I'm a technology executive. For more than a decade I've run IT, security and compliance,
development, ecommerce, and data as a CIO, mostly in businesses where technology was
underinvested and needed to carry growth. This site is where I keep my track record, my
writing, and what I'm reading.
0major nonconformities across six ISO 27001 / SOC 2 / HIPAA audit cycles
~30 FTEequivalent productivity gains via AI & automation, ROI-quantified
~$330Knet annual savings replacing an MSP with the right hire
~10acquisitions led through technology diligence & integration
Track record
Problems I've worked on.
“A major customer just asked for our SOC 2.”
Most companies meet this problem cold: a major customer or prospect suddenly requires SOC 2, ISO 27001, or HIPAA, nobody in-house has done it before, and the clock is contractual. I have been through that full cycle, starting from zero.
Boards want AI; budgets want returns you can defend. The hard part is measuring honestly, and being straight about where AI will not work in a given business.
Growing companies often discover they are paying managed-service prices for break-fix outcomes, with rising costs, slow support, and nobody owning technology strategy. I have rebuilt that situation more than once.
Technology risk can quietly reprice a deal, or stall an integration for years. Most diligence checklists miss client dependencies, key-person risk, and the real cost of systems consolidation.
Systems that don’t talk to each other, reporting nobody trusts, projects that never land, and no one senior enough to own the roadmap or challenge vendors. Most growing companies hit this wall eventually; untangling it has been the core of my career.