lastmod>2026-07-08T19:12:27.243Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/piv-card-deployment-without-the-vendor-lock-in</loc><lastmod>2026-07-08T19:08:39.176Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-ai-exploit-a-cve-before-we-patch-it</loc><lastmod>2026-07-08T19:04:31.844Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cyber-shield-exposes-three-failures-that-led-to-uk-s-2026-breach-wave</loc><lastmod>2026-07-08T19:01:53.559Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-driven-defense-readiness-uk-cyber-shield-checklist</loc><lastmod>2026-07-08T18:59:48.657Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-agents-don-t-need-your-permission-to-start</loc><lastmod>2026-07-08T18:57:43.983Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/shadow-ai-or-sanctioned-agent-your-control-framework-decision</loc><lastmod>2026-07-08T18:55:42.235Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/securing-cloud-based-home-care-a-privacy-officer-s-deployment-guide</loc><lastmod>2026-07-08T18:53:43.143Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/most-shadow-it-controls-miss-the-point-entirely</loc><lastmod>2026-07-08T18:51:35.202Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-ai-integration-mistakes-that-expose-your-risk-program</loc><lastmod>2026-07-08T18:49:42.892Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/iot-device-breach-what-happens-when-lifecycle-security-fails</loc><lastmod>2026-07-08T18:47:30.661Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/can-we-just-map-ai-controls-to-800-53-and-call-it-done</loc><lastmod>2026-07-08T18:43:58.247Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/choosing-your-nist-800-63-4-implementation-path</loc><lastmod>2026-07-08T18:41:57.630Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cedar-policies-stop-multi-agent-privilege-creep</loc><lastmod>2026-07-08T18:39:01.874Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/eu-sustainability-rules-just-got-simpler-what-changed-and-what-you-do-next</loc><lastmod>2026-07-08T18:38:57.832Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cve-response-windows-are-closing-four-shifts-your-team-must-make</loc><lastmod>2026-07-08T18:38:41.667Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pci-secure-software-v2-0-five-myths-blocking-your-transition</loc><lastmod>2026-07-08T17:53:44.546Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/non-us-llc-beneficial-ownership-disclosure-template-for-new-york</loc><lastmod>2026-07-08T17:51:52.480Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-image-processing-under-gdpr-your-15-point-readiness-checklist</loc><lastmod>2026-07-08T17:49:58.565Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fca-s-cryptoasset-gateway-what-happens-if-you-miss-september-2026</loc><lastmod>2026-07-08T17:47:32.119Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/which-data-broker-path-applies-to-you-under-drop</loc><lastmod>2026-07-08T17:45:44.102Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stop-auditing-your-privacy-notice-every-quarter</loc><lastmod>2026-07-08T17:43:25.701Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-cyber-failures-that-cost-fiig-securities-aud-2-5-million</loc><lastmod>2026-07-08T17:40:36.910Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/public-procurement-compliance-template-for-spain-s-draft-integrity-law</loc><lastmod>2026-07-08T17:37:53.172Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/circia-and-cisa-2015-your-reporting-strategy-reference</loc><lastmod>2026-07-08T17:36:00.081Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-eu-law-overrides-national-rules-your-faq</loc><lastmod>2026-07-08T17:33:54.721Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/when-the-bartender-knows-your-address-utah-s-sb-275-breakdown</loc><lastmod>2026-07-08T17:31:42.378Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fedramp-cr26-readiness-your-pre-certification-checklist</loc><lastmod>2026-07-08T17:29:56.775Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/reg-s-p-myths-that-ll-cost-you-in-2026</loc><lastmod>2026-07-08T17:27:51.615Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gsa-cui-compliance-your-90-day-implementation-plan</loc><lastmod>2026-07-08T17:26:02.952Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/uk-data-complaints-regime-five-mistakes-you-ll-make-before-june-2026</loc><lastmod>2026-07-08T17:25:55.818Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/state-privacy-laws-five-myths-blocking-your