Senior technology judgment for companies in transition.
A fractional CIO/CISO practice for organizations navigating acquisitions, integrations, leadership changes, and compliance milestones — where the IT function needs an experienced hand, not a full-time executive.
An embedded technology partner — for a deliberately small number of clients.
For more than two decades, I’ve worked as the embedded fractional CIO, CTO, or CISO for a small, carefully limited roster of clients — typically a few hours each week, with senior judgment available on demand for incidents, audits, and M&A events. This is long-tenured, embedded work, not project work. Several current engagements have run twenty years or more.
The model fits organizations that need senior-level judgment in the room — for acquisitions, audits, incidents, vendor decisions, and long-range planning — but don’t need, or can’t justify, a full-time executive. I set direction, own the security and compliance posture, advise the CEO and board, and partner with internal IT staff or outside MSPs who handle day-to-day execution.
Three areas, one consistent standard.
M&A IT Integration
Consolidating acquired entities onto unified Microsoft 365 tenants, identity, security, and operational standards — without breaking the producers, books of business, or carrier relationships that made the acquisition worth doing.
Cybersecurity & Compliance
Defensible security programs aligned to NYDFS 23 NYCRR 500, SOC 2, and the cyber requirements increasingly imposed by carriers and E&O markets. Practical controls, real evidence, audit-ready.
Fractional Executive Leadership
Acting as the senior IT voice in the room — for the CEO, the board, the PE sponsor, the auditor — while a leaner internal team or existing MSP handles execution. Judgment, accountability, and continuity.
Business Email Compromise & wire-fraud investigation.
Business Email Compromise is among the costliest cyber events a company can face — a single spoofed thread or hijacked mailbox can redirect a six- or seven-figure wire. When it happens, the first 24 to 72 hours decide how much is recoverable. I lead the investigation and the response, working alongside your bank, your cyber insurer, and your existing IT team to contain the incident, recover what can be recovered, and produce the record everyone downstream will ask for.
Containment & triage
Lock down the compromised account, revoke active sessions and tokens, and reset access before more evidence is lost or a second wire goes out.
Microsoft 365 & Google Workspace forensics
Reconstruct how and when the mailbox was accessed from Microsoft 365 or Google Workspace audit and sign-in logs, and surface the malicious inbox rules, mail forwarding, and OAuth app grants attackers leave behind.
Financial recovery
Coordinate the bank recall, the FBI IC3 filing, and the Financial Fraud Kill Chain while the recovery window is still open.
Scope & exposure
Determine which accounts, data, and counterparties were affected — and whether the event rises to a reportable breach.
Reporting & compliance
Produce the written record insurers, carriers, and regulators require — including NYDFS 23 NYCRR 500 notification where it applies.
Hardening
Close the gaps that let it happen — MFA, conditional access, and out-of-band payment verification — so the next attempt fails.
Clear model. Clear boundaries.
- StructureRetainer-based, with hourly available for project-bounded work.
- AvailabilityTypically 4–20 hours per week, with senior judgment on demand for incidents, audits, board meetings, and M&A events.
- EngagementLong-tenured and embedded — most client relationships run for years, many past two decades.
- Working styleRemote-primary, with on-site visits as needed for key events like audits and integration kickoffs.
- ConfidentialityNDA at the outset; active engagements are never named publicly. Case work is discussed privately.
What I’m not
- Not your help desk — day-to-day end-user support stays with internal IT or an MSP.
- I don’t replace existing IT staff or MSPs; I work alongside them and make them more effective.
- Not on-call rotation for monitoring, patching, or routine incident response.
- Not break-fix or hands-on system administration as the core of the engagement.
Two decades of continuity through real change.
The work has included a twelve-year fractional CIO role at a multi-site distribution business held through two private-equity ownerships, and twenty-plus-year continuous relationships with publishing and design-industry brands — including continuity straight through public-company acquisition events. The through-line is staying valuable to leadership across transitions, not just standing up systems once.
Let’s talk about what you’re facing.
Whether it’s an acquisition, a compliance deadline, a carrier’s cyber requirement, a suspected email compromise, or a leadership gap — I’m happy to walk through relevant case work in a conversation.
Connect on LinkedIn