heygrc
Engineeringthe heygrc team

Three risk entries. Only one can be quantified.

CTRL+F on the rebuilt GRC Engineer site turns GRC engineering into a daily two-minute rep. Tuesday's puzzle is about risk registers that wear costumes. heygrc is the complementary read at the pull request.

GRC Engineer just dropped CTRL+F #002: Tuesday is run the numbers. Three risk register entries, all of them looking real, and only one that can actually be quantified as written, a scenario with a frequency and a magnitude you could argue about. The other two are wearing costumes. Two minutes, three guesses, wrong answers explain themselves at grcengineer.com/ctrl-f.

That puzzle is not a side quest. It is what the rebuilt GRC Engineer site is for: a place where the practice gets reps, not just weekly essays. This note is the pointer, and a short take on where heygrc sits in the same stack.

A front door you can practice through

The new GRC Engineer site is the home for the weekly releases, the archive, the State of GRC Report 2026, the Workshop Terminal, and now CTRL+F, a daily game minted from that same corpus. No login. Your streak lives in the browser. One real problem a day, and one place where the artifact quietly fails.

The weekday tracks map the whole job: get machine-readable on Monday, run the numbers on Tuesday, test the intent on Wednesday, spot the assurance on Thursday, ship it on Friday, translate on Saturday, pick your battles on Sunday. That is GRC engineering as a skill you can train, not a title you inherit from a policy binder.

What #002 is actually teaching

We are not spoiling which of RISK-014, RISK-021, or RISK-030 is the real one. The lesson is upstream of the answer. A risk register full of entries that look serious is not the same as a register you can put a defensible number on. Frequency and magnitude you can argue about are the difference between quantification and costume.

That is the GRC engineering habit: read the artifact for what it can actually support, not for how official it looks. The same habit shows up in a SOC 2 report, a detection rule, a policy line, and a deploy gate. CTRL+F is daily practice for that habit.

Where heygrc sits in the same stack

heygrc is not the daily puzzle, the newsletter, or the workshop chat. It is the layer that reads each pull request against the frameworks you are audited on and names the exact control a change touches, at the diff. CTRL+F trains the judgment. heygrc applies a related judgment at the moment a control can still move for free: before merge.

Friday's track on the game is ship it: deploy-time controls, find it, fix it, gate it. That is the surface heygrc lives on every day, for every change, whether a person or an agent wrote it. Stack the layers. Play the puzzle at grcengineer.com/ctrl-f, read the LinkedIn note, keep learning from GRC Engineer, and put a compliance read on the pull request so the craft shows up where the commits do.

We did not build heygrc to replace that workshop. We built it for the part of GRC engineering that only exists if someone, or something, actually looks at the diff.

grc-engineeringctrl-fpracticecode-review