<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Think Week 🧠</title>
    <description>It&#39;s like making lemonade from lemons except this lemonade stand does ISO.</description>
    
    <link>https://intel.mastermindassurance.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/Vmov9AFmCp.xml" rel="self"/>
    
    <lastBuildDate>Sat, 28 Feb 2026 20:40:16 +0000</lastBuildDate>
    <pubDate>Tue, 06 Aug 2024 12:00:00 +0000</pubDate>
    <atom:published>2024-08-06T12:00:00Z</atom:published>
    <atom:updated>2026-02-28T20:40:16Z</atom:updated>
    
      <category>Business</category>
      <category>Artificial Intelligence</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, Think Week 🧠</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/5cce741c-592e-498b-9ca6-ac22c10a6961/Favicon-800x800.png</url>
      <title>Think Week 🧠</title>
      <link>https://intel.mastermindassurance.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>75 days of growth</title>
  <description>A world&#39;s first milestone and a new partnership</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/38493f71-9662-497b-a7a6-0b0a8e43f0e9/Newsletter_Thumbnail.png" length="721948" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/75-days-growth</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/75-days-growth</guid>
  <pubDate>Tue, 06 Aug 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-08-06T12:00:00Z</atom:published>
    <dc:creator>David Forman 🧠</dc:creator>
    <category><![CDATA[Building In Public]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">I took a break from hitting send on this newsletter in July, but it was not for lack of things to share. </p><p class="paragraph" style="text-align:left;">Excuse the temporary writing hiatus as I have been reallocating some of the “scrappy” available to this startup and shifted brainpower to a few alternate but timely initiatives.</p><p class="paragraph" style="text-align:left;">Let’s get caught up while revisiting milestones from July.</p><p class="paragraph" style="text-align:left;"><b>Professional things (Rating: A-)</b></p><ul><li><p class="paragraph" style="text-align:left;">Attended 53 virtual meetings and 4 in-person meetings</p></li><li><p class="paragraph" style="text-align:left;">Sent proposals for 20 new projects </p></li><li><p class="paragraph" style="text-align:left;">Delivered 7 customer audits</p></li><li><p class="paragraph" style="text-align:left;">Guest on the <b>CSA Security Update</b> <a class="link" href="https://csa303731.buzzsprout.com/303731/15455331-iso-iec-27001-2022-unpacked-embracing-auditing-themes?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">podcast</a> hosted by the Cloud Security Alliance</p></li><li><p class="paragraph" style="text-align:left;">Recorded an <a class="link" href="https://open.spotify.com/episode/6hEcWBNAZJvyuBFLQ2fVJH?si=moqbOnDxTOC3cKvPrh5Y8A&nd=1&dlsi=174794f461dc411a&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">episode</a> with <b>One Golden Nugget</b>, the collaboration spearheaded by Joe Foster (founder of Reebok)</p></li><li><p class="paragraph" style="text-align:left;">Closed the books on June 2024 – we are officially profitable! 💸</p></li></ul><p class="paragraph" style="text-align:left;"> <b>Personal highlights (Rating: B+)</b></p><ul><li><p class="paragraph" style="text-align:left;">Went to an Atlanta Braves game with my Dad </p></li><li><p class="paragraph" style="text-align:left;">Long weekend in Highlands, NC with my family and our dog Bear after the Fourth of July holiday</p></li><li><p class="paragraph" style="text-align:left;">Prioritized physical fitness: continued a twice weekly program with a personal trainer</p></li></ul><p class="paragraph" style="text-align:left;">And, the most remarkable achievement from the last 30 days is <a class="link" href="https://www.linkedin.com/posts/masterminddavid_certifyai-iso42001-activity-7218963818566008832-3dAd?utm_source=share&utm_medium=member_desktop" target="_blank" rel="noopener noreferrer nofollow">announcing</a> our award as the world’s first certification body to support ISO 42001 under accreditation. 🚀</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0a43f574-e72d-419b-91f8-dd792945dd02/Announcement.png?t=1722784975"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d3db55c4-cb48-4b67-a271-556d656953d3/Horizontal_Rule.png?t=1707680705"/></div><h4 class="heading" style="text-align:left;" id="its-time-to-certify-ai">It’s time to #CertifyAI</h4><p class="paragraph" style="text-align:left;">For those unfamiliar with this space, <a class="link" href="https://www.iso.org/standard/81230.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">ISO 42001</a> is an International Standard that details requirements and technical controls for organizations that produce, develop, provide, or use artificial intelligence (AI) systems as part of their service offerings. </p><p class="paragraph" style="text-align:left;"><b>TL;DR: </b>ISO 42001 is at least <i>partially</i> applicable to nearly every company that slaps AI as a buzzword on their marketing material or quarterly financial reports – it’s a big deal.</p><p class="paragraph" style="text-align:left;">The homepage Lottie animation on our website succinctly displays our core certification schemes, including ISO 27001 (information security management), ISO 27017 (cloud security), ISO 27018 (cloud privacy), ISO 27701 (privacy management), and a related extension scheme published by the Cloud Security Alliance. </p><p class="paragraph" style="text-align:left;">ISO 42001 (AI management) easily supplements these core offerings since security and data privacy continue to be core tenets of strong AI governance.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3baaeeeb-b78c-4c77-a36f-44852b6104bf/Mastermind_Homepage.png?t=1722783999"/><div class="image__source"><span class="image__source_text"><p>Such a limited menu of assessment offerings means Mastermind is the In-N-Out burger of certification bodies</p></span></div></div><p class="paragraph" style="text-align:left;">This standard was published by ISO in December 2023, just after the draft EU AI Act legislation text leaked. It quickly gained attention from cybersecurity and legal professionals as AI technologies&#39; rapid growth outpaced regulatory oversight. </p><p class="paragraph" style="text-align:left;">ISO 42001 is currently the only AI certification mechanism available for companies, allowing major cloud service providers like Salesforce, PayPal, and Oracle to engage independent vendors like Mastermind to assess their compliance. The audit results in a pass/fail certification issued by the independent auditor if the organization meets the requirements of the ISO 42001 standard.</p><p class="paragraph" style="text-align:left;">Several laws already require periodic, independent reviews of AI technologies, with some (e.g., EU AI Act, Art. 17) demanding a management system for continuous control. ISO 42001 certification helps service providers meet these emerging legal requirements, providing trust to consumers and businesses, especially those using these AI services within their supply chains.</p><p class="paragraph" style="text-align:left;">At Mastermind, we are that independent vendor — and now, we can formally assess and issue certification for this new standard. In fact, we are the first in the world to be authorized for ISO 42001. Officially, this is known as an accreditation expansion; however, you can think of it as an additional business license. It’s a temporary distinction as other audit vendors will earn the same accreditation in the coming months, but we think it’s a <i><b>fricking cool</b></i> milestone to add to our credibility in the early innings of Mastermind.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d3db55c4-cb48-4b67-a271-556d656953d3/Horizontal_Rule.png?t=1707680705"/></div><h4 class="heading" style="text-align:left;" id="creating-a-multiplier-effect">Creating a multiplier effect </h4><p class="paragraph" style="text-align:left;">To support our customers that utilize AI systems, Mastermind is partnering with various industry experts to create a resource network that can address questions pertaining to consultancy and systems implementation. This initiative aims to accelerate the adoption of AI governance standards. </p><p class="paragraph" style="text-align:left;"><b>Editor’s Note:</b> Mastermind never accepts commissions, referral fees, or kickbacks with partners – it&#39;s simply a curated list of service providers for our customers to explore!</p><p class="paragraph" style="text-align:left;">Today, Mastermind announces one such partnership with <a class="link" href="https://stackaware.com/?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">StackAware</a>, who helps organizations manage AI-related cybersecurity, privacy, and compliance risks.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">There are plenty of similarities between Mastermind and StackAware – a narrow focus on a limited group of service offerings allowing for deep specialization. Additionally, StackAware is dogfooding its own service and <a class="link" href="https://www.youtube.com/watch?v=PjhNhyGvCZ0&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">slick API tool</a> as an early adopter of ISO 42001. StackAware is also nearing formal certification to ISO 42001 for its itself with an alternate auditor.</p><p class="paragraph" style="text-align:left;">Check them out <a class="link" href="https://mastermind.stackaware.com/?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=75-days-of-growth" target="_blank" rel="noopener noreferrer nofollow">here</a> to receive 1 month free.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/31876118-467f-4efd-8d46-22a5c12f2909/StackAware.png?t=1722785895"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d3db55c4-cb48-4b67-a271-556d656953d3/Horizontal_Rule.png?t=1707680705"/></div><p class="paragraph" style="text-align:left;">It&#39;s been 75 days since our launch, and our momentum is on fire.</p><p class="paragraph" style="text-align:left;">Our vision is starting to take shape as we highlight the advantages of being a pure-play certification body. This focus enables Mastermind to move faster and innovate more effectively than other audit providers juggling busier interests.</p><p class="paragraph" style="text-align:left;">While we don&#39;t expect to remain the only vendor in the U.S. to recognize this advantage, we remain confident we&#39;ll be the best at what we do.</p><p class="paragraph" style="text-align:left;">David 🧠</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d3db55c4-cb48-4b67-a271-556d656953d3/Horizontal_Rule.png?t=1707680705"/></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share This Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Auditor is a swear word</title>
  <description>Rated 18+ for crude language 🤬</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2d541a5-6b2d-4d1d-b05d-d482024ce697/Investor_Weekly_Newsletter.png" length="71284" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/auditor-swear-word</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/auditor-swear-word</guid>
  <pubDate>Wed, 12 Jun 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-06-12T12:00:00Z</atom:published>
    <dc:creator>David Forman 🧠</dc:creator>
