
Strategic planning, program and project management, and transformations that actually finish.
This page is operating-model and execution work. Technology-and-security program build lives on Cyber & Innovation. The two pages should not be collapsed into one noun.
A strategy that cannot be dated, owned, and budgeted is a narrative. We help organizations write a plan a board can adopt: a small number of objectives, the regulatory and funding constraints that bound them, and a twelve-month sequence of work.
Execution is the rest of the engagement: a cadence, a decision log, and a point at which we say the plan has changed and needs to be rewritten. We will not keep a strategy “alive” by ignoring a new rule or a failed hire.
For nonprofits, the plan usually turns on funding mix, reserve policy, and whether the next program can be absorbed without breaking the control environment. For commercial and financial-services organizations, it usually turns on examination readiness and the operating model that makes a control program survivable.
01Energy sector transformation
Energy operators sit under a stack of cyber and operational expectations that do not look like a bank’s and do not look like a nonprofit’s: OT and IT boundaries, federal policy aimed at critical infrastructure, and — since 2025 — executive-order language that treats AI as both a defensive tool and a new attack surface.
We have published on that stack. The January 17, 2025 Insights post on the energy-sector cybersecurity executive order is the firm’s public read of what the order signaled for critical-infrastructure protection. The June 16, 2026 read of EO 14409 continues that thread: hardening systems, protecting intellectual property, and what “AI-enabled defense” means as an operational requirement rather than a press line.
The work, when we are engaged to do it, is translation and program design: which parts of a federal instrument actually bind a given operator, which controls already in place cover the gap, which other regimes still reach the entity because of what else it does, and what an OT change does to the incident-notice clock. We do not sell “transformation” as a synonym for a software rollout.
If a matter is pure generation-asset engineering or a NERC CIP attest engagement we are not staffed to sign, we will say so.
02Program and project management
We run programs the same way we want a grant file or a certification file run: a scope, a named owner, a change log, and evidence that a milestone happened.
Typical work includes a single-audit remediation program, a cybersecurity program build against a fixed certification deadline, a finance-system cutover with its control set intact, or a capital-project reporting structure for a nonprofit building.
We are a small firm. Program management here is partner-led. It is not a PMO layer that reports on work other people are doing in another city.
A plan a board can adopt
A small number of objectives, the constraints that bound them, and a twelve-month sequence of work with a decision log.
03Digital strategy and transformation
On this page, digital strategy is operating-model work: what should be built, bought, or stopped; who owns the process after go-live; how the board will know the change worked. Technology architecture, identity, and security-control design for the same change live on Cyber & Innovation — Digital Transformation.
A digital strategy that ignores federal procurement rules, vendor-oversight requirements, or the recordkeeping a tax authority expects is not a strategy. We put those constraints in the first draft, not in a risk appendix nobody reads.
The output is a sequenced plan with decision rights — and a recommendation to stop, when the organization is about to buy a system it cannot staff or examine.
04Related Insights
Energy-sector EO (January 17, 2025). EO 14409 (June 16, 2026).
Sosa & Arvelo, LLCNext step
Tell us what you’re facing.
A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.
