AI strategy and governance, translated into board-ready decisions.

24+ years in enterprise technology — 11 years building and running infrastructure and security programs at Cisco, then 7 years advising Intuit's leadership at the executive level. I help boards and executive teams make sound decisions on AI adoption and cyber risk, before either becomes a crisis.

AI Strategy & Governance · Cybersecurity & Risk Advisory

Experience Across Fortune 100 Enterprises

  • Cisco
  • Intuit
  • GE
  • HP
  • DirecTV
  • Wachovia
  • AOL
  • Constellation Energy

Why now

The risk your CIO isn’t reporting.

68% of security leaders admit to using unauthorized AI tools themselves. 43% of security incidents now involve shadow AI — more than doubled from 20% last year. The people writing the policy are often routing around it.

Shadow AI isn’t an awareness problem. It’s an authority problem — and boards are being asked to oversee AI decisions they cannot evidence.

Sources: UpGuard State of Shadow AI (Nov 2025); IBM Cost of a Data Breach Report 2026.

A point of view

What most AI governance gets wrong

01

It catalogs use cases instead of governing decisions.

A list of AI pilots tells the board nothing about what it must be able to evidence.

02

It’s written to satisfy auditors, not directors.

Checkbox compliance produces binders. Boards need judgment they can defend.

03

It’s sold by vendors.

Advice paid for by the vendor it recommends isn’t advice — it’s distribution.

Virtuminds takes no vendor incentives and no referral fees. The principal who signs is the principal who delivers.

Portrait of the Virtuminds founder and AI governance advisor

About

Operator experience, board-level perspective

Built it before advising on it

I spent 11+ years directly building and running enterprise infrastructure and security programs at Cisco, then 7 years advising Intuit's leadership at the executive level.

Technical risk, governed as business risk

Through Virtuminds, I help boards and executive teams translate AI and technical risk into governed business decisions — before a crisis forces the conversation.

Track record at scale

24+ years across Cisco, Intuit, and Fortune 100 enterprises, including a $150M regulatory compliance program guided to zero missed deadlines.

Track Record

Selected results

The operating record behind the advisory — two decades of technology and risk leadership at enterprise scale.

A default that quietly cost millions

A default that quietly cost millions

3.5% cut in annual leased-asset spend

A platform that funded its own growth

A platform that funded its own growth

25 → 200+ internal teams in 2 years

Six months of downtime, recovered fast

Six months of downtime, recovered fast

6-week recovery vs. 6-month estimate

Four deadlines, one framework, zero misses

Four deadlines, one framework, zero misses

$150M saved, zero missed deadlines

Services

How I help

AI Governance Readiness Briefing

A focused 90-minute session for boards and executive teams working through AI adoption, oversight, or investment decisions. You leave with a clear picture of your AI exposure, the trade-offs, and a board-defensible path forward.

Board & Executive Advisory

Ongoing counsel as the AI decisions get bigger — governance frameworks, board reporting, and a second set of eyes before commitments get made.

AI Risk Due Diligence

For M&A, private equity, and portfolio companies: rapid assessment of AI exposure — shadow AI usage, third-party and model risk, data leakage — with findings a deal team can act on.

The Briefing deliverable

What you walk away with

Every Readiness Briefing ends with a one-page AI exposure map — what we confirmed, what’s inferred, and what we still don’t know. Below is an illustrative sample (anonymized).

Illustrative sample

AI exposure map

  1. 01Shadow AI

    confirmed

    14 unsanctioned AI tools detected in network traffic across 3 business units, including 2 with access to customer PII.

  2. 02Third-party & model risk

    inferred

    Vendor contracts for 6 of 11 AI-enabled SaaS tools lack data-retention and model-training clauses.

  3. 03Data leakage paths

    confirmed

    Code and customer records observed in prompts sent to external LLMs via browser extensions.

  4. 04Governance gaps

    unknown

    No inventory of AI models in production; ownership unclear for 2 customer-facing pilots.

  5. 05Board-ready next steps

    3 priority actions sequenced by risk reduction — full detail in the Briefing readout.

Honesty, not false precision: every finding is labeled confirmed, inferred, or unknown.

How we start

01

Introductory conversation

30 minutes, no obligation. We talk through the decision in front of you and whether I'm the right help.

02

Readiness Briefing

A focused 90-minute working session. You leave with your AI exposure mapped, the trade-offs laid out, and a board-defensible path forward.

03

Advisory

Ongoing counsel as the AI decisions get bigger — governance frameworks, board reporting, and a second set of eyes before commitments get made.