CISSP  |  CISM  |  vCTO Practice Lead

Building security programs that actually work — for financial services and healthcare.

vCTO Practice Lead at Abacus — serving hedge funds and private equity firms with $50B+ in combined AUM. Twenty years in IT and cybersecurity across financial services and healthcare.

Jason Benner

Credentials & Roles

  • CISSP
    ISC²
    CISSP — Certified Information Systems Security Professional
  • CISM
    ISACA
    CISM — Certified Information Security Manager
  • vCTO Practice Lead
    Abacus (Financial Services MSP)
    Current
  • VP & Director of IT
    BlueNovo / Medicus IT · 11 Years
    Prior Roles
  • Director of IT
    SOME / AnalySys · 8 Years
    Prior Roles
$50B+
Client AUM Managed
20+
Cloud Migrations Delivered
50%
Reduction in Orphaned Accounts
75%
Server Footprint Reduction
95%+
Client Satisfaction (11 yrs)
38
Task Engineer Playbook
01

Areas of Expertise

🔐

M365 Security Posture Assessment

Automated, repeatable assessments covering Entra ID, Exchange Online, SharePoint, Defender, Conditional Access, and AI Tool Discovery & Controls. Built the PowerShell-based collection engine — accelerated with AI tooling — that drives consistent, auditable output across a portfolio of financial services clients.

Entra ID MS Graph SDK PowerShell AI Tool Discovery
📊

Power BI Reporting & Dashboards

Executive summaries, remediation roadmaps, and access review dashboards built in Power BI. Complex DAX, Deneb/Vega custom visuals, and data models designed for client-ready delivery to boards and compliance teams.

Power BI DAX Deneb / Vega
👥

Team & Practice Leadership

Built and managed teams of 15+ across MSP environments. Owned client IT budgets in the $500K–$1M+ range, managed vendor and partner relationships, and developed the standardized frameworks, playbooks, and intake processes that make advisory practices scalable.

Team Management Budget Ownership Vendor Management Client Advisory
🛡️

Zero Trust Architecture

ZTNA design and implementation for financial services environments, including Entra Private Access and Cisco Umbrella SIG as a VPN replacement and layered network security model.

Entra Private Access Cisco Umbrella ZTNA
📋

Compliance, Governance & AI Advisory

SEC-aligned technology assessments, HIPAA Security Risk Assessments, and AI governance frameworks for regulated clients. Evaluating and mapping AI platforms — M365 Copilot, Claude Enterprise, ChatGPT, Gemini — against SEC/FINRA requirements, compliance logging obligations, and supervisory control frameworks.

SEC / FINRA HIPAA SRA AI Governance Claude Enterprise M365 Copilot
🏗️

Practice Productization

Turning ad-hoc security advisory into scalable, repeatable practices — standardized workflows, intake questionnaires, engineer playbooks, and tiered deliverables across client portfolios. AI tooling applied throughout to accelerate development, documentation, and delivery.

MSP CTM Process Design AI-Assisted Dev

Frameworks & Standards

NIST CSF SOC 2 SEC Reg S-P HIPAA PCI-DSS Zero Trust FINRA ISO 27001 ITIL CIS Controls NIST SP 800-53 AI Governance Claude Enterprise M365 Copilot ChatGPT Enterprise
02

Selected Work

Power BI · Executive Reporting

CTM Assessment Power BI Template

Client-ready Power BI report with Executive Summary, Remediation Roadmap (Deneb/Vega swimlane visual), and control scoring dashboards. Designed for consistent delivery across a portfolio of financial services clients.

Power BI DAX Deneb Vega-Lite

Access Review · Dashboard

File Server & SharePoint Access Review Dashboard

Power BI dashboard built on Varonis exports providing structured permission visibility across NTFS ACLs and SharePoint sites. Features disconnected slicer patterns for reviewer-driven filtering and exception tracking.

