Senior technology + security leadership, without a full-time hire

You don’t have to hire a CIO to have one.

I’m the person you call when something technical lands on your desk and there’s nobody here who knows the answer.

You get that senior person without adding another full-time executive—and I stay involved enough to know your organization.

Not sure what to call the problem? That’s fine. Tell me what happened.

Who I work with

Mission-driven organizations doing serious work without a giant technology department.

Nonprofits, healthcare organizations, and the people carrying technology decisions on top of the job they were actually hired to do.

Where the risk lives

What it looks like when nobody owns this

Funder

“Can you send us your security policy?”

Medical director

“I signed up for an AI scribe. Do we know where the recordings go?”

Operations director

“I don’t think our IT vendor is delivering what we approved. Who is managing that relationship?”

Board chair

“The board is wondering if we’re falling behind on technology. Did we ever do an IT strategic plan?”

Staff

“The client files are locked. Is there someone we’re supposed to call?”

None of these are technology failures. They’re decisions nobody was assigned to make.

Executive director

“Send it to ByrdTail. Dani will tell us what matters and what to do next.”

Forward it to ByrdTail →

I’m not your IT company. I’m not trying to replace them.

They keep the systems running. I own the layer above: what you sign, what you allow, what you tell your board, and where you’re exposed. I don’t install or resell, so my advice isn’t tied to selling you anything.

Why a specialist

You don’t need a generalist. You need someone who only does this.

01

If you’re a nonprofit

Explaining IT to your board is hard. You don’t have to carry it alone. I turn funder, vendor, insurer, and staff-tool questions into decisions your leadership team can make.

Fractional leadership for nonprofits →
02

If you’re HIPAA-regulated

Security governance, AI scribes, vendors, business associates, risk analysis, and executive reporting need an owner—not another checklist.

Technology leadership for healthcare →

A fair question

“Can’t AI do this?”

Some of it, genuinely. I use it myself, and I’d rather you did too.

But a model can’t hold organizational context, sit with your board, coordinate the humans when something goes wrong, or put its name behind a decision. The useful question is how to use AI well without handing it something it shouldn’t have. That’s part of the work now.

Why ByrdTail

You get the senior person. Every time.

Dani Byrd, CISSP, CISA · Principal

No handoff after the sale. No account manager relaying questions to someone technical. I know the environment and I stay in the work.

CISSP · CISA
CISSP means I’ve been independently tested on protecting information. CISA means the same for whether those protections work. Funders, auditors, and insurance carriers recognize both.
Works with your team
I set priorities, manage the vendor relationship, and translate risk. Your IT team runs the systems. I don’t bypass them.
Continuity built in
Critical contacts, decisions, and next steps are documented. The work never lives only in my head.

Who I am

I’m Dani. I’ve lived in Tulsa my whole life.

Most of the last fifteen years I spent protecting information for heavily regulated financial institutions, where the audits are constant and the tolerance for a mistake is zero. That’s where I learned what actually goes wrong.

The organizations closest to me are the ones doing harder work with less. I’ve served on the boards of Tulsa CARES, Oklahomans for Equality, and Mental Health Association Oklahoma. I sat on the IT steering committee there and mentored their IT director.

I’ve been in your seat. I’ve watched a board ask whether we’re protected and watched everyone in the room look at each other. That question deserves a real answer. That’s why this exists.

Citizen of the Cherokee Nation. Built here, for organizations here.

See the workAssessments your board can actually use.Open two examples →

Not a wall of technical findings. Your board gets the condition, the consequence, the decision, the owner, and what happens next.

Fictional examples—not client documents or legal advice.
Sample 01 · Security controlsLoose controls are creating avoidable exposure.View sample
ByrdTail RiskBoard technology + security assessment

Illustrative organization · Community nonprofit · 42 staff · Outside IT provider · Three locations

Overall conditionNeeds directed remediation

Core systems are operating, but several important controls depend on memory, informal practice, or an outside vendor whose work is not being independently verified. We found no evidence of an active breach. We did find gaps that make a preventable incident more likely and a recovery harder to manage.

Access
Material gap. Departed-worker access is not consistently reviewed across email, cloud applications, and vendor-managed systems. Privileged accounts do not have a single accountable owner.
Recovery
Needs evidence. Backups are reported as successful, but leadership has not received a recent restore-test result showing that critical files and systems can actually be recovered.
Assets
Incomplete. The organization cannot produce one current list of computers, software, owners, replacement dates, and security status. Budget decisions are therefore reactive.
Vendors
Unowned. Technology contracts renew without a consistent review of service commitments, security terms, administrator access, data handling, or exit requirements.
Incident readiness
Informal. Staff know to call the IT provider, but the sequence for executive, insurance, legal, communications, and board notification is not written or rehearsed.

Recommended 90-day plan

  1. 30 daysConfirm every privileged account, remove stale access, establish an offboarding checklist, and complete the asset inventory.
  2. 60 daysWitness a backup restore, create the vendor register, and assign an executive owner for every critical system.
  3. 90 daysRun a short incident exercise and give the board a one-page dashboard showing what is fixed, accepted, transferred, or still open.
Decision requested from leadership

Approve the 90-day stabilization plan, name the executive director as accountable owner, require the IT provider to supply evidence of completed work, and return unresolved high-risk items to the board.

Sample 02 · AI riskCan this nonprofit approve ChatGPT?View sample
ByrdTail RiskAI product risk assessment

Illustrative organization · Holds PHI · Serves minors experiencing domestic violence · Operates a syringe-services program

RecommendationApprove a limited, low-risk pilot—not client-data use.

