Dr. Ken Knapton

CIO · Cybersecurity Leader · Board Member · Author

Dr.Ken Knapton

I help executives turn technology complexity into business clarity.

CIO operator, cybersecurity leader, board member, IDC advisor, author, and business translator. My work focuses on reducing friction, exposing risk, simplifying systems, and turning technology into measurable business leverage.

  • CISSP
  • C|CISO
  • DIT
  • MBA
  • 3 U.S. PATENTS
  • 2 BOOKS
Dr. Ken Knapton
20+
Years C-level IT leadership
7
CIO roles across industries
3
U.S. patents
2
Published books
127
Countries · banking platform designed
IDC
Adjunct Research Advisor, IEP
View research profile →

What I Help Leaders Do

Make technology easier to understand, fund, govern, and improve.

The work is practical: reduce friction, make risk visible, improve decision quality, and align technology investment with business outcomes.

For executives

Technology strategy, cybersecurity and identity governance, technical health assessment, AI readiness, and AI agent governance for CEOs, CFOs, boards, and ownership groups.

Explore advisory services →

For event leaders

Keynotes, panels, podcasts, and executive roundtables on tech debt, cybersecurity leadership, AI readiness, agent governance, identity and passwordless, and data governance.

View speaking topics →

For CIOs & IT leaders

Practical frameworks and field-tested language for turning technical complexity into business conversations leaders can act on.

See the frameworks →

AI Readiness

Three questions, in order, before you deploy AI.

Most AI programs stall for reasons that have nothing to do with the AI. They stall on portfolio clutter, on data nobody owns, and on agents granted authority no person would be given. These questions run in sequence, and skipping one shows up later as cost, delay, or exposure.

01

What deserves to survive?

The Value Density Index divides the annual business value a system delivers by the annual cost of the complexity it introduces. Decide what to amplify, simplify, consolidate, or retire on evidence instead of politics — and simplify your highest-value systems before you chase retirements.

IDC Research · Published
02

Is the foundation ready?

Tech debt inside infrastructure and data is the most common reason AI pilots never reach production. Sprawl, unclear ownership, and unmanaged data create drag before the first model runs. Readiness is a cleanup sequence, not a purchase.

IDC Research · Published
03

Can agents be trusted with it?

Least privilege and segregation of duties, applied to AI agents. Most organizations have handed a single agent read access, write access, and approval authority — a combination that would fail an audit if a person held it. Security tooling does not catch this.

IDC Research · In review

Try It · Step 01

Score a system in your estate. Amplify, simplify, consolidate, or exit.

Pick one application you already argue about internally. Put a defensible annual dollar figure on the value it delivers, then on the complexity it costs you to keep it running. The ratio is its value density. Treat both sides as estimates with documented assumptions, reviewed with finance and the business owner — the point is comparability across your portfolio, not accounting precision.

VDI = annual business value delivered ($/year) ÷ annual complexity cost ($/year)

Annual business value delivered

$450,000

Annual complexity cost

$140,000
$35,000
$15,000
$10,000
ExitSimplifyStandardizeAmplify
Set the inputs

Move any slider to score this system.

Operational

Tickets, incidents, on-call load, manual runbooks, environment sprawl, and the specialist skills required to keep it supported.

Integration

Number of integrations, tight versus loose coupling, fragile pipelines, and custom middleware or glue code someone has to maintain.

Change

Lead time for change, deployment constraints, testing burden, change failure rate, and upgrade friction from customization or version lock.

Data

Duplicate sources of truth, reconciliation work, downstream dependency chains, quality remediation, and manual pulls in place of real pipelines.

Security & resilience

Patch exceptions, compensating controls, privileged access sprawl, DR and continuity overhead, audit remediation, and regulatory exposure.

A VDI above 2.0 indicates strong value per complexity dollar. Scores are meant for relative comparison across your own portfolio, not as an absolute benchmark. Full methodology, worked examples, and portfolio-level application are in Value Density Index: A Practical Framework for Measuring Business Value Against IT Complexity Cost (IDC #US54465526, April 2026) — request a briefing.

The Readiness Agenda

AI does not land on a clean digital core. It lands on yours.

Most AI programs are not constrained by model access. They are constrained by app sprawl, fragmented data, brittle integration, and uneven governance — conditions built up over years of practical necessity. Readiness is an enterprise capability agenda, not a tooling decision. Five priorities, and what progress actually looks like in each.

