Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.
How we engage
Advisory
Interim / Fractional Leadership
Full-Cycle Transformation
Services
What we do
We provide strategic business and technology leadership three ways: as advisors, as interim or fractional executives inside your organization, and as the team that runs a full transformation end to end. The work follows one path — assess what you have, change what needs changing, then keep it working.
Enterprise Shared Services
Finance sits in one building, human resources in another, and information technology answers to whoever escalates loudest. Every site you added came with its own version of the same back office.Operational Governance
Your enterprise resource planning system went live years ago and the access list has grown every year since. Nobody has re-approved who can post a journal entry, change a vendor's bank details, or push code to production since the implementation team packed up.Technology Managed Services
Your technology function is one person who knows everything and a vendor who answers when it suits them. When that person takes a week off, you find out exactly how much of the business runs on their memory.Information Security Services
You have antivirus, a firewall, and a vendor who says you are covered. What you do not have is a written answer to the question of what happens on the Tuesday morning someone in accounting opens the wrong attachment.Risk and Compliance
Three different reviews this year asked for versions of the same evidence, and your team assembled it three times from scratch. The findings were not the expensive part.AI Governance
Nobody approved it, but people across your organization are pasting contracts, patient details, and payroll files into chat tools to get through the day. The tools are useful. That is the problem.Application & Systems Development
The process everyone depends on lives in a workbook one person maintains, or in a system bought in 2011 that nobody will upgrade because of what it might break. Both work until they don't.AI Solutions & Enablement
Someone demoed something impressive in the spring. It is September and nothing has changed about how the work gets done.
Industries
Industries we know
We work with organizations where technology failure is a regulatory event, not just an inconvenience: health centers, banks, defense suppliers, public agencies, manufacturers, and property and construction firms. Knowing your rules before the first meeting is the difference between advice and homework.
Financial Services and Banking
The examination window is on the calendar and your last report left open items that were supposed to be closed by now. You are reasonably sure they aren't.Manufacturing and Distribution
A controller on the plant floor runs an operating system the vendor stopped supporting years ago, and replacing it means scheduling downtime nobody will approve. Meanwhile your largest customer just sent a security questionnaire.Government and Public Sector
The system was procured correctly, implemented on schedule, and is used by roughly half the staff it was bought for. The next council or board meeting will ask about the other half.Construction and Property Management
Field crews track work on paper or in a phone, the office rekeys it days later, and the margin on a job is only clear once it is too late to do anything about it.Healthcare Operations and Technology
Your last security risk analysis was done during an electronic health record implementation and has not been touched since. The rule requires it to be current, and a breach investigation starts by asking for it.Defense Contractors (CMMC)
A solicitation you have won for years now carries a cybersecurity requirement, and your options are to meet it, subcontract around it, or stop bidding.
Why IT21
- CISA credential held since
- 1997
- Years across audit, security & governance
- 25+
- Leadership on the partner bench
- CIO + COO
Certified Information Systems Auditor since 1997, with backgrounds spanning the Information Risk Management practice at KPMG, City National Bank, a CPA-firm partnership, and career CIO and ERP leadership.
- BT Western
- JWCH
- Seiko
- South Central Family Health Centers
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

