Technology and risk judgment, at board level.
A standing, independent advisor who helps your Chair, CEO and board see clearly on AI, cybersecurity, architecture and regulation, across every board cycle and without adding another executive layer.
Standing Technology & Risk AdvisorAdvises the board. Does not sit on it.
Boards govern what they cannot easily see.
Management reports come from the people the board oversees. Auditors test against a scheme. Consultants are engaged to deliver a project. None of them is there to give the board an independent, senior reading of what technology risk means for the decision in front of it, meeting after meeting.
Where AI belongs in the business, what it exposes, and who is accountable when it is wrong.
Whether the organisation is resilient or merely compliant, and what the board would want to have asked before an incident.
Whether major platform, vendor and build decisions are sound before the money is committed.
What certification, supply-chain and security obligations in Europe and the United States mean for strategy, markets and contracts.
Better questions. Clearer decisions.
Independent senior judgment
A view that owes nothing to the operating line, a vendor or the audit plan.
Risk translated into decisions
Technical exposure turned into the trade-offs and questions a board can actually decide on.
Pattern recognition across domains
AI, cybersecurity, architecture and regulation read together, where one area’s decision becomes another’s exposure.
Challenge without taking over
Assumptions tested firmly and respectfully, without owning the operating line or doing management’s job.
Continuity across cycles
The same advisor at every cycle, so context builds rather than restarting each quarter.
Clarity without another layer
Executive clarity without a new hire, a new department or another reporting line.
Judgment formed where technology, security and regulation meet.
William Ochs founded Donegal Studio after more than a decade at Cisco. His work has sat where enterprise technology, high-assurance security and regulation have to agree, which is where most board-level technology risk now lives.
- Federal readiness and continuous monitoring
Built Cisco’s U.S. federal readiness baseline and continuous monitoring program, and has worked across federal and international security frameworks.
- Federal, high-assurance markets
At Cisco, opened access to a federal market worth billions. William has worked across nearly 20 successful FedRAMP Moderate and High authorization efforts.
- Security architecture
Led the IOS XE security overhaul that moved a core networking and SD-WAN platform from a high-risk posture to a hardened, low-risk one.
- European regulation and standards
Pioneered Cisco’s cloud-compliance work across Europe. Co-chaired CSP CERT, serves on the EUCS AHWG, and contributes to CEN-CENELEC standards for a member state.
- AI and secure systems
Patent-pending AI work, and the applied AI and secure-systems products Donegal builds today.
- Translating risk for decision-makers
Six years teaching cybersecurity as a professor: making complex risk clear enough for a room to act on.
A standing advisor, on the board’s rhythm.
A 12-month engagement built around your calendar: steady contact with the Chair or CEO, and real preparation before the meetings that matter.
- 01
- 02
- 03Board cycle
- 04
- 05
- 06Board cycle
- 07
- 08
- 09Board cycle
- 10
- 11
- 12Board cycle
- MonthlyA 60-minute call with the Chair or CEO.
- Up to 4 a yearBoard or committee cycles, prepared for in depth.
- Before each cycleA written pre-read memo on the technology and risk questions in the papers.
- Up to 2 a monthBounded written questions between meetings.
12-month engagement, billed quarterly in advance.
From €4,500 per month, quoted to the board’s cycle and regulatory load.
The pre-read memo is part of Board Advisory. Private Strategic Advisory remains a conversation, without written deliverables.
Built for boards where technology is now strategy.
A strong fit
- Chairs, CEOs, owners and boards where technology, AI or cyber risk now shapes strategy.
- Organisations in, or entering, regulated markets: EU certification, US federal, critical supply chains.
- Boards without a senior technology and risk voice of their own.
- Leadership facing a major platform, AI, security or market-entry decision in the year ahead.
Not the right fit
- You need a CISO, an implementation team or incident response.
- You need a legal opinion or a certification.
- You are looking for a director, a vote or a board appointment.
- You want unlimited access rather than a defined rhythm.
Independent because it is bounded.
The value of the role depends on staying outside the operating line. These limits protect it.
- No implementation
- No line management
- No incident command
- No legal opinion
- No certification
- No unlimited access
Not a board seat. Advises the board. Does not sit on it. William holds no vote and no director role.
Six engagements. No more.
Board Advisory is capped at six engagements at any one time, so every board gets real preparation and attention rather than a slot in a rotation.
Capacity is reviewed on a rolling 90-day basis. If new advisory work would compromise commitments to existing clients or Donegal’s own product work, all new advisory intake pauses.
Qualification before commitment.
- ApplicationTell us about your organisation, your board and the decisions ahead.
- Fit reviewDonegal confirms fit, independence and capacity before anything is scheduled.
- Chemistry & strategy callA 90-minute working session with William. €2,500, credited to the first quarter if the engagement proceeds.
- Proposal & agreementScope, cadence and fee set out for the 12-month engagement.
- Engagement beginsThe year’s calendar is agreed and preparation for the first cycle starts.
What to include in your application
- Your role, organisation and sector
- How your board and committees are structured
- The technology, AI, security or regulatory decisions on the horizon
- When you would want the engagement to begin