6%
of European CIOs said they were ready to move forward after completing infrastructure and data initiatives
IDC · Dec 2025
42%
name data duplication and fragmentation as the leading data quality issue affecting AI
IDC CIO/CTO Pulse · May 2026
50%
higher AI failure rates predicted by 2027 for CIOs who never start data debt remediation
IDC FutureScape · Oct 2025
$1.52T
estimated accumulated software technical debt in the United States
CISQ · 2022
01

Portfolio visibility

Leaders cannot reduce complexity they cannot see. Most organizations track applications but hold no map of integration paths, duplicate capabilities, data dependencies, or the shadow processes running outside governed architecture.

Inventory the whole digital environment, not the application list — integrations, data sources, unstructured concentrations, and ungoverned workflows — then use that baseline to find the friction that actually touches your priority AI use cases.

Progress looks like: integration map completed · shadow processes documented · duplicate capabilities identified
02

Application rationalization

Heavily used systems can still be poor strategic fits. High utilization hides data fragmentation, fragile integration dependencies, and weak governance — and none of that shows up in a license review.

Score the portfolio on business importance, integration burden, data quality impact, security exposure, and AI workflow relevance. The Value Density Index surfaces the systems consuming disproportionate complexity relative to what they return.

Progress looks like: redundant platforms retired · high-burden low-value systems decommissioned · clear systems of record established
03

Data governance

AI depends on timely, traceable, well-governed data. Duplicate records, conflicting definitions, unmanaged unstructured content, and inconsistent access controls constrain model performance and cap how far a deployment can scale.

Treat governance as a scaling discipline rather than a compliance exercise: metadata standards, lineage requirements, retention policy, access control, and named stewardship across both structured and unstructured information — starting with the domains your target use cases depend on.

Progress looks like: lineage documented for AI-adjacent workflows · stewardship ownership assigned · access policy enforced
04

Integration modernization

ETL jobs, custom scripts, API wrappers, and manually maintained logic hold critical workflows together. They work well enough for transactions and fail quietly under AI workloads that need real-time, governed, traceable data movement.

Document the integration dependencies behind your priority use cases and replace brittle point-to-point logic where it creates real operational or security risk. Tighten access controls and monitoring on AI-adjacent dataflows, especially those crossing third-party services.

Progress looks like: brittle integrations replaced or isolated · latency reduced in AI-relevant pipelines · third-party dataflow controls verified
05

Investment sequencing

The common pattern is a successful pilot, a stalled rollout, and disappointing enterprise adoption. It usually traces back to attempting scale before enough complexity was removed to support it.

Define a limited set of priorities with measurable outcomes and sequence modernization into manageable waves — beginning where data quality, ownership, and sponsorship are already strong. Use each wave to simplify the environment further, so the next one is cheaper.

Progress looks like: AI priorities tied to operational or financial outcomes · each wave linked to prior complexity reduction · governance keeping pace with deployment

Drawn from AI Readiness: Reducing App Sprawl, Data Debt, and Integration Risk to Scale Enterprise AI (IDC #US54661126, June 2026). See how this runs as an engagement →

Background

A career built at the intersection of technology, security, and business.

Dr. Ken Knapton has spent more than two decades in C-level IT roles, leading transformation across financial services, mortgage origination, healthcare, high-tech, hospitality, and entertainment. He is known for one core ability: making technology legible and accountable to the business leaders who fund it.

His background spans software development, enterprise security, CIO and CISO leadership, IDC research, graduate cybersecurity faculty work, and authorship. That mix gives his work a practical point of view. Technology should reduce friction, improve trust, protect the business, and create measurable leverage.

Today, Ken serves as CIO at WIN Brands, the hospitality company behind Costa Vida Fresh Mexican Grill and FatCats Family Entertainment. He also advises small and mid-market businesses through Rocky Mountain CIO, contributes published research as an IDC Adjunct Research Advisor for IT Executive Programs, and teaches graduate-level cybersecurity at ECPI University.

Technology complexity is business friction. Great CIOs reduce that friction until the business can move faster with more confidence.

Signature Frameworks

Clear language for complex technology decisions.

These frameworks turn technical complexity into management discipline. They help leaders see where technology creates leverage, where it creates risk, and where simplification will move the business faster.

Agent Governance

Agent Authority Boundary

Least privilege and segregation of duties applied to AI agents. Scope authority deliberately, gate high-impact actions, treat ingested content as untrusted, and keep an inventory of what every agent can reach. Structured to align with ISO/IEC 42001.

