How to Be a GRC Hero (Without Heroics)
Stas Bojoukha (Founder and CEO · Comply)
BSidesSF 2026 · Day 1 · AMC Theatre 03
Overview
In his compelling BSides SF talk, "How to Be a GRC Hero (Without Heroics)," Stas Bojoukha, the Founder and CEO of Comply, dissects the fundamental flaws in traditional Governance, Risk, and Compliance (GRC) practices and presents a visionary path forward. Bojoukha argues that the GRC landscape, once a niche and often overlooked domain, is now at a critical inflection point, driven by rapid technological evolution and escalating regulatory demands. He posits that the prevailing manual, reactive approaches to GRC are not only inefficient but also unsustainable in today's complex, multi-cloud, and vendor-rich environments.
Key moments
- 0:00 Introduction to speaker and GRC's historical challenges
- 2:20 Agenda and AI's game-changing impact on GRC
- 3:00 The 'audit session hero': GRC's broken fire drill nature
- 4:00 Shift to auditor read-only observability for compliance
- 5:00 How GRC evolved: Cloud, vendors, regulations, AI
- 6:00 Quantifying GRC's growth: 40 to 400 vendors in 10 years
- 6:40 The emerging concept of GRC engineering
How to Be a GRC Hero (Without Heroics)
Speakers: Stas Bojoukha, Founder and CEO, Comply
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=xIsen_rKkDA
Overview
In his compelling BSides SF talk, "How to Be a GRC Hero (Without Heroics)," Stas Bojoukha, the Founder and CEO of Comply, dissects the fundamental flaws in traditional Governance, Risk, and Compliance (GRC) practices and presents a visionary path forward. Bojoukha argues that the GRC landscape, once a niche and often overlooked domain, is now at a critical inflection point, driven by rapid technological evolution and escalating regulatory demands. He posits that the prevailing manual, reactive approaches to GRC are not only inefficient but also unsustainable in today's complex, multi-cloud, and vendor-rich environments.
Bojoukha's central thesis revolves around transforming GRC from a burdensome, back-office "fire drill" into a strategic, automated, and proactive business function. He champions the concept of GRC engineering, advocating for the design of intelligent systems that leverage automation and artificial intelligence (AI) to collect evidence autonomously, continuously monitor controls, and provide real-time risk insights. This paradigm shift, he asserts, allows GRC professionals to evolve from mere "compliance gatekeepers" to indispensable strategic partners, enabling organizations to build resilient programs at scale and make informed decisions without the constant scramble for evidence. The talk is particularly relevant for security practitioners, compliance officers, and business leaders grappling with the increasing complexity and demands of modern GRC.
Background
▶ Watch: Introduction to speaker and GRC's historical challenges (0:00)
Stas Bojoukha, with over two decades of experience in information security across the US, Canada, and the UK, including a degree from one of the earliest information system security programs, brings a practitioner's perspective to the GRC challenge. His journey into GRC automation began in financial services, where he intimately experienced the pain points of traditional compliance, particularly with user access reviews mandated by regulations like Sox (Sarbanes-Oxley) and its predecessors, SAS 70 (now SOC 2). He vividly recalls the frustration of "headless chickens" chasing evidence, struggling to produce key performance indicators (KPIs), and manually uploading data into cumbersome platforms like Archer – a process that remains "way more difficult than it should be even in 2026."
The core problem, as Bojoukha highlights, is that GRC's original purpose – to pass an audit, collect evidence, and avoid failure – is no longer sufficient. The technological landscape has undergone a seismic shift. A decade ago, a typical organization might have managed 40 vendors, three environments, and one framework. Today, it's common to see 400+ vendors, a dozen SaaS identity boundaries, six frameworks, and new expectations like continuous vendor breach monitoring and AI policies, all without proportional increases in funding or resources. The cloud explosion, once viewed with suspicion in 2018, is now the default, leading to an exponential increase in vendors and complexity. Simultaneously, regulations have accelerated, and framework adoption has become ubiquitous.
This evolving environment has rendered traditional GRC obsolete. The job has transformed from simply documenting controls to operating a control surface. Old tools merely tracked what was already known; new tools must reveal "what I don't know yet." Furthermore, GRC is no longer a back-office function confined to security teams. It has become a crucial, cross-departmental operation, touching legal (contractual obligations, regulatory deltas), finance (Sox assertions, operational risk), HR (joiner-mover-lever cycles, insider risk), product, and engineering (exception workflows, risk acceptance, change management). These siloed departments are all converging on GRC because they need automated processes and decision infrastructure to manage their day-to-day operations and ship faster with appropriate guardrails.
