IT strategy and leadership
Roadmaps, budgets, and technology decisions explained in business terms. Executive and board reporting that says what the risks are and what they cost.
I’m Ben Schulson. Through Calyer Consulting, I step in as fractional CIO, IT Director, vCISO, or technology compliance officer for small and mid-sized businesses. I set the strategy, build the security and compliance programs, get you through SOC 2 and ISO 27001, and stay accountable for how it all runs.
Based in New York and Lisbon, working with clients in the US and Europe.
Some of the frameworks and audits I work with
Bring me in for one role or several. The work overlaps, and having one person cover it means nothing falls between the cracks.
Owns technology strategy, budget, and roadmap. Advises the CEO on technology, risk, and investment, and reports to the board.
Runs IT day to day: systems, projects, vendors, and your MSP. Handles migrations, integrations, and the problems nobody else owns.
Builds and runs your security program: risk assessments, identity and access, monitoring, incident response, and business continuity.
Gets you audit-ready and keeps you there: SOC 2, ISO 27001, GDPR, AI governance, and more. Policies, controls, evidence, auditors, and customer security reviews.
Most clients call when technology or compliance suddenly matters to the business, and nobody in the building owns it.
One senior person across strategy, security, and compliance.
Roadmaps, budgets, and technology decisions explained in business terms. Executive and board reporting that says what the risks are and what they cost.
Risk assessments, identity and access, endpoint and email protection, logging and monitoring, incident response, and continuity and disaster recovery plans that hold up when they’re needed.
SOC 2, ISO 27001, GDPR, SOC 1, SOX, and regulatory exams. Gap assessments, policies, controls, evidence, and the auditor relationship, from first assessment through the report.
AI acceptable use policies, AI risk assessments, reviews of AI vendors and subprocessors, controls over AI-assisted development, and gap analysis against ISO 42001, NIST AI RMF, and the EU AI Act.
Separating tenants and identities, migrating data, and moving vendors under a transition services agreement, on either side of the deal and on a fixed timeline.
Third-party risk reviews, contract negotiation, and an independent check on your MSP’s recommendations before they reach leadership. Cloud and licensing costs brought back under control.
Compliance is most of my work. For six years I was a Chief Technology Compliance Officer running 20+ audits a year. I bring the same discipline to smaller companies: pick the right framework, build controls that fit how you actually work, and make the audit uneventful.
Matrix is a fixed income technology service bureau owned by the broker-dealer South Street Securities. I helped relaunch its internal collateral management platform as the company’s first external product, turning IT from a cost center into a profitable division. Its four products came to handle more than $10 trillion a month in collateral management and settlement for 15+ institutional clients.
As Chief Technology Compliance Officer, I owned technology compliance, risk, and governance for Matrix and the South Street family of two broker-dealers and an RIA, reporting to executives and the board. I led SOC 1 and SOC 2 for three products, SOX, SEC and FINRA exams, and due diligence from institutional clients including BNY Mellon, Pershing, and Standard Chartered.
In 2025, MG Stover sold its fund administration business to Securitize. As MG Stover’s fractional CIO, I led the IT separation: tenants, identities, data, and vendors moved under a transition services agreement.
Securitize then brought me in as fractional Director of IT to run the receiving side. I folded 110+ users and about 80 vendors into a 250+ user environment and reached integration and audit readiness inside a fixed six-month window, while spearheading their SOC 2 program.
Other recent work includes SOC 2 Type II and ISO 27001 readiness for a $30M fintech after a security incident, and AI governance and SOC 2 readiness for early-stage software companies in a venture portfolio.
We talk through what’s happening, what’s at stake, and whether I’m the right fit.
I review your systems, vendors, risks, and compliance obligations, then give you a written, prioritized plan in plain language.
I take the seat for as long as it’s useful: running the program, managing vendors and your MSP, reporting to leadership, and seeing you through audits. The time commitment scales with what you need.
I’ve spent more than twenty years running technology and compliance side by side. Most of that was at Matrix Applications and South Street Securities, where I helped turn an internal IT department into a service bureau whose platforms handled more than $10 trillion a month for institutional clients. I went from AVP to VP of Technology to Chief Technology Compliance Officer, reporting IT risk and audit results to executives and the board.
I started Calyer Consulting in 2022 to give smaller companies that same senior judgment without a full-time executive salary. My roots are in financial services, so I’m at home with auditors and regulators, but most of what I do applies to any company that handles data and depends on its systems.
Before all of that, I designed missions for Star Trek: Bridge Commander, founded one of the web’s first streaming video sites, and earned a degree in theatre.
You get an experienced executive on a part-time, ongoing basis, accountable for outcomes the way a full-time hire would be, without the full-time salary. The time commitment is set by what you need and can change as you grow.
No. Auditors have to be independent of the controls they test. I get you ready, help you choose an auditor, and manage the process with them, so the audit itself is uneventful.
No. My background is in financial services, which is why I’m comfortable with regulators and auditors. I also work with software companies and other small and mid-sized businesses that handle data and depend on their systems.
Not necessarily. I manage MSPs, hold them to their commitments, and review their recommendations before they reach you. If the arrangement isn’t working, I’ll help you change it.
Yes. I’m based in New York and Lisbon and work with clients in both. I also help US companies meet European obligations such as GDPR and the EU AI Act.
Email is the fastest way to reach me. A few lines about your company and what prompted you to write are plenty to start.