    <category><![CDATA[Building In Public]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">If you were ever to dig through the content creators I follow, you might think I have some sort of identity crisis. </p><p class="paragraph" style="text-align:left;">For a while now, I couldn&#39;t figure out why some of these social engines and their algos thought I would be interested in certain promoted influencers. Yet, here I am, subscribing, viewing, and reacting to their posts. Where are all my <a class="link" href="https://www.youtube.com/watch?v=1gKAqpgQYWE&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=auditor-is-a-swear-word" target="_blank" rel="noopener noreferrer nofollow">Boys with the Bus</a> fans?</p><p class="paragraph" style="text-align:left;">Recently, I began following Adam Aleksic, a self-proclaimed lexophile and the operator behind Etymology Nerd. He posts short-form reels on Instagram (@etymologynerd) every few days, usually featuring him holding up his phone selfie-style and enthusiastically explaining why he thinks certain Gen Alpha slang words like “rizz” or “brainrot” will fizzle out in popularity over the next few months, while others like “selfie” or “cancel” (e.g., cancel culture) have staying power. </p><p class="paragraph" style="text-align:left;">His entertaining style hooks your attention during moments of mindless scrolling and then teaches you something about linguistics. </p><p class="paragraph" style="text-align:left;">See for yourself. ⤵️</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/3M8ZxQiK4qo" width="100%"></iframe><p class="paragraph" style="text-align:left;"><b>Disclaimer: </b>He is <i>qualified</i> in the subject having studied linguistics during his undergraduate education at Harvard.</p><p class="paragraph" style="text-align:left;">But what I found even more appealing about Etymology Nerd is that he took a topic I had no prior awareness of—linguistics, which I would have completely avoided as a college elective—and made it fascinating in the short time since I started following him. Call it expertise and knowledge, but I think what we are seeing here is actually a much greater superpower that some people either have or they don’t.</p><p class="paragraph" style="text-align:left;">While Aleksic shows off his incredible skill with Etymology Nerd and pulls me in like bait, we see the same storytelling effect with figures like Bob Ross, who taught us the joy of painting, and Steve Irwin, who educated us on crocodiles and wildlife conservation. Most recently, Marie Kondo had her 15 seconds as she showed us her methods for tidying and folding clothes.</p><div class="image"><img alt="" class="image__image" style="" src="https://media0.giphy.com/media/PmABbbUe3IqUKSOIBV/giphy-downsized.gif?cid=2450ec30bzxetssw10orkhe4a1xvtvsiefhe3oog4kr04e7h&ep=v1_gifs_search&rid=giphy-downsized.gif&ct=g"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;" id="how-to-make-the-ordinary-interestin">How to make the ordinary interesting</h4><p class="paragraph" style="text-align:left;">It&#39;s a subtlety that I think most of us discount or, at a minimum, don&#39;t clearly recognize. But to understand how these people break down seemingly boring or complicated topics into a genre that demands eyeballs while turning passersby into roaring fans—it&#39;s a lesson in gaining sponsorship, or more plainly put, a masterclass in creating interest in something otherwise considered ordinary.</p><p class="paragraph" style="text-align:left;">Gary Vaynerchuk, widely known as &quot;Gary Vee&quot; and the co-founder of Resy, is celebrated for his loud, energetic, and passionate approach towards building companies and obtaining customers. </p><p class="paragraph" style="text-align:left;">One of his most notable early successes was transforming his family&#39;s liquor store, Shopper&#39;s Discount Liquors, into an online wine business called Wine Library. By launching WineLibrary.com and starting a video blog, where he fervently reviewed wines, Gary Vee grew the business significantly, from $3 million to $60 million in annual sales. This venture helped him amass a large following and established himself as an influencer, securing million-dollar book deals.</p><p class="paragraph" style="text-align:left;">Yet, Gary Vee was selling basic wines and liquors in an industry with nearly 50,000 retail locations in the United States alone, where all of these stores advertise similar products. What propelled Shopper&#39;s Discount Liquors and Gary Vee to experience such rapid growth?</p><div class="image"><img alt="gary vaynerchuk monday GIF by GaryVee" class="image__image" style="" src="https://media0.giphy.com/media/kh6JRj1IVo7u2qgIyP/giphy.gif?cid=2450ec30if7nv1svuy8l5ynypq24x95p1eqx8paqk7zmxrwl&ep=v1_gifs_search&rid=giphy.gif&ct=g"/><div class="image__source"><span class="image__source_text"><p>gary vee talking about mining bitcoin in antarctica, probably</p></span></div></div><p class="paragraph" style="text-align:left;">It&#39;s a lesson frequently observed in both pop culture and the business world. When someone is specialized and abnormally passionate about something, others—even those not directly involved—tend to listen a little longer. People are drawn to excitement, buzz, and, most consistently, winning attitudes.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f40102d5-ebca-413b-9700-55f7b3055cb0/image.png?t=1718069299"/></div><p class="paragraph" style="text-align:left;">It’s the same phenomena behind why half the baseball caps worn by teenagers in Asia bear the logos of historically successful clubs like the Dodgers or Yankees, and why Japanese baseball star Shohei Ohtani chose those Dodgers this offseason (maybe that last one was speculation). 🙄</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;">Breaking the paradigm</h4><p class="paragraph" style="text-align:left;">Considering all this, is it possible to make a topic like compliance interesting? In reality, several opposing forces are at play. </p><p class="paragraph" style="text-align:left;">Compliance often brings to mind audits and the humans performing these despicable assessments—the auditors—subjects that, apart from the 2016 film <i>The Accountant</i> with Ben Affleck, aren&#39;t frequently glamorized.</p><p class="paragraph" style="text-align:left;">Then there are scandals—everyone recalls Enron. Enron&#39;s collapse in December 2001 due to widespread corporate fraud and accounting irregularities further tarnished the image of these auditors due to the role of one of the world’s largest accounting firms, Arthur Andersen.</p><div class="image"><img alt="The Simpsons Dreams GIF" class="image__image" style="" src="https://media1.giphy.com/media/zLAXQgJ87nM9q/giphy.gif?cid=2450ec30vy7091xu49n72w5qx6hg9tdjqcyaod63isfe1cvz&ep=v1_gifs_search&rid=giphy.gif&ct=g"/></div><p class="paragraph" style="text-align:left;">Finally, there&#39;s even the stereotype of what an auditor physically looks like, portrayed in films like <i>Office Space</i> by characters like the Bobs. </p><p class="paragraph" style="text-align:left;">Or worse, the image of the young graduate who immediately adopts the uniform of a brown leather shoulder messenger bag and buys five shades of a blue button-down dress shirt upon accepting his Big 4 job offer.</p><div class="image"><img alt="Work Reaction GIF by H&Z Management Consulting" class="image__image" style="" src="https://media1.giphy.com/media/xpX7EFdRVczD9avaHo/giphy.gif?cid=2450ec30g0vhqss8wc7ei4xe5p9bi3c8mmwq8cjaa356lyta&ep=v1_gifs_search&rid=giphy.gif&ct=g"/></div><p class="paragraph" style="text-align:left;">These are some of the challenges we face at Mastermind. </p><p class="paragraph" style="text-align:left;">How do we foster more openness, authenticity, and, as embarrassing as it is to admit, <b>likability</b> within this line of work?</p><p class="paragraph" style="text-align:left;">By changing the narrative of security audits from a necessary chore to an eagerly anticipated annual event for our clients, we might begin to chip away at this longstanding reputation—and that single shift could have compounding effects: client work becomes more enjoyable for our staff, partnerships form more naturally, customer satisfaction ratings improve, and more individuals are drawn to the field, while elevating the quality of our work product.</p><p class="paragraph" style="text-align:left;">It&#39;s a cyclical process that continually requires fuel, and we are positioning <b>Mastermind </b>to be the catalyst for giving the compliance topic that much-needed boost.</p><p class="paragraph" style="text-align:left;">So, next time, think twice before you call me or any of the others an <i>a*ditor</i>.</p><p class="paragraph" style="text-align:left;">David 🧠</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d3db55c4-cb48-4b67-a271-556d656953d3/Horizontal_Rule.png?t=1707680705"/></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share This Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Pick up the phone already</title>
  <description>Time to get locked in with the heavy hitters</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2d541a5-6b2d-4d1d-b05d-d482024ce697/Investor_Weekly_Newsletter.png" length="71284" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/pick-phone-already</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/pick-phone-already</guid>
  <pubDate>Wed, 05 Jun 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-06-05T12:00:00Z</atom:published>
    <dc:creator>David Forman 🧠</dc:creator>
    <category><![CDATA[Building In Public]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">The initial buzz has passed, and it’s time to get to work. </p><p class="paragraph" style="text-align:left;">It’s funny how something can be at the forefront of our minds one moment and then quickly fades into the background as we move on to the next <i>something</i>. I’ve been reading books about startups for what feels like forever, and one consistent theme in these entrepreneur chronicles is the rollercoaster of highs and lows.</p><div class="image"><img alt="Happy Plastic Surgery GIF by E!" class="image__image" style="" src="https://media0.giphy.com/media/SJ5soYY4snWDQIXjzu/giphy-downsized.gif?cid=2450ec30uz266o0fkkoy890cdx6tmqkypoprkv3g1u9tcu99&ep=v1_gifs_search&rid=giphy-downsized.gif&ct=g"/></div><p class="paragraph" style="text-align:left;">It’s a looping sequence. For me, these feelings can fluctuate within the same week, and even within the same day. Earlier last week, I was deeply immersed in a side quest: constructing a multi-step automation on Zapier to streamline part of our project management and invoicing process. I was energized about the prospect of saving 1.5 hours per project while envisioning how those savings might multiply across 10 projects. </p><p class="paragraph" style="text-align:left;">However, I soon realized I had made a stupid error at the start of the automation rule that would require another weekend’s worth of work to fix and recreate. Within the span of 10 minutes, my feelings that I was the world’s smartest automation engineer were humbled and turned into frustration as I begrudgingly added the issue to my whiteboard parking lot. I’ll have to address Zapier later now.</p><p class="paragraph" style="text-align:left;">I’ve come to embrace these momentum swings, recognizing that today’s problems contribute to the ongoing struggles of building a business and that these problems are exactly that —<i>today’s problems,</i> and nothing more. </p><p class="paragraph" style="text-align:left;">The motivation remains clear: to build something that requires minimal maintenance in areas of the business that I find less enjoyable (e.g., invoicing and collections), and to reclaim time for activities I actually do like, such as talking with clients and partners.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;" id="finding-your-cohort">Finding your cohort</h4><p class="paragraph" style="text-align:left;">I follow several startup thought leaders on platforms like LinkedIn, and one individual I particularly like is David Cummings. As the founder of Pardot (now owned by Salesforce) and the Atlanta Tech Village, Cummings is a serial entrepreneur and venture capitalist who shares his insights through a weekly blog titled “<a class="link" href="https://davidcummings.org/?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=pick-up-the-phone-already" target="_blank" rel="noopener noreferrer nofollow">David Cummings on Startups</a>”. His reflections, spanning from 2009 to present day, offer insights into the startup ecosystem, while emphasizing one thing more consistently than any other weapon in the this founder’s arsenal — <b>the importance of community and mentorship</b>.