Straight answers for business leaders on IT, security, compliance and AI

CIO Support is an executive technology library published by LAN Service Group, Inc. โ€” an IT management, cybersecurity, compliance and AI services firm in San Ramon, California, serving businesses since 1992.

Browse the questions Free readiness scorecards

Topics

Questions leaders are asking

Does a biotech startup need a fractional CIO?

A biotech company usually needs a fractional CIO once it holds valuable research data, plans GxP-regulated work or faces investor and partner diligence. The role owns IT strategy, data integrity, validated-system planning, IP protection and vendor oversight part time. It fits pre-commercial companies that need executive judgment on these risks but not a full-time CIO.

What does a fractional CIO do for a regulated company?

For a regulated company, a fractional CIO owns the technology side of compliance: governance, risk decisions, system choices, vendor oversight and the evidence auditors and customers ask for. It suits small and mid-size firms under CMMC, HIPAA, FDA GxP or similar rules that need executive accountability for IT risk without a full-time CIO, provided the role has real authority.

What is an outsourced IT help desk and how does it work?

An outsourced IT help desk is a contracted provider that handles your employees' IT requests, such as login problems, device issues, software access and outages, by phone, email, chat or portal. It works best as part of a provider that also manages your devices, accounts and systems, so the people answering tickets can actually fix the underlying problem rather than log and forward it.

What should I look for in a managed service provider contract?

A good managed service provider contract clearly defines scope and exclusions, service levels by priority, security responsibilities on both sides, incident notification and handling, who holds administrator access, your ownership of data and documentation, pricing and change rules, and exit terms including handover. If any of these are vague, clarify them in writing before you sign.

What is CUI?

Controlled Unclassified Information (CUI) is information the government creates or possesses, or that a contractor creates for the government, that a law, regulation or government-wide policy requires to be safeguarded, but that is not classified. For defense contractors, holding CUI is what triggers DFARS 252.204-7012, the 110 requirements of NIST SP 800-171 Rev 2 and CMMC Level 2.

What does DFARS 252.204-7012 require?

DFARS 252.204-7012 requires defense contractors that handle covered defense information to implement NIST SP 800-171 Rev 2, use only cloud providers meeting FedRAMP Moderate-equivalent requirements, report cyber incidents to DoD within 72 hours, preserve affected system images for at least 90 days and flow the clause down to subcontractors. It remains fully in effect during the CMMC Phase 2 suspension.

Can employees use ChatGPT with company data?

Yes, but only on an account your company controls. OpenAI states that by default it does not use inputs or outputs from ChatGPT Business, Enterprise, Edu or its API to improve its models, while personal ChatGPT accounts may be used for training unless the user opts out. Pair a business plan with a written AI policy, data-classification rules and admin-managed sign-in.

What should a company AI governance policy include?

An AI governance policy should name the approved AI tools, define which data may and may not be used in them, require human review of AI output that affects customers or decisions, assign an accountable owner, and set a process for approving new tools and reporting incidents. NIST's voluntary AI Risk Management Framework is the most widely used reference for structuring it.

How can a biotech company protect its intellectual property when employees use AI?

Keep research data on company-controlled AI services whose terms exclude your data from model training, never on personal accounts. Then label confidential data, fix file permissions before connecting AI to them, restrict connectors, and write a policy covering unpublished results, sequences and patent drafts. The goal is that no trade secret or pre-filing disclosure leaves an environment you govern.

Can AI be used in a GxP-regulated environment?

Yes, but AI that creates, changes or influences GxP records or quality decisions must be treated like any other regulated computerized system: risk-assessed for its intended use, validated or assured, access-controlled, and auditable under 21 CFR Part 11 and the applicable predicate rules. AI used only for non-GxP work, such as drafting internal emails, needs governance but not validation.

Free readiness scorecards

Who writes CIO Support?

The team at LAN Service Group: fully outsourced or co-managed IT, fractional CIO leadership, ISSO-led CMMC / NIST SP 800-171 compliance, Microsoft 365 GCC High, GxP-regulated IT and secure AI development, for businesses in the San Francisco Bay Area and across the United States since 1992.

Talk to LAN Service Group About CIO Support