Keith Formell — Technology & Security Executive

From the Desk of

Keith Formell

CIO · VP of Information Technology

Enterprise IT & Cybersecurity Leadership · AI Governance & Assurance · U.S. Air Force Veteran · Girl Dad ×3

ISC2 · Certified in Cybersecurity
Google · Cybersecurity Certificate
PeopleCert · ITIL Foundation


Nearly thirty years building, securing, and governing enterprise technology.

Profile ↓

Profile

I'm a foundational CIO — the leader who builds the base an organization runs on. Sometimes the ground is empty: a function that has never existed, stood up from nothing. More often it isn't — the environment has never been fully mapped, and what is actually running is not quite what the organization believes is running. That gap is not a scandal; it is what happens to every enterprise given enough time. Empty lot or occupied one, the first deliverable is the same, and it is never the rebuild. It's the assessment: an honest picture of what is there, what it depends on, and what it will take to make it enterprise grade. Then the plan. Then the documentation. Then the execution — and then a base the organization can actually run on. Then continual improvement, so it never quietly drifts back into being unmapped.

Nearly thirty years, and the pattern holds. Established a CIO function where none existed. Rebuilt an enterprise systems environment in forty-six days following an international cyberattack. Built a business intelligence department from nothing. I've done that work from the Chief Information Officer's chair, and it's the chair I'm built for — and the founder's seat isn't new to me either. I've built and run my own ventures since the 1990s, which is why I read technology from both sides of the table: the founder who builds from zero, and the executive who has to make it scale and keep it secure.

What makes that foundation rare is the depth underneath it. I lead security at a level most CIOs delegate — identity, vulnerability, governance, and the layer most programs reduce to a checkbox: awareness and training, built so that people stop being the softest control in the building. Because an organization's risk appetite sets its security posture long before any control does. And I treat AI the way I treat any production system: provenance, source-of-truth governance, and verification, so it's a capability an organization can stand behind rather than a liability it can't see. Design it right, secure it, sign your name to it. One discipline, three layers, one signature.

That standard has a date on it. Long before any of this I was an operational crew chief on KC-135E tankers, holding Red X authority — the aircraft flew or it sat grounded on my inspection and my signature, and by technical order no one could direct me to change the call. Rank could not overrule it. The systems have changed since. The standard has not.

The discipline is old. Only the system is new.


Capabilities


On Security

Every organization already knows its risks. They sit in a register somewhere — documented, ranked, signed. The breach almost never happens in the gap between the threat and the control. It happens in the gap between the risk that was written down and the remediation that was funded.

Controls don't accept risk. Architecture doesn't accept risk. People do.

That gap is not a technical failure. It is a decision — made by someone, in a room, with a budget in front of them. Closing it is the work I care most about.

Read the full perspective →

Perspectives


Proof of Practice

Three ventures. Each one proves a different half of the argument above.


Contact

A true north on the wall is easy. The will to follow it is not. Those are the only companies I'm interested in — and if the technology underneath yours doesn't yet match the ambition, that's the problem I want.