</p><p class="paragraph" style="text-align:left;">Reflecting on my own path, my first career step after graduating from The University of Georgia in 2014 was a 3-year stint at Ernst & Young (EY). The experience of joining a cohort of campus hires can easily be summed up as the purist form of terror (at least, that is how I anticipated that first day). </p><p class="paragraph" style="text-align:left;">On the contrary, from the moment I stepped into the EY Atlanta office for that first orientation day, I felt belonging with the rest of the new hires making up my start class. Despite the challenges of navigating the corporate landscape as a newcomer, there was a shared understanding between us that we were going to do this together. The first weeks, spent in a bootcamp setting isolated in a suburban Marriott hotel, were a whirlwind of training sessions, case study presentations, and bonding experiences at the less-than-stellar conference center lobby bar. Looking back, those early days were limited in project value, as we transitioned from bootcamp to our first billable client engagements. That first client project provided a healthy dose of imposter syndrome for each of us as we experienced our own feelings of <a class="link" href="https://intel.mastermindassurance.com/p/fake-till-make?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=pick-up-the-phone-already" target="_blank" rel="noopener noreferrer nofollow">fake it till you make it</a>. </p><p class="paragraph" style="text-align:left;">At <b>Mastermind</b>, one lesson I’ve already become dependent on is the staying power of cultivating a strong network and actively engaging with it. While the early innings of a professional services career may be challenging, having a support system can make all the difference — maybe that is why I needed 10 years of working for the “man” before I took this step as an entrepreneur.</p><p class="paragraph" style="text-align:left;">With this new chapter, I’m once again leaning on the mentors, friends, and former colleagues who are part of my personal network. While there may not be a cohort of 30+ campus hires this time around, I’m finding my new support system and embracing this stage of connections.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;" id="stop-texting-and-call-them-already">Stop texting, and call them already!</h4><p class="paragraph" style="text-align:left;">I love talking and I especially like talking on the phone. During the shortened Memorial Day holiday week, I called 15 people just to catch up. Primarily, I am talking with people that I consider part of my <b>mid-life crisis cohort</b> (ok, that’s dramatic). These are my favorite communications and I make several of these types of calls each day. These calls are not a chore, but rather something I very much enjoy, are almost never scheduled in advance, and frequently hit well later than closing time at 5PM.</p><p class="paragraph" style="text-align:left;">You know that you are on my short list if your significant other knows that an inbound call from me means you are going to be busy for more than just the next few minutes.</p><div class="image"><img alt="Step Brothers Ryan GIF" class="image__image" style="" src="https://media0.giphy.com/media/WDn21GO1KmpNK/giphy-downsized.gif?cid=2450ec30146rga9u6o3gn0lrqpo905sgyrt822km7r28f0kc&ep=v1_gifs_search&rid=giphy-downsized.gif&ct=g"/></div><p class="paragraph" style="text-align:left;">I use these calls as a way to invest in my network, get second opinions, and create a trusted sounding board for my ideas. I hope I am not naïve with this statement, but I think my friends and professional connections receiving these calls feel similarly about their value, too.</p><p class="paragraph" style="text-align:left;">I haven’t performed a real investigative data analysis, but I would estimate these calls last no fewer than 25 minutes each and, I would argue the most important detail about these calls is to be free of distractions when we are engaging with each other. For me, I like to pop in my AirPods and go for a walk with Bear (the best pup) or make these calls when I know I have at least a 30-minute commute ahead of me — otherwise, IMO we would just text.</p><p class="paragraph" style="text-align:left;">Your network is an incredible asset, but you have to nurture and invest in it consistently.</p><p class="paragraph" style="text-align:left;">Your career will undergo several pivots over time, and I’ve found myself experiencing the same rush of excitement (read: terror) and uncertainty all over again similar to my first steps inside Corporate America.</p><p class="paragraph" style="text-align:left;">This time, however, I’m forging a new path, supported by a different network. As I navigate this period, one thing remains unchanged: your network is your net worth.</p><p class="paragraph" style="text-align:left;">David 🧠</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The power of a name</title>
  <description>Explained with help from Robert De Niro</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2d541a5-6b2d-4d1d-b05d-d482024ce697/Investor_Weekly_Newsletter.png" length="71284" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/power-name</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/power-name</guid>
  <pubDate>Wed, 29 May 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-05-29T12:00:00Z</atom:published>
    <dc:creator>David Forman 🧠</dc:creator>
    <category><![CDATA[Building In Public]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Total chaos.</p><p class="paragraph" style="text-align:left;">This first week, we had 32 meetings with customers, prospects, partners, and old friends extending from San Francisco to Dubai. The reception has been warm, lending to trace feelings of validation that the late nights and sacrificed weekends may have been worth it. 🤗</p><p class="paragraph" style="text-align:left;">There was one question, however, that appeared to recur throughout last week.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">It’s a fair question, and it made me smirk recalling the process from last October. If you ever find yourself in this position, this was my thought process.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ae2440d8-9fc5-4f32-954d-2f3157838326/Mastermind_is_Alive.JPEG?t=1716729564"/><div class="image__source"><span class="image__source_text"><p>the birth of mastermind</p></span></div></div><p class="paragraph" style="text-align:left;">Mastermind sells B2B cybersecurity and data protection assessments. If you are familiar with this field, Mastermind finds itself at the crossroads of the traditional accounting firm stereotype and SaaS-y technology (think images of a hacker wearing a black hoodie hunched over a computer).</p><p class="paragraph" style="text-align:left;">When reviewing the current players, a few methods stood out as inspiration for names of these companies.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;" id="group-1-founders-keepers">Group 1: Founders Keepers</h4><p class="paragraph" style="text-align:left;">The most recognized companies in global accounting are known as the “Big Four”: Deloitte, PwC, EY, and KPMG. And, the Big Four have a gap on basically everybody else, as 424 companies comprising the Fortune 500 hired the Big Four as their financial statements auditor of record in 2023.</p><p class="paragraph" style="text-align:left;">These are all rooted in what I call the <i>founders keepers</i> method for naming a company, which is essentially naming the company after yourself, your founding partners, or using the initials of these people.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/77b00ecc-4b43-4cd0-a021-198b90618e3b/image.png?t=1716663735"/><div class="image__source"><span class="image__source_text"><p>listing of the highest grossing accounting firms in 2024 with Big Four at the top</p></span></div></div><p class="paragraph" style="text-align:left;">Interestingly, only one firm within the top 10 is not named after a dead guy.</p><p class="paragraph" style="text-align:left;">At 9th, FORVIS, founded in June 2022, is a word intended to abbreviate their catchphrase “Forward Vision” — but, FORVIS was really only the merger of two preexisting accounting firms: Baird, Kurtz & Dobson (BKD) and Dixon Hughes Goodman. 🥴</p><p class="paragraph" style="text-align:left;">We steered clear of this naming method although “Forman & Co.” was enticing, or my initials “DLF” — last one did poorly in focus groups.</p><div class="image"><img alt="Oh My God No GIF by CBC" class="image__image" style="" src="https://media1.giphy.com/media/xk5vxDNaIhvzpWQzdT/giphy-downsized.gif?cid=2450ec30aviyu2dkhopqopkdqrckeye1cmj3kip83r6vgrh3&ep=v1_gifs_search&rid=giphy-downsized.gif&ct=g"/></div><h4 class="heading" style="text-align:left;" id="group-2-compound-words-compound-ret">Group 2: Compound Words = Compound Returns?</h4><p class="paragraph" style="text-align:left;">This second way of naming a company is leveraging word play (sometimes, literal compound words or combining two buzz words).</p><p class="paragraph" style="text-align:left;">Think of popular cloud companies like CrowdStrike, SecureWorks, OneTrust, Fortinet, Proofpoint, Cloudflare, SentinelOne, and even Microsoft.</p><p class="paragraph" style="text-align:left;">But, none of those are really iconic ✨, and you can easily forget the name after a brief first-time impression. I was looking for <b>staying power</b>.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><h4 class="heading" style="text-align:left;" id="group-3-consult-the-heavens">Group 3: Consult the Heavens</h4><p class="paragraph" style="text-align:left;">Brands like Nike, Pandora, Apollo Global Management, and Vulcan Materials each utilize Greek or Roman mythology as a starting point for their names to indirectly convey a company vision — it was difficult to locate many cybersecurity companies using this method but a fun one to investigate nonetheless.</p><h4 class="heading" style="text-align:left;" id="group-4-trailblazers">Group 4: Trailblazers</h4><p class="paragraph" style="text-align:left;">And, the last group is simply the GOAT when it comes to defining a category to such an extent that their brand eventually is synonymous with the product or service it provides. </p><p class="paragraph" style="text-align:left;">Attorneys refer to this group of names as “genericized trademark” or “proprietary eponym”. Terms like escalator, dumpster, and yo-yo were all originally a company or product name trademarked by the private sector before evolving into the public domain.</p><p class="paragraph" style="text-align:left;">Modern day, we are seeing genericization with Google (to perform an internet search), Photoshop (digital image editing), and Taser (electric shock weapons).</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">So, with all that background on <i>how</i> we used this context to choose the name, <i>why</i> did we actually name it Mastermind?</p><h4 class="heading" style="text-align:left;" id="the-verdict">The Verdict</h4><p class="paragraph" style="text-align:left;">Our indirect competitors’ names are either the founder’s name or some acronym that no one understands except the token HR person doubling as the in-house, company historian.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/339f7e0f-66d7-4bf1-bc98-988e4f0a5a52/Competition.jpg?t=1716664848"/><div class="image__source"><span class="image__source_text"><p>some of the competition</p></span></div></div><p class="paragraph" style="text-align:left;">We landed on Mastermind for a few reasons:</p><ol start="1"><li><p class="paragraph" style="text-align:left;"><span style="font-family:Times New Roman;font-size:7pt;"> </span>It was memorable. Most of our competition more-or-less resembles each other — poor differentiation.</p><p class="paragraph" style="text-align:left;"></p></li><li><p class="paragraph" style="text-align:left;">Gives off the impression of best-in-class, high quality, expertise</p><p class="paragraph" style="text-align:left;"></p></li><li><p class="paragraph" style="text-align:left;">The domain name for Mastermind Assurance was available. Take that, squatters.