Tech Debt

Tech Debt Leverage

A business-facing way to quantify, communicate, and govern enterprise tech debt so it can be discussed with CEOs, CFOs, and boards.

Simplification

Value Density Index

Business value delivered per dollar of complexity introduced, scored system by system. The goal is not fewer applications for its own sake — it is higher value density across what remains.

AI Readiness

Data as Tech Debt

Data sprawl, hoarding, and rot create operational drag and AI risk. Data governance is part of the technology debt conversation.

Resilience

Systemic IT Risk

Third-party services, APIs, cloud dependencies, and shared data flows extend the risk perimeter. Leaders need visibility before failure exposes it.

Assessment

Technical Health

Tech debt leverage expressed as a health rating — healthy, unhealthy, or sick — system by system. A positive frame executives engage with, and a shared language between IT and the rest of the business.

Identity & Trust

The Passwordless Enterprise

Credentials remain the leading way attackers get in. A phased, standards-based migration to FIDO2 and WebAuthn, sequenced by user risk, with legacy applications handled deliberately instead of left as permanent exceptions.

Governance

The Complexity Ledger

Run cost, integration upkeep, change friction, and resilience overhead tracked as a managed liability with named owners — plus guardrails on integration standards, customization limits, and deprecation.

Advisory

Put them to work

Rocky Mountain CIO applies these frameworks inside growing organizations — assessment, governance, and executive decision support.

Visit Rocky Mountain CIO →

Research

Published work behind the frameworks.

Research contributed as an IDC Adjunct Research Advisor for IT Executive Programs, written for technology buyers and the executives who fund them. Five perspectives, published across tech debt, simplification, AI readiness, identity, and agent governance.

01

The Value Density Index

Measuring the value an enterprise actually receives from any individual system against the complexity cost of keeping it, so leaders can prioritize what to amplify, simplify, consolidate, or retire. IDC #US54465526, April 2026.

IDC · Published
02

Tech Debt as an AI Constraint

How tech debt inside infrastructure and the data estate inhibits AI implementation, and the sequence for preparing an enterprise before it invests.

IDC · Published
03

Governing AI Agents Against the Risks Your Security Tools Won't Catch

Least privilege and segregation of duties applied to AI agents — the control failures that scanning, monitoring, and endpoint tooling are not designed to detect.

IDC · In review
04

The Passwordless Enterprise

Why credential-based authentication has become the primary attack surface rather than a defense, what the ROI of a passwordless program actually looks like, and how to phase a FIDO2 and WebAuthn migration around legacy constraints. IDC, December 2025.

IDC · Published
05

Evaluating Enterprise Technical Health

Turning tech debt leverage into a technical health rating that executives and boards can act on, and a common language for prioritizing which debt gets paid down first. With Rob Baigert. IDC #US51849424, September 2024.

IDC · Published

Full text is published by IDC. View the complete IDC research profile or request an executive briefing.

Current Operating Lens

Grounded in real distributed operations, not theory.

At WIN Brands, Ken leads technology across Costa Vida and FatCats, where IT is tightly connected to guest experience, store operations, cybersecurity, data, infrastructure, support, and enterprise platforms. In restaurant and entertainment environments, technology decisions show up quickly in guest friction, order accuracy, loyalty adoption, support volume, and store execution. That makes simplification and governance practical operating disciplines, not abstract IT ideals.

Multi-brand technology leadership

Balancing standardization, brand needs, and operational practicality across distinct businesses.

Customer-facing digital experience

POS, web, mobile app, loyalty, support, and enterprise customer data workflows that shape guest experience.

Shared services discipline

Infrastructure, helpdesk, cybersecurity, data intelligence, and enterprise platforms.

Executive translation

Turning technical work into risk, value, friction, speed, and business outcomes.

Field Notes

How the work shows up in real leadership conversations.

Governing agents before they scale

Agents inherit whatever access they are handed. What may this agent reach, and who approves what it does, are questions worth answering before the second and third agent arrive.

Reducing operational friction

Platform choices affect speed, accuracy, support burden, and guest experience. The CIO role is to make those tradeoffs visible and actionable.

Turning tech debt into leverage

The conversation changes when tech debt is framed as business drag, decision latency, risk concentration, and reduced ability to execute.

Making cybersecurity manageable

Security improves when risk is documented, ownership is clear, controls are understood, and leaders can see whether exposure is increasing or decreasing.

Improving customer-facing digital experience

In restaurant and entertainment environments, technology decisions show up in guest friction, order accuracy, loyalty adoption, support volume, and store execution.