Power BI Varonis NTFS SharePoint

AI Governance · Compliance · Abacus Group

Claude Enterprise Controlled Deployment Framework

Compliance architecture analysis for a financial services client deploying Claude Enterprise across multiple access paths. Maps Web/Desktop, Cowork, and Direct API against device management, Conditional Access, identity coverage, file scope, agentic visibility, and compliance capture — identifying gaps and required compensating controls for each path.

Anthropic Compliance API SEC / FINRA Entra ID Cisco Umbrella OTLP

Network Monitoring · Reporting · BlueNovo / Medicus IT

Multi-Site Network Monitoring & Reporting Pipeline

Built a Power BI reporting layer on top of Auvik network monitoring data across the full MSP client base — surfacing uptime, alert volume, bandwidth utilization, and critical device status across 87 sites, 338 managed network devices, 5,000+ connected endpoints, and 420 hosts and servers. Delivered 99.67% average network uptime visibility and provided MSP leadership and clients with a consistent monthly operational view tied to the MBR/QBR reporting cadence.

Auvik Power BI Network Monitoring MBR / QBR Healthcare MSP
03

Case Studies

Client details anonymized. Outcomes are real.

AI Governance · Financial Services · Abacus Group Board-ready framework

Claude Enterprise Compliance Architecture for a Regulated Investment Firm

A financial services client was deploying Claude Enterprise across multiple access paths — browser, Claude Desktop, Cowork, and direct API — without a clear picture of where compliance coverage existed and where it didn't. With SEC examination cycles in view, compliance leadership needed a definitive map of what was captured, what wasn't, and what compensating controls were required.

Conducted a structured analysis of all three Claude access paths against six compliance dimensions: device management, Conditional Access, identity and access, file scope, agentic security visibility, and compliance capture and archiving. Identified that Cowork operates outside the Compliance API perimeter by design and requires a separate OTLP archiving pipeline to achieve partial coverage. Documented the key gaps — BYOD exposure via Conditional Access, API key usage bypassing web auth, Cowork session content not natively captured — and designed a layered control model using Entra ID, Cisco Umbrella DNS enforcement, and an AI gateway for programmatic API paths.

Delivered a controlled deployment reference document mapping every access path to its compliance posture, with explicit notation of coverage gaps and required compensating controls. Framework was presentable directly to compliance leadership and external counsel.

AI Governance Anthropic Compliance API SEC / FINRA Entra ID Cisco Umbrella OTLP
Practice Development · Financial Services · Abacus Group Practice-wide standard

Building a Repeatable M365 Security Assessment Engine for Financial Services

The CTM practice lacked a consistent, scalable way to assess client M365 security posture. Assessments were largely manual, inconsistent across engineers, and didn't produce structured data that could drive reporting or track remediation over time. With a growing portfolio of hedge funds and PE firms, the practice needed a repeatable process that could be run reliably by any engineer and deliver uniform client-facing output.

Designed and built a PowerShell-based assessment engine from scratch, covering 16 modules across Entra ID, Exchange Online, SharePoint, and Microsoft Defender. Migrated from deprecated MSOL and AzureAD modules to MS Graph SDK v2 and Exchange Online REST. Defined a Content_ID-keyed data schema producing structured JSON output consumed directly by a Power BI reporting layer — including an Executive Summary page, Deneb/Vega swimlane Remediation Roadmap, and control scoring dashboards. Authored a 38-task CTM Engineer Playbook standardizing the assessment workflow across the team.

Assessment engine deployed and running against live financial services clients. Consistent, automated data collection replaced manual processes. Power BI template provides uniform client-ready deliverables across the practice regardless of which engineer runs the engagement.

PowerShell MS Graph SDK v2 Power BI Deneb / Vega Entra ID Exchange Online
Client Recovery · Healthcare · BlueNovo 7-year retention

Rebuilding a Fractured Client Relationship and Delivering a 12-Project Transformation

A community health center serving 34,000+ patients annually had a badly damaged relationship with their IT provider. Trust was low, projects had stalled, and leadership was weighing a full transition. Inherited the engagement mid-crisis as the technical lead on day one.