</p><p class="paragraph" style="text-align:left;"></p></li><li><p class="paragraph" style="text-align:left;">Tons of opportunities for word play while building the brand (big-brained, brainiac, masterclass, cerebral, think week…)</p><p class="paragraph" style="text-align:left;"></p></li><li><p class="paragraph" style="text-align:left;">Most importantly, the name contains <i>hidden meaning</i> related to our charter: to raise awareness and make masterminds of our customers, employees, and partners with the long-term goal of improving the utility of these frameworks (i.e., ISO standards) throughout the marketplace.</p><p class="paragraph" style="text-align:left;"></p></li></ol><p class="paragraph" style="text-align:left;">And, call it founder’s bias, but <b>Mastermind</b> sounds cool. Try saying it fast 3 or 4 times in a row — rolls off the tongue. 😙🤌</p><div class="image"><img alt="Season 5 Nbc GIF by The Office" class="image__image" style="" src="https://media4.giphy.com/media/dXFKDUolyLLi8gq6Cl/giphy-downsized.gif?cid=2450ec30i4cczzfd17wzcx1nh567ttpxo14hgdt31font9iq&ep=v1_gifs_search&rid=giphy-downsized.gif&ct=g"/></div><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">I had a phone call with my Dad on Friday night, and I explained to him that this sector is tenured now and saturated with the accountant/auditor stereotypes. Yet, the ICP, or Ideal Customer Profile, has evolved to fledging tech companies, predominantly staffed with fresh graduates in their 20s who are products of the iPad generation.</p><p class="paragraph" style="text-align:left;">It’s an odd juxtaposition where the audit side of the industry has not yet caught up with its target customer base.</p><p class="paragraph" style="text-align:left;">It reminds me of that scene in <i>The Intern</i> movie with Robert De Niro, where he plays Ben, a retired 70-year-old. He gets a job as an intern at an online fashion start up. </p><p class="paragraph" style="text-align:left;">The below clip shows the disparity between Ben during his first day at the start up amongst a sea of developers in an open office workplace – Ben showing up in his suit and tie is a hilariously accurate analogy of the contrast between the average auditor and the people that these auditors are expected to connect with on a daily basis.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5213972f-eb2a-407b-be50-9cc7ff3647c9/The_Intern__Full_Movie_Preview__Warner_Bros._Entertainment_-_6519971716663148.gif?t=1716663192"/><div class="image__source"><span class="image__source_text"><p>the chances that these seatmates want to get a drink with Ben after work are low</p></span></div></div><p class="paragraph" style="text-align:left;">Ben is a fish out of water. But, this is not Ben’s fault. He’s showing up in the way he always has, and this conduct is not up-to-date with the company he finds himself working at.</p><p class="paragraph" style="text-align:left;">It’s Sales 101 that people want to buy from other people that remind them of themselves or what they aspire to be — it’s the basis for why people that share common interests form trust, rapport, familiarity, and relatability more easily.</p><p class="paragraph" style="text-align:left;"><b>Mastermind </b>is an audit company, but it should not look, talk, or feel like your average auditor. In fact, we are building something iteratively different.</p><p class="paragraph" style="text-align:left;">David 🧠</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Fake it till you make it</title>
  <description>Why we chose to build in public.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2d541a5-6b2d-4d1d-b05d-d482024ce697/Investor_Weekly_Newsletter.png" length="71284" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/fake-till-make</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/fake-till-make</guid>
  <pubDate>Wed, 22 May 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-05-22T12:00:00Z</atom:published>
    <dc:creator>David Forman 🧠</dc:creator>
    <category><![CDATA[Building In Public]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">It’s launch week.</p><p class="paragraph" style="text-align:left;">Almost 200 days ago, the first steps towards creating <b>Mastermind</b> and making it a reality started to take shape.</p><p class="paragraph" style="text-align:left;">I quit my job of 7 years last month and took a trip to Uruguay with my wife Tori to get lost. My mind had been racing nonstop since deciding to move forward with Mastermind – I needed a <b><i>think week</i></b>. </p><p class="paragraph" style="text-align:left;">Think weeks slow down life and act like a pop up blocker to the daily routines that demand my attention. Think weeks are when I finally obtain stillness — and, in these moments, I form my best ideas.</p><p class="paragraph" style="text-align:left;">From time-to-time, teasers to these think weeks show up while taking a shower or during a long drive in the car but starting a business required several days of uninterrupted deep work.</p><p class="paragraph" style="text-align:left;">To give the setting, this first newsletter was written while spending the prior few days mentally resetting and hunkering down in Faro de José Ignacio, Uruguay. There are no direct flights to Uruguay from the United States. Once you connect by plane into the capital city of Montevideo, you have to rent a car and then drive 2 hours towards the border of Brazil to this fishing village that more recently has gained popularity with vacationers from Argentina. </p><p class="paragraph" style="text-align:left;">May is one of the dullest travel months for this area which led to Tori and me being the only guests at this small inn throughout our stay. Each day, I would take my laptop down to the library of the hotel, sit by the wood-burning fireplace and indulge in the world’s darkest coffee roast to the background effects of 40 mph wind gusts and crashing ocean waves — <b>I had found my think week.</b></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f0cdbee7-24f3-4e0b-88be-ab878eece3c2/IMG_0792.JPEG?t=1715866835"/><div class="image__source"><span class="image__source_text"><p>Posada del Faro in Jose Ignacio, the site of some big-brained moments last week</p></span></div></div></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;"><i>Building in public</i> is not a novel idea but I have only seen it tried a few times. For it to be effective, it requires near total transparency and a rigid schedule of updates. Treat the readers as investors in the company, and give them access to semi-private data points as if they were employees.</p><p class="paragraph" style="text-align:left;">The primo example of building in public is Tyler Denk, the founder of <a class="link" href="http://www.beehiiv.com?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=fake-it-till-you-make-it" target="_blank" rel="noopener noreferrer nofollow">beehiiv</a>, the platform used to send this exact email and that competes with juggernauts like Mailchimp and Substack. Tyler and I are not connected (yet) but I feel that I know his vision for beehiiv on a personal level thanks to the openness he has communicated to his followers through his newsletter. </p><p class="paragraph" style="text-align:left;">beehiiv is nearing $10M ARR and announced its Series B just last month. If you like this style of entrepreneurship, I recommend you subscribe to Tyler’s newsletter <b>Big Desk Energy</b> linked below. 👇</p><div class="recommendation"><figure class="recommendation__logo"><img alt="Big Desk Energy" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/42a3ec75-e696-48fc-8fd5-ab11bc0dd08a/bde.png"/></figure><h3 class="recommendation__title"> Big Desk Energy </h3><p class="recommendation__description"> startup insights, stories, and vibes sent to your inbox every Tuesday </p><a class="recommendation__link" href="https://magic.beehiiv.com/v1/42a3ec75-e696-48fc-8fd5-ab11bc0dd08a?recommendation_id=2e6045f2-d67c-4136-9eb2-031471ed0cb8&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=fake-it-till-you-make-it"> Subscribe </a></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><h4 class="heading" style="text-align:left;">Building in Public</h4><p class="paragraph" style="text-align:left;"><b>Lesson #1: You are the company, and the company is you. </b></p><p class="paragraph" style="text-align:left;">Previously, if you made a mistake, you have the air cover of a bigger machine that guarantees payroll every two weeks. Now, the company is a reflection of what you put into it.</p><p class="paragraph" style="text-align:left;">Suddenly, work is very personal.</p><p class="paragraph" style="text-align:left;">It is not only gambling on your knowledge and your ability to succeed. It is betting that you can create something iteratively different and that the customers within your target market even want something different.</p><p class="paragraph" style="text-align:left;">A good friend (CG) shared this quote, and it captures the essence of this phase of building that I refer to as the <i>fake it till you make it </i>stage.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">Call it assembling the plane while you are flying it, or whatever.</p><p class="paragraph" style="text-align:left;">This shit is hard.</p><p class="paragraph" style="text-align:left;">These last few months and in states of panic, I attempted to isolate what exactly was unnerving about starting Mastermind. My anxiety was not rooted in one specific thing, but rather an unconsciousness, or, better said, the things that I did not know I needed to be worrying about.</p><ul><li><p class="paragraph" style="text-align:left;">S-Corp vs. C-Corp vs. Single-Member LLC but the last one is a “disregarded entity”</p></li><li><p class="paragraph" style="text-align:left;">Do I need a registered address or can my house be the principal location?</p></li><li><p class="paragraph" style="text-align:left;">How do I decide on a color palette and a brand guide?</p></li><li><p class="paragraph" style="text-align:left;">Why did Chase bank only give me a $3,000 credit card limit?!</p></li></ul><p class="paragraph" style="text-align:left;">Building in public is about sharing the behind-the-curtains moments. When things look well-constructed, this open newsletter format shows readers the Instagram vs. reality.</p><p class="paragraph" style="text-align:left;">The company launch video required 3 weeks of edits with a designer in India. Completely worth it, but sending ACH payments over Wise when Mastermind has no revenue is not for the faint of heart.</p><p class="paragraph" style="text-align:left;">Other expenses you can expect if you decide to take the founder’s plunge:</p><ul><li><p class="paragraph" style="text-align:left;">GoDaddy/WordPress: $239</p></li><li><p class="paragraph" style="text-align:left;">Letterhead: $420 (designer in Pakistan)</p></li><li><p class="paragraph" style="text-align:left;">Swag: $554 😎</p></li><li><p class="paragraph" style="text-align:left;">QuickBooks: $622</p></li><li><p class="paragraph" style="text-align:left;">Registration Fees: $624</p></li><li><p class="paragraph" style="text-align:left;">beehiiv: $767</p></li><li><p class="paragraph" style="text-align:left;">Insurance: $2,723</p></li><li><p class="paragraph" style="text-align:left;">Website Design: ~$4,000 (developer in Indonesia)</p></li><li><p class="paragraph" style="text-align:left;">Professional Association Membership: $5,000</p></li></ul><p class="paragraph" style="text-align:left;">The above is a tiny sample of these initial expenses. As of this writing, we’ve spent $35,000+ starting this thing before collecting our first dollar.</p><p class="paragraph" style="text-align:left;">But, we did it. </p><p class="paragraph" style="text-align:left;">It’s here, and it’s launch week.