Compliance That Breaks: Why GRC Fails in Practice (and What Actually Works)

Most compliance programs look solid on paper but fail in practice. This talk breaks down where GRC efforts break—missing enforcement, weak evidence, and tool gaps—and how to turn compliance into something that actually runs.


Many organizations invest heavily in compliance frameworks, policies, and audits, yet still struggle during real assessments or security events. The issue isn’t a lack of understanding—it’s a failure to translate requirements into operational reality. This session examines where GRC programs consistently break down: controls marked “implemented” but not enforced, evidence that doesn’t hold up under scrutiny, and security tooling that isn’t aligned to compliance objectives. Using real-world patterns and examples, we’ll walk through what happens when these gaps are exposed—during audits, incidents, or customer scrutiny—and why traditional approaches fall short. We’ll then shift to what actually works: mapping controls directly to systems and telemetry, generating continuous evidence as a byproduct of operations, and aligning security and compliance into a single execution model. Attendees will leave with practical ways to identify weak points in their own environments and move from static compliance to something that holds up when tested.

Dustin D. Cloos

Dustin Cloos is the Chief Growth Officer (CGO) at Taurean, where he helps organizations navigate the intersection of cybersecurity, compliance, technology, and business operations. With more than 30 years of leadership experience spanning military service, government contracting, enterprise IT, cybersecurity, and business growth, he has led teams and programs supporting organizations ranging from small businesses to large Federal agencies.

Dustin has worked across operations, program management, capture, solution architecture, and executive leadership, giving him a unique perspective on why security and compliance programs succeed—or fail—in practice. His experience includes helping organizations implement cybersecurity frameworks, prepare for regulatory requirements, improve operational maturity, and align technology investments with business objectives.

Dustin is a true believer that if it doesn't run it doesn't matter.