Events

A GRC Engineer's Guide to BSides Atlanta 2026

A practical path through GRC, AI, identity, evidence, and security engineering

A curated BSides Atlanta 2026 conference path for GRC practitioners and people interested in GRC Engineering.

GRC Engineering is most useful when governance practitioners understand what engineers, attackers, defenders, identity teams, and AI builders are working on. So we went through the full BSides Atlanta schedule and built a path that moves between the GRC track and the rest of the conference when another room offers a particularly useful perspective.

Best of all, BSides Atlanta has something we do not always get at a security conference: a dedicated Governance, Risk & Compliance track.

The goal is not to collect the most talks possible or stay in the same conference rooms all day. The goal is to leave with better questions, stronger technical context, and a few ideas you can take back to your own program.

Three Compliance Topics to Watch

AI governance becoming operational. Several sessions move beyond AI principles into management systems, decision rights, technical controls, and the ways AI-enabled workflows can fail.

Evidence becoming engineering. The schedule includes a direct look at evidence-as-code and continuous compliance. Pay attention to where evidence can come from systems instead of screenshots and annual collection exercises.

Identity as control architecture. IAM is not just an access-control policy. The Entra session is a chance to connect identity design, hidden privilege, Conditional Access, and business risk.

How to use this guide

This is a recommended path, not a mandate. Best Choice marks the sessions we think are most directly useful for a GRC Engineering audience. Recommended highlights sessions that add valuable technical, risk, or community context. Skip a session if another topic is more useful to you, and take a hallway conversation when it is going somewhere.

BSides Atlanta uses two assigned lunch waves: Wave #1 from 11:30 AM-12:30 PM and Wave #2 from 12:30-1:30 PM. Attendees are asked to follow their assigned time, although lunch-wave tickets may be traded with another attendee. That creates unavoidable conflicts with some of our recommendations. We are keeping one simple recommended path rather than building separate itineraries, so watch the schedule notes around lunch and adjust for your assigned wave.

Sessions are subject to change and come from the official BSides Atlanta schedule.

Recommended path

BSides Atlanta 2026 GRC Engineering path

  1. 9:00 AM9:25 AM
    RecommendedKeynote

    Keynote address

    Liz Morton

    What you'll hear

    A short opening keynote before the conference splits into parallel tracks.

    Reasons to attend

    Start with the shared room, then move into the GRC Engineering path with the same context as the rest of the conference.

  2. 9:30 AM10:20 AM
    Best ChoiceGRC

    The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It

    Eric Logan

    What you'll hear

    Lessons from defending a large K-12 environment where sensitive data, broad exposure, limited staffing, and governance gaps collide.

    Reasons to attend

    A strong opening on institutional risk, constrained resources, governance, and what other organizations can learn from a difficult operating environment.

  3. 10:30 AM10:50 AM
    Best ChoiceGRC

    ISO 42001 in the Real World: I Actually Implemented the AI Standard So You Don't Have to Guess

    Randy Hanooman

    What you'll hear

    A practitioner field report on implementing ISO/IEC 42001, including difficult areas, audit attention, and common implementation mistakes.

    Reasons to attend

    Rare implementation-level AI governance content from someone who has actually built an AI management system and taken it through the realities of an audit.

  4. 11:00 AM11:20 AM
    RecommendedOffensive Security

    No Model Was Harmed in the Making of This Exploit

    Harsh Akshit

    What you'll hear

    A case study in interface laundering: repackaging an AI feature through a standard API so intended UI friction and usage assumptions stop functioning as controls.

    Reasons to attend

    Useful control-design thinking about where scope, authorization, and abuse prevention must actually be enforced.

  5. 11:30 AM11:50 AM
    Best ChoiceCommunity

    More Than a Member: Our Experience Investing in Cybersecurity Affinity Communities

    Grace Pfohl, Lindsey Nicholas

    What you'll hear

    How individuals and organizations move from passive membership to sustained investment in cybersecurity communities, including sponsorship and internal business cases.

    Reasons to attend

    Directly relevant to practitioners deciding how to invest in community and to the kind of durable local ecosystem the Atlanta chapter is trying to build.

    Check your assigned lunch wave. Wave #1 begins at 11:30 and conflicts with this session; lunch-wave tickets may be traded with another attendee if you want to adjust your schedule.

  6. 12:00 PM12:20 PM
    RecommendedGRC

    Nine Seconds: The AI Governance Gaps Nobody’s Naming

    Shikirra Williams

    What you'll hear

    AI governance lessons drawn from published incidents and mapped to the NIST AI RMF and Generative AI Profile.

    Reasons to attend

    A compact governance session with practical AI risk framing before the afternoon evidence and control-engineering sessions.

    Consider your assigned lunch wave when planning this block. Wave #1 runs during this session; Wave #2 begins at 12:30.

  7. 12:20 PM1:00 PM

    Lunch

    Plan this block around your assigned lunch wave. Wave #1 is 11:30 AM-12:30 PM and Wave #2 is 12:30-1:30 PM. Attendees are asked to follow their assigned time, though lunch-wave tickets may be traded. Evidence-as-Code begins at 1:00 PM, so Wave #2 attendees should account for that conflict.

  8. 1:00 PM1:50 PM
    Best ChoiceGRC

    Evidence-as-Code: Automating Compliance Without the Audit Theater

    Darius Davis

    What you'll hear

    Automated mapping of system configurations to controls, continuous drift detection, and evidence pipelines designed for both engineers and auditors.

    Reasons to attend

    This is one of the clearest GRC Engineering sessions on the schedule: control evidence becomes continuous technical telemetry instead of an annual collection exercise.

    Wave #2 lunch runs 12:30-1:30 PM, so this session conflicts with that assigned lunch window. Consider your lunch schedule before relying on this recommendation.

  9. 2:00 PM2:50 PM
    Best ChoiceGRC

    Tiered IAM for Entra Users

    James Stephens

    What you'll hear

    Real-world identity compromise examples and practical ways to reduce Entra risk through Conditional Access and privilege design.

    Reasons to attend

    A concrete control-engineering session connecting identity architecture, hidden privilege, and business risk.

  10. 3:00 PM3:20 PM
    RecommendedGRC

    Cybersecurity Safety Culture™: Leveraging Nuclear Safety Culture Principles to Cybersecurity Risk Management

    Juan F Villarreal, David Garchow

    What you'll hear

    How lessons from nuclear safety culture can inform cyber risk management, leadership behavior, incident reporting, training, and resilience.

    Reasons to attend

    A useful cross-industry risk-management perspective on building systems and culture that can withstand operational failure.

  11. 3:20 PM3:30 PM

    Between sessions

    Optional: if you want to find Atlanta GRC Engineering folks before the next session, look for the orange GRC flag.

  12. 3:30 PM3:50 PM
    Best ChoiceEmerging Tech

    Hacking the Process: Governance as an Attack Surface

    Isaac Obune

    What you'll hear

    How attackers can target policy-as-code and AI-assisted compliance workflows through poisoned inputs, prompt injection, and compromised governance tooling.

    Reasons to attend

    A very GRC Engineering question: what happens when the control system itself becomes part of the attack surface?

  13. 4:30 PM5:00 PM

    Closing remarks and giveaways

    BSides Atlanta closes the conference day in the Grand Ballroom. The official after-party begins at 6:00 PM at Hudson Grille Midtown.

Before you go

Keep up with the chapter

More from the A.

Browse other updates, explore events, or join the roster to hear what the Atlanta chapter is building next.