A global commercial aircraft lessor backed by one of the world’s largest banks augmented its lean internal team with Corsica Technologies—turning audits into routine, delivering 24/7 support across three continents, and freeing IT to focus on strategy.
Client
Global commercial aircraft leasing firm headquartered in San Francisco, owned by Mitsubishi MUFG
Challenge
A small internal IT team supporting a complex, 24/7 global operation across three continents—under bank-grade compliance
Solution
Co-managed IT services, 24/7 help desk, security, and audit-readiness delivered through IT staff augmentation
Results
Audit-ready operations, a help desk that consistently exceeded expectations, and an internal team freed for strategic work
Jackson Square Aviation (JSA) is a global leader in commercial aircraft leasing. From its San Francisco headquarters and offices in Dublin, Ireland and Singapore, the company manages a young, high-value fleet—roughly 334 aircraft worth approximately $13 billion—leased to about 63 customers across 32 countries. With an average aircraft age of around five years, JSA pairs competitive financing with customized fleet solutions for airlines worldwide.
What began as a ten-person, private-equity-owned business changed dramatically in 2013, when JSA was acquired by Mitsubishi MUFG—one of the largest banks in the world. Overnight, a lean startup inherited the compliance expectations, audit cadence, and security mandates of a global financial institution. As the business expanded internationally, technology stopped being a back-office support function and became the operating backbone of the company.
They don't really care it's two AM in the morning. What they care about is predictability. And that's the name of the game. We, you know, heroics suddenly no longer matter. Good afternoon. Today, we're going to be talking about what happens when a company goes global, and most specifically, when IT and security stop becoming a support function and transform into the operating backbone of a global organization. With me today is Jonathan Santos, senior vice president of information services, technology, and governance at Jackson Square Aviation. And Jonathan has had the opportunity to lead such an international growth expansion endeavor within IT and security, and we're going to be getting into that today. So first of all, welcome Jonathan, and maybe start out by talking a little bit about Jackson Square. Thank you, Peter. Jackson Square Aviation is a global leader in commercial aircraft leasing. We have about three thousand three hundred and thirty four aircraft, about two eighty owned, the rest committed. We have about 63 customers at the time of today and we are spread across 32 different countries. We are valued with the fleet wise at 13 billion dollars and our average aircraft is about five years old. My role in Jackson Square Aviation is to communicate all the IT initiatives to our home office and implement without surprises these projects globally and have them scale. Then, yeah, that's what I do. Excellent. Well, wow. So given those locations, that's the definition of growing and expanding internationally. You know, first of all, on all the success. Maybe to start out, can you talk a little bit about how, you know, some of the expectations of IT have changed as you've expanded globally? Absolutely. Yeah. So back in 2013, is when we got acquired and, from 2013 to 2016 when we started expanding as a company. One thing that changed is the compliance. When we were acquired by Mitsubishi, we did fall into the JSOX compliance very soon. So Sarbanes Oxley for those of you that don't know. We also had multiple time zones all of a sudden. And then as we grew more and more in 2016, we did have the audits, the regulators, and we also have a lot of the security mandates that were unfamiliar to us as a company. We started off as a ten person private equity owner and this institute Mitsubishi purchased us and gave us all this new compliance standards. Wow. Through that growth, I mean, kind of a startup, really focused on being good enough, having good enough infrastructure, good enough tools and processes. When does that become a roadblock? How do you overcome that? That's a great thought process. For me, at least, boards and shareholders, they don't really care it's two am in the morning. What they care about is predictability, And that's the name of the game. You know, heroics suddenly no longer matter. So the good enough topology really, really changes. I mean, are the days where they say, Hey Jonathan, run into the boardroom and fix the telepresence, for instance. Something more consistent. When anything breaks, IT suddenly becomes something that people notice. Instead it's more when anything breaks, it's a cause of IT. You know, it's funny we talk about as simple as the coffee espresso machine because it has a smart function. You know, it's an IT problem. So yeah, so the good thing about good enough infrastructure, good enough, it works, but it doesn't scale. When you're scaling in the growth that Jackson Square Aviation has, you start leaning towards the latency issue. For example, we used to have a ERP system called Great Plains. And when we, when you expanded to Dublin, Ireland, a lot of the users there needed to, to access this ERP system. And, you know, latency is considered failure for many of us in IT, failure in the shareholder level. It's more, it's not even outages, it's more friction. When there's friction between departments, whether it's accounting that can speak to another department to close a book, for instance, that's friction. And that's what we want to stay off. And that's, that's what happens when you have good enough infrastructure. One example that we also were able to show that good enough wasn't good enough was during the pandemic. So our CEO actually asked IT, are