The prevailing GRC methodology, characterized by excessive manual work (screenshots, log uploads), disconnected systems, and endless evidence chasing, forces organizations into a perpetual "survival mode" or "scavenger hunt." This leads to "heroics" becoming the default process – frantic, last-minute efforts to gather evidence, reconcile discrepancies, and appease auditors. Bojoukha emphasizes that business lines are not GRC experts, and clunky, non-intuitive systems only exacerbate the problem, leading to corners being cut and less mature products being adopted in a rush, often requiring additional tools later. The underlying issue, therefore, isn't GRC itself, but how GRC is currently being done.
Key Findings
▶ Watch: The 'audit session hero': GRC's broken fire drill nature (3:00)
Bojoukha's talk unveils several critical findings that redefine the landscape of modern GRC:
- Traditional GRC is Fundamentally Broken: The existing manual, reactive, and documentation-heavy approach to GRC is unsustainable and leads to constant "fire drills" and burnout. It cannot cope with the exponential growth in cloud adoption, vendor sprawl, regulatory complexity, and the speed of business.
- AI is a GRC Game-Changer: Unlike many other industries where AI integration feels forced, Bojoukha asserts that AI is "game-changing" for GRC. Its ability to process vast amounts of data, detect anomalies, and automate complex tasks offers unprecedented opportunities for efficiency and proactive security.
- Shift from Gatekeepers to Strategic Partners: GRC teams must transition from being perceived as "speed bumps" or "blockers" to becoming indispensable strategic partners. This involves providing clear, data-driven insights to leadership and enabling faster business operations with integrated guardrails.
- GRC as Decision Infrastructure: The role of GRC is evolving beyond mere compliance documentation to become a critical decision infrastructure for the entire organization. It interconnects disparate departments (legal, finance, HR, engineering) by providing automated processes and real-time data for risk management and operational efficiency.
- The Rise of GRC Engineering: This new paradigm focuses on building intelligent systems where evidence collects itself, controls subscribe to telemetry streams, and risks are automatically identified and quantified. It's about engineering processes and workflows around existing data and applications to create a truly resilient program.
- Proactive, Not Reactive Security: The emphasis must shift from detective controls and reacting to incidents to preventive measures. GRC platforms should proactively identify potential issues (e.g., critical CVEs, dormant privileged users, policy drift) before they escalate into incidents, enabling management by exception.
- Continuous Monitoring and Reuse: Modern GRC programs should not "reset every year." Instead, they must implement continuous monitoring, allowing for the reuse of existing evidence stacks and control mappings when new frameworks or regulations emerge. This adaptability is crucial for navigating the rapidly changing compliance landscape (e.g., new NIST revisions, EU AI Act).
- The Value of GRC is its Indispensability: Bojoukha challenges organizations to consider what would happen if their GRC program disappeared overnight. If the business would "fall apart" or if critical functions like access reviews, vendor risk management, or incident learning would cease, then GRC was not "overhead" but essential infrastructure – a telemetry layer and translation engine for organizational health.
Technical Deep Dive
▶ Watch: Shift to auditor read-only observability for compliance (4:00)
Bojoukha delves into specific technical shifts that underpin the transformation of GRC into an engineered, automated discipline. The core idea is to move from manual, point-in-time evidence collection to continuous control monitoring powered by real-time data and intelligent systems.
A key proposal is the implementation of auditor read-only observability layers. Drawing parallels with platforms like Snowflake, DataDog, and Splunk, Bojoukha suggests that auditors should have direct, secure access to an organization's compliance data set. This would allow them to select their own timeframes, filter for specific identities (e.g., privileged users), export evidence in their preferred format, and ask questions directly about the data. This eliminates the "scavenger hunt" of current audit processes, fostering confidence in the presented data and streamlining the audit experience.
Central to this new approach is the concept of controls subscribing to telemetry streams. Instead of manual checks or spreadsheets, controls are directly linked to real-time data sources. For instance, if MFA coverage in Octa for privileged users drops from 99% to 95%, the associated control status should automatically change. This immediate feedback loop removes the need for manual updates and allows for real-time visibility into control effectiveness, enabling prompt intervention.
Another significant technical advancement is risk register gap detection. Modern GRC platforms, integrated with other security tools, should automatically detect and quantify risks. Examples include identifying critical CVEs (Common Vulnerabilities and Exposures) that have been detected but not assigned for remediation, unassigned security incidents, missing encryption across critical assets, or the presence of dormant privileged users. These platforms can then automatically create and assign these risks, shifting the focus from detective to preventive security by flagging potential issues before they escalate into full-blown incidents.
