Senior IT, security, and compliance leadership, without a full‑time hire.

I’m Ben Schulson. Through Calyer Consulting, I step in as fractional CIO, IT Director, vCISO, or technology compliance officer for small and mid-sized businesses. I set the strategy, build the security and compliance programs, get you through SOC 2 and ISO 27001, and stay accountable for how it all runs.

Based in New York and Lisbon, working with clients in the US and Europe.

Some of the frameworks and audits I work with

  • SOC 2
  • ISO 27001
  • GDPR
  • ISO 42001
  • EU AI Act
  • NIST CSF
  • NIST AI RMF
  • SOC 1
  • SOX
  • SEC
  • FINRA
  • NYDFS

The seats I take

Bring me in for one role or several. The work overlaps, and having one person cover it means nothing falls between the cracks.

  • Fractional CIO

    Owns technology strategy, budget, and roadmap. Advises the CEO on technology, risk, and investment, and reports to the board.

  • Fractional IT Director

    Runs IT day to day: systems, projects, vendors, and your MSP. Handles migrations, integrations, and the problems nobody else owns.

  • vCISO

    Builds and runs your security program: risk assessments, identity and access, monitoring, incident response, and business continuity.

  • Fractional Technology Compliance Officer

    Gets you audit-ready and keeps you there: SOC 2, ISO 27001, GDPR, AI governance, and more. Policies, controls, evidence, auditors, and customer security reviews.

When companies bring me in

Most clients call when technology or compliance suddenly matters to the business, and nobody in the building owns it.

  • A customer or investor just asked for your SOC 2 report.
  • A key prospect sent a security questionnaire, and no one knows how to answer it.
  • You’re selling into Europe and need GDPR and ISO 27001 handled properly.
  • You had a security incident and need to know it won’t happen again.
  • You’re buying, selling, or carving out a business, and the IT has to move with it.
  • Your MSP bill keeps growing and no one inside can tell whether their advice is right.
  • Your team already uses AI tools, and there’s no policy behind them.
  • You’ve outgrown “the person who’s good with computers” but aren’t ready for a full-time CIO.

What I do

One senior person across strategy, security, and compliance.

IT strategy and leadership

Roadmaps, budgets, and technology decisions explained in business terms. Executive and board reporting that says what the risks are and what they cost.

Security programs

Risk assessments, identity and access, endpoint and email protection, logging and monitoring, incident response, and continuity and disaster recovery plans that hold up when they’re needed.

Compliance and audit readiness

SOC 2, ISO 27001, GDPR, SOC 1, SOX, and regulatory exams. Gap assessments, policies, controls, evidence, and the auditor relationship, from first assessment through the report.

AI governance

AI acceptable use policies, AI risk assessments, reviews of AI vendors and subprocessors, controls over AI-assisted development, and gap analysis against ISO 42001, NIST AI RMF, and the EU AI Act.

Acquisitions, carve‑outs, and integrations

Separating tenants and identities, migrating data, and moving vendors under a transition services agreement, on either side of the deal and on a fixed timeline.

Vendors, MSPs, and cost

Third-party risk reviews, contract negotiation, and an independent check on your MSP’s recommendations before they reach leadership. Cloud and licensing costs brought back under control.

Technology compliance, start to finish

Compliance is most of my work. For six years I was a Chief Technology Compliance Officer running 20+ audits a year. I bring the same discipline to smaller companies: pick the right framework, build controls that fit how you actually work, and make the audit uneventful.

How I take you through it

  1. Scoping and gap assessment. Which framework you actually need, and how far you are from it today.
  2. Policies and controls. Written to match how your company works, then put into practice, not left in a binder.
  3. Compliance platform. Vanta or Drata set up to automate monitoring and evidence collection, where it’s worth it.
  4. The audit. Choosing an auditor, preparing evidence, and managing fieldwork through to the report.
  5. Staying compliant. Ongoing monitoring, annual audits, security questionnaires, and customer due diligence.

Which framework you need

SOC 2
US customers ask for it before they buy, especially from software and service providers.
ISO 27001
The international security standard, often expected by European and global customers.
GDPR
Applies when you handle personal data of people in the EU.
ISO 42001 and the EU AI Act
For companies building or using AI. The AI Act sets legal obligations; ISO 42001 is the certifiable management system.
SOC 1 and SOX
When your systems affect your customers’ financial reporting, or you’re public or preparing to be.
SEC, FINRA, and NYDFS
For broker-dealers, advisers, and financial firms licensed in New York.
NIST CSF and NIST AI RMF
Practical structures for a security or AI risk program when no certificate is required.

