<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BlackSheep Blog</title>
    <description>Cybersecurity compliance guidance for regulated firms — RIAs, banking, credit unions, accounting, and mortgage.</description>
    <link>https://www.goblacksheep.io/blog</link>
    <atom:link href="https://www.goblacksheep.io/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <language>en-us</language>
    <item>
      <title>Your Clients Can Receive Phishing Emails That Look Like They Came From You</title>
      <description>83% of RIA domains have no DMARC. Anyone can send emails that appear to come from your firm — wire transfers, account updates, password resets. Your clients can&apos;t tell the difference.</description>
      <link>https://www.goblacksheep.io/blog/your-clients-can-be-phished-from-your-domain</link>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/your-clients-can-be-phished-from-your-domain</guid>
    </item>
    <item>
      <title>Your Cyber Insurance Renewal Is About to Get Harder — What RIAs Need to Know</title>
      <description>Insurers now require documented proof of MFA, IR plans, and email authentication. No documentation = denied claims or higher premiums. Here&apos;s what to prepare.</description>
      <link>https://www.goblacksheep.io/blog/cyber-insurance-requirements-ria</link>
      <pubDate>Sat, 28 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cyber-insurance-requirements-ria</guid>
    </item>
    <item>
      <title>55 Days Until Reg S-P: What Your RIA Needs to Do Right Now</title>
      <description>Most firms need 2-3 months to build a compliance program. You have less than 2. Here&apos;s a week-by-week countdown plan that gets you there.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-55-days-what-to-do-now</link>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-55-days-what-to-do-now</guid>
    </item>
    <item>
      <title>Your Fiduciary Duty Now Includes Cybersecurity — What That Means for RIAs</title>
      <description>The SEC says protecting client assets includes protecting client data. If a client gets phished from your domain, that&apos;s a fiduciary failure — not just a tech problem.</description>
      <link>https://www.goblacksheep.io/blog/fiduciary-duty-cybersecurity-ria</link>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/fiduciary-duty-cybersecurity-ria</guid>
    </item>
    <item>
      <title>We Scored 8,802 RIAs on Cybersecurity. Here&apos;s How Your Firm Compares.</title>
      <description>Average score: 57/100. Only 3% earned an A. 83% have no DMARC. See the full breakdown by category, AUM tier, and state — then check your own firm.</description>
      <link>https://www.goblacksheep.io/blog/ria-cybersecurity-scorecard-how-you-compare</link>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/ria-cybersecurity-scorecard-how-you-compare</guid>
    </item>
    <item>
      <title>Are You Managing Cybersecurity Compliance or Cybersecurity Risk? You Need Both.</title>
      <description>You can be compliant and at risk. You can be secure and non-compliant. The SEC expects both — and most RIAs are only doing one.</description>
      <link>https://www.goblacksheep.io/blog/managing-compliance-or-cybersecurity-risk-you-need-both</link>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/managing-compliance-or-cybersecurity-risk-you-need-both</guid>
    </item>
    <item>
      <title>7 Questions to Ask Your MSP Before the Reg S-P Deadline</title>
      <description>Forward this to your MSP. Their answers will tell you whether you have a compliance partner or just an IT vendor.</description>
      <link>https://www.goblacksheep.io/blog/7-questions-ask-msp-before-reg-sp-deadline</link>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/7-questions-ask-msp-before-reg-sp-deadline</guid>
    </item>
    <item>
      <title>Top 10 Cybersecurity Mistakes RIAs Make (From Scanning 8,802 Firms)</title>
      <description>83% no DMARC. No documented IR plan. No vendor oversight. Count your mistakes — 0-2 means you&apos;re ahead of 97% of the industry.</description>
      <link>https://www.goblacksheep.io/blog/top-10-cybersecurity-mistakes-rias-make</link>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/top-10-cybersecurity-mistakes-rias-make</guid>
    </item>
    <item>
      <title>4 Questions Your Board Should Be Asking About Cybersecurity</title>
