Skip to content
IT21

About & Team

Two partners, one perspective on business and technology

C-level operational and technology leadership brought to organizations that do not have it in-house.

Who we are

IT21 is two partners who spent their careers on opposite sides of the same problem. One ran technology functions and led enterprise resource planning programs as a CIO — accountable for systems that had to work on Monday. The other audited functions like it, first in the Information Risk Management practice at KPMG, then as a bank's information security director, then as a partner in a CPA firm — accountable for saying so when they did not.

That combination is the reason the firm exists. Consultants who have only built things tend to leave controls for later, and later arrives as a management letter. Consultants who have only audited things write findings that are correct and unbuildable. Work that holds up needs both perspectives in the room, and at IT21 they are in the room by default.

IT21 is partner-led. The people who scope your engagement and sit across the table from your auditor are the ones accountable for the work — the person who wrote your report is the one who defends it when the auditor pushes back.

The partners

Oscar Chacon

Partner — IT Risk, Governance & Assurance

  • CISA

Summary

Oscar Chacon is a founding partner of IT21 with more than 25 years of public accounting, consulting, and corporate management experience across information systems audit and assurance, information security, financial auditing, and technology governance. He leads IT21’s evaluation of technology controls and governance and the implementation of technology assurance and information security programs, and is a recognized specialist in banking and healthcare IT regulatory controls.

Focus areas

  • IT governance, risk, and compliance (GRC) system assessments and implementations
  • Information security architecture and program implementation
  • Internal audit outsourcing and co-sourcing, and third-party assurance (SSAE 18 / SOC)
  • Bank and healthcare IT regulatory compliance
  • ERP implementation controls, Sarbanes-Oxley readiness, business process analysis, and disaster preparedness and resiliency

Background

Oscar spent nearly a decade in KPMG’s Information Risk Management practice, where he managed the IT audit workstream for a large public university system. He served as Head of Information Security at City National Bank, where his information security initiatives were commended by the Office of the Comptroller of the Currency, and as the partner in charge of the IT Risk & Advisory Services practice at a public accounting firm.

Education & credentials

Oscar holds a B.S. in Computer Information Systems and a B.S. in Business Administration from California State University, Los Angeles, and a certificate in EDP Auditing / Quality Assurance from UCLA Extension. He has been a Certified Information Systems Auditor (CISA), certified by ISACA, since 1997.

John Gilboy

Partner — Strategy, Operations & Transformation

  • MBA

Summary

John Gilboy is a partner at IT21 and a seasoned COO and CIO with more than 35 years of hands-on experience creating and leading technology and shared-services organizations. He has worked across banking, financial services, healthcare, manufacturing and distribution, global supply chain, and technology services. His strength is IT and operations assessments, strategy and planning, and building roadmaps that organizations can confidently execute.

Focus areas

  • IT and operations assessment and strategy
  • Global shared services and team optimization, with operating-cost reductions of up to 25%
  • Digital transformation and intelligent automation
  • Regulatory and compliance (HIPAA, SOX, JSOX, GDPR, CMMC)
  • M&A, integration, de-mergers, and turnaround, often alongside venture-capital and private-equity ownership

Background

Most recently, as SVP and Global Head of Shared Services & Technology Services at a global IT managed-services provider, John led an innovation strategy that combined generative AI with a strong human service layer, improving customer retention and reducing operating costs by 15% within 180 days. Earlier, as Chief Information & Digital Transformation Officer at a global media and communications enterprise, he served as a primary technology liaison to the board, remediated 13 SOX material weaknesses, and reduced global security incidents by 50%.

Education & credentials

John holds an MBA, with certificates in Strategy, Finance, and Leadership, from the Claremont Graduate University School of Business.

Oscar Chacon, CISA

Certified Information Systems Auditor since 1997

Certified Information Systems Auditor with more than 25 years across IT risk, information security, and technology governance.

Strategic partners

Pending confirmation these carry over from the current site.

  • AdvisoryCloud
  • Care Expand
  • Service Prime
  • Concision Global Consulting

Why IT21

CISA credential held since
1997
Years across audit, security & governance
25+
Leadership on the partner bench
CIO + COO

Certified Information Systems Auditor since 1997, with backgrounds spanning the Information Risk Management practice at KPMG, City National Bank, a CPA-firm partnership, and career CIO and ERP leadership.