</p><div class="image"><img alt="The Daily Show Boom GIF" class="image__image" style="" src="https://media4.giphy.com/media/mks5DcSGjhQ1a/giphy.gif?cid=2450ec30e1hdc85e203alquu1nyax8ubvo9au2tfubdev9rv&ep=v1_gifs_search&rid=giphy.gif&ct=g"/></div><p class="paragraph" style="text-align:left;">Whether you are a personal friend, an old coworker, a customer, a competitor, my parents, or you stumbled across this newsletter on your LinkedIn feed amongst so many <i>truly humbled</i> connections, thanks for giving a shit.</p><p class="paragraph" style="text-align:left;">Now, let’s go make a million bucks.</p><p class="paragraph" style="text-align:left;">David 🧠</p></div><p class="paragraph" style="text-align:left;"></p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>There&#39;s a standard for that!</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ee2732e0-ce2e-46df-9e63-8e5d85b9d89b/Picture9.png" length="339749" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/theres-standard</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/theres-standard</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">ISO standards are all around us, and it&#39;s overwhelming to comprehend the sheer scale that these documents have embedded themselves into our everyday movements.</p><ul><li><p class="paragraph" style="text-align:left;">Interested in fair trade chocolate? There’s a standard for that – <a class="link" href="https://www.iso.org/standard/64765.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=there-s-a-standard-for-that" target="_blank" rel="noopener noreferrer nofollow">ISO 34101</a>.</p></li><li><p class="paragraph" style="text-align:left;">Required to submit CPE every few years to maintain that license? <a class="link" href="https://www.iso.org/standard/52993.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=there-s-a-standard-for-that" target="_blank" rel="noopener noreferrer nofollow">ISO 17024</a> is to thank.</p></li><li><p class="paragraph" style="text-align:left;">Not sure about scanning that QR code to pay for parking? <a class="link" href="https://www.iso.org/standard/69266.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=there-s-a-standard-for-that" target="_blank" rel="noopener noreferrer nofollow">ISO 37180</a> wants to enforce minimum security requirements for QR technologies impacting consumers.</p></li><li><p class="paragraph" style="text-align:left;"><span style="font-family:Times New Roman;font-size:7pt;"> </span>And, a long-time favorite, <a class="link" href="https://www.iso.org/standard/70907.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=there-s-a-standard-for-that" target="_blank" rel="noopener noreferrer nofollow">ISO 8601</a> thinks that the first day of the week is Monday – mainly to provide consistency across systems and regions where the representation of dates and times is critical.</p></li></ul><p class="paragraph" style="text-align:left;">In fact, ISO has published over 25,000 standards, crossing this milestone for the first time in 2023.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/381ce5fd-426e-4a6d-906c-bf8ff4c6545d/Picture1.png?t=1705267743"/><div class="image__source"><span class="image__source_text"><p>Toblerone was forced to drop its logo of the Matterhorn in 2022 after it moved its production facilities to Slovakia putting the iconic image in violation of the Swissness Act designed to combat selling counterfeit Swiss products.</p></span></div></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">It’s similar to the experience when you first discovered that there is an image hidden within a recognizable image you encounter daily, such as a popular brand logo like Toblerone (find the bear). Or, even a third meaning beyond the second image – that bear is a nod to Bern, Switzerland known as the “City of Bears”.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">ISO standards, in many respects, act as an invisible hand, but they have far less sinister intentions than a Big Brother seemingly perpetually surveilling you. As the name suggests, ISO is the International Organization for <b>Standardization</b>. Think consistency, repeatability, calibration. These are all positive attributes when attempting to define or mature processes, systems, and products that require interdepartmental, intercompany, and cross-border collaboration.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/50607f99-5c36-48da-9490-14f51630e140/Toy_Story.gif?t=1708351784"/></div><p class="paragraph" style="text-align:left;">According to its website, ISO “brings global experts together to agree on the best ways of doing things, from making products to managing processes.”</p><p class="paragraph" style="text-align:left;">As a group of experts in our subject matter, it is wise for us not only to be aware when these standards are at play but also to investigate the meaning behind the content and its defined boundaries to avoid ghost requirements. Commonly, we refer to this practice as understanding the source material.</p><p class="paragraph" style="text-align:left;">For us to be students of the text, we need to know not only all layers of the requirements (more on that in the future) but by whom so we can learn their backgrounds and incentives.</p><p class="paragraph" style="text-align:left;">By learning these behind-the-curtain topics, we will combat the trend of checkbox auditors and practitioners akin to soldiers blindly following their general into danger.</p><p class="paragraph" style="text-align:left;">Stay tuned.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>How do you pronounce ISO?</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/801bcebb-8a95-4ca7-abda-b877c1e9c5d6/Picture8.png" length="351326" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/pronounce-iso</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/pronounce-iso</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">In our quest to understand the source material behind ISO standards, let’s start with the very basics: what do we mean when referencing ISO?</p><p class="paragraph" style="text-align:left;">ISO is an acronym for the International Organization for Standardization. Contrary to popular understanding, “ISO” was never short for “International Standards Organization” or a similar sequence of words, even in an alternate language than English. Commonly, American practitioners will say that the long name of ISO translates into a phrase that can be abbreviated as “ISO” in the French language due to the location of the Central Secretariat, but the acronym would actually be “OIN,” short for “Organisation internationale de normalisation,” so that argument lacks validity.</p><p class="paragraph" style="text-align:left;">And, if you want to argue the short name should be “IOS”– well, you will lose that battle too, as ISO has selectively registered “International Organization for Standardization” and the short name “ISO” as international trademarks while omitting registration of any other acronym variation.</p><p class="paragraph" style="text-align:left;">If you are the type that spells out the acronym as I-S-O when talking about the entity or describing a standard like ISO 27001, the origins of the name will give you a clue on how to pronounce it. ISO is derived from the Greek “isos,” meaning equal. From here, it is plausible to think that the organization intended for the short name to be pronounced as a single word like “eye-so.”</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/31064137-9cef-48ef-8e80-e62d34ef1b3b/ISO_Headquarters.jpg?t=1705870324"/><div class="image__source"><span class="image__source_text"><p>ISO world headquarters in Geneva, Switzerland</p></span></div></div><p class="paragraph" style="text-align:left;">Let’s triple confirm. Here is a <a class="link" href="https://youtube.com/clip/Ugkx7h4bTLG1wwhr5w_Ywk9xEg9fW5568JWs?si=-55IDH6MkbVgCl2S&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=how-do-you-pronounce-iso" target="_blank" rel="noopener noreferrer nofollow">10-second clip</a> from the 2023 ISO Annual Meeting in Brisbane. This is Vanessa Von der Mühll, who has been Head of Communications and Engagement at ISO for the past 4 years.</p><h4 class="heading" style="text-align:left;" id="debunked-buckle-up">Debunked? Buckle up.</h4><p class="paragraph" style="text-align:left;">From an interview published in 1997 with Willy Kuert, a Swiss delegate who had traveled to London in 1946 to attend the meetings that originally formed ISO, he details the following:</p><p class="paragraph" style="text-align:left;">“The first question that had to be settled in London was that of the name of the new organization. There were different proposals. The English and the Americans wanted “International Standards Coordinating Association,” but we fought against the word “coordinating.” It was too limited. In the end, ISO was chosen. I think it is good; it is short. I recently read that the name ISO was chosen because “iso” is a Greek term meaning “equal.” There was no mention of that in London!”</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8a9861b9-61a9-4fb5-b89b-835ccb76acb9/familyguy.gif?t=1708352073"/></div><p class="paragraph" style="text-align:left;">And, it appears we are back to our starting point. We may never know the original intent of the name, as modern-day ISO seems to be romanticizing the importance of the short name selection. This is probably a case of picking the name because it <a class="link" href="https://www.youtube.com/watch?v=rbfcvF1smKA&t=13s&utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=how-do-you-pronounce-iso" target="_blank" rel="noopener noreferrer nofollow">sounded cool</a>.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>What, or rather who, is ISO?</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6f0017f8-51f7-4a59-b214-81c2d8054907/Picture7.png" length="345849" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/rather-iso</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/rather-iso</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">Let’s shed light on this somewhat closed-door organization, giving it a reputation akin to that of the <i>Knights Templar </i>or the <i>Freemasons.</i></p><p class="paragraph" style="text-align:left;">From its website, ISO is an independent, non-governmental international organization with a membership of 169 national standards bodies. ISO was officially formed over 75 years ago in London at the Institute of Civil Engineers during a conference of national standardizing organizations spanning two weeks from October 14 to October 26, 1946. Its headquarters, or the location of the “Central Secretariat,” would not move to Geneva until 1949.</p><p class="paragraph" style="text-align:left;">When ISO was first formed, it happened immediately following the conclusion of the Second World War—an era where the winners of the world war were restructuring international participation and heavily influencing who would have a seat at the table. In fact, ISO originally blocked the membership of any delegates represented by neutral or Axis countries.</p><p class="paragraph" style="text-align:left;">The formation of ISO was the unity of two preexisting bodies – The International Federation of the National Standardizing Associations (ISA) established in 1926 out of New York, and the United Nations Standards Coordinating Committee (UNSSC), which formalized two years earlier in 1944 with operations out of London.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/89d64260-5cb5-46c5-bacc-6f5c4ab790e3/2012_the-iso-story_bw-1.png?t=1705877096"/><div class="image__source"><span class="image__source_text"><p>25 countries were represented by 65 delegates at the London meetings that formed ISO in 1946.</p></span></div></div><p class="paragraph" style="text-align:left;">From the memoir &quot;<a class="link" href="https://www.iso.org/files/live/sites/isoorg/files/about%20ISO/docs/en/Friendship_among_equals.pdf?