      <description>Share this with your managing partner before the next board meeting. If your CCO can answer all four with evidence, you&apos;re ahead of 97% of RIAs.</description>
      <link>https://www.goblacksheep.io/blog/4-questions-board-should-ask-cybersecurity</link>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/4-questions-board-should-ask-cybersecurity</guid>
    </item>
    <item>
      <title>6 Signs Your Compliance Tool Isn&apos;t Actually Protecting You</title>
      <description>If your tool can&apos;t tell you your DMARC status without you checking a box, it&apos;s a tracking tool, not a security tool.</description>
      <link>https://www.goblacksheep.io/blog/6-signs-compliance-tool-not-protecting-you</link>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/6-signs-compliance-tool-not-protecting-you</guid>
    </item>
    <item>
      <title>The Complete Reg S-P Compliance Checklist for RIAs (15 Items for 2026)</title>
      <description>15 items across 5 categories. Score yourself: are you exam-ready?</description>
      <link>https://www.goblacksheep.io/blog/complete-reg-sp-compliance-checklist-2026</link>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/complete-reg-sp-compliance-checklist-2026</guid>
    </item>
    <item>
      <title>What Your MSP Isn&apos;t Telling You (And Why It Matters for Your RIA)</title>
      <description>8 gaps between what your MSP delivers and what the SEC requires. The 72-hour breach notification clause alone could cost you an exam finding.</description>
      <link>https://www.goblacksheep.io/blog/what-your-msp-isnt-telling-you-ria</link>
      <pubDate>Fri, 10 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/what-your-msp-isnt-telling-you-ria</guid>
    </item>
    <item>
      <title>Compliance Theater vs. Actual Security: Why Your GRC Tool Can&apos;t Tell You If Your Controls Work</title>
      <description>GRC tools document controls. They don&apos;t verify them. 83% of RIAs have policies requiring DMARC but no DMARC configured. That gap is what attackers exploit and examiners find.</description>
      <link>https://www.goblacksheep.io/blog/compliance-theater-vs-actual-security</link>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/compliance-theater-vs-actual-security</guid>
    </item>
    <item>
      <title>What Happens After You Sign Up for BlackSheep? Your First Week, Day by Day</title>
      <description>Day 1: scan. Day 2: policies. Day 3: IR plan. Day 5: exam-ready. Here&apos;s exactly what your first week looks like — no surprises.</description>
      <link>https://www.goblacksheep.io/blog/what-happens-after-you-sign-up-blacksheep</link>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/what-happens-after-you-sign-up-blacksheep</guid>
    </item>
    <item>
      <title>BlackSheep Pricing, Plans, and Everything You Need to Know Before Signing Up</title>
      <description>$249/mo. Month-to-month. No hidden fees. Here&apos;s every question answered — pricing, setup, frameworks, cancellation, and how it compares.</description>
      <link>https://www.goblacksheep.io/blog/blacksheep-pricing-faq</link>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/blacksheep-pricing-faq</guid>
    </item>
    <item>
      <title>What Actually Happens During a SEC Cybersecurity Exam (And How to Prepare)</title>
      <description>How firms get selected, what documents they request, what they check technically, common findings, and what happens after. The full walkthrough.</description>
      <link>https://www.goblacksheep.io/blog/what-happens-during-sec-cybersecurity-exam</link>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/what-happens-during-sec-cybersecurity-exam</guid>
    </item>
    <item>
      <title>Is Your RIA Too Small for Cybersecurity Compliance? (No. Here&apos;s Why.)</title>
      <description>Reg S-P applies to ALL SEC-registered RIAs regardless of size. No exemption. The SEC is specifically targeting smaller firms in 2026.</description>
      <link>https://www.goblacksheep.io/blog/is-your-ria-too-small-for-cybersecurity-compliance</link>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/is-your-ria-too-small-for-cybersecurity-compliance</guid>
    </item>
    <item>
      <title>You Already Have a Compliance Solution. Is It Actually Working?</title>
      <description>5 questions to ask about your current tool. If you answer &apos;no&apos; to 2 or more, you have gaps the SEC will find.</description>