Vendor risk propagation offers a revolutionary approach to third-party risk management (TPRM). Instead of relying on static questionnaires like SIG (Standardized Information Gathering) or periodic reviews, GRC systems can continuously monitor vendors, suppliers, and third parties. If a vendor's risk or compliance levels change (e.g., a data breach, a downgrade in security posture detected through public sources or continuous monitoring feeds), the system automatically updates associated internal risks, pauses contract renewals, and flags contractual violations (e.g., SLAs - Service Level Agreements). This moves TPRM from a labor-intensive, point-in-time exercise to an automated, real-time risk management function, leveraging open-source intelligence (OSINT), deep web, and dark web analysis for comprehensive data gathering on even nascent companies.
Policy drift detection addresses the notoriously difficult challenge of policy management. Bojoukha highlights that most organizations struggle with outdated policies that are rarely reviewed or understood. New GRC systems can actively compare documented policies with actual operational behavior and system configurations. If a policy states a certain remediation frequency for vulnerabilities, but the operational data shows a different cadence, the system can detect this drift and suggest policy adjustments. Furthermore, these platforms can automatically align policies with new or updated regulations and frameworks like NIST, ISO, HIPAA, High Trust, or the EU AI Act, identifying gaps and suggesting necessary changes without requiring manual reconciliation. This provides a bidirectional feedback loop between policy and reality.
Finally, the automation of joiner-mover-lever (JML) processes is crucial for identity and access management. Historically, managing segregation of duties (SoD) and toxic pair combinations has been aspirational and difficult to maintain. Automated GRC systems can detect scenarios like an engineer moving to a finance role while retaining inappropriate permissions, automatically flagging potential SoD issues. The system can also manage exceptions, allowing legitimate over-privileges to be documented and tracked, preventing auditors from flagging necessary access as a compliance violation. This ensures identity hygiene is maintained in real-time, preventing the silent accumulation of privileged accounts.
In essence, Bojoukha argues that if a computer can perform a GRC task, it should. This includes transforming GRC into the organization's telemetry layer for security and compliance health, providing leadership with real-time insights into encryption coverage, MFA adoption, backup status, and vendor exposure. It also acts as a translation engine between abstract rules and concrete operational reality, ensuring policies are living documents that reflect and guide organizational behavior.
Demo / Proof of Concept
▶ Watch: Quantifying GRC's growth: 40 to 400 vendors in 10 years (6:00)
While Stas Bojoukha's talk outlines a powerful vision for the future of GRC and describes numerous capabilities that modern platforms should offer, it does not include a live demonstration or a detailed proof of concept of a specific tool. Instead, he presents a series of conceptual examples under the "New GRC" and "Real GRC Engineering" sections, illustrating how these automated processes would function in an ideal state.
For instance, he describes how evidence collection would shift from attaching screenshots to controls subscribing to telemetry streams, allowing control statuses to change automatically based on real-time data like MFA coverage. He elaborates on risk register gap detections, where platforms automatically identify critical CVEs, unassigned incidents, or dormant privileged users, transforming them into quantifiable risks. Similarly, vendor risk propagation is explained as a system that continuously monitors third parties and automatically updates associated risks or flags contract violations if a vendor's risk profile changes. Policy drift detection is conceptualized as a system that compares policy statements with enforcement realities, suggesting adjustments. Lastly, the joiner-mover-lever example illustrates automatic detection of segregation of duties issues.
These examples serve to paint a clear picture of the functionalities and benefits of an engineered GRC program rather than showcasing a particular product in action. The emphasis is on the systemic transformation and the capabilities that are "doable now" with advanced AI models and interconnected platforms.
Defensive Implications
▶ Watch: The emerging concept of GRC engineering (6:40)
The insights shared by Stas Bojoukha carry significant implications for security defenders seeking to mature their GRC programs and enhance their organization's overall security posture. The core message is a call to action to move away from outdated, reactive methods and embrace a proactive, automated, and strategic approach.
- Embrace GRC Engineering: Defenders must adopt a mindset of GRC engineering. This means viewing GRC not as a documentation chore but as a system to be built and operated. Focus on designing workflows where evidence is collected automatically via telemetry streams from existing security and IT tools (e.g., identity providers, vulnerability scanners, cloud configuration tools). This drastically reduces manual effort and improves data accuracy and timeliness.
- Leverage Automation and AI Aggressively: Actively seek out and implement GRC platforms that integrate AI and machine learning for tasks such as risk register gap detection, policy drift analysis, and automated vendor risk propagation. These technologies can identify risks and compliance gaps far faster and more comprehensively than human analysts, allowing teams to focus on high-value remediation and strategic decision-making.