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=what-or-rather-who-is-iso" target="_blank" rel="noopener noreferrer nofollow">Friendship Among Equals</a>,&quot; the last surviving delegate of these London meetings was Willy Kuert. In a 1997 interview, he recalled, “The atmosphere at first was a bit uncertain! We were sizing each other up. We feared that the UNSCC didn’t want an organization like the ISA had been, but an organization which was dominated by the winners of the war. We wanted to have an organization open to every country that would like to collaborate, with equal duties and equal rights. The inch system and the metric system were also constantly at the back of our minds. There was an inch bloc and a metric bloc. We didn’t talk about it. We would have to live with it. But we hoped that ISO might provide a place where we could get consensus in this area.”</p><h4 class="heading" style="text-align:left;" id="modern-day-iso">Modern Day ISO</h4><p class="paragraph" style="text-align:left;">Today, while there are fewer than 200 full-time, directly employed staff at ISO, there are thousands of volunteers and experts comprising the 169 bodies or “members,” further broken down into three tiers: member bodies, correspondent members, and subscriber members. Member bodies maintain voting rights, while correspondent members have more limited privileges, such as observing standards development meetings only, and subscribers are notified on an informed basis post-meeting.</p><p class="paragraph" style="text-align:left;">From a standards development perspective, there are 800+ technical committees and subcommittees in operation across a range of subject matters, including information technology, health, transportation, sustainability, energy, diversity and inclusion, food, engineering, and government. China, France, Germany, United Kingdom, Japan, and Korea lead among all active member bodies as the most participatory within these technical committees.</p><p class="paragraph" style="text-align:left;">It is important to note which countries are influencing standards today at the highest levels, as these are the same delegates that are calibrating and determining global requirements and rules for critical processes, such as artificial intelligence management, data privacy, and cybersecurity.</p><p class="paragraph" style="text-align:left;">For example, the joint technical committee (JTC) 1 is chaired by ANSI, the United States member body, via Phil Wennblom, an executive with Intel. JTC 1 is responsible for authoring the current revision of ISO 27001 for information security management systems.</p><p class="paragraph" style="text-align:left;">We will dive deeper into JTC 1 and its subcommittees (SC), especially <a class="link" href="https://www.iso.org/committee/45306.html?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=what-or-rather-who-is-iso" target="_blank" rel="noopener noreferrer nofollow">SC 27</a>, in future discussions due to this group’s heavy focus on development of the ISO 27000 series.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>You&#39;ll get breached if you implement ISO 27001</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/20584b6a-7c42-4ce8-bf9b-4bcae6e878b1/Picture6.png" length="338260" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/youll-get-breached-implement-iso-27001</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/youll-get-breached-implement-iso-27001</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">Wait a second. We were told that implementing and certifying to ISO 27001 was <i>best</i> practice when considering benchmarks for information security.</p><p class="paragraph" style="text-align:left;">In theory, it can be considered best practice, but only if your organization rigorously follows the governance aspects outlined in this International Standard. Let us explain.</p><p class="paragraph" style="text-align:left;">Your opinion might differ, but it&#39;s crucial to highlight that the single most important requirement when setting up your management system for the first time is outlined in section 6 of this standard.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2e088da7-b166-4b52-84b1-ecea6a704f47/Spaceballs.gif?t=1708351622"/></div><p class="paragraph" style="text-align:left;">Let’s use the above requirement in the context of passwords. Every system and application had some form of authentication mechanism with the most common example being a username + password combo. If we take ISO 27001 at face value without applying the governance elements of section 6.1.3, this “best practice” standard states only the following:</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">That’s it. Those are the only requirements around “authentication”. In fact, the keyword “password” is not mentioned anywhere in the 2022 revision of ISO 27001, which actually might be forward-looking by JTC 1 since we are quickly moving to password-less authentication. In reality, technology frequently outpaces these standards as they do not receive major revisions but approximately once per decade.</p><p class="paragraph" style="text-align:left;">For instance, an organization can meet both controls by implementing a policy specifying password requirements, such as an 8-character length using letters only and enforcing this configuration for all users. The policy does not have to address complexity, rotation, or prohibiting the use of recent passwords by the same user.</p><h4 class="heading" style="text-align:left;" id="supplemental-guidance-from-iso-2700">Supplemental Guidance from ISO 27002</h4><p class="paragraph" style="text-align:left;">If we look for further information, ISO 27002 says “when passwords are used as authentication information, strong passwords according to best practice recommendations are selected.” This standard goes onto to provide examples by stating not to use personal information (e.g., date of birth) or dictionary words in a password while suggesting the use of “easy to remember passphrases and try to include alphanumerical and special characters” while ensuring passwords have a minimal length.</p><p class="paragraph" style="text-align:left;">At first glance, this seems to be basic password security, but even when considered collectively, it still raises questions. Why are we encouraging an “easy to remember passphrase”? That recommendation does not scream security.</p><p class="paragraph" style="text-align:left;">Additionally, “alphanumerical” – in other words, a combo of letters and numbers – should not be a “try” but a must at all costs when that password is protecting unauthorized access to any system containing even the lowest levels of sensitive data.</p><p class="paragraph" style="text-align:left;">Even if ISO 27002 had some defensible criteria, this standard is informative (i.e., guidance) only and is not required to be implemented by an organization seeking ISO 27001 certification.</p><p class="paragraph" style="text-align:left;">However, if you were to re-read these control statements under the perspective of section 6.1.3 where the standard states controls should be applied while “taking account of the risk assessment results” then these controls inherit a completely different flavor. Now, we have to consider what these authentication mechanisms are protecting, such as the data stored within the systems being authenticated through this form of access control. If there is customer data in these systems, as an example, then an auditor can say that your organization may have met the most minimal requirements for authentication, but it failed to consider the risks of unauthorized access when designing its authentication policies and procedures.</p><p class="paragraph" style="text-align:left;">This theme is just the tip of the iceberg. Following the risk will be a recurring theme as we delve deeper into the common pitfalls of implementing these global frameworks.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Tales from the front lines... with some added drama</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bf05199e-73ea-46e1-9e03-75315f2cce6b/Picture5.png" length="345772" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/tales-front-lines-added-drama</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/tales-front-lines-added-drama</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">It&#39;s 8:30 in the morning, and you and your coworkers are already in the office, venti-sized coffees in hand, ready to start. The team is never in the office anymore, and certainly not this early. Jason is out of character, seemingly rehearsing lines as if he is about to audition for a play, all while knowing he will be responsible for walking through employee onboarding evidence this morning.</p><p class="paragraph" style="text-align:left;">You&#39;ve circled the dates on your calendar for months, and then they arrive. Like a scene out of the 1999 film Office Space, the Bobs walk into the building&#39;s front entrance. You can see them from the window of the boardroom. The executives always claim this conference room, but they feel bad for the team that is about to sit through 4 days of interrogation.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c748a898-708c-4884-8b39-f5cdacdd3a60/Auditor_Bobs.jpg?t=1705879640"/><div class="image__source"><span class="image__source_text"><p>This story’s antagonists, our road warriors</p></span></div></div><p class="paragraph" style="text-align:left;">Maddie notices that the auditors are dressed in suits and ties. Did no one tell them that the company’s name is “Field Day”? Most of the staff comes to the office in athletic wear. Immediately, an inferiority complex creeps in, and the team starts flipping through their printout of the standard, wondering if workplace attire could be a finding.</p><p class="paragraph" style="text-align:left;">The part-time receptionist is stuttering her words. You sat down with her 15 minutes earlier and walked her through the exact procedure she should have been following for the last 3 years of her employment. One hello, two who are you here to see, three can I see some ID, and four please follow the prompts on the iPad to complete sign-in. The door is open to the conference room, and you all sit quietly, acting like you are working on your laptop but actually hoping the weakest link in the chain doesn’t misstep before the audit opening meeting can even take place.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">The Bobs chuckle. Phew, looks like they have some humor and semblance of humanity to them. We are off.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">Jason hears the question and vaults his arm to the sky to wave at Bob 1 and Bob 2. Bob 1 returns a one-finger wave and tells the receptionist that it is that group in the conference room.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">Of course, they are on your list. She pretends to click on her monitor while the Bobs are hovering over the ledge of the front desk.</p><p class="paragraph" style="text-align:left;">Bob 1 shows his driver’s license. Bob 2 pulls out an employee badge with a picture and name issued by his company.</p><p class="paragraph" style="text-align:left;">Curveball. Is this some type of test? Why did Bob 2 not show a driver’s license or maybe, and I mean maybe, a passport? Can we accept that employee badge as a form of identification?</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">Bob 2 returns a smirk to Bob 1 before returning his employee badge to his wallet.</p><p class="paragraph" style="text-align:left;">Dang it, we got played. Was this a stress test? Is that in-scope? Are you really going to issue a finding to our part-time receptionist? She might actually cry.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Who audits the ISO auditors?</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/481c836a-8c3d-4443-ac6c-46a988659060/Picture4.png" length="346986" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/audits-auditors-fc43</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/audits-auditors-fc43</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">Every year, you hear about how an organization can prepare for ISO 27001 down to the sub-requirement level, but then bam! They get hit with some random topic chosen by their auditor on a whim – maybe it’s a flavor of the day.