      <link>https://www.goblacksheep.io/blog/already-have-compliance-solution-is-it-enough</link>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/already-have-compliance-solution-is-it-enough</guid>
    </item>
    <item>
      <title>5 Best Cybersecurity Compliance Platforms for RIAs in 2026</title>
      <description>An honest comparison of BlackSheep, Vanta, Secureframe, Drata, and traditional consultants. Who wins on price, SEC-specificity, and automation.</description>
      <link>https://www.goblacksheep.io/blog/best-cybersecurity-compliance-platforms-ria-2026</link>
      <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/best-cybersecurity-compliance-platforms-ria-2026</guid>
    </item>
    <item>
      <title>The 10-Point SEC Cybersecurity Exam Checklist Every RIA Needs in 2026</title>
      <description>WISP, risk assessment, IR plan, DMARC, MFA, encryption, vendor management, training, BCP, and board oversight. Score yourself: are you exam-ready?</description>
      <link>https://www.goblacksheep.io/blog/sec-cybersecurity-exam-checklist-ria-2026</link>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/sec-cybersecurity-exam-checklist-ria-2026</guid>
    </item>
    <item>
      <title>8 Things Your MSP Should Be Doing for SEC Compliance (But Probably Isn&apos;t)</title>
      <description>Print this list. Send it to your MSP. If they can check all 8, you have a great IT partner. If they can&apos;t, you have a gap.</description>
      <link>https://www.goblacksheep.io/blog/8-things-msp-should-do-sec-compliance</link>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/8-things-msp-should-do-sec-compliance</guid>
    </item>
    <item>
      <title>5 Reg S-P Requirements Most RIAs Are Still Missing With 54 Days Left</title>
      <description>Written IR program, 72-hour vendor clause, 30-day client notification, documented risk assessment, evidence of implementation. How many does your firm have?</description>
      <link>https://www.goblacksheep.io/blog/5-reg-sp-requirements-most-rias-missing</link>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/5-reg-sp-requirements-most-rias-missing</guid>
    </item>
    <item>
      <title>3 Ways RIAs Handle SEC Cybersecurity Compliance (And Which Actually Works)</title>
      <description>Hire a consultant ($15-30K), DIY with templates ($0), or use a compliance platform ($249/mo). An honest comparison with a decision matrix.</description>
      <link>https://www.goblacksheep.io/blog/3-ways-rias-handle-cybersecurity-compliance</link>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/3-ways-rias-handle-cybersecurity-compliance</guid>
    </item>
    <item>
      <title>Does Your Cybersecurity Compliance Vendor Actually Automate Anything?</title>
      <description>Most compliance platforms promise automation but deliver dashboards full of manual checklists. Here&apos;s what actual automation looks like — and what still needs your judgment.</description>
      <link>https://www.goblacksheep.io/blog/compliance-automation-that-actually-works</link>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/compliance-automation-that-actually-works</guid>
    </item>
    <item>
      <title>Should Your Compliance Consultant Handle Your Cybersecurity Too?</title>
      <description>Your compliance consultant can write a WISP. They can&apos;t tell you your DMARC is misconfigured. Policy without verification is just paper — here&apos;s what the SEC actually wants.</description>
      <link>https://www.goblacksheep.io/blog/should-compliance-consultant-handle-cybersecurity</link>
      <pubDate>Tue, 17 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/should-compliance-consultant-handle-cybersecurity</guid>
    </item>
    <item>
      <title>Should Your MSP Be Your vCISO? Why RIAs Need Independent Compliance Oversight</title>
      <description>Your MSP is offering vCISO services. That&apos;s like your contractor inspecting their own work. Here&apos;s why independence matters and what it actually costs.</description>
      <link>https://www.goblacksheep.io/blog/should-your-msp-be-your-vciso</link>
      <pubDate>Fri, 13 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/should-your-msp-be-your-vciso</guid>
    </item>
    <item>
      <title>Is Your MSP Actually Protecting Your RIA? How to Tell</title>
      <description>Most RIAs outsource IT to an MSP. But MSPs don&apos;t know what the SEC requires. We scanned 8,802 RIA websites — 83% had gaps their IT provider should have caught.</description>