we ready to, to work from home? Are we, or even questions like, can we recover from a bad day? Can we pass an audit? These types of questions, when you have good enough infrastructure, it really doesn't fly. Yeah. And lastly, you know, if, if, if your model is because it's good enough, if, if it's like Peter knows how it works or Jonathan knows how it works, that's not a, not a security solution. That's a vacation risk nightmare. Yeah, for sure. For sure. So something you brought up, you mentioned that you migrated from Great Plains to another ERP, and that's not uncommon, not so much the technology, but the migrating applications, certainly in a growth mode of an organization. One of the things that we see a lot of companies struggle with is the accumulation of technical debt. There might be applications, there might be infrastructure. So how do you recommend, especially as you're expanding globally, that gets reconciled and rationalized? Another great topic, technical debt is very, it's a key to expanding. It's not really about old systems. It's about old decisions that no one wants to revisit. I feel it's also most bad debt isn't really due to bad choices, where a lot of us might think it's good choices that were never retired. Let me explain. For instance, as we mentioned, we moved from our former ERP to the new one. Unfortunately, we didn't bring any historical data over. And because of that mishap, we had two ERPs rolling at the same time causing double the management costs, the licensing. I mean, SQL Server costs already pretty high. So yeah, you can see that type of debt compounds as you grow. And one thing I also learned is that debt kind of grows linearly ideally, but when it grows laterally, much like a virus, it's really unmanageable and can really, really get you. Yeah. So that's kind of what we've been doing. Okay. You know, you've been at Jackson Square for how long now? Over ten years, right? Thirteen years. Thirteen years. Last week. Okay. Yeah. So obviously in the last thirteen years, as any ten year period in technology, a lot changes. But what's changed a ton over the past thirteen years has been risks, specifically cybersecurity risks, security risks. So, you know, can can you talk a little bit about how that has changed, both in terms of, you know, maybe over the past thirteen years, but but more importantly, as you've expanded internationally, you know, what what have you been had to really focus on and account for the most? Yeah. That's so as as we expand globally, get you get more locations, right? More locations, more visibility. You get you get more identities we have more domains for instance in Azure. You have more vendors you have more work streams and even most importantly more assumptions. I fell victim to that as well I mean even some something something as simple as ordering IT infrastructure and going through customs, drastically different from Singapore and to Dublin. So then you talk about the cyber risk as well, right? We talked about where once you go global, you got to think about the single points of failure. We had a recent incident, from our servicer, not unrelated to JSA, where they actually, I think the personal mail got hacked, and they sent wires out to another company and it was a company related to JSA. Always a single point of failure and there's always cyber risk everywhere regardless where you are in the world. One thing we also notice is when with regard to cyber risk we do have a business continuity program and what we found once we went global it shifts from just IT to organizational. All of our business continuity plans works hand in hand with IT processes. So we have a hand in almost every single BCP plan. And at scale, the risk is really the inconsistencies in the processes. And then, you know, lastly, as you expand, you know, these cyber risks, these actors, if you will, they're not, it's not about really the hackers more so, it's about complexity. And because complexity is there, it creates gaps. Once you have gaps, you create exposure. Those things we typically, experience as we do it globally. And one thing I always like to say is, know, we're not, we don't need to be smarter than the packers or the actors or or they don't even need to be smart in the business. They just need to find out where our process got created. Yeah. And that would be a single point if they come in. Yep. Yep. Yeah. Mean, you know, this is this is such hot topic, obviously, across the globe for organizations as they they try and protect their infrastructure, protect their data, protect their business. You know, you're really looking at it, and you're in a position where where you're having to look at it through two lenses. One is operate it, execute it, make sure that you're protecting your business. I'm sure you're partnering with partner organizations to help facilitate that. But you also have to report to the rest of the executive team and the board. So how do you translate that message in a way, in a nomenclature, that the business understands? Typically executives and boards understand risk very, very well. Maybe talk a little bit about that, how you've been able to manage both the execution side as well as working with communicating transparently to the executive team of the board. Yeah absolutely and with leadership you know they don't want dashboards they want clarity And I've learned that the hard way, which is Corsica proven. They, they really want to translate these type of risks, to leadership and to the board and to kind of business interruptions, if you will. Maybe financial exposure or more importantly for our home office's reputational impact. My, my boss used to always say let's do fewer metrics and better narratives. And by then, you know, again, our job as it leaders is not to teach cyber. I'm not here to teach the board cybersecurity. We want