Mike Stafford - Professional headshot

Mike Stafford

Converged Security & Technology Leader

M&A Due Diligence | IT/OT | Fractional CIO/CISO

CISSP | CISM | CMMC CCP | Secret-Eligible

Holland, Michigan | Remote-First

"I find the million-dollar risks hiding in plain sight - whether they're buried in systems, processes, or the things people aren't saying."
Scroll
15+
Years Enterprise Experience

Manufacturing, automotive, defense-adjacent, PE portfolio companies, tribal enterprises. Scale-agnostic.

$50K→20hrs
Entra Migration

Vendor quoted $50K; scripted it in ~20 hours with automation tooling.

$300K/yr
Savings Identified

Business case for IT internalization across portfolio IT spend documented three years running.

Days→Real-Time
Quality Transformation

Paper-based tracking to real-time MES. Still in production 10+ years later.

Multi-Domain
Data Correlation

Frameworks connecting HR, production, quality, machine, and financial data.

Shop→Boardroom
Trusted Advisor

Equally comfortable troubleshooting with technicians or presenting to PE partners.

The Engine Underneath

Here's why I operate differently - the cognitive architecture that enables the outcomes you just saw.

Perceptual Reasoning 96th percentile
Working Memory 77th percentile
Verbal Comprehension 58th percentile
Processing Speed 77th percentile
Cognitive Profile Radar Chart A radar chart showing cognitive test scores: Perceptual Reasoning 127 (96th percentile), Working Memory 111, Verbal Comprehension 103, Processing Speed 111. Baseline is 100.

"The asymmetry is the asset. Rapid holistic pattern detection rather than sequential verbal processing."

96th percentile perceptual reasoning (PRI: 127)
Processes complex systems in parallel, not sequentially
Finds root causes while others chase symptoms
Decision hygiene: explicit assumptions, pre-mortems, second-order risk checks - catches biases in real-time

Assessment: WAIS-IV cognitive battery, September 2025, Dr. Shannon Connell (licensed neuropsychologist)

Read the full cognitive profile →

What This Actually Means

Bridging from "interesting cognitive profile" to "here's what I do for your business" - both analytical AND human capabilities.

Pattern Recognition

Finds coupling, dependencies, and failure modes that don't show up in documentation. Correlates data across disconnected systems to surface what's actually happening vs. what people think is happening.

Systems Thinking

Holds IT, OT, operations, and organizational dynamics in one mental model - sees how changes cascade across technical and human systems.

Data Correlation & Integration

Bridges systems that don't talk to each other. Work tickets to invoices, production data to quality metrics, CRM to operations. Finds the gaps and the money left on the table.

Stakeholder Alignment & Org Dynamics

Detects unvoiced concerns, misalignment, and organizational dynamics before they surface as problems. Figures out what's not being said. Trusted advisor across all levels.

Influence-Based Leadership

Drives outcomes through trust, expertise, and stakeholder alignment rather than hierarchical authority. Navigates from shop floor to boardroom with equal fluency.

Trusted Stabilizer

High emotional intelligence applied to organizational dynamics. The person executives bring in when things get tense. Stays clear on priorities while creating space where people can be honest without fear. Incident command mindset.

Strategic Foresight

Identifies risks and opportunities 6-18 months before they surface. Runs scenarios, spots second-order effects.

Cross-Domain Fluency

Walks into unfamiliar territory, gets productive fast, adapts to what's actually needed. Manufacturing, defense-adjacent, PE, tribal enterprises - different contexts, same rapid orientation.

Behavioral Threat Assessment

Reads micro-expressions, detects deception, and identifies behavioral threat indicators in real-time. Applies structured assessment frameworks to personnel risk, insider threat, and organizational dynamics — where security meets human psychology.

Where I Create Value

Highest Leverage

Strong Fit

Engagement Models

Retainer-Based Advisory

8-20 hours/month of strategic guidance

Project-Based Engagements

Defined scope with clear deliverables

Interim Leadership

Stability during transitions

Professional Track Record

Waséyabek Development Company work environment

IT Operations & Cybersecurity Manager

Waséyabek Development Company, LLC

January 2022 - April 2025 | Grand Rapids, MI | Remote

Managed IT operations and cybersecurity across a tribal enterprise portfolio with multiple subsidiaries, each in different industries with different compliance requirements. Functionally CISO-level scope across the entire portfolio

  • Coordinated MSP/MSSP partners and SOC providers to deliver security operations at scale with a lean internal team - managed vendor relationships end-to-end including third-party risk
  • Built incident response capability from zero: runbooks, triage processes, escalation paths, forensic procedures. Led investigations and coordinated response. Built disaster recovery and business continuity plans
  • Built and managed compliance programs around NIST 800-171, CMMC, and DFARS for government contracting operations. Aligned security controls across subsidiaries with varying technical maturity and maintained audit readiness
  • Portfolio included subsidiaries with HIPAA and PCI requirements - provided architectural guidance and compliance direction across those frameworks
  • Led IT and cybersecurity due diligence for M&A activity, assessing targets and managing post-close integration. Developed security awareness training. Managed IT budgets across the portfolio
  • Drove all initiatives through influence without authority, working across subsidiary leadership teams with different cultures and building trust to advance security improvements
RSI Manufacturing facility environment

Director of Information Technology

RSI Manufacturing

August 2011 - January 2022 | Muskegon, MI | Hybrid

Operated as ownership's #2 for a decade with hybrid IT Director/COO influence across technology, production, logistics, finance, and HR. The person people came to when ownership wasn't available - and the person people came to with problems they couldn't take to ownership

