Professional Profile
I’m a technology executive with global leadership experience spanning enterprise infrastructure, cybersecurity architecture, and large-scale IT transformation — aligning infrastructure and security strategy with business continuity, risk management, and long-term operational resilience.
Today I bring that multinational practice to the small and mid-sized market. These organizations face the same threats and the same architectural questions as the Fortune 500, without the budget and without exposure to how large enterprises answer them. My work is to close that gap — enterprise-level structure, rigor and best practice, without enterprise-level overhead.
For Smaller Organizations
Most of what follows on this page happened at multinational scale — global carriers, Fortune 500 outsourcing, hundreds of thousands of employees. That is worth knowing, but it is not the reason a forty-person organization would hire me.
The reason is that a parish, a clinic, a dealership, and a forty-person nonprofit face the same threat landscape as the enterprises do, with none of the budget and usually without ever having been shown how large organizations answer it. Phishing-resistant hardware security keys. End-to-end encrypted email. Network and infrastructure practices that are routine at scale and unheard of at forty people. Much of the value is simply exposure to what exists.
The rest is structure: security architecture built against NIST CSF 2.0 and CIS Controls, resilient network design, supplier and dependency strategy, and the governance layer that usually does not exist yet — scaled to what the organization can actually operate. I run a business with payroll, contractors, insurance, and renewals of my own, and I make the same trade-offs with my own money.
The practice
The complete IT department function, on a standing engagement
There are two ways to work with me. Advisory engagements are scoped individually — architecture, security posture, supplier strategy, a decision that needs an independent read. The other is the standing one: the complete IT department function, delivered through my practice on a fixed monthly basis, covering strategy, security, infrastructure, and day-to-day operations under one accountable relationship. Both carry the alignment of an employee rather than a reseller — no hardware sales, no commissions, no manufacturer agreements. The department engagement usually starts with a structured review of what an organization already has, and the findings come before any discussion of terms.
Writing
Lead paper
Before SD-WAN and SASE Had Names
Rebuilding a 500-site global network on the public Internet, 2007–2009
Two independent datasets pointed at the same architectural layer: the local access loop consumed most of the WAN budget and caused nearly all of the outages. So we stopped buying a carrier network and built our own — ordinary local Internet access, IPsec we controlled, and ten points of presence in carrier-neutral interconnection facilities across 60 countries. Years before the industry had names for any of it.
Three companion papers take a single argument from that project and examine it on its own.
Companion paper
Where congestion management actually belongs — and what multi-class MPLS is really buying
Queuing only does something when a link is congested. In our environment the congested link was almost never the carrier backbone — it was the local access circuit, commonly the narrowest hop in the path. That changes what you should be willing to pay a provider to arbitrate, and where congestion management actually belongs.
If the provider’s network is congested, don’t buy the network. If it isn’t congested, don’t buy multi-class MPLS.
Companion paper
Your SLA Is Measuring the Part That Isn’t Failing
What carrier service level agreements actually cover, and what to buy instead
Roughly 98 percent of our circuit outages happened in local access — the portion of the service our contracts protected least, and frequently the portion the SLA measurement span excluded entirely. A carrier can report an excellent result across a span that doesn’t include where you actually fail.
An SLA is a contractual response to failure. Resiliency is an engineering response to failure.
Companion paper
The economics of WAN redundancy, and designing availability to business requirements
Providers discount the network half of a backup connection and charge full price for the local access circuit — which was 75–80% of our WAN cost. So a “discounted” standby ran $1,500 against a $2,000 primary, billed 8,760 hours a year and used for six. Pricing that per avoided hour of downtime changes which sites should have it.
Redundancy has value only in relation to the business impact of the failure it prevents.
From the same period, a paper that turns from the network itself to the companies supplying it.