Need executive IT advisory support?

Rocky Mountain CIO has service details, the engagement model, and a direct contact path.

Visit Rocky Mountain CIO →

Speaking & Media

Practical thought leadership for executive audiences.

Ken speaks to CIO, CISO, board, and business audiences on AI agent governance, AI readiness, enterprise tech debt, identity and passwordless authentication, cybersecurity leadership, and the work of translating technology into business outcomes.

Signature Talk

Your AI Agent Would Fail an Audit

Least privilege and segregation of duties are enforced on every employee. Most organizations abandoned both the moment they deployed an agent — and no security tool will flag it.

Signature Talk

The Tech Debt Under Your AI Strategy

Why AI readiness starts with infrastructure and data, how to sequence the cleanup, and what to fund first.

Signature Talk

The Business Language of Tech Debt

How CIOs can turn technical drag into an executive management discipline using leverage, risk, speed, and value.

Signature Talk

When Time Turns Against You

What negative time-to-exploit means for cyber resilience and how leaders should think beyond patch availability.

Signature Talk

Data as Tech Debt

Why AI readiness starts with cleaning up the data estate, clarifying ownership, and reducing unmanaged data sprawl.

Signature Talk

Cybersecurity Is Change Management

Why awareness alone does not create adoption, and what leaders must do to build durable security behavior.

Signature Talk

The Password Is the Breach

Compromised credentials remain the leading initial attack vector. What a phased passwordless program costs, what it returns, and why legacy applications set the timeline.

Signature Talk

Healthy, Unhealthy, or Sick

Rating the technical health of core systems, and reporting that rating to a board in language that changes funding decisions.

KeynotesExecutive roundtablesPanels and podcasts CIO and CISO eventsBoards and leadership teams

Published Works

Books that turn technology into executive language.

Unveiling Tech Debt book cover
Latest Book · 2024

Unveiling Tech Debt

A Business Leader's Guide to Measuring and Managing Enterprise Tech Debt Leverage.

Enterprise tech debt slows decisions, raises risk, and makes execution harder. This book gives executives a practical way to discuss, measure, and manage that drag in business terms — and a common language for the AI readiness work that follows.

Ken is also the author of Cyber Safety: A Family Guide to Online Security & Technology Standards.

Advisory · Rocky Mountain CIO

Where the research becomes an engagement.

Rocky Mountain CIO applies these frameworks inside growing organizations. Each engagement produces an artifact a CEO, CFO, or board can act on — a ranked portfolio, a sequenced plan, a health baseline, an authority inventory — not a slide deck of observations.

01 · Simplification

Value density assessment

Score your tier 1 and tier 2 systems on annual business value delivered against annual complexity cost. Calibrated with finance and the business owner.

You get: a ranked portfolio, an action per system — amplify, simplify, consolidate, or exit — and the complexity dollars attached to each.

02 · AI Readiness

AI readiness assessment

Inventory applications, integration paths, data dependencies, and shadow processes against the AI use cases you actually intend to fund.

You get: a dependency map, the structural friction blocking each use case, and modernization sequenced into waves with owners and measurable outcomes.

03 · Governance

Agent authority review

Least privilege and segregation of duties applied to AI agents. What each agent can reach, where read, write, and approval authority overlap, and which actions need a human gate.

You get: an agent inventory, an authority boundary per agent, and a control set structured to align with ISO/IEC 42001.

04 · Assessment

Technical health review

Rate core systems across a continuum from healthy to sick, grouped the way the business thinks — customer-facing, financial, employee productivity.

You get: a health baseline, a refresh cadence, and a funding case executives and boards will engage with.

05 · Identity

Identity & passwordless roadmap

Phase a FIDO2 and WebAuthn migration by user risk, extend your existing IAM rather than standing something up beside it, and decide deliberately what happens to legacy applications.

You get: a phased rollout plan, a three-to-five year cost and benefit model, and a legacy strategy that doubles as tech debt reduction.

Start Here

An executive briefing

Most engagements begin with a working session — one system, one use case, or one agent — to establish whether the framework fits your environment before anyone commits to scope.

Schedule a briefing →
Visit Rocky Mountain CIO →

Get in Touch

Let's talk strategy.

Use the calendar for advisory, speaking, media, or executive briefing conversations — including briefings on any of the published research.

Dr. Ken Knapton

Based in Utah, serving clients and audiences nationally. Available for executive advisory work, keynotes, panels, podcasts, and board-level briefings.

Schedule time with Dr. Knapton