  • Scaled infrastructure to 3x capacity while reducing unplanned downtime. Architected ERP and real-time analytics platform that moved decision-making from gut feel to data-driven operations
  • Functionally served as HR advisor for much of tenure: complaints, concerns, conflict resolution, mentoring, team development across technical and non-technical roles. Built trust-based relationships where people could be honest
  • Managed IT/OT convergence across the manufacturing environment: PLCs, SCADA interfaces, machine monitoring, and quality tracking systems connected to enterprise IT infrastructure
  • Took on increasing information security responsibilities: network hardening, endpoint protection, access control policies, and security awareness. Managed physical building security including surveillance, access control hardware, perimeter monitoring, and facility assessments
  • Negotiated vendor contracts generating significant annual savings. Became the go-to resource for cross-departmental problem-solving, process improvement, and strategic planning across the organization
PSI SaaS startup work environment

Chief Technology Officer

Production Software Integrated, LLC

April 2016 - December 2021 | Muskegon, MI

Led product development of a SaaS manufacturing execution system (MES) from concept through production deployment, addressing operational challenges observed on manufacturing floors

  • Built real-time production visibility through touchscreen interfaces, visual work instructions, and machine monitoring. Replaced paper-based quality tracking. System still in production 10+ years later
  • Applied enterprise architecture thinking to startup context, designing for long-term sustainability. Bridged development, sales, and implementation, translating customer needs into effective solutions
  • Designed and implemented security architecture for the SaaS platform: authentication, access controls, data protection, and secure multi-tenant infrastructure. Deepened a broader shift into information security that carried forward across subsequent roles

Credentials

Industry certifications and demonstrated outcomes over academic credentials. 15 years of continuous learning in a field that reinvents itself every few years.

CISSP Badge

CISSP

ISC2 · 2021

Verify →
CISM Badge

CISM

ISACA · 2023

Verify →
CMMC CCP Badge

CMMC CCP

Cyber AB · 2024

Verify →
Microsoft Certified Expert Badge

Cybersecurity Architect Expert

Microsoft · 2023

Verify →
Microsoft Certified Expert Badge

M365 Enterprise Admin Expert

Microsoft · 2025

Verify →
CompTIA Security+ Badge

Security+

CompTIA · 2021

Verify →

Federal Tier 3 Security Determination

NBIS · 2024 · Valid through 2034

Secret-Eligible

GCFA

GIAC / SANS FOR508 · In Progress

Expected 2026

Best Fit

Where I'm Most Valuable

  • Complex environments with multiple moving parts and competing priorities
  • Situations requiring rapid orientation and adaptation - walking into chaos and making sense of it
  • Strategic decisions with technical implications where someone needs to translate across domains
  • M&A, integration, transformation - anything with ambiguity and stakes
  • Organizations that value outcomes over process theater
  • Teams that want honesty, even when it's uncomfortable
  • Operational challenges where systems thinking applies beyond technology - process improvement, organizational dynamics, efficiency optimization

Probably Not the Best Use of My Time

  • Compliance documentation and checkbox auditing I architect security programs and identify risk; I don't write the procedural artifacts to satisfy an auditor's checklist.
  • Routine operations and ticket queues I'm built for novel problems and strategic work, not steady-state maintenance.
  • Hands-on implementation without strategic scope I can build, but my highest value is in designing, directing, and connecting dots.
  • Bureaucratic environments If process matters more than outcomes, we'll both be frustrated.
  • Subcontracting through MSPs for routine managed services Project-based consulting and advisory work through security and consulting firms? Absolutely. Buried under an MSP doing ticket work? Not the best use.

This isn't about what's "beneath me." It's about fit and ROI. You're paying for pattern recognition, systems thinking, and strategic judgment. Using that to fill out compliance templates is like using a surgeon to apply band-aids.

How I Work

Growth Partner, Not Break-Fix

I'm not here to get calls at 3am when things break. I want to work alongside you to build systems, improve processes, and make your business more profitable and efficient. Where should we spend effort? What moves the needle? That's the conversation I want to be in.

Remote-First

Based in Holland, MI. Available for travel when it makes sense, especially for initial relationship-building or critical moments.

Async-Preferred

Complex insights come out clearer in writing. I do my best thinking with time to process and articulate. Happy to jump on calls when real-time is needed, but don't expect me to be the fastest talker in the room - expect me to be the most thoughtful.

Direct But Not Harsh

I tell you what you need to hear, not what you want to hear. But I do it in a way that lands. Honesty with empathy. You'll never wonder where you stand with me.

The Quiet Stabilizer

I've been called this more than once. When things get sideways, I'm the person who shows up and somehow makes people feel like it's going to be okay. Not through cheerleading - through competence and calm.

Trust is the Foundation

I create space where people can be honest without fear of it backfiring. If someone's frustrated or struggling, I hear that as information, not as a problem to escalate. That's how you actually fix things.

Strategic Scope

I map the system, identify the risks, design the architecture. Your team handles execution, or I can help coordinate resources. I stay involved for decision points, not status meetings.

Where This Goes

These are the functional roles this experience and capability set points toward - whether as formal titles or as the work within fractional/advisory engagements.

Fractional CIO / CISO / CTO PE Operating Partner (Technology) IT/OT & Integration Advisor Digital Resilience Lead Converged Security Consultant Critical Infrastructure Security Advisor M&A Technology Integration Lead

Building a portfolio of ongoing advisory relationships - companies that get strategic technology leadership without the full-time overhead. High trust, high impact, sustainable engagement.

Let's Talk

Fractional CIO/CISO, converged security assessment, M&A due diligence, critical infrastructure — or something I haven't listed yet. Reach out — I read everything.

or