to simply explain the risk as it's any other risk in any other business decision. And, know, lastly, if you, if you plan on communicating this to leadership and you have a forty page slide deck, you might not be the right person to explain it yet. Yeah. No. That makes sense. And and, you know, in my experience in in talking with, you know, IT executives across a number of and industries, the most successful cybersecurity programs starts at the top. It starts with the executive buy in, and it sounds like you've been able to successfully get that buy in and really have that executive team lead by example. And if they lead by example, it's a waterfall effect. Is that what you find? Absolutely. And we have a process within our JSA leadership where we actually communicate investment committee opportunities, working hand in hand with our home office. Only then when we really delineate and explain the benefits of the said investment to the business. Okay. Okay. So, you know, kind of shifting from cybersecurity over to another another area, a little bit risk focused on on the business is compliance. You know, as as organizations grow internationally, requirements change quite a bit. Domestically as well as in the regions that you're operating in. Can you talk a little bit about how complexity of compliance requirements have changed for you in the operation and really how you've grown it and matured it? Absolutely. Again, we came from a ten person private equity owner to a JSOX. So expectations were that we were governable. And one thing I learned is they don't expect, they don't ask if you're governable, they expect it. One thing that we did when we grow is we got more visible to the regulators, the partners, the insurances, there was more audits, specifically our value. One thing we noticed with compliance is the fact that it should be a continuous effort. For compliance, we can't treat that as events instead of more of a day to day continuous exercise. You know, we really grew up our company in 2013 when asked us, when the auditors asked us questions that we really didn't know. So with those expectations, was expected with the growth and visibility, and that's what we encountered. Yeah, I think it's music to an auditor's ears. If they hear you say, not an event, but you know, a daily routine. And how do you, you know, how do you transition towards that as a company? How do you mature into that mode of making audits not in an event, a point in time that everyone quite frankly is not looking forward to or might even be fearful of to just routine? That's a great question as well. Peter, let me correct here. It's uneventful. Always hear we pass, we survive the audit. For us, I think that the key is to make sure it's uneventful. Silence is golden. Over the past decade, working with the internal audits and external audits, we found that again, it fails when they're treated like events, when it's a one time thing. Hey, look, we have an audit in three years. Let's not touch it until then. Success in an audit is really, again, making part of a business as usual, a day to day activity. One thing we did great with the Corsica help test team is we created a custom queue specific for audit events so that when the auditors come the following year or whenever our audit is, we are ready and we have metrics to prove it. As long as, but here's the key, as long as you know who is the owner of each task, good documentation, good cadence, that's suddenly the panic, if you will, for audits become more affirming. So those are the essentials, the documentation, cadence, working with your partners, whether it's an MSP or another partner, and really setting up a process to have that evidence ready to go. That's really how you've been able to turn it into a routine. Absolutely. And with cadence specifically, it builds trust. Right. And, so that's, that's one thing that we, we wanted to set first and obviously the documentation follows and then just being able to repeat, these requests anywhere globally. Okay. Okay. So, you know, we've been talking a lot about the global expansion, and we've talked about, you know, some of the IT transitions, some of the cybersecurity, now we're talking about, governance and compliance. As a leader, you have a lot on your plate, a ton on your plate, and the business is continuing to grow. So what do you do to balance what you can delegate versus what you really need to own? You talk about that a little bit? From an operating model standpoint, what do you feel that you can delegate to the team versus on yourself? Okay, that's a tough one. Let's see. Well, four things I think. One thing you can't really delegate as a leader is direction, right? Maybe even risk appetite. And I think lastly is priorities, business priorities. We can always delegate execution and that's something that we champion with all that with MSPs as well and partners, but we can't delegate accountability and that's that's very important especially as complexity increases globally. You know you got to remember that clarity kind of empowers teams and partners. It's and again my job is not to make decisions faster to make just to make better informed decisions. And I think that's, that's important. One thing that we, we, I fell victim to is the, the old saying, oh, we thought so and so had that. We have subsidiaries around the world with Mitsubishi. And I often hear the fact that, hey, we have this software at this place or a new hire that came from academia says, hey, we have this software, can we get it over here? And I learned that can be a security risk. Owning that and knowing that complexity that can arise, it's important because sometimes when you implement some of these, we had that in the other company, it's a security risk. It's also, that should be more harmful a spam or a virus. Sure. And you mentioned partners. And