</p><p class="paragraph" style="text-align:left;">And let&#39;s talk about auditors—they have this stereotype. They&#39;re seen as these compliance police carrying a quota of findings just to prove they did a thorough job. It&#39;s the reason why organizations, especially the mature ones, start getting frustrated when auditors are wrapping up and suddenly decide to dive deep. You&#39;re there, pointing to the same policy they&#39;ve checked three times already, and then, out of the blue, it&#39;s like they&#39;ve had a revelation. That annual user access review? Apparently, it&#39;s not &quot;frequent enough&quot; anymore, and now they&#39;re quoting ABC framework and some benchmark from their other clients. Hold up, are we being audited for more than just ISO 27001?</p><p class="paragraph" style="text-align:left;">It&#39;s in these moments that irritation kicks in. It&#39;s like they&#39;re playing a game of &quot;moving the goalposts.&quot; You thought you had the rules down, but in the blink of an eye, everything changes.</p><h1 class="heading" style="text-align:left;">So, who is auditing these auditors?</h1><p class="paragraph" style="text-align:left;">In the world of ISO management system standards, a hierarchy of command is most simply expressed as follows:</p><p class="paragraph" style="text-align:left;">An auditor may be part of an audit team overseen by a Lead Auditor.</p><p class="paragraph" style="text-align:left;">The Lead Auditor ultimately determines a recommendation for certification, which is then passed off to a review committee within the Certification Body.</p><p class="paragraph" style="text-align:left;">The Certification Body follows its own internally developed procedures in conformance with ISO/IEC 17021-1 and undergoes regular assessments to this standard by an Accreditation Body.</p><p class="paragraph" style="text-align:left;">An Accreditation Body is a member of a larger group of accreditation oversight entities formed under mutual recognition practices of the International Accreditation Forum.</p></div><p class="paragraph" style="text-align:left;">If your organization finds itself in a situation involving not necessarily a challenging auditor but an unfair assessor, there&#39;s a way out. First off, check if that auditor is the Lead Auditor assigned to the project. If not, appeal any finding where there&#39;s a disagreement with the actual Lead Auditor, and if you want to be particularly tactful, phrase it as a request for the Lead Auditor to take a second look.</p><p class="paragraph" style="text-align:left;">Now, if the Lead Auditor is the issue, ask for information on the appeals process owned by the certification body they represent. In theory, the appeals process should be communicated during the audit closing meeting, but we&#39;ve known some seasoned auditors to conveniently forget to mention it when they think an auditee might try to escalate an issue they&#39;d rather put to bed.</p><p class="paragraph" style="text-align:left;">Filing an appeal with the representing certification body gives you a chance to present your case to a new set of appointees from the certification body for their opinion. Note that it&#39;s rare for the certification body to overturn a determination from its lead auditor staff. They usually lean on the additional time the lead auditor has spent learning your system over the abbreviated meeting they had with you as the appellant. To successfully overturn a finding, objective evidence is your best friend. Our experience shows that a mutually beneficial appeal involves a clear misunderstanding by the audit team when applying the requirement to the client’s management system or possibly an omission of evidence (e.g., reviewing the wrong evidence item, but conformity evidence did actually exist).</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e6a316a6-8d32-4dfc-adaf-7a9cceab8861/the-office.gif?t=1708350964"/><div class="image__source"><span class="image__source_text"><p>*not a pyramid</p></span></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">To bring it to life, let&#39;s go back to the scene in <span style="color:red;"><a class="link" href="https://intel.mastermindassurance.com/p/tales-front-lines-added-drama?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=who-audits-the-iso-auditors" target="_blank" rel="noopener noreferrer nofollow">Audit Nightmares #1</a></span>. Bob 2 might have a case to issue a physical security or visitor sign-in procedure finding to our fictitious company “Field Day”. However, Field Day may be able to defend their procedure. Does their policy explicitly require government-issued identification to be presented to the front desk receptionist, or does it only state a photo ID? If it&#39;s the latter, the employee badge that Bob 2 presented seems sufficient to conform to the documented process.</p></div><p class="paragraph" style="text-align:left;">So, does Bob 2 then tag the finding to the policy itself, stating that the policy is insufficiently written to address the underlying risk? If he goes this route, we now get into a situation where the burden of proof is on Bob 2 to demonstrate how a physical security risk is exposed by the presumably insufficient control language.</p><p class="paragraph" style="text-align:left;">In short, it can be a headache, but knowing your options as an auditee will at least give you some ground to stand on when facing a situation that feels unfair or like a stretch of a requirement.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The clock to transition to the new revision already started.</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/03327330-d57a-436b-ac26-dc784d159d63/Picture3.png" length="340326" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/clock-transition-new-revision-already-started</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/clock-transition-new-revision-already-started</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">On October 25, 2022, the first <a class="link" href="https://www.iso.org/standard/27001?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=the-clock-to-transition-to-the-new-revision-already-started" target="_blank" rel="noopener noreferrer nofollow">major revision</a> to the popular ISO 27001 standard in almost 10 years was published, triggering the simultaneous withdrawal of the longstanding 2013 revision.</p><p class="paragraph" style="text-align:left;">While revisions to these standards are not uncommon, the transition periods that follow these releases vary depending on the extent of the changes to the underlying criteria and organizational circumstances, such as whether a scope is currently certified or at an earlier pre-decision and award issuance stage via a certification body.</p><p class="paragraph" style="text-align:left;">Make no mistake – this release meets the eye test for qualifying as a major revision, as the entire structure of the standard has been renewed to the latest Annex SL outline variant known as the Harmonized Structure (HS). Similarly, a consolidation of the previous 114 Annex A controls was implemented alongside the introduction of 11 net new controls. The result is a new look for this standard with a modern control set tackling more current risks (e.g., threat intelligence, IoT, IAM) affecting service organizations operating within public cloud.</p><p class="paragraph" style="text-align:left;">To guide this transition or upgrade from the prior 2013 revision to the 2022 revision of the standard, the International Accreditation Forum (IAF) published its instructions in the form of Mandatory Document (MD) 26 approximately 90 days before the release of ISO/IEC 27001:2022. However, once the standard was published, feedback from accreditation bodies (e.g., ANAB, IAS, UKAS) resulted in a revision to <a class="link" href="https://iaf.nu/iaf_system/uploads/documents/IAF_MD26_Issue_2_15012023.pdf?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=the-clock-to-transition-to-the-new-revision-already-started" target="_blank" rel="noopener noreferrer nofollow">IAF MD 26</a>, extending some of these transition timelines. </p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2ccb33de-e1a6-4d44-94a7-133a1a2010fc/Picture_1.png?t=1706475187"/><div class="image__source"><span class="image__source_text"><p>When seeking out the source on these transition timelines, ensure you are inspecting Issue 2 published on February 13, 2023 – you can find this publication date within the footer of each page of this MD.</p></span></div></div><p class="paragraph" style="text-align:left;">Let’s get to the brass tax.</p><ol start="1"><li><p class="paragraph" style="text-align:left;">If your organization is pursuing certification for the first time to ISO 27001, you can continue using ISO/IEC 27001:2013 through <b>April 30, 2024</b>; however, after that date, all certificate decisions for ISO 27001 have to be against ISO/IEC 27001:2022. <br><br><b>Note:</b> This is a decision date for certification, so please consider quality review processes and lead times required by the certification body before your organization schedules its initial certification to the old revision of the standard. It is wise to transition to the new revision (2022) now versus flirting with this hard deadline where your certification body does not have the authority to provide exceptions or extensions.<br><br></p></li><li><p class="paragraph" style="text-align:left;">Likewise, for all currently certified scopes that are due for a recertification audit, that recertification audit must be decided on or before <b>April 30, 2024</b>, as well, if the organization intends to remain on the 2013 revision. Again, please initiate the discussion early with your certification body to ensure there is no risk to the schedule affecting both your live audit and auditor’s reporting timelines if you intend to remain on the 2013 revision. Our advice is to be strongly considering the transition to the 2022 revision for any initial certification or recertification audits scheduled as of January 1, 2024, or later.<br><br></p></li><li><p class="paragraph" style="text-align:left;">And, the last scenario, which would include certified scopes that are not due for recertification in 2024. In this circumstance, the drop-dead date for transitioning to the 2022 revision of ISO 27001 is <b>October 31, 2025</b>, or 3 years following the last day of the month of publication. As of November 1, 2025, all ISO/IEC 27001:2013 certificates will expire.</p></li></ol><p class="paragraph" style="text-align:left;">Similar to recertification and initial certification timelines, it is wise to consider at least a 120-day buffer to this deadline of November 1, 2025, while understanding this date represents the transition period limit for undergoing a transition audit and receiving a positive decision from an accredited certification body before any existing ISO/IEC 27001:2013 certificates are rendered invalid and suspended.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Don&#39;t sleepwalk into your transition audit.</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b95bc5fe-2131-4888-b4b9-43c8e0639641/Picture1.png" length="335301" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/dont-sleepwalk-transition-audit</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/dont-sleepwalk-transition-audit</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">You have purchased a <a class="link" href="https://www.iso.org/standard/27001?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=don-t-sleepwalk-into-your-transition-audit" target="_blank" rel="noopener noreferrer nofollow">license</a> for the new 2022 revision of ISO 27001, and, after a moment of converting the &quot;CHF&quot; currency to something more local, you are relieved that this expense report might actually go through without anyone questioning why ISO standards cost money yet again — ugh, a topic for another day. 