      <link>https://www.goblacksheep.io/blog/is-your-msp-protecting-your-ria</link>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/is-your-msp-protecting-your-ria</guid>
    </item>
    <item>
      <title>Cybersecurity Policy Template for SEC-Registered RIAs: What to Include (And What Templates Get Wrong)</title>
      <description>SEC examiners have seen every template. Here&apos;s what a compliant policy must include, what most templates miss, and why generated beats generic.</description>
      <link>https://www.goblacksheep.io/blog/cybersecurity-policy-template-sec-ria</link>
      <pubDate>Tue, 20 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cybersecurity-policy-template-sec-ria</guid>
    </item>
    <item>
      <title>Cybersecurity Risk Management Software for RIAs: What to Look For in 2026</title>
      <description>Enterprise tools cost six figures. GRC tools don&apos;t scan. Here&apos;s what RIAs actually need — and how to evaluate the options.</description>
      <link>https://www.goblacksheep.io/blog/cybersecurity-risk-management-software-ria</link>
      <pubDate>Thu, 12 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cybersecurity-risk-management-software-ria</guid>
    </item>
    <item>
      <title>Cybersecurity Risk Assessment Software for RIAs: Automate What the SEC Requires</title>
      <description>Self-assessment questionnaires aren&apos;t risk assessments. 83% of RIAs would check &apos;DMARC configured&apos; and be wrong. Here&apos;s what real assessment software does.</description>
      <link>https://www.goblacksheep.io/blog/cybersecurity-risk-assessment-software-ria</link>
      <pubDate>Sun, 15 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cybersecurity-risk-assessment-software-ria</guid>
    </item>
    <item>
      <title>Third-Party Risk Management for RIAs: What Reg S-P Requires and How to Automate It</title>
      <description>Most RIAs have 15-30 vendors and no oversight program. Reg S-P requires 72-hour breach notification clauses in every contract. Here&apos;s how to get compliant.</description>
      <link>https://www.goblacksheep.io/blog/third-party-risk-management-software-ria</link>
      <pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/third-party-risk-management-software-ria</guid>
    </item>
    <item>
      <title>What Does Regulation S-P Require for Investment Advisers in 2026?</title>
      <description>The amended Reg S-P requires a written incident response program, 30-day client notification, and 72-hour vendor notification. Here&apos;s what every RIA needs to know.</description>
      <link>https://www.goblacksheep.io/blog/regulation-sp-requirements-investment-advisers-2026</link>
      <pubDate>Thu, 08 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/regulation-sp-requirements-investment-advisers-2026</guid>
    </item>
    <item>
      <title>How to Build a Written Information Security Program (WISP) for Your RIA</title>
      <description>The SEC requires written policies covering administrative, technical, and physical safeguards. Here&apos;s what goes in a WISP, what examiners check, and how to avoid the $15K consultant fee.</description>
      <link>https://www.goblacksheep.io/blog/ria-written-information-security-program-wisp</link>
      <pubDate>Tue, 13 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/ria-written-information-security-program-wisp</guid>
    </item>
    <item>
      <title>How to Conduct a GLBA-Compliant Risk Assessment for Your Community Bank</title>
      <description>The GLBA Safeguards Rule requires a written risk assessment. FFIEC examiners evaluate it against IT Handbook standards. Here&apos;s what to include and what trips banks up.</description>
      <link>https://www.goblacksheep.io/blog/glba-risk-assessment-community-banks</link>
      <pubDate>Sat, 17 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/glba-risk-assessment-community-banks</guid>
    </item>
    <item>
      <title>GLBA Breach Notification Requirements for Banks in 2026</title>
      <description>Two notification paths: 36 hours to your regulator, 30 days to consumers. Missing either is an independent violation. Here&apos;s how both work.</description>
      <link>https://www.goblacksheep.io/blog/glba-breach-notification-requirements-2026</link>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/glba-breach-notification-requirements-2026</guid>
    </item>
    <item>
      <title>What Does a Bank Cybersecurity Exam Cost and How Do You Prepare?</title>