New paper · Supplier strategy
Managing service providers without becoming dependent on them
A customer holds real negotiating power twice: when the provider is competing for the business, and when the contract is nearly over. What shifts the balance in between isn’t the contract — it’s dependency, accumulated one convenient service at a time until changing any of them means changing all of them. How we designed against that across 60 countries, and why leverage is built into the architecture rather than won at the table.
A provider never has to say you cannot leave. The architecture says it for them.
And one that turns from carrier-scale infrastructure to the other end of the scale.
New paper · Cybersecurity
Spend Where the Attacks Actually Start
A cost-effective defense-in-depth architecture for organizations with limited IT resources
A parish, a clinic, and a forty-person nonprofit face the same threat landscape as the enterprises, with none of the budget — but attacks that diverge wildly once inside converge sharply at the way in, and nearly all of them arrive through a message or a login. This paper sets out one architecture built on that convergence: how to choose the standards bodies you build against, eleven control categories in six layers, why each sits where it does, and how a single phishing attempt meets five independent chances to end.
Two controls are two layers only if the technique that defeats one does not defeat the other.
Career Highlights
-
Fractional CTO & Cybersecurity Advisor
Frisco Computer Service LLC · 2020–Current
Bringing multinational enterprise practice to the small and mid-sized market. These organizations face the same threat landscape and the same architectural questions as the Fortune 500 — without the budget, and frequently without ever having been shown how large enterprises answer them. Much of the value is exposure: phishing-resistant hardware security keys, end-to-end encrypted email, and network and infrastructure practices that are routine at scale and unheard of at forty people. The rest is structure — security architecture built against NIST CSF 2.0 and CIS Controls, resilient network and infrastructure design, supplier and dependency strategy, and the governance layer that usually does not exist yet. Recent work includes a published SMB security architecture, Spend Where the Attacks Actually Start.
-
Chief Technology Officer
Exinda Networks · 2012–2013
Recruited to succeed the departing technical founder. Led a 100+ person global Systems Engineering organization; served as primary technical liaison to Fortune 500 clients and industry analysts including Gartner; partnered with the Chief Scientist and CMO on product positioning and executive messaging.
-
Global Infrastructure Architect
Cadbury & Kraft Foods · 2008–2010
Led global and country-level infrastructure architecture across Cadbury's 60-country, 500-site, 100,000-employee footprint through the Kraft Foods acquisition — scaling to a combined 100+ countries, 2,000+ sites, and 500,000 employees; ran large-scale global RFPs with national and regional telecom providers, partnering directly with country managers, the CTO/CIO, and executive leadership.
-
Director of Technology — Outsourcing
BT Global Services · 2001–2008
Served as technical lead for BT's international outsourcing team, architecting multinational IT solutions for Fortune 500 clients on deals ranging from $500M to over $1B in total contract value across hundreds to thousands of sites; worked directly with client CIOs/CTOs and executive teams, and was routinely named in outsourcing agreements to ensure continuity post-sale.
-
Foundational Technical Training
Pacific Bell & AT&T Systems and Technologies · 1993–1996
Began my career in the early 1990s trained through Bell Labs and AT&T Systems and Technologies — widely regarded as some of the most rigorous engineering training in the industry — establishing the systems and network engineering foundation that has carried through every role since.
Across these roles I led large-scale enterprise infrastructure, network architecture, and global IT transformation initiatives in multinational environments — spanning secure network design, global data center strategy, infrastructure modernization, and large enterprise outsourcing engagements.
Core Focus Areas
- Cybersecurity & Perimeter Defense Architecture
- Enterprise Network Architecture & Security Engineering
- Infrastructure Modernization
- Operational Resilience & Continuity
- Executive Technology Advisory
- Security Architecture & Governance
Contact
For strategic advisory engagements or executive consultation:
Advisory engagements are scoped individually. Ongoing IT leadership, security, and infrastructure — the complete department function, on a standing basis — runs through Frisco Computer Service, which supports organizations across several states, delivered remotely with on-site work where it is warranted.