SAINTCON 26 · Session
Smells Like GRC Spirit
In the early 1990s, grunge killed polished, overproduced rock by exposing how fake it had become. Modern GRC is facing the same moment. For years, security teams have lived through endless audit theatre focussed on screenshots pretending to be assurance, dashboards pretending to be insight, and “automation” platforms that digitized noise instead of delivering truth. This talk argues that compliance has become the hair metal of cybersecurity. It's technically polished, commercially successful, and emotionally hollow. Enter GRC Engineering: a new approach built on live telemetry, data pipelines, AI, and continuous assurance. Using concepts like AgenticGRC, the Model Context Protocol (MCP) and autonomous evidence workflows, this session explores how governance is becoming an engineering discipline rather than a paperwork exercise. We’ll examine why traditional audit models are failing, why most compliance automation only accelerated bad processes, and why engineers now have a massive opportunity to reshape security through data-driven assurance systems. Like grunge, this isn’t about rebellion for its own sake. It’s about authenticity replacing performance. The future of GRC isn’t cleaner dashboards or faster screenshots. It’s systems that continuously prove trust through signals, context, and operational truth. The industry is exhausted by polished compliance. This talk is about what comes next.