"Over time, credibility becomes your greatest asset."
Ana Roldán has spent 35+ years building and defending enterprise technology — rising through cybersecurity, IT leadership, and now AI governance in industries that for decades were run almost exclusively by men: healthcare systems, higher education, and regulated infrastructure. She's held HIPAA Security Officer, PCI Compliance Officer, CISO, and CTO titles, and in 2026 launched TechExec Consulting Services, offering fractional CIO/CTO/CISO advisory to organizations navigating AI-driven transformation. This is her story, told between the lines.
You've spent over three decades in cybersecurity and technology leadership — fields that, especially when you started, were overwhelmingly male. What got you in the door, and what kept you there?
What got me in the door was my passion for solving business problems through technology. I never viewed technology as just hardware or software — I saw it as a way to improve organizations, empower people, and create meaningful business value.
What kept me there was a commitment to continuous learning, delivering results, and earning trust. Throughout my career, I focused less on proving that I belonged and more on consistently demonstrating that I could lead, solve complex challenges, and build high-performing teams.
Over time, credibility becomes your greatest asset.
Looking back at your path—from Baptist Health, to AvMed, Miami Dade College, and Nova Southeastern—what's the moment that changed how you saw your own potential?
Every role prepared me for the next, but becoming CTO at Nova Southeastern University was a defining moment. It gave me the opportunity to lead enterprise-wide transformation, moving beyond managing technology to helping shape institutional strategy.
That experience changed how I viewed my own contribution. I realized my greatest value wasn't simply running IT operations—it was helping executive leadership understand how technology, cybersecurity, data, and AI could become strategic drivers of growth, innovation, and long-term resilience.
You've sat at the board level advising on cyber risk and AI governance. What's different about being in the room versus being the one briefing the room?
When you're briefing the board, your responsibility isn't to explain technology—it's to translate risk into business language.
Boards don't want technical jargon. They want clarity. They want to understand how cyber risk, AI, compliance, and technology decisions affect revenue, reputation, operations, and long-term strategy.
The most effective technology leaders don't impress boards with technical expertise; they build confidence by helping executives make informed business decisions.
After 35 years inside large institutions, you launched TechExec Consulting Services this year. What made now the right time to go out on your own?
After more than three decades in executive leadership, I realized that the experience I'd gained could help far more organizations than just one.
Today, many companies need executive-level technology and cybersecurity leadership, but they don't necessarily require—or have the budget for—a full-time CIO, CTO, or CISO.
Launching TechExec Consulting Services allows me to bring decades of executive experience to organizations seeking strategic guidance in cybersecurity, AI governance, digital transformation, technology strategy, and mergers and acquisitions.
It's an opportunity to help organizations make smarter technology decisions while providing executive-level expertise without the overhead of a permanent leadership role.
AI governance is now central to your advisory work. What's the biggest misconception executives still have about what “AI strategy” actually requires?
The biggest misconception is that AI strategy starts with selecting AI tools.
It doesn't.
AI strategy begins with business strategy. Organizations first need to understand the problems they're trying to solve, establish governance, define accountability, assess risk, ensure data quality, and create policies for responsible use before deploying AI across the enterprise.
Technology is only one piece of the equation. Governance is what enables AI to create sustainable business value.
You've led through HIPAA, FERPA, and PCI, and now AI-related regulatory uncertainty. How does an executive build a governance framework for technology that's evolving faster than the rules around it?
I've learned that good governance shouldn't depend solely on regulations.
The best organizations build principles-based governance focused on accountability, risk management, transparency, privacy, ethics, and business objectives.
Regulations will continue to evolve, but organizations with strong governance foundations can adapt quickly because their decision-making processes are already mature.
Governance isn't about checking compliance boxes—it's about building resilience.
For the next generation of women moving into CIO, CTO, and CISO roles, what's the one piece of advice you wish someone had given you 35 years ago?
Don't wait until you feel completely ready.
Many talented women believe they need to meet every qualification before pursuing leadership opportunities. In reality, leadership is developed by stepping into challenges before you have every answer.
Believe in your experience, trust your judgment, keep learning, and don't be afraid to take a seat at the table. Your perspective is valuable, and organizations need diverse leadership now more than ever.
As you look at where enterprise technology and AI are heading over the next five years, what excites you most—and what keeps you up at night?
What excites me most is that AI has the potential to fundamentally improve how organizations operate, make decisions, serve customers, and empower employees. Used responsibly, it can unlock levels of innovation and productivity we've never seen before.
What concerns me is that many organizations are moving faster than their governance, security, and risk management capabilities. AI adoption without proper oversight can create significant operational, legal, ethical, and cybersecurity risks.
The organizations that succeed won't necessarily be the ones that adopt AI the fastest. They'll be the ones that implement it responsibly, with strong governance, clear strategy, and a focus on long-term business value.