Prioritized relationship repair through transparency — assessed the environment honestly, communicated clearly about what was broken and what a realistic path forward looked like, and delivered quickly on the highest-visibility issues. Conducted a full IT SWOT analysis, then designed and scoped a multi-year technology strategy across four focus areas: security enhancements, hardware modernization, network and VoIP upgrades, and EHR transition support. Drove execution across all 12 concurrent projects including M365 migration, HIPAA SRA, Windows 10 refresh of 100+ devices, Meraki network upgrade, MFA deployment, and eClinicalWorks implementation support.

Relationship fully recovered. All 12 projects delivered. Client remained a managed services partner for seven years.

HIPAA SRA M365 Meraki EHR Transition IT Strategy MFA
Infrastructure · Network · Healthcare · BlueNovo 30+ findings resolved

Multi-Site Network Overhaul and Security Remediation for a Rural Health System

A multi-site rural FQHC had accumulated significant technical debt across every layer of its environment — end-of-life routers and switches, self-hosted infrastructure with no redundancy, 1,000+ stale AD computer accounts, unmonitored UPS systems, no MDM, legacy Exchange still running, and critical OS versions well past end-of-support. A security assessment surfaced 30+ high and critical findings across network, identity, endpoint, and infrastructure.

Scoped and structured a phased remediation program across four execution tracks: immediate fixes, hardware procurement, post-deployment configuration, and ongoing managed services onboarding. Replaced aging Cisco routers with Meraki MX SD-WAN firewalls across all sites, refreshed LAN switches and wireless infrastructure, migrated self-hosted servers to a HIPAA-compliant data center, deployed Intune MDM, and led an identity remediation sprint disabling stale accounts and enforcing MFA across M365 and VPN. Decommissioned legacy Exchange and restructured network segmentation with VLANs.

All critical and high findings resolved. Cloud-managed SD-WAN deployed across all sites. Self-hosted infrastructure decommissioned and migrated. Identity posture materially improved with over 1,000 stale accounts addressed and MFA enforced organization-wide.

Meraki SD-WAN HIPAA Active Directory Intune / MDM Data Center Migration Network Segmentation
IT Transformation · Healthcare · BlueNovo $500K+ program

End-to-End IT Modernization for a Large Urban Community Health Center

A large urban health center was operating on aging workstations, unsupported servers, and outdated SQL infrastructure with no formal patch management, minimal endpoint security, and VPN access that hadn't been meaningfully reviewed in years. The organization needed a partner to own the full technology roadmap — not just respond to tickets.

Assessed the environment, prioritized findings, and designed a comprehensive multi-year modernization program. Scoped and managed a hardware and services budget in excess of $500K covering hyperconverged infrastructure, workstation and server replacement, Meraki network refresh across all sites, and software licensing. Led execution across data center consolidation, M365 migration, MFA deployment, VPN modernization, SQL upgrades, MDM rollout, and encryption compliance — coordinating procurement, vendors, and project delivery across all tracks simultaneously.

Full technology modernization delivered. Organization transitioned from reactive break-fix to a managed, proactive model with documented policies, automated patching, cloud-managed infrastructure, and enforced endpoint security.

IT Budgeting M365 / Azure Meraki MFA HCI HIPAA
04

Insights & Writing

MSP · Client Advisory LinkedIn

Stability Isn't the Finish Line

You put in the work, fixed the obvious issues, tightened controls, and suddenly the environment behaves the way it always could. That's a win — but it's also when your value proposition has to change. On showing value after the chaos is gone.

Compliance · Frameworks LinkedIn

Most Small IT Teams Are Already Doing Compliance Work

NIST, ISO, and CIS aren't out of reach for smaller organizations. Most teams are already patching, backing up, running MFA, and managing EDR — they just don't think of it in control numbers. On bridging the gap between real-world practice and framework language.