-program</loc><lastmod>2026-07-08T16:36:38.915Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/audit-patient-portal-trackers-before-the-lawsuit-finds-you</loc><lastmod>2026-07-08T16:16:35.363Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-scientific-research-notice-template</loc><lastmod>2026-07-08T16:12:29.387Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hsm-cloud-migration-gone-wrong-lessons-from-pci-pts-5-0</loc><lastmod>2026-07-08T16:09:33.601Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dfs-frontier-ai-guidance-under-part-500</loc><lastmod>2026-07-08T16:06:38.012Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/stakeholder-input-prep-for-circia-town-halls</loc><lastmod>2026-07-08T16:03:57.316Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/risk-analysis-doesn-t-prevent-ransomware-attacks</loc><lastmod>2026-07-08T16:01:36.309Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pci-dss-v4-0-1-rfc-a-security-engineer-s-submission-guide</loc><lastmod>2026-07-08T15:59:38.882Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gps-in-company-cars-what-120k-fine-teaches-about-employee-monitoring</loc><lastmod>2026-07-08T15:57:41.764Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/don-t-lock-ex-employees-out-of-their-inboxes</loc><lastmod>2026-07-08T15:55:33.470Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-breach-notifications-six-errors-that-delay-your-72-hour-clock</loc><lastmod>2026-07-08T15:53:59.957Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/pci-dss-compliance-build-your-control-choice-framework</loc><lastmod>2026-07-08T15:51:50.330Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/acd-penalty-structures-now-live-in-27-jurisdictions</loc><lastmod>2026-07-08T15:49:46.118Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/kev-catalog-adoption-without-federal-mandates</loc><lastmod>2026-07-08T15:47:49.917Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/buffer-overflow-in-industrial-control-systems-a-field-guide-for-energy-sector-security-teams</loc><lastmod>2026-07-08T15:46:01.193Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-dependencies-don-t-excuse-http-in-2026</loc><lastmod>2026-07-08T15:43:46.695Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/critical-infrastructure-gaps-two-digi-cves-expose</loc><lastmod>2026-07-08T15:41:44.084Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/web-tracker-consent-script-for-patient-portals</loc><lastmod>2026-07-08T15:36:30.479Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/which-pci-dss-audit-path-applies-to-your-business</loc><lastmod>2026-07-08T15:36:21.699Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/hr-questionnaires-and-gdpr-five-myths</loc><lastmod>2026-07-08T15:36:12.476Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-notification-timelines-when-investigation-meets-obligation</loc><lastmod>2026-07-08T15:36:02.064Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/six-myths-about-third-party-breaches-that-settlements-disprove</loc><lastmod>2026-07-08T14:33:53.173Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/breach-costs-up-80-since-2019-what-changed</loc><lastmod>2026-07-08T14:31:46.603Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/geofence-warrants-five-costly-missteps</loc><lastmod>2026-07-08T14:28:36.168Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/aml-information-sharing-under-gdpr-what-art-75-means-for-your-program</loc><lastmod>2026-07-08T14:25:47.990Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/eu-ai-act-delays-won-t-save-you-later</loc><lastmod>2026-07-08T14:23:41.333Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-threat-window-90-day-security-upgrade-plan</loc><lastmod>2026-07-08T14:20:28.523Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/research-sites-are-just-processors-right</loc><lastmod>2026-07-08T14:17:34.171Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-hire-legal-or-technical-expertise-first</loc><lastmod>2026-07-08T14:14:32.747Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/building-a-gdpr-compliant-data-repurposing-program</loc><lastmod>2026-07-08T14:10:27.459Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-assessments-won-t-stop-breaches</loc><lastmod>2026-07-08T14:07:48.952Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/state-health-data-laws-vermont-field-guide</loc><lastmod>2026-07-08T14:06:23.246Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-eyes-ai-alert-what-to-add-to-your-framework</loc><lastmod>2026-07-