obviously, we're partners together in this journey. But I have to imagine that your ecosystem of partners, vendors, etcetera, has expanded quite a bit through the past thirteen years. And there can be complexity that comes with that. Certainly, finger pointing at times. Other times, just maybe a little bit of lack of clarity. How do you overcome that in terms of making sure that everyone's responsibilities are clear and you can hold the appropriate teams, whether they're internal or partners accountable? Yeah. And I think that leads into an earlier question. You know, we got one thing I want to remember is MSPs, partners, and even internal teams, they, we extend capability for the business and we act as a team almost augmented. We always hear, oh, this MSP augments my current team. One thing it doesn't do is own the ownership. So when we coexist effectively, you have to have clear balances. You have to have expectations. Sure. And you have to, you have to, set, set these clear cadences. For me, expectations matter more in contracts, the SLAs, the service delivery model, and more importantly everybody needs to decide and know who does what. The last thing is if you have an issue and you have like four MSPs politely blaming each other to your point. Yeah. That's not an MSP problem. That's a leadership gap. And, and in fact, I would like to share that I had this specific issue many moons ago during a Thanksgiving, where we blocked out a set of IPs. They were blacklisted, and we put them in non proof list. And, and sure enough, a couple of years later, Microsoft purchased that block of IPs. Unbeknownst to us, we did unblock that. And so many of our Intune deployment were, were effectively not working and requiring all our MSPs to kind of fingerprint the firewall or it's a, it's a web proxy issue. Anyway, again, that was poor document. That was an undocumented decision and going back to my previous point, it's important that the document needs. Yeah. So that was, that was my experience there. Yeah. That, that documentation, I mean, it's not only helping from, you know, a compliance and governance perspective, also just in really driving home that clarity internally and with your partner. That makes a ton of sense. I love the line that that you said where, you know, the blame game is is not really the the the partners. It's a it's a leadership gap. Really owning that and making sure that there's there's crystal clear clarity on who owns what is super important. So, you know, we're talking a lot about leadership here as we close out. What do you feel is most important as you've expanded and grown? What are those most attributes that a leader has to have to grow an organization globally? What have you seen? I know we've talked a lot recently, I know you spend a lot of time talking with other peer executives and constantly sourcing and looking for lessons learned and as any good, but also trying to solicit and understand what other leaders have learned and maybe misstepped on. What are some of the areas where maybe some of those other leaders or that have grown, globally have underestimated? For me, at least, it was the is it tech well, the technology cost. We got that down. All IT leaders, we have the technology cost down and that and leadership trusts you with the technology cost. For me, what what lacked when we grew globally was the coordination cost. A small example was was our building move. We had a wonderful building move over to in Dublin, Ireland, and we we didn't focus much on the coordination cost more so than the technology cost from IT. So there was a lot of overlap and mishaps there. One thing we also noticed is the coordination cost within Azure. One thing that I've encountered is, hey, this technology is free now that we have Azure, let's get rid of our original point solution. But what I didn't take account for is the coordination costs, the engineering, the adoption, the, even the support. So I think really it's the, it's the, it's a coordination cost that really we underestimate as leaders. And when you underestimate some of these coordination costs, creates gaps and gaps create exposure. Yeah. That's one thing we found and I experienced. Okay. So, you know, I want to go back to something you said earlier, and I think this comes back leadership as well. You said that you're in a position where you're not necessarily looking to make decisions faster. But I hear from a lot of leaders that they are looking to make decisions faster and more accurately. So how do you most effectively balance that speed with precision? To not get too over indexed on precision, but at the same time not be careless and make decisions too quickly. Absolutely. One thing that we do is we start off with a great RFP, right? And I think what maybe I'm wrong here, but if you're referring to kind of point solutions versus operating models, we found out point solutions are fast, they're fast, they're nimble, but they don't scale. And operating models, they're boring, but but they do scale. With that being said it's a consistency, of of these implementations that really matter. Yeah it's kind of almost like a pyramid right? You got to be honest and speed, and the accuracy and something's gotta give. One thing that we do within our RFP model is to kind of balance and produce these ROAs ROIs. And I kind of wanna say overestimate the outcome. One thing that we do in Jackson Square Aviation is do a three to five year plan. It would impact, despite sometimes solutions could be inaccurate and that might be mildly uncomfortable, but those aren't usually the right decisions. Take for example our new ERP system. We actually did a digital transformation in JSA and it's increased our closing time. Time to close your books. Exactly. Really? Yeah. Okay. That's our goal. Yeah. That's awesome. What did it what did it increase by? So, you