Controls
The fundamental building block of GRC. We design controls, test controls, remediate control gaps, and build compensating controls.
Community-run. In person. Slightly opinionated.
The first community-driven GRC conference for practitioners who are done with compliance theatre and ready to build GRC like engineers.
No sales pitches. No buzzword bingo. Just real controls, real threats, and real implementation experience.
Community-run. In person. Slightly opinionated, genuinely welcoming.
A practitioner-led conference built for real implementation detail, threat-driven controls, and honest conversations.
London, September 2026. Date to follow soonish.
Get early access to London 2026 updates, speaker announcements, and planning details.
A practitioner-first conference with zero compliance theatre.
If you're looking for real conversations about building GRC that actually reduces risk, you're in the right place.
CtrlCon is a community-organised series of events around the world promoting GRC Engineering, threat-driven compliance, and modern automation practices.
We believe the industry is evolving from audit-driven compliance factories to product-focused engineering teams. Practitioners need a space to share implementation patterns, challenge vendor marketing, and build the next generation of GRC infrastructure.
Hallway-first, implementation-heavy, and unapologetically practitioner-led.
CtrlCon is built around the famous hallway track. Events are designed to feel more like a practitioner meetup than a vendor expo. People come to:
And yes, there are always great talks and workshops, because that is the main focus of every CtrlCon event.
The fundamental building block of GRC. We design controls, test controls, remediate control gaps, and build compensating controls.
Ctrl+C, Ctrl+V, Ctrl+F. We live in spreadsheets. We automate with code.
No more audit-driven compliance theatre. No more vendor marketing disguised as thought leadership. We're taking control back.
GRC Engineering represents an evolution in how organisations approach governance, risk, and compliance. Instead of optimising for audit outcomes, GRC Engineering applies software and security engineering principles to build threat-driven programs that actually reduce risk.
CtrlCon exists to give practitioners a place to share how this works in the real world.
CtrlCon London will take place September 2026 (date to follow soonish). This is the founding CtrlCon event and will be held in person in London. Expect actually helpful sessions, honest practitioner discussions, and the kind of hallway conversations you don't get at vendor-led conferences.
Automation patterns, IaC, CI/CD integration, data pipelines
System design, vendor evaluation, build vs buy, integrations
Scaling programs, team structures, stakeholder management, CCM
Threat-driven frameworks, risk quantification, board reporting, maturity models
New here?
CtrlCon sponsorship is different.
We only work with vendors who:
Contact: <TBD>
Want to volunteer?
Reach out via LinkedIn or email: <TBD>
LinkedIn: https://www.linkedin.com/company/ctrlcon/
More channels will be added as the community grows.
We're looking for talks that share real implementation experience.
Ideal topics include:
Submit: <TBD>
CtrlCon is a professional environment focused on learning and collaboration.
CtrlCon values honesty over perfection, curiosity over certainty, and learning over posturing.
Coming soon
[TODO: Newsletter signup block text]