From the Desk of
CIO · VP of Information Technology
Enterprise IT & Cybersecurity Leadership · AI Governance & Assurance · U.S. Air Force Veteran · Girl Dad ×3
ISC2 · Certified in Cybersecurity
Google · Cybersecurity Certificate
PeopleCert · ITIL Foundation
Nearly thirty years building, securing, and governing enterprise technology.
Profile ↓I'm a foundational CIO — the leader who builds the base an organization runs on. Sometimes the ground is empty: a function that has never existed, stood up from nothing. More often it isn't — the environment has never been fully mapped, and what is actually running is not quite what the organization believes is running. That gap is not a scandal; it is what happens to every enterprise given enough time. Empty lot or occupied one, the first deliverable is the same, and it is never the rebuild. It's the assessment: an honest picture of what is there, what it depends on, and what it will take to make it enterprise grade. Then the plan. Then the documentation. Then the execution — and then a base the organization can actually run on. Then continual improvement, so it never quietly drifts back into being unmapped.
Nearly thirty years, and the pattern holds. Established a CIO function where none existed. Rebuilt an enterprise systems environment in forty-six days following an international cyberattack. Built a business intelligence department from nothing. I've done that work from the Chief Information Officer's chair, and it's the chair I'm built for — and the founder's seat isn't new to me either. I've built and run my own ventures since the 1990s, which is why I read technology from both sides of the table: the founder who builds from zero, and the executive who has to make it scale and keep it secure.
What makes that foundation rare is the depth underneath it. I lead security at a level most CIOs delegate — identity, vulnerability, governance, and the layer most programs reduce to a checkbox: awareness and training, built so that people stop being the softest control in the building. Because an organization's risk appetite sets its security posture long before any control does. And I treat AI the way I treat any production system: provenance, source-of-truth governance, and verification, so it's a capability an organization can stand behind rather than a liability it can't see. Design it right, secure it, sign your name to it. One discipline, three layers, one signature.
That standard has a date on it. Long before any of this I was an operational crew chief on KC-135E tankers, holding Red X authority — the aircraft flew or it sat grounded on my inspection and my signature, and by technical order no one could direct me to change the call. Rank could not overrule it. The systems have changed since. The standard has not.
The discipline is old. Only the system is new.
Stand a function up from nothing where none has existed — or walk into an environment nobody has fully mapped, establish what is actually there and what it depends on, then document, plan, and execute the rebuild to a standard that holds. Either way the assessment comes first, because no one can approve a plan for a system they cannot see.
Established the CIO function and rebuilt the enterprise systems environment in forty-six days following an international cyberattack. At a ~$150M manufacturer, grew the IT budget by roughly 55% — because the investment case was argued in the business’s own terms, not IT’s.
ERP ownership across two multi-plant food manufacturers — Infor Adage and Infor M3 owned, Oracle JD Edwards operated — and with it the planning stack the plants actually run on: MRP, production scheduling, capacity planning, materials management, procurement, product costing, inventory, and order fulfillment. MES and PLM alongside ERP, warehouse management, EDI integration, enterprise HRIS, and the OT/SCADA production networks that make plant-floor security a manufacturing problem before it is an IT one.
Identity and access management, threat and vulnerability management, governance, risk, and compliance — and security awareness and training, so the human layer is a control rather than the gap. Built and led, not delegated. I identified and documented a critical exposure with supporting data ahead of the incident that proved it, owned the recovery, and established the security program, vendor strategy, and cyber-insurance posture that replaced what failed. ISC2 Certified in Cybersecurity; Google Cybersecurity Certificate.
Built a business intelligence department from nothing and led it, inside a ~$12M six-unit public-sector IT bureau — data warehousing, reporting, and predictive analytics that moved the organization from describing what happened to anticipating what came next. All of it resting on the source-of-truth discipline that decides whether you are measuring reality or measuring your own assumptions.
ITIL-disciplined service management. Version control, provenance, and source-of-truth governance applied to AI exactly as they are applied to any production system — so what it produces can be traced, verified, and stood behind.
Building and running ventures since the 1990s — brand, infrastructure, and product from zero. The founder’s instinct for building and the executive’s discipline for scaling and securing it, in the same pair of hands.
Every organization already knows its risks. They sit in a register somewhere — documented, ranked, signed. The breach almost never happens in the gap between the threat and the control. It happens in the gap between the risk that was written down and the remediation that was funded.
Controls don't accept risk. Architecture doesn't accept risk. People do.
That gap is not a technical failure. It is a decision — made by someone, in a room, with a budget in front of them. Closing it is the work I care most about.
Why an organization's risk appetite sets its security posture long before any control does.
Why governing AI is less about the model than about whether you can trace — and stand behind — what it tells you.
Why the discipline everyone calls bureaucracy is the only thing holding the building up when the pressure arrives.
The Assessment Is the Deliverable
Why the first thing an organization needs is not a plan, but an honest picture of what it actually has.
Why forbidding a failure is not the same as catching one — and what it takes to prove a framework is actually holding.
Three ventures. Each one proves a different half of the argument above.
The practice — proves the seat
Fractional CIO practice for the mid-market — the seat, not an outside opinion. Five practices: enterprise IT leadership; cybersecurity and incident recovery; data and source-of-truth discipline, including master data management; governance, oversight and AI assurance mapped to ISO/IEC 42001 and NIST AI RMF (alignment, not certification); and M&A systems integration. I run my own ventures on the same governed AI operating system I would stand up for a client — the discipline is proven on my own businesses before it is ever proposed to yours.
Technology, commercialized
Veteran-owned garage and surface coatings company, co-founded with a fellow veteran; I serve as CTO. I built the customer-facing platform: an instant online estimate that prices a job in five minutes from a guided form, and a Digital Garage Preview that turns a homeowner’s photo into an AI-generated view of the finished floor. A quote without a sales call — a combination that is rare in this trade. Technology as the competitive advantage, built into the business from the first day.
Governance and data discipline, proven
A commissioned heritage studio producing DNA-grounded, archivally rigorous family history books; I founded it and serve as CEO. I built the platform underneath it: custom production technology with an automated eleven-gate quality pass; AI-leveraged research workflows where the machine retrieves and every editorial judgment stays human; and master data management that reconciles DNA, GEDCOM exports, military personnel files, and foreign civil and parish archives into a single authoritative record — conflicts disclosed, never quietly resolved. Client DNA files and archival source material move through it under encryption, multi-factor authentication, scoped access, and defined retention — nothing held beyond the commission. The heirloom is what the client keeps. The discipline underneath it is what I build.
A true north on the wall is easy. The will to follow it is not. Those are the only companies I'm interested in — and if the technology underneath yours doesn't yet match the ambition, that's the problem I want.