The 11 PM Scavenger Hunt

▶ Watch (4:12)

“It’s 11:47 at night. You’re still chasing evidence. Slack is blowing up.” Stas Bojoukha painted this as the default state of GRC today. Auditors request MFA coverage for privileged users. The response: IT pulls Okta exports, someone screenshots Azure, HR checks spreadsheets, and uploads PDFs. This is not a control environment. “This is a scavenger hunt.” The real shift: give auditors read-only access to live telemetry so they can filter time frames, pull evidence, and ask questions without manual back-and-forth.

From Gatekeeper to Business Partner

5:32

GRC’s old purpose was “pass an audit, don’t fail.” That worked until cloud, vendors, and frameworks exploded. Ten years ago a company had 40 vendors, 3 environments, 1 framework. Today it has 400 vendors, 12 SaaS identity boundaries, 6 frameworks, and continuous breach monitoring. The job changed from documenting controls to operating a control surface. Old tools track what you know. New tools must tell you what you don’t know yet. GRC is becoming decision infrastructure for the whole organization.

Automation That Collects Itself

15:05

Evidence should not be screenshots. Controls should subscribe to telemetry streams. If Okta MFA drops from 99% to 95%, the control status changes automatically. Risk registers should auto-detect gaps: unpatched CVEs, missing encryption, dormant privileged users. Vendor risk should propagate automatically: if a third party’s compliance level drops, the risk register updates, renewals pause, contracts flag for SLA violations. Policy drift detection compares what the policy says to what is actually enforced and suggests corrections.

The GRC Hero: Build Systems, Not Spreadsheets

23:35

“A GRC hero doesn’t save the day. They have all the data at their fingertips.” Bojoukha defined the new profile: “Think like a risk leader, speak like an executive, build systems and not spreadsheets, focus on insights, not documentation.” If a computer can do it, let it. The next generation of GRC leaders will not be the fastest evidence collectors. They will be people who design systems where evidence collects itself. “Design systems where nothing breaks” is unrealistic; design systems that surface exceptions fast.

Q&A

How do you tie detection to remediation without causing an ignorance-to-negligence jump? Bojoukha agreed the risk is real. He pointed to agentic AI that can now close vulnerabilities and patch issues automatically, not just detect them. ▶ Watch (24:32)

How does the technology find policy drift and distinguish old policies from wrong actions? He described a bidirectional approach: policies must be holistically mapped to frameworks (NIST, ISO), and the platform suggests adjustments when reality drifts from policy (e.g., patch frequency). ▶ Watch (29:54)

Notable Quotes

It’s 11:47 at night. You’re still chasing evidence. Slack is blowing up. Stas Bojoukha · ▶ Watch (3:46)

This is not a control environment. This is a scavenger hunt. Stas Bojoukha · ▶ Watch (4:35)

A GRC hero doesn’t save the day. Stas Bojoukha · ▶ Watch (14:04)

If a computer can do it, we should be letting it do it. Stas Bojoukha · ▶ Watch (21:57)

The next generation of GRC leaders won’t be people who collect evidence the fastest, but they’ll be people who design systems where evidence collects itself. Stas Bojoukha · ▶ Watch (24:10)

Key Takeaways

  • Manual evidence collection and spreadsheet chasing are obsolete; GRC needs live telemetry feeds.
  • The GRC hero shifts from gatekeeper to business partner by designing automated, exception-aware systems.
  • AI and interconnected platforms can detect policy drift, propagate vendor risk, and auto-update risk registers.

About the Speaker(s)

Stas Bojoukha is the Founder and CEO of Compyl, a leading GRC automation platform headquartered in New York City. With more than 20 years of experience in cybersecurity, Stas has served in executive leadership roles including CISO and Head of Information Security across organizations.