AI · Support Operations LinkedIn

The Real Bottleneck in AI-Powered Support Isn't the AI

AI is great at aggregating and connecting data. End users are notoriously bad at providing it. "It just doesn't work" isn't a ticket — it's a guess. The next big improvement in support isn't automation, it's better intake.

Metrics · Leadership LinkedIn

Without Curiosity, Data Is Just Decoration

Tickets closed, MTTR, CSAT, uptime — the numbers tell you what changed, but connecting the dots takes context and judgment. A drop in ticket volume could mean users are happier, or it could mean they've given up. On measuring progress, not just motion.

Supply Chain · Risk LinkedIn

Tool Diversification Doesn't Always Lower Supply Chain Risk

Diversification reduces single-vendor exposure — but every tool you add creates new pathways for incidents to travel. Before expanding your stack, it may be smarter to understand the connections you already have inside your environment.

05

Career Timeline

2026 – Present
vCTO Practice Lead
Abacus · Financial Services MSP

Leading the Client Technology Management practice for a portfolio of hedge funds and PE firms with $50B+ in combined AUM. Building automated assessment tooling, Power BI reporting infrastructure, and standardized advisory frameworks for financial services clients.

FinServ M365 Posture vCTO Advisory
2014 – 2025
Senior Consultant → VP of IT
BlueNovo / Medicus IT · Healthcare MSP & MSSP

Eleven years across four roles at a healthcare-focused MSP/MSSP. Served as vCTO for some of the largest Federally Qualified Health Centers in the country — delivering multi-site infrastructure modernizations, HIPAA security programs, M365 migrations, and EHR transition support across organizations serving hundreds of thousands of patients. Managed SOC and NOC operations with a team of 15+, sustained 95%+ client satisfaction, and reduced DR/BCP costs by 50% across the client base.

HIPAA / HITECH Healthcare IT SOC / NOC M365 Infrastructure
2006 – 2014
IT Consultant → Director of IT
So Others Might Eat (SOME) / AnalySys Ent. · Non-profit / Healthcare

Started through an MSP engagement and transitioned to a full-time director role. Led HIPAA and PCI-DSS compliance programs, reduced the server footprint by 75% through VMware virtualization, and managed Windows Server and Exchange migrations for a growing multi-site nonprofit serving Washington, D.C.

HIPAA PCI-DSS VMware Non-profit
06

About Me

Jason Benner

Security programs succeed when they're built to scale — not just to pass an audit.

I manage the vCTO practice at Abacus, a financial services MSP where I own the assessment and advisory relationship for a portfolio of hedge funds and private equity firms with $50B+ in combined assets under management. My work sits at the intersection of technical delivery, practice standardization, and client-facing security leadership — building the tooling and frameworks that let a team deliver consistent, credible advisory at scale.

Before Abacus, I spent eleven years at BlueNovo / Medicus IT in roles from Senior Consultant through VP of IT — running SOC and NOC operations, driving cloud migrations for 20+ clients, and building security programs across a healthcare MSP/MSSP environment. Prior to that, I led IT for SOME, a nonprofit in Washington D.C., where I ran HIPAA and PCI-DSS compliance work and reduced the server footprint by 75% through virtualization.

I hold the CISSP and CISM and bring a practitioner's perspective to every engagement — equally focused on technical outcomes and business impact. I actively apply AI tooling across assessment development, documentation, and client advisory work, and have developed formal AI governance frameworks for regulated clients navigating SEC examination exposure.

20+
Years in IT & Security
4
Roles at BlueNovo/Medicus
A+ · Net+
CCNA · MCSE
Prior Certifications
FQHC
Healthcare Specialist
  • Hedge Funds & Private Equity (SEC-registered)
  • Registered Investment Advisers (RIAs)
  • Healthcare MSP / HIPAA-covered entities
  • Non-profit organizations
07

Get in Touch

Open to conversations about director and VP-level IT and cybersecurity roles, security practice development in financial services, and M365 security consulting engagements.