😒</p><p class="paragraph" style="text-align:left;">You skim the standard, and it appears that all the favorites, such as scope, risk assessment, internal audit, management review, and the ISO 27002 controls, are still there to some extent.</p><p class="paragraph" style="text-align:left;">Maybe a few controls look removed, and there are a few newcomers — 11 net new controls to be exact. Oh, and some controls appear to be combined — 24 consolidated controls in this release.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">So, what do you really need to do to prepare your management system for one of these transition audits from your certification body in the first 36 months after ISO/IEC 27001:2022 was published?</p><p class="paragraph" style="text-align:left;">Let’s break it down using <a class="link" href="https://iaf.nu/iaf_system/uploads/documents/IAF_MD26_Issue_2_15012023.pdf?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=don-t-sleepwalk-into-your-transition-audit" target="_blank" rel="noopener noreferrer nofollow">IAF MD 26</a>.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7b451a5b-f731-43ed-9eb6-577f105b4fd2/Picture_2.png?t=1706494856"/><div class="image__source"><span class="image__source_text"><p>Within Section 4.2 of these instructions, the IAF outlines actions of the CAB (i.e., conformity assessment body, but you can think “certification body” for our purposes).</p></span></div></div><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Gap Analysis:</b> What you see in this bullet point is the only guidance that certification bodies also have at their disposal. For this one, we are looking for anything documented via a form of self-assessment. We have accepted assessments performed through compliance SaaS platforms as well as a simple Excel workbook demonstrating a side-by-side of the requirements of ISO/IEC 27001:2022 and how the organization believes they meet the criteria. There are several open-source documents comparing the 2013 and 2022 revisions of ISO 27001 you can find with simple online searches if you need a starting point.<br><br>Common pitfall: Organizations attempt to leverage their second-party audit (i.e., internal audit) for this evidence. Your internal audit activity should be limited to a verification mechanism that your system has upgraded to meet the 2022 revision and not performing this upfront gap analysis on behalf of the management system operators.<br><br></p></li><li><p class="paragraph" style="text-align:left;"><b>Statement of Applicability (SoA):</b> New control set, new you. Frequently, organizations will apply the Annex A controls detailed explicitly within the ISO 27001 standard as a form of risk mitigation to inherent risks affecting their management system scope. If you fall into this bucket, your organization will need to re-map these controls since the ISO/IEC 27001:2013 standard is no longer applicable. Additionally, for the 11 net new controls, there will be extra attention on clause 6.1.3(d) to ensure that these controls have been listed, justified for inclusion or exclusion with explanatory notes, as well as represented by a documented implementation status.<br><br>Pro tip: Stop relying on Annex A controls. Most of these controls are written at such a high level that purist security practitioners attempt to discredit the entire ISO 27001 standard before thinking about how these controls are intended to be applied via a risk-based approach and methodology. The most mature certified organizations have internal control sets balancing all of their compliance obligations and simply map their control sets to any ISO 27001 controls that they have justified for inclusion in their scope before going above and beyond the baseline control descriptions.<br></p><p class="paragraph" style="text-align:left;"><br></p></li><li><p class="paragraph" style="text-align:left;"><b>Modifications to Risk Treatment Plans, as appropriate:</b> This one is probably the simplest of the 4 objectives explicitly stated within IAF MD 26. In simple terms, if you have any open risk treatment plans from prior cycles or previous reviews AND these plans have applied an Annex A control from ISO/IEC 27001:2013, these Annex A controls will need to be re-mapped to the control set within ISO/IEC 27001:2022. Your organization does not need to address this objective for already completed risk treatment plans. Then, of course, on a go-forward basis, ensure your organization is applying the ISO/IEC 27001:2022 control set for newly identified risk treatment plans.</p><p class="paragraph" style="text-align:left;"><br></p></li><li><p class="paragraph" style="text-align:left;"><b>Implementation & Effectiveness of New or Changed Controls:</b> When we first read this objective, we were initially confused as this really feels like number 1 but maybe a follow-on action. Let’s call it number 1b.<br><br>In essence, this is the next step after your self-administered gap analysis. You review the changes in ISO/IEC 27001:2022, decide where gaps exist, determine their severity, create an action plan, and ensure the minimum requirements are complete prior to an external audit. Your certification body has to obtain objective evidence that your management system has implemented the new standard, and this process flow of corrective action identification through to corrective action close-out is easy and defensible evidence to meet this objective.</p></li></ol><p class="paragraph" style="text-align:left;">And, for added bonus, this last item is not listed within IAF MD 26, but is hidden in the standard itself.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">Yes, your certification body must also determine that the internal audit activity was executed against ISO/IEC 27001:2022 and cannot certify the scope to the new revision with this omission.</p><p class="paragraph" style="text-align:left;">In summary, these steps feel intuitive for a major release but note that each of these items above will need to be supported by objective evidence in the form of documented information.</p><p class="paragraph" style="text-align:left;">Breathe easy – this standard apparently only receives major updates once every 10 years.</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Careful! Not all options are created equal here.</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3211dff2-4547-441f-a14f-b62f7ab81d1b/Picture2.png" length="336056" type="image/png"/>
  <link>https://intel.mastermindassurance.com/p/3-options-required-transition-audit-isoiec-270012022</link>
  <guid isPermaLink="true">https://intel.mastermindassurance.com/p/3-options-required-transition-audit-isoiec-270012022</guid>
  <pubDate>Mon, 20 May 2024 10:00:00 +0000</pubDate>
  <atom:published>2024-05-20T10:00:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/33e119ff-d0d5-4a26-b668-22a4d30ba999/image.png?t=1707699211"/></div><p class="paragraph" style="text-align:left;">Great – at this point, we have determined the<a class="link" href="https://intel.mastermindassurance.com/p/clock-transition-new-revision-already-started?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=careful-not-all-options-are-created-equal-here" target="_blank" rel="noopener noreferrer nofollow"> timeline</a> for when we need to complete the transition of our certified Information Security Management System (ISMS) to the new 2022 revision. But what exactly do we need to communicate to transition or upgrade our certificate?</p><p class="paragraph" style="text-align:left;">First, let’s recall our source material for this topic, which is<a class="link" href="https://iaf.nu/iaf_system/uploads/documents/IAF_MD26_Issue_2_15012023.pdf?utm_source=intel.mastermindassurance.com&utm_medium=newsletter&utm_campaign=careful-not-all-options-are-created-equal-here" target="_blank" rel="noopener noreferrer nofollow"> IAF MD 26</a>. This will serve as our reference file in case there are further transition topics we need to investigate.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5eb85332-2609-4073-a61d-cd500c3a7001/Timer.jpg?t=1706490500"/><div class="image__source"><span class="image__source_text"><p>Luckily, this counter is fake and you have more time to transition to ISO/IEC 27001:2022 as of this writing.</p></span></div></div><p class="paragraph" style="text-align:left;">Next, how long are these transition audits?</p><p class="paragraph" style="text-align:left;">It depends, but not all options are as cost-effective as their alternatives per the below:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Option #1:</b> Conduct the transition audit at the same time as your recertification audit. This option will be the most cost-effective, as your certification body auditor is only required to add <b>½ day</b> to its audit plan. Likewise, you are knocking out this one-time transition audit in parallel with a required annual audit, limiting the time you need your staff to step away from their day jobs to address external audit inquiries.<br><br></p></li><li><p class="paragraph" style="text-align:left;"><b>Option #2:</b> Conduct the transition audit at the same time as your surveillance audit. You may not be due for a recertification audit, or the timing of your recertification audit in 2025 would put you right up against the hard deadline of October 31, 2025, to transition. If this is your scenario, you should still consider bundling your transition with a regularly scheduled annual audit (i.e., surveillance), but IAF MD 26 requires a <b>full 1.0 day</b> to be planned as supplemental time by the certification body auditor. This option is not as cost-effective, but you at least benefit from completing the transition at the same time as a related external audit by your certification body.<br><br></p></li><li><p class="paragraph" style="text-align:left;"><b>Option #3:</b> Schedule an out-of-cycle transition audit separate from the recurring annual audit of your ISMS by the certification body. This option is the costliest in terms of both budget and resources, as you are requesting your external auditor and your internal staff to be available for an ad hoc audit sometime throughout the year for a second time. IAF MD 26 requires the certification body to plan for a <b>full</b> <b>1.0 day</b> for this transition audit; however, since this activity is not bundled with an annual audit, your certification body may have to charge additional fees compared to Option #2 due to the separate report it will have to generate vs. a few extra explanatory notes as a supplemental section in the annual report.</p></li></ul><p class="paragraph" style="text-align:left;">Do yourself a favor and plan ahead for this transition audit by engaging early and as a co-collaborator with your certification body on a plan to transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022.</p><p class="paragraph" style="text-align:left;">This engagement does not necessarily mean your organization should transition early, but at least will force all parties to define a schedule to get this activity completed (and, hopefully, while leveraging Option #1 or Option #2, as both are feasible with preparation).</p><p class="paragraph" style="text-align:left;">🧠 🧠 🧠 🧠 🧠 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/246074ae-0248-41d0-8918-5329f095aee6/Horizontal_Rule.png?t=1707680685"/></div></div><div class="section" style="background-color:transparent;border-color:#8770cd;border-radius:20px;border-style:solid;border-width:4px;margin:30.0px 30.0px 30.0px 30.0px;padding:15.0px 15.0px 15.0px 15.0px;"><p class="paragraph" style="text-align:center;"><b>We are all about creating awareness while poking fun. Will your team avoid the office with a 10-foot pole but is the last to leave the happy hour? This newsletter might be for them.</b></p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share this Post </span></a></div></div></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
