Portrait generated by AI.
Information Systems Security Manager · Certified in Governance, Risk and Compliance · CompTIA Security+
24 years across cybersecurity, governance, and regulated federal environments — translating the discipline of the most demanding security frameworks into defensible AI governance for law firms.
My career has been built in environments where documentation is not a formality — it is the difference between a system that can operate and one that cannot. As an Information Systems Security Manager supporting the Department of Defense and the Intelligence Community, I have been accountable for the security posture of systems where the standard of care is absolute, the framework is federal, and the documentation has to survive the most rigorous scrutiny imaginable.
That experience — applying the NIST Risk Management Framework to live environments, managing Authority to Operate processes, and building governance structures that hold up under real examination — is not a background that translates to every industry. But it translates precisely to law firms navigating AI.
Law firms operate under a parallel obligation: the ABA Rules of Professional Conduct require competence, confidentiality, and supervision — and AI governance is where all three converge. I founded Modern Data Decisions to bring the same rigor I applied to classified federal systems to the law firms now deploying AI without the governance frameworks to match.
The methodology is the same. The documentation discipline is the same. The standard — if it is not written down and dated, it did not happen — is the same. What changes is the audience and the regulatory language. Everything else is the framework I have spent 24 years building.
Independent AI governance advisory translating the ABA Rules of Professional Conduct into documented, auditable NIST AI Risk Management Framework controls for law firms. Services span AI Governance Assessments, Policy & Workflow Architecture, and Fractional AI Governance Officer retainers.
Accountable for the security posture of systems handling sensitive and regulated data in federal environments. Responsible for applying the NIST Risk Management Framework to live systems, managing the Authority to Operate process, enforcing NIST SP 800-53 security controls, and producing documentation that survives federal audit scrutiny.
Graduate research focused on information systems security and governance in regulated environments.
Foundation in computer networking, systems administration, and technology security.
Every engagement produces dated, signed, auditable artifacts — not summaries or slides. The documentation is the deliverable, because documentation is what holds up when a carrier, a client, or a court asks the question.
AI tools will change. The NIST AI Risk Management Framework will not. Building governance around functions — Govern, Map, Measure, Manage — means the firm's posture survives tool turnover, vendor changes, and the next wave of AI adoption.
Modern Data Decisions accepts no vendor fees, no referral arrangements, and no affiliate relationships with AI tool providers. Every recommendation is made on the merits of the firm's risk posture — not on what generates revenue elsewhere.
ABA Formal Opinion 512 and the Rules of Professional Conduct establish minimum obligations, not ceiling targets. The question is not whether a firm uses AI — it is whether the firm can evidence that it governs AI deliberately. That is the bar this work holds firms to.
Engagements begin with a 30-minute confidential intake call. There is no obligation and no sales process — just an honest assessment of where your firm stands.
Request a Consultation →