GRC Engineering is most useful when governance practitioners understand what engineers, attackers, defenders, identity teams, and AI builders are working on. So we went through the full BSides Atlanta schedule and built a path that moves between the GRC track and the rest of the conference when another room offers a particularly useful perspective.
Best of all, BSides Atlanta has something we do not always get at a security conference: a dedicated Governance, Risk & Compliance track.
The goal is not to collect the most talks possible or stay in the same conference rooms all day. The goal is to leave with better questions, stronger technical context, and a few ideas you can take back to your own program.
Three Compliance Topics to Watch
AI governance becoming operational. Several sessions move beyond AI principles into management systems, decision rights, technical controls, and the ways AI-enabled workflows can fail.
Evidence becoming engineering. The schedule includes a direct look at evidence-as-code and continuous compliance. Pay attention to where evidence can come from systems instead of screenshots and annual collection exercises.
Identity as control architecture. IAM is not just an access-control policy. The Entra session is a chance to connect identity design, hidden privilege, Conditional Access, and business risk.
How to use this guide
This is a recommended path, not a mandate. Best Choice marks the sessions we think are most directly useful for a GRC Engineering audience. Recommended highlights sessions that add valuable technical, risk, or community context. Skip a session if another topic is more useful to you, and take a hallway conversation when it is going somewhere.
BSides Atlanta uses two assigned lunch waves: Wave #1 from 11:30 AM-12:30 PM and Wave #2 from 12:30-1:30 PM. Attendees are asked to follow their assigned time, although lunch-wave tickets may be traded with another attendee. That creates unavoidable conflicts with some of our recommendations. We are keeping one simple recommended path rather than building separate itineraries, so watch the schedule notes around lunch and adjust for your assigned wave.
Sessions are subject to change and come from the official BSides Atlanta schedule.
Recommended path
BSides Atlanta 2026 GRC Engineering path
- 9:00 AM9:25 AM
Keynote address
Liz Morton
What you'll hear
A short opening keynote before the conference splits into parallel tracks.
Reasons to attend
Start with the shared room, then move into the GRC Engineering path with the same context as the rest of the conference.
- 9:30 AM10:20 AM
The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It
Eric Logan
What you'll hear
Lessons from defending a large K-12 environment where sensitive data, broad exposure, limited staffing, and governance gaps collide.
Reasons to attend
A strong opening on institutional risk, constrained resources, governance, and what other organizations can learn from a difficult operating environment.
- 10:30 AM10:50 AM
ISO 42001 in the Real World: I Actually Implemented the AI Standard So You Don't Have to Guess
Randy Hanooman
What you'll hear
A practitioner field report on implementing ISO/IEC 42001, including difficult areas, audit attention, and common implementation mistakes.
Reasons to attend
Rare implementation-level AI governance content from someone who has actually built an AI management system and taken it through the realities of an audit.
- 11:00 AM11:20 AM
No Model Was Harmed in the Making of This Exploit
Harsh Akshit
What you'll hear
A case study in interface laundering: repackaging an AI feature through a standard API so intended UI friction and usage assumptions stop functioning as controls.
Reasons to attend
Useful control-design thinking about where scope, authorization, and abuse prevention must actually be enforced.
- 11:30 AM11:50 AM
More Than a Member: Our Experience Investing in Cybersecurity Affinity Communities
Grace Pfohl, Lindsey Nicholas
What you'll hear
How individuals and organizations move from passive membership to sustained investment in cybersecurity communities, including sponsorship and internal business cases.
Reasons to attend
Directly relevant to practitioners deciding how to invest in community and to the kind of durable local ecosystem the Atlanta chapter is trying to build.
Check your assigned lunch wave. Wave #1 begins at 11:30 and conflicts with this session; lunch-wave tickets may be traded with another attendee if you want to adjust your schedule.
- 12:00 PM12:20 PM
Nine Seconds: The AI Governance Gaps Nobody’s Naming
Shikirra Williams
What you'll hear
AI governance lessons drawn from published incidents and mapped to the NIST AI RMF and Generative AI Profile.
Reasons to attend
A compact governance session with practical AI risk framing before the afternoon evidence and control-engineering sessions.
Consider your assigned lunch wave when planning this block. Wave #1 runs during this session; Wave #2 begins at 12:30.
- 12:20 PM1:00 PM
Lunch
Plan this block around your assigned lunch wave. Wave #1 is 11:30 AM-12:30 PM and Wave #2 is 12:30-1:30 PM. Attendees are asked to follow their assigned time, though lunch-wave tickets may be traded. Evidence-as-Code begins at 1:00 PM, so Wave #2 attendees should account for that conflict.
- 1:00 PM1:50 PM
Evidence-as-Code: Automating Compliance Without the Audit Theater
Darius Davis
What you'll hear
Automated mapping of system configurations to controls, continuous drift detection, and evidence pipelines designed for both engineers and auditors.
Reasons to attend
This is one of the clearest GRC Engineering sessions on the schedule: control evidence becomes continuous technical telemetry instead of an annual collection exercise.
Wave #2 lunch runs 12:30-1:30 PM, so this session conflicts with that assigned lunch window. Consider your lunch schedule before relying on this recommendation.
- 2:00 PM2:50 PM
Tiered IAM for Entra Users
James Stephens
What you'll hear
Real-world identity compromise examples and practical ways to reduce Entra risk through Conditional Access and privilege design.
Reasons to attend
A concrete control-engineering session connecting identity architecture, hidden privilege, and business risk.
- 3:00 PM3:20 PM
Cybersecurity Safety Culture™: Leveraging Nuclear Safety Culture Principles to Cybersecurity Risk Management
Juan F Villarreal, David Garchow
What you'll hear
How lessons from nuclear safety culture can inform cyber risk management, leadership behavior, incident reporting, training, and resilience.
Reasons to attend
A useful cross-industry risk-management perspective on building systems and culture that can withstand operational failure.
- 3:20 PM3:30 PM
Between sessions
Optional: if you want to find Atlanta GRC Engineering folks before the next session, look for the orange GRC flag.
- 3:30 PM3:50 PM
Hacking the Process: Governance as an Attack Surface
Isaac Obune
What you'll hear
How attackers can target policy-as-code and AI-assisted compliance workflows through poisoned inputs, prompt injection, and compromised governance tooling.
Reasons to attend
A very GRC Engineering question: what happens when the control system itself becomes part of the attack surface?
- 4:30 PM5:00 PM
Closing remarks and giveaways
BSides Atlanta closes the conference day in the Grand Ballroom. The official after-party begins at 6:00 PM at Hudson Grille Midtown.
Before you go
- Check the official BSides Atlanta schedule again before conference day for room or program changes.
- See the BSides Atlanta event listing for the conference link and location.
- Leave room for the hallway. A useful conversation can be worth more than forcing yourself into every recommended session.