- Shift to Proactive Risk Management: Move beyond simply detecting incidents to actively preventing them. Implement systems that automatically identify potential risks like critical CVEs, unassigned security incidents, missing encryption, or dormant privileged users, and integrate these findings directly into risk registers and remediation queues. This enables management by exception, focusing resources on true anomalies rather than chasing every minor issue.
- Modernize Third-Party Risk Management (TPRM): Transition from static, questionnaire-heavy TPRM to continuous monitoring. Utilize platforms that leverage open-source intelligence (OSINT), deep web, and dark web analysis, alongside direct integrations, to infer and continuously track vendor security postures. This allows for more targeted follow-up questions, reducing the burden on both the assessing organization and the vendor, and proactively flagging contractual violations or changes in risk.
- Automate Identity and Access Management (IAM) Controls: Implement GRC systems that automatically detect and flag segregation of duties (SoD) violations and over-privileged accounts, especially during joiner-mover-lever (JML) processes. Crucially, these systems must also support robust exception management, allowing legitimate deviations to be documented, approved, and continuously monitored, rather than being a source of constant audit findings.
- Transform Policy Management: Re-evaluate and modernize policy management. Adopt tools that can analyze policy alignment with frameworks (NIST, ISO, HIPAA, EU AI Act) and detect drift between documented policies and actual operational behavior. Such tools can suggest policy updates and ensure policies remain living, relevant documents that reflect the organization's current state and risk appetite.
- Position GRC as a Strategic Asset: Elevate the GRC function from a compliance cost center to a strategic business partner. By providing real-time telemetry on the organization's security and compliance posture (e.g., MFA coverage, encryption status, vendor exposure), GRC can inform executive decision-making, build trust, and demonstrate the tangible value of security investments.
- Invest in Skill Development: GRC professionals need to evolve their skill sets. The future GRC hero is not just a documentarian but a system designer, an analyst of data, and a strategic communicator. Training in automation, data analytics, and understanding the integration points between various security and IT systems will be paramount.
By embracing these defensive implications, organizations can move beyond the "heroics" of traditional GRC, building resilient, scalable, and continuously compliant security programs that are deeply integrated into the business's operational fabric.
Key Takeaways
- GRC's Evolution is Critical: Traditional, manual GRC processes are broken and cannot keep pace with the accelerating demands of cloud adoption, vendor sprawl, and regulatory complexity. A fundamental shift is required.
- AI is a Game-Changer for GRC: Unlike many other domains, AI's application in GRC is genuinely transformative, enabling unprecedented automation, continuous monitoring, and proactive risk detection.
- Embrace GRC Engineering: The future lies in "GRC engineering"—designing systems where evidence automatically collects itself via telemetry streams, controls are continuously monitored, and risks are proactively identified and quantified.
- Shift to Proactive and Exception-Based Management: GRC must move from reactive "fire drills" to a proactive stance, detecting issues like critical CVEs, policy drift, and segregation of duties (SoD) violations before they become incidents, and managing legitimate exceptions effectively.
- GRC as Strategic Decision Infrastructure: GRC is no longer a back-office function but a cross-departmental decision infrastructure, providing real-time insights to leadership and enabling informed strategic choices across legal, finance, HR, and engineering.
- Continuous Monitoring and Reuse are Key: Modern GRC programs should not reset annually but continuously monitor and build upon existing evidence, adapting to new frameworks and regulations by reusing established controls and data.
About the Speaker(s)
Stas Bojoukha, whose last name rhymes with "Bazooka," is the Founder and CEO of Comply, a Series A startup that he describes as already leading the GRC automation space. With over 20 years of experience in the information security domain, Bojoukha is a seasoned practitioner. He holds a degree in information system security, having been part of the second cohort ever offered for that specific program. His extensive career has seen him build security practices within financial services across the US, Canada, and the UK. Bojoukha's personal experience with the inefficiencies of traditional GRC, particularly the arduous process of user access reviews and manual evidence uploading, directly inspired him to found Comply five years ago, aiming to transform the GRC landscape through innovative automation. He expresses genuine excitement about the growing interest in GRC and its potential for significant transformation in the coming months and years.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A polished vendor pitch dressed as a practitioner talk. Bojoukha has real GRC scars, which gives the framing credibility, but the entire 'technical deep dive' is a capabilities brochure for Comply with no implementation specifics, no data, and no demo. BSides deserves better than this.
Heather Calloway (CISO) — WEAK
Bojoukha correctly diagnoses a real and underappreciated problem — GRC as a manual, audit-centric function cannot scale to modern complexity — but the talk never clears the bar from diagnosis to decision. The vision is coherent, the framing is reasonable, and the speaker has genuine practitioner credibility, but the entire presentation is built on concepts that conveniently map to his own product, and there's nothing here a CISO can act on that they couldn't have arrived at independently.