Vision

Expertise shouldn't be an enterprise privilege.

I'm Jacob Lehnert. More than a decade of security and technology leadership — Azure and M365 architecture, gap analyses, SOC 2, HIPAA, HITRUST, and PCI-DSS readiness, auditor liaison, and forensics when something has already gone wrong. Lately that work runs straight into AI: governing Copilot and agent rollouts, and securing the data those systems reach.

That's the background. What follows is why the practice exists.

The organizations that need this most are the ones priced out of it

A large enterprise carries a CISO, a compliance function, and a firm on retainer. A thirty-person clinic handling patient records has the same legal obligations, a comparable attack surface, and none of that budget. So it goes without — or it buys a checkbox from a vendor and calls it a security program.

That gap isn't acceptable and it isn't inevitable. Fractional leadership exists to close it: the same judgment an enterprise pays seven figures for, sized to an organization that can't. Serving small businesses and startups isn't where I landed — it's the point. Scope and pricing get shaped around the problem rather than handed down from a rate card, because a company that can't afford to be told what it needs will guess instead, and guessing is how small organizations end up in the news.

Data privacy should carry real consequences

I want to see privacy law with teeth. As it stands, the incentives too often run backward: penalties get absorbed as a cost of doing business, settlements arrive years after the harm, and the people whose information was lost get a letter and a year of credit monitoring. Meanwhile the organization that quietly did the work — encrypted what it stored, collected less to begin with, deleted what it no longer needed — gets no advantage for it.

My position, and it's a long-standing one: stronger consumer data protection, statutes with real enforcement behind them, and penalties sized so negligence costs more than diligence would have. Not to punish companies for being breached — breaches happen to careful people — but to make carelessness expensive.

Until the law catches up, the only protection most people have is the judgment of whoever is holding their data. Data is something an organization holds in trust, not a resource to be extracted. I build client systems to that standard, and I hold this site to it: no cookies, no analytics, no third-party requests, nothing about your visit recorded, profiled, or sold.

I won't design anything into a client's system that I wouldn't accept for my own data.

Responsible AI is an architecture decision

AI is where data stewardship gets tested fastest. Every prompt is a disclosure. Staff paste contracts, patient notes, and source code into whatever tool is open, and the terms governing that data can change on a schedule nobody in the building controls. Most responsible-AI programs amount to a policy document and an acceptable-use memo — useful, and nowhere near sufficient.

The durable answer is structural: run the model where the data already lives. I design, build, and hand over local AI systems on hardware the client owns — capable models, no per-token metering, no data crossing a boundary you can't audit, no stewardship handed to a third party by default. Every engagement opens with an honest feasibility read, and sometimes that read says a private deployment isn't the right call. Cloud AI is genuinely the right answer for plenty of organizations.

I hold myself to the same standard. The AI I use daily runs on hardware I own, on models I host locally — my work and my clients' context stay on equipment under my control. It's the same architecture I deploy for clients.

Why fractional

Most organizations under $100M don't need a full-time CISO or CTO and can't justify one. What they need is judgment: someone who has made these decisions before, in the room when the decisions get made. Sometimes that means serving as the executive. Just as often it means supporting the one already in the seat — working alongside sitting CISOs, CTOs, and IT directors as a confidential sounding board to sharpen strategy, find cost, defend budgets, and prepare for the board.

I can do the hands-on work when it's needed, but I'm most useful drawing the roadmap and directing execution, whether through your team or trusted partners I bring in. An assessment that ends as a PDF on a shelf helps no one, so I stay accountable to outcomes rather than deliverables.


When I'm not working, I'm usually under the hood of one of the Mazdas, on skis, or out on a trail with a pack — or somewhere deep in whatever I've decided to learn next.

Professionally, I'm direct and practical. I give straight answers in plain language, focus on what matters most first, and follow through on what I said I'd do.