      <description>Exam prep typically costs $15K–$50K in consultant fees. FFIEC examiners in 2026 focus on access controls, vendor management, and ransomware response. Here&apos;s what to expect.</description>
      <link>https://www.goblacksheep.io/blog/bank-cybersecurity-exam-preparation-cost</link>
      <pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/bank-cybersecurity-exam-preparation-cost</guid>
    </item>
    <item>
      <title>What Does NCUA Letter 26-CU-01 Require for Credit Union Cybersecurity?</title>
      <description>NCUA&apos;s 2026 supervisory priorities put cybersecurity and payment security at the top. Here&apos;s what examiners will assess and how to prepare.</description>
      <link>https://www.goblacksheep.io/blog/ncua-letter-26-cu-01-cybersecurity-requirements</link>
      <pubDate>Sat, 31 Jan 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/ncua-letter-26-cu-01-cybersecurity-requirements</guid>
    </item>
    <item>
      <title>What Does 12 CFR Part 748 Require for Credit Union Information Security Programs?</title>
      <description>Every federally insured credit union needs a written information security program approved by the board. Here&apos;s what goes in it and how certification works.</description>
      <link>https://www.goblacksheep.io/blog/12-cfr-part-748-credit-union-information-security</link>
      <pubDate>Thu, 05 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/12-cfr-part-748-credit-union-information-security</guid>
    </item>
    <item>
      <title>NCUA Cybersecurity Exam Priorities for Credit Unions in 2026</title>
      <description>Four focus areas: payment security, vendor oversight, member data protection, and insider threats. Examiners want written documentation and evidence of testing.</description>
      <link>https://www.goblacksheep.io/blog/ncua-cybersecurity-exam-priorities-2026</link>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/ncua-cybersecurity-exam-priorities-2026</guid>
    </item>
    <item>
      <title>Does a Small Credit Union Need a Cybersecurity Compliance Program?</title>
      <description>Yes. 12 CFR Part 748 applies regardless of asset size. There is no small-institution exemption. Here&apos;s what the minimum looks like.</description>
      <link>https://www.goblacksheep.io/blog/small-credit-union-cybersecurity-program</link>
      <pubDate>Sat, 14 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/small-credit-union-cybersecurity-program</guid>
    </item>
    <item>
      <title>HIPAA Security Rule Requirements for Small Medical Practices in 2026</title>
      <description>The Security Rule is size-scalable but OCR enforces the same 8 administrative safeguards regardless of practice size. More than half of recent enforcement actions cited risk analysis failures.</description>
      <link>https://www.goblacksheep.io/blog/hipaa-security-rule-small-practice-requirements</link>
      <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/hipaa-security-rule-small-practice-requirements</guid>
    </item>
    <item>
      <title>The HIPAA Security Rule Proposed Update: What It Will Require</title>
      <description>The January 2025 NPRM removes the addressable/required distinction, mandates MFA and encryption, and requires annual asset inventories. Here&apos;s what to prepare for.</description>
      <link>https://www.goblacksheep.io/blog/hipaa-security-rule-proposed-update-2025</link>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/hipaa-security-rule-proposed-update-2025</guid>
    </item>
    <item>
      <title>How Much Can OCR Fine a Healthcare Provider for HIPAA Violations?</title>
      <description>OCR levied $6.6M+ in fines in 2025. HITECH penalties range from $100 to $50K per violation with annual caps up to $1.9M. The most common citation: missing risk analysis.</description>
      <link>https://www.goblacksheep.io/blog/hipaa-ocr-fines-penalties-2026</link>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/hipaa-ocr-fines-penalties-2026</guid>
    </item>
    <item>
      <title>HIPAA Encryption Requirements for Electronic Protected Health Information (ePHI)</title>
      <description>Encryption is currently &apos;addressable&apos; but OCR treats unencrypted ePHI as willful neglect when a breach occurs. The proposed update makes it mandatory.</description>
      <link>https://www.goblacksheep.io/blog/hipaa-encryption-requirements-ephi</link>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/hipaa-encryption-requirements-ephi</guid>