ChatGPT can help with administrative work, but this organization’s information can reveal health conditions, age, location, family violence, and participation in harm-reduction services. A disclosure could create physical-safety, privacy, legal, and trust consequences. Personal ChatGPT accounts are not an acceptable place for that information.

Data sensitivity
Critical. Do not enter names, dates of birth, addresses, shelter or appointment locations, case narratives, clinical details, service dates, or any combination that could identify a participant.
Account control
High. Individual accounts leave the organization without consistent onboarding, offboarding, access rules, or administrative oversight. Use an organization-managed workspace for any approved pilot.
Product terms
High. Consumer ChatGPT content may be used to improve models unless the individual changes the setting. Business workspace data is excluded from training by default, but PHI use requires a separately approved HIPAA-eligible product and a BAA.
Output reliability
High. Outputs may be incomplete or wrong. ChatGPT must not make eligibility, safety, clinical, mandatory-reporting, or crisis-response decisions.
Connected tools
Not approved. Email, file-storage, case-management, and other connected applications require separate review because they expand what data the tool can reach.

Approved for the pilot

  • Drafting public-facing communications from public information
  • Brainstorming fundraising language without donor or client data
  • Creating agendas, job descriptions, and training outlines
  • Working with fabricated examples that cannot be traced to a real person

Not approved

  • Case notes, medical information, or client histories
  • Information about minors, survivors, locations, or safety plans
  • Syringe-services participation or other highly sensitive service records
  • Automated client decisions, clinical guidance, or crisis recommendations
Decision requested from leadership

Authorize a 30-day administrative pilot in an organization-managed workspace. Adopt a written no-client-data rule, provide staff training, require human review of every output, disable unreviewed connected tools, and reassess before any broader use. If a future use case requires PHI, stop and perform a separate technical, contractual, privacy, and BAA review.

Product facts checked August 2026 against OpenAI’s business data commitments, consumer privacy controls, and HIPAA-eligible products. Product terms and features can change; verify again before approval.

What you get

All of it. All year.

A senior security and technology person who already knows your environment, working alongside your outside IT company and your team.

When you need me
  • Reach me directly.Phone, email, or text. No queue and no ticket number.
  • Vendor management and contracts.I manage the relationship, translate the work, and make sure what was promised is actually happening—before and after you sign.
  • AI tools.Before they touch your data or quietly become policy.
  • Board, funder, and incident questions.I write the answer or sit in the meeting and give it.
Even when you don’t
  • Monthly.A standing call so context never goes stale.
  • Quarterly.A short written review and an updated AI and vendor register.
  • Ongoing.Your assessment kept current and changes flagged when they matter to you.
  • Annually.A board-ready summary you can hand over without rewriting.

A practical place to start

Nobody decided to start using AI. It just started.

Your staff has been pasting client information into chatbots for months. Your medical director wants a scribe. A funder is about to ask what your policy is, and there isn’t one.

This isn’t about catching people doing it wrong. AI needs someone to decide what’s allowed, write it down clearly, and give staff a safe way to use tools that help.

It’s also about what comes next. We’ll look at where your organization is today, find the work AI could genuinely improve, and choose a practical next step—without chasing every new tool.

One AI decision“Should we approve this tool?”

Bring one product, contract, scribe, or board question. I’ll help you understand the decision, the risks that matter, and what to ask next.

Bring the decision →
Organization-wide“What should AI change for us?”

We’ll look at current use, responsible guardrails, staff needs, and where AI could genuinely improve the work. The result is a practical direction—not a pile of tools.

See the whole picture →
Talk through your AI questions →

AI is a leadership decision that got handed to whoever was standing closest to it.

Ways to start

You don’t need to choose the right service before you call.

Bring me what landed on your desk. We’ll decide together whether you need one answer, a wider look, a plan, or someone to keep owning it.

01Bring me one decision.View details

A contract, an AI product, a vendor concern, or a board question nobody feels comfortable answering yet. I’ll help you understand what matters and what to do next.

Examples: “Should we approve this AI scribe?” · “Is our MSP delivering what we bought?” · “What should I tell the board?”

Talk through the decision →
02See the whole picture.View details

If the questions keep multiplying, we’ll look at your technology, security, AI use, vendors, and organizational priorities together. You leave with clear priorities—not another checklist.

Useful when leadership needs to know where things stand, what is exposed, and what should happen in the next 90 days.

Start with an assessment →
03Plan what comes next.View details

Technology should help the organization move forward, not merely keep the lights on. I work with leadership, your IT provider, and your board to turn the current environment into a practical technology and AI direction.

Annual planning, board-ready priorities, responsible AI opportunities, vendor direction, and a roadmap the organization can actually follow.

Talk about strategic planning →
04Add ongoing leadership.View details

When you need someone to keep owning these decisions, ByrdTail can stay involved as your advisory, fractional, or embedded technology and security leader.

I work above—not instead of—your outside IT company or internal IT team: technology decisions, security and AI rules, vendor oversight, board communication, and organizational risk.

Explore ongoing leadership →
How pricing worksView details

Clear scope before the work begins. Fixed-scope projects are quoted after a short conversation. Ongoing nonprofit pricing is tailored to organizational size, complexity, and how much support you need.

You’ll know what is included, what it costs, and where the boundaries are before we start. If you only need one conversation—not an engagement—I’ll tell you.

Tell me what landed on your desk

Twenty minutes tells you whether you need me at all.

Bring the messy version. You don’t have to know the right words. If you don’t need me monthly, I’ll say so.