08T14:05:54.390Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/data-breach-response-checklist-for-healthcare</loc><lastmod>2026-07-08T14:05:25.097Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-patch-every-kev-vulnerability</loc><lastmod>2026-07-08T06:41:42.861Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/five-genetic-privacy-mistakes-that-trigger-ag-enforcement</loc><lastmod>2026-07-08T00:29:45.830Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ftc-independence-ends-what-the-slaughter-decision-means-for-enforcement</loc><lastmod>2026-07-08T00:21:28.466Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/gdpr-consistency-myths-compliance-teams-believe</loc><lastmod>2026-07-08T00:03:41.364Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/multi-state-privacy-compliance-without-burning-out-your-team</loc><lastmod>2026-07-07T23:59:45.645Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/sar-automation-won-t-save-you</loc><lastmod>2026-07-07T23:55:34.082Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/genesis-tech-takedown-subscription-fraud-at-scale</loc><lastmod>2026-07-07T23:39:30.910Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/article-50-disclosure-template-for-ai-systems</loc><lastmod>2026-07-07T23:25:39.583Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dpas-issued-hundreds-of-right-to-object-decisions</loc><lastmod>2026-07-07T23:21:37.298Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/fedramp-20x-implementation-field-guide</loc><lastmod>2026-07-07T23:19:30.010Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/penalties-won-t-fix-your-aml-controls</loc><lastmod>2026-07-07T23:13:46.048Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-risk-in-healthcare-a-field-guide</loc><lastmod>2026-07-07T23:01:48.445Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/should-you-build-609-e-compliance-before-you-need-it</loc><lastmod>2026-07-07T22:57:44.845Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/most-compliance-teams-are-auditing-the-wrong-screen</loc><lastmod>2026-07-07T22:57:24.290Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/ai-ransomware-runs-itself-defense-playbook</loc><lastmod>2026-07-07T21:11:30.782Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/cftc-whistleblower-rule-changes-what-to-prioritize-now</loc><lastmod>2026-07-07T21:09:22.531Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-data-breach-prevention-checklist</loc><lastmod>2026-07-07T21:05:44.188Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/dpf-contingency-plan-template-when-your-transfer-mechanism-fails</loc><lastmod>2026-07-07T20:59:52.755Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/healthcare-breaches-keep-happening-stop-believing-these-six-myths</loc><lastmod>2026-07-07T20:57:37.472Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/anssi-just-changed-the-crypto-timeline-what-does-2027-mean-for-you</loc><lastmod>2026-07-07T20:25:55.657Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/legacy-systems-under-siege-hardening-inter-agency-networks</loc><lastmod>2026-07-07T20:17:48.650Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/vendor-risk-myths-that-lead-to-data-breaches</loc><lastmod>2026-07-07T20:11:37.433Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/third-party-vendor-access-policy-template</loc><lastmod>2026-07-07T20:09:44.744Z</lastmod></url>
  <url><loc>https://compliancebureau.org/blog/legacy-platform-security-after-the-hsin-breach</loc><lastmod>2026-07-07T20:05:58.773Z</lastmod></url>
  <url><loc>https://compliancebureau.org/vendors</loc><lastmod>2026-01-18T17:17:41.172Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/about</loc><lastmod>2026-08-31T16:23:13.935Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/privacy</loc><lastmod>2026-08-31T16:23:13.935Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/terms-and-conditions</loc><lastmod>2026-07-03T13:03:13.118Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/submit-vendor</loc><lastmod>2026-07-03T13:03:13.116Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/cookies</loc><lastmod>2026-07-03T13:03:13.111Z</lastmod></url>
  <url><loc>https://compliancebureau.org/pages/contact</loc><lastmod>2026-07-03T13:03:13.109Z</lastmod></url>
  <url><loc>https://compliancebureau.org/webinars</loc><lastmod>2026-09-15T11:58:18.652Z</lastmod></url>
  <url><loc>https://compliancebureau.org/webinars/digital-compliance-101-and-the-road-to-2027</loc><lastmod>2026-09-15T11:58:18.652Z</lastmod></url>
</urlset>