    </item>
    <item>
      <title>The SEC Reg S-P Deadline Is June 3, 2026. Here&apos;s What That Actually Means for Your Firm.</title>
      <description>What changed in the 2024 amendments, who has to comply, and what happens if you&apos;re not ready. A plain-language breakdown for RIAs.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-compliance-deadline-june-2026</link>
      <pubDate>Sat, 15 Mar 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-compliance-deadline-june-2026</guid>
    </item>
    <item>
      <title>How to Build a Reg S-P Incident Response Plan That Won&apos;t Fall Apart During an Exam</title>
      <description>The SEC now requires a written incident response program. Here&apos;s what goes in it, how to test it, and what &apos;reasonably designed&apos; actually means.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-incident-response-plan</link>
      <pubDate>Tue, 18 Mar 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-incident-response-plan</guid>
    </item>
    <item>
      <title>The 72-Hour Rule: What Reg S-P Vendor Oversight Means for Your Firm</title>
      <description>Your vendors now have 72 hours to tell you about a breach. That means you need it in writing. Here&apos;s how to handle vendor contracts, due diligence, and monitoring.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-vendor-oversight</link>
      <pubDate>Sat, 22 Mar 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-vendor-oversight</guid>
    </item>
    <item>
      <title>What Does Reg S-P Compliance Actually Cost? A Realistic Breakdown for RIAs</title>
      <description>DIY, consultant, or software? We break down the real numbers so you can budget without guessing.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-compliance-cost</link>
      <pubDate>Tue, 25 Mar 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-compliance-cost</guid>
    </item>
    <item>
      <title>Reg S-P vs. Reg S-ID: Two Rules, Two Jobs, One Firm That Needs to Handle Both</title>
      <description>One protects data. The other catches identity theft. Most RIAs need both. Here&apos;s how they differ and where they overlap.</description>
      <link>https://www.goblacksheep.io/blog/reg-sp-vs-reg-sid</link>
      <pubDate>Fri, 28 Mar 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/reg-sp-vs-reg-sid</guid>
    </item>
    <item>
      <title>The NYDFS 500 Annual Certification: What to Know Before April 15</title>
      <description>Two filing options, dual signature, five-year retention. Here&apos;s how to prepare for the annual certification without scrambling.</description>
      <link>https://www.goblacksheep.io/blog/nydfs-500-annual-certification</link>
      <pubDate>Tue, 01 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nydfs-500-annual-certification</guid>
    </item>
    <item>
      <title>The NYDFS 500 CISO Requirement: Who Qualifies, and Can You Outsource It?</title>
      <description>You need a CISO. But it doesn&apos;t have to be a full-time hire. Here&apos;s what the regulation actually requires and how to comply.</description>
      <link>https://www.goblacksheep.io/blog/nydfs-500-ciso-requirement</link>
      <pubDate>Fri, 04 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nydfs-500-ciso-requirement</guid>
    </item>
    <item>
      <title>NYDFS 500 vs. SEC Reg S-P: Which Applies and Which Sets the Higher Bar?</title>
      <description>One is prescriptive. The other is principles-based. If you&apos;re subject to both, here&apos;s how to build one program that covers both.</description>
      <link>https://www.goblacksheep.io/blog/nydfs-500-vs-reg-sp</link>
      <pubDate>Tue, 08 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nydfs-500-vs-reg-sp</guid>
    </item>
    <item>
      <title>What Changed from NIST CSF 1.1 to 2.0 (and What It Means for Your Firm)</title>
      <description>New Govern function, expanded scope, implementation examples. If you&apos;re still on 1.1, here&apos;s the transition roadmap.</description>
      <link>https://www.goblacksheep.io/blog/nist-csf-1-1-vs-2-0</link>
      <pubDate>Sat, 12 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nist-csf-1-1-vs-2-0</guid>
    </item>
    <item>
      <title>How to Use NIST CSF 2.0 to Prepare for Your Next SEC Exam</title>
      <description>SEC examiners reference NIST CSF when evaluating your program. Here&apos;s how to use that to your advantage.</description>