Track record

Eighteen years at Matrix Applications and South Street Securities

Matrix is a fixed income technology service bureau owned by the broker-dealer South Street Securities. I helped relaunch its internal collateral management platform as the company’s first external product, turning IT from a cost center into a profitable division. Its four products came to handle more than $10 trillion a month in collateral management and settlement for 15+ institutional clients.

As Chief Technology Compliance Officer, I owned technology compliance, risk, and governance for Matrix and the South Street family of two broker-dealers and an RIA, reporting to executives and the board. I led SOC 1 and SOC 2 for three products, SOX, SEC and FINRA exams, and due diligence from institutional clients including BNY Mellon, Pershing, and Standard Chartered.

Both sides of the same deal

In 2025, MG Stover sold its fund administration business to Securitize. As MG Stover’s fractional CIO, I led the IT separation: tenants, identities, data, and vendors moved under a transition services agreement.

Securitize then brought me in as fractional Director of IT to run the receiving side. I folded 110+ users and about 80 vendors into a 250+ user environment and reached integration and audit readiness inside a fixed six-month window, while spearheading their SOC 2 program.

Other recent work includes SOC 2 Type II and ISO 27001 readiness for a $30M fintech after a security incident, and AI governance and SOC 2 readiness for early-stage software companies in a venture portfolio.

  • $10T+a month in collateral management and settlement ran on the Matrix platforms I helped run and secure, at 99.99% uptime.
  • 18 yearsat Matrix and South Street without a single successful cyberattack on our systems.
  • 97%of 20+ technology audits a year closed with zero exceptions, across SOC 1, SOC 2, SOX, SEC, and FINRA.
  • 100+IT and security policies written or audited, including 55+ at Matrix and 23+ at MG Stover aligned to SOC 2 and ISO 27001.
  • 95%reduction in risk exposure from the risk program I built at Matrix: IAM across 100+ systems, SIEM, DLP, BCP, and DR.
  • Zerodowntime through Hurricane Sandy and COVID, on continuity plans built years before they were needed.
  • 40%cut from AWS and Microsoft 365 costs at MG Stover, with stronger security after the move.
  • 350+vendor relationships managed across my career, including third-party risk reviews and contract negotiation.

How an engagement works

  1. Introductory call

    We talk through what’s happening, what’s at stake, and whether I’m the right fit.

  2. Assessment and roadmap

    I review your systems, vendors, risks, and compliance obligations, then give you a written, prioritized plan in plain language.

  3. Fractional leadership

    I take the seat for as long as it’s useful: running the program, managing vendors and your MSP, reporting to leadership, and seeing you through audits. The time commitment scales with what you need.

About Ben

I’ve spent more than twenty years running technology and compliance side by side. Most of that was at Matrix Applications and South Street Securities, where I helped turn an internal IT department into a service bureau whose platforms handled more than $10 trillion a month for institutional clients. I went from AVP to VP of Technology to Chief Technology Compliance Officer, reporting IT risk and audit results to executives and the board.

I started Calyer Consulting in 2022 to give smaller companies that same senior judgment without a full-time executive salary. My roots are in financial services, so I’m at home with auditors and regulators, but most of what I do applies to any company that handles data and depends on its systems.

Before all of that, I designed missions for Star Trek: Bridge Commander, founded one of the web’s first streaming video sites, and earned a degree in theatre.

Common questions

What does “fractional” mean?

You get an experienced executive on a part-time, ongoing basis, accountable for outcomes the way a full-time hire would be, without the full-time salary. The time commitment is set by what you need and can change as you grow.

Do you perform the SOC 2 or ISO 27001 audit?

No. Auditors have to be independent of the controls they test. I get you ready, help you choose an auditor, and manage the process with them, so the audit itself is uneventful.

Do you only work with financial services firms?

No. My background is in financial services, which is why I’m comfortable with regulators and auditors. I also work with software companies and other small and mid-sized businesses that handle data and depend on their systems.

Will you replace our MSP?

Not necessarily. I manage MSPs, hold them to their commitments, and review their recommendations before they reach you. If the arrangement isn’t working, I’ll help you change it.

Do you work with companies in Europe?

Yes. I’m based in New York and Lisbon and work with clients in both. I also help US companies meet European obligations such as GDPR and the EU AI Act.

Tell me what’s going on.

Email is the fastest way to reach me. A few lines about your company and what prompted you to write are plenty to start.