NOW SHIPPING ⚙ CTRL+F: THE DAILY GAME — A NEW RUN EVERY DAY AT 13:00 LONDON ✦ THE PR APPROVAL IS DECAYING. YOUR CHANGE MANAGEMENT CONTROL HASN'T NOTICED. ✦ THE DEFINITIVE GRC ENGINEERING GUIDE TO INFRASTRUCTURE AS CODE ✦ 5 METRICS THAT PROVE A CONTROL WORKS. "IT EXISTS" DIDN'T MAKE THE LIST. ✦ THE COMPLIANCE LEVERAGE LADDER: YOUR GRC ROADMAP IS PULLING THE WEAKEST LEVERS ✦NOW SHIPPING ⚙ CTRL+F: THE DAILY GAME — A NEW RUN EVERY DAY AT 13:00 LONDON ✦ THE PR APPROVAL IS DECAYING. YOUR CHANGE MANAGEMENT CONTROL HASN'T NOTICED. ✦ THE DEFINITIVE GRC ENGINEERING GUIDE TO INFRASTRUCTURE AS CODE ✦ 5 METRICS THAT PROVE A CONTROL WORKS. "IT EXISTS" DIDN'T MAKE THE LIST. ✦ THE COMPLIANCE LEVERAGE LADDER: YOUR GRC ROADMAP IS PULLING THE WEAKEST LEVERS ✦
THE WORKSHOP TERMINAL
77 RELEASES INDEXED · ANSWERS CITE THEIR SOURCES
POWERED BY THE FULL CORPUS · OPEN MODELS AT THE EDGE · NO ACCOUNT NEEDED
Agent velocity is hollowing out the one artifact every change-management control leans on: the screenshot still looks fine while the approval underneath it means less every quarter.
Existence checks are the weakest claim you can make about a control. Five GRC Engineering effectiveness checks: what each replaces, how to measure it, and what it lets you decide.
AppSec escaped the "think like a hacker" trap with an operational method, tested across 400+ products. Here is the GRC Engineering port, one workflow at a time.
For the first time, GRC ingests more context than the work it governs produces. You get raw material, and the teams that notice first will write guardrails everyone else inherits.
A GRC engineering guide to triaging your controls: where to spend real hardening effort, which ones to just keep honest, and which to stop using bandwidth on.
The SOC 2 narratives, questionnaire answers and control docs crossing your desk are now written by AI, and built to pass, not to be true. Leaning on AI to check them erodes the judgment that would have caught them. Here is how to stay sharp!
You're shipping from day one. The question is whether you understand what you're building into. Five things I focus on in parallel with the build, so I don't lock in the wrong decisions early.
Borrow the discipline behind modern software, and apply it to policy, controls, risk, and TPRM in whatever tools your team already uses. Without forcing your team into Git, and without pretending the audit trail you already keep is somehow not a Git workflow.
Four layers of inheritance are running your GRC programme. Here is an audit framework to find out what is intentionally designed and what is just left over and you have to engineer for.
Observability exists because understanding the true state of a system is hard. Control for the same reason. GRC Engineering can help you get there by leveraging observability principles.
Why the future GRC team looks more like a basketball team than a football team, what that means for ICs and managers, and how to position yourself for either path.
How the discipline collapsed into evidence collection, what enterprise GRC teams I know actually focus on, and why the audit should be a translation layer, not the foundation it's built on.
We cycled through four GRC tools in four years before we built our own. The exercises that made us better builders are the same ones that make you a better buyer.
The math behind compliance assurance does not work the way you think it does. Why moving at agentic speed means rebuilding the primitives of what GRC Engineering has to cover.
The data, the patterns, and the gaps nobody's talking about. Everything you need to understand where GRC stands today through the largest independent practitioner survey ever conducted.
The ideas, the pillars, and the resources to go further. Everything you need to understand why GRC can be better than it is today through the GRC Engineering revolution.
A GRC Engineering-native answer to the trust and compliance exchange challenges. Open-source and free to sign. Assurance through cryptography instead of PDFs.
GRC has the budget, the executive access, and the cross-functional visibility. It uses all of it to farm faster instead of leading the team to victory.
As a GRC industry, we leveraged APIs and scripting to spark what became a revolution. We followed the path of least resistance. Here's why GRC Engineering is risking becoming shelfware.
A year of frameworks, practitioner stories, and community building that moved GRC Engineering from theory to practice. Here's what resonated most—and where we're headed in 2026.
#046 · DEC 18, 2025 · 17 MIN · STAKEHOLDER MANAGEMENT
The GRC Engineering guide to CISOs: strategic alignment, board communication, synthesizing risk data, and going beyond sales enablement. Moving from audit prep to security strategy.
The GRC Engineering guide to Software Engineers: protecting flow state, routing requests properly, and staying invisible. Embedding requirements in systems.
#043 · NOV 27, 2025 · 11 MIN · STAKEHOLDER MANAGEMENT
How modern GRC practitioners are building empathy with stakeholders, designing systematic processes, and leveraging better tools to transform programmes beyond compliance theatre.
#042 · NOV 14, 2025 · 13 MIN · STAKEHOLDER MANAGEMENT
How threat-driven GRC Engineering transforms your technical stack, stakeholder relationships, and value delivery from annual audits to continuous monitoring.
#040 · OCT 30, 2025 · 16 MIN · STAKEHOLDER MANAGEMENT
Why GRC teams are optimising the wrong variable in AI adoption, and what the GRC Engineering approach to workflow discipline means for stakeholder trust and automation ROI
How two GRC engineers, in six months, were able to completely rebuilding a GRC program at a major tech company by leveraging GRC Engineering principles everywhere.
The framework that separates GRC engineering thinking from tool requirements, and the specific actions you can take this week to advance GRC objectives
How GRC automation shifted from evidence storage to active control assessment, and what that means for your audit relationship and your GRC Engineering practice
Why your defence lines need systems thinking and shared intelligence, not just functional independence and isolated processes, a GRC Engineering approach.
The Step-by-Step GRC Engineering Practical Guide to Leveraging Existing IAM Infrastructure to automate Quarterly Access Reviews and get better visibility
A 5-step methodology that addresses coordination challenges, leverages existing infrastructure, and delivers business value without creating the technical debt that kills most initiatives
Why building parallel GRC infrastructure wastes resources, alienates teams, and fragments authority across competing systems. Also, what to do instead!
Pierre-Paul Ferland has scaled Coveo's GRC program from startup to IPO. This deep-dive explores their technical architecture, tooling decisions, and engineering integration strategies.
On the back of the news of the acquisition of the Styra team behind Open Policy Agent by Apple, we'll discuss how Policy-as-Code has been fitting into GRC Engineering and the way forward.
The 2x2 matrix that reveals why the industry is asking the wrong questions about your GRC maturity, assess if you need GRC Engineering, GRC Engineers or both.
A step-by-step framework for GRC professionals to build decision support systems, implement risk-driven metrics, and engineer security foundations that make compliance effortless
#017 · MAY 29, 2025 · 10 MIN · STAKEHOLDER MANAGEMENT
GRC Engineering Podcast | Season 2 Episode 1: Build vs. Buy, GRC Success Metrics and Compliance Commoditisation with Justin Pagano, Director of Security Risk & Trust at Klaviyo