      <link>https://www.goblacksheep.io/blog/nist-csf-sec-exam-prep</link>
      <pubDate>Tue, 15 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nist-csf-sec-exam-prep</guid>
    </item>
    <item>
      <title>The NIST CSF 2.0 Govern Function: Why It Matters More Than the Other Five</title>
      <description>Governance sits at the center of the framework for a reason. Here&apos;s what the 6 categories cover and how RIAs should implement them.</description>
      <link>https://www.goblacksheep.io/blog/nist-csf-govern-function</link>
      <pubDate>Fri, 18 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nist-csf-govern-function</guid>
    </item>
    <item>
      <title>SEC Cybersecurity Exam Checklist: What Examiners Actually Ask For</title>
      <description>The documents SEC EXAMS staff actually request, common deficiency findings, and how to prepare before they show up.</description>
      <link>https://www.goblacksheep.io/blog/sec-cybersecurity-exam-checklist</link>
      <pubDate>Tue, 22 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/sec-cybersecurity-exam-checklist</guid>
    </item>
    <item>
      <title>What Happens If Your Firm Fails an SEC Cybersecurity Exam</title>
      <description>Deficiency letters, enforcement actions, remediation timelines, and what it actually costs to be non-compliant.</description>
      <link>https://www.goblacksheep.io/blog/what-happens-sec-exam-failure</link>
      <pubDate>Fri, 25 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/what-happens-sec-exam-failure</guid>
    </item>
    <item>
      <title>How to Write a Cybersecurity Policy for Your RIA (Without Hiring a Lawyer)</title>
      <description>Section-by-section WISP breakdown covering data classification, access controls, incident response, and vendor management.</description>
      <link>https://www.goblacksheep.io/blog/cybersecurity-policy-template-ria</link>
      <pubDate>Mon, 28 Apr 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cybersecurity-policy-template-ria</guid>
    </item>
    <item>
      <title>Cybersecurity Requirements for Small RIAs: What Actually Applies to You</title>
      <description>Which requirements apply to firms under 20 employees, what you can defer, and what a minimum viable compliance program looks like.</description>
      <link>https://www.goblacksheep.io/blog/small-ria-cybersecurity-requirements</link>
      <pubDate>Thu, 01 May 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/small-ria-cybersecurity-requirements</guid>
    </item>
    <item>
      <title>NYDFS 500 Penalties: Real Enforcement Actions and What They Cost</title>
      <description>First American ($1M), Excellus ($5.1M), EyeMed ($4.5M). How penalties are calculated and what triggers an investigation.</description>
      <link>https://www.goblacksheep.io/blog/nydfs-500-penalty-examples</link>
      <pubDate>Sun, 04 May 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/nydfs-500-penalty-examples</guid>
    </item>
    <item>
      <title>RIA Vendor Management: What SEC and NYDFS Actually Require</title>
      <description>The 72-hour notification rule, due diligence checklists, contract provisions, and a practical quarterly workflow.</description>
      <link>https://www.goblacksheep.io/blog/ria-vendor-management-requirements</link>
      <pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/ria-vendor-management-requirements</guid>
    </item>
    <item>
      <title>How Much Does a Cybersecurity Risk Assessment Cost? (2026 Pricing)</title>
      <description>Consultant ($5K-$50K+), DIY ($0-$500), or software ($249/mo). Real pricing for every approach, with what regulators actually expect to see.</description>
      <link>https://www.goblacksheep.io/blog/cybersecurity-risk-assessment-cost</link>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/cybersecurity-risk-assessment-cost</guid>
    </item>
    <item>
      <title>Best Cybersecurity Risk Assessment Tools &amp; Software (2026)</title>
      <description>Comparison of tools for regulated industries: BlackSheep, Vanta, Drata, Secureframe, and DIY approaches. Framework coverage, pricing, and which fits your firm.</description>
      <link>https://www.goblacksheep.io/blog/best-cybersecurity-risk-assessment-tools</link>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://www.goblacksheep.io/blog/best-cybersecurity-risk-assessment-tools</guid>
    </item>
  </channel>
</rss>