know, we didn't have a full percentage. We're still in the middle of the of our DX transformation. Okay. But it it took out the hesitation. Right? We were we were prone to a lot of manual input causing delays in the books. And now we have kind of a system that does it automatically. We're still integrating albeit, but for the most part, we did decrease our closing time and the hesitation from our users putting these manual inputs in. Okay. Okay. And that's that's globally. Yeah. Okay. Yeah. That's that's excellent. That's that's great to hear. So, know, as as leaders, you know, are are put in the position, IT leaders specifically are put in the position to expand globally. Their business is expanding into a new region. What should they be thinking about? What's their priority number one, priority number two that they should be thinking about? You know this is great because my we have a new head of HR and she asked me a great question that I've been thinking about if you were to redo this all over again rebuild this this your IT in reference to internal expansion in our current enterprise application set, how would you rebuild it? And to answer your question, you really want to design for scale. You want to build boring systems with clear ownership. We found that was key back when I started in 2013. We had a whole bunch of silo systems with independent ownership and they're almost like different companies not working together. So now we are integrating all our enterprise systems and we're understanding who's the business owners and who works closely with the system owner. And I think by doing that you reduce gaps, you reduce hesitation, You also be able to translate risk into clear business languages. I think when you go international expansions, you really don't want to scale technology. Many IT leaders think, hey, we're scaling technology. No, we're actually scaling judgment, discipline, and maybe even clarity. Okay. Okay. Excellent. So this wouldn't be an IT podcast if I didn't bring up the topic of To dovetail it into this conversation of global expansion, I'm sure you're getting a lot of inputs, lot of requests from the field. Mentioned offices in Dublin, Singapore, obviously here in the States. How is JSA approaching AI from technology standpoint, maybe from a governance standpoint? How are you thinking about that? So as it stands today, our home office has dictated a policy with regards to AI. Back in May, they wanted to make sure that it's not a one lo or less scenario. Since then, we've prohibited the generative AI sites and we followed the process. So the process is, let's make a policy, let's get that really nailed down and then communicate that to your user base. Upon doing that, we then insert into our manuals, our IT manuals, and then we do repeatable recurring training. Within our policy, then identify each AI enhancement that affects our system. Since then we've enabled Copilot, Microsoft's Copilot, but not yet the other generated AI sites. So right now we are edging a learning game much like many other companies. My focus in the next fiscal year is to secure the AI transactions. We are looking in many models. I think we just started our RFP with that. Yeah, so that's kind of where you are in our AI journey as it stands. As far as technical reasoning of how we use AI for our industry, it's it's few and far between, but there are a lot of AI embedded within our enterprise applications. So our ERP systems, has some AI benefits in there. We have our contract legal, possibilities, but it's more discovery at this point in time. Yeah. Yeah. No. That's that's great. And that's a very thoughtful and I would say, mature approach to AI. We're obviously in a position where we get asked from a lot of our clients and prospects on where do we start, where do we go with AI. It really does start with having a policy in place, some governance in place, and it sounds like JSA has that, which is excellent. It's not the Wild Wild West. Again, as we were talking earlier about balancing that speed with precision, this is another area where companies are going to have to really balance that speed and innovation without endangering the business and putting the business at risk. Kudos to yourself and the JSA team. Great work there. Well, Jonathan, to to close out, first of all, you know, thank you so much for for spending the time with us here today in in beautiful San Francisco. Appreciate the the weather as as well. We close out, is there any advice, parting advice, that you would give to an executive as they are maybe even contemplating that international expansion. You talked about some of those priorities, but maybe even reflecting on your own journey. If you were sitting down with an executive over a cup of coffee, would you advise them on? You almost want to wrap that up in a single sentence. But let's see. Growth is not it's less about shiny new IT systems. Right? So it's about fewer surprises, I think. The less surprises that we give to our leadership, the better IT is. And I think I said earlier, science is golden. But as you prepare for global expansion and scale, you know, again, I think there was a couple instances where we want to kind of remember boring systems being scaled, setting ownership, setting cadences, and having that trust with an MSP is important. As you know, Peter, trust cannot be dictated, it must be earned. And we're fortunate to have Corsica as a trusted partner in our office. So as long as you have solid partners, know the boundaries, just understand that scaling systems is really as verbatim as it is. Just knowing the risks globally is probably what I would recommend. Okay. So fewer surprises. Fewer surprises. Fewer surprises. Is the key. That's great. Well, Jonathan, again, thank you so much for the time. Appreciate it. And looking forward to continuing the road ahead.
The Challenge:
A Lean Startup Gains Complex Mandates for Compliance, Security, and 24/7 Support
In the early days, JSA’s entire IT department was just two people: Senior Vice President Jonathan Santos and Manager of Information Systems John Doioka, both hired as generalists. As the company grew across three continents, they hired a third IT generalist, yet the demands on that small team continued to increase. JSA needed to provide 24/7 IT support for a complex, highly technical infrastructure spanning very different time zones—while keeping headcount deliberately lean.
The Mitsubishi acquisition raised the stakes. JSA fell under J-SOX compliance—similar to Sarbanes-Oxley—and faced regulators, auditors, insurers, and security mandates that were unfamiliar to a former startup. As Santos put it, a global parent doesn’t ask whether you’re compliant; it expects it.
At the same time, scaling exposed the limits of “good enough” infrastructure:
- Latency and friction. As users in Dublin began accessing systems hosted elsewhere, “good enough” became a source of friction between departments—slowing the ability to close the books and coordinate globally.
- Technical debt. A migration off a legacy ERP left two systems running in parallel, doubling licensing and management costs—the kind of technical debt that compounds as an organization grows.
- Concentrated knowledge. When critical know-how lived only in one person’s head, that wasn’t a security model—it was, in Santos’s words, a “vacation-risk nightmare.”
- Expanding cyber risk. More locations, identities, vendors, and domains meant more complexity—and complexity creates the gaps and single points of failure that attackers look for.
“We don’t need to be smarter than the attackers. They just need to find the one place where our process got creative.”
—Jonathan Santos | Senior Vice President & Head of IT
The Hunt for a Solution
JSA didn’t want to build a large internal department, and adding specialized hires would only have increased cost, churn, and management overhead. The leaner, smarter path was IT staff augmentation—partnering with a managed services provider (MSP) that could extend the team’s capability rather than replace it. JSA wanted a single, trusted partner spanning everything from the security landscape to day-to-day help desk and even website design.
“We were looking for an MSP partner with whom we could build a close, collaborative relationship. That mattered to us because we run a small IT team.”
—John Doioka, Manager of Information Systems
Crucially, the trust was already there. JSA’s network operations were originally handled by ClearPoint, which was acquired by AccountabilIT, which in turn became part of Corsica Technologies. By the time the relationship carried the Corsica name, JSA already had years of established, high-level trust with the team—removing the single biggest risk in choosing an outsourced IT services partner.
The Solution:
Co-Managed IT, 24/7 Support, and Audit-Readiness
JSA engaged Corsica Technologies under a co-managed IT model—one integrated, accountable partner working hand in hand with JSA’s internal leaders. Rather than taking over, Corsica filled the gaps and scaled the team’s reach across San Francisco, Dublin, and Singapore.
The engagement brought together several Corsica capabilities under one roof:
- A 24/7 global help desk. Corsica’s help desk team absorbed day-to-day end-user support across all three regions—the kind of always-on, follow-the-sun coverage that a small IT team could never sustain alone.
- Help desk outsourcing that augments the internal team rather than replacing them. The model extended JSA’s capability while keeping ownership, direction, and accountability firmly with JSA leadership.
- Security and risk support. As complexity grew with global expansion, Corsica helped JSA close the gaps that single points of failure exploit—supporting a business-continuity program that now runs hand in hand with IT processes.
- A repeatable audit-readiness routine. The Corsica team helped build a custom queue dedicated to audit evidence, with clear ownership, documentation, and cadence—so audits became a steady routine rather than a fire drill.
“An MSP extends the capability of the business and augments the team. What it can’t do is own the ownership—so you set clear boundaries, expectations, and cadences. Expectations matter more than contracts.”
—Jonathan Santos | Senior Vice President & Head of IT
For a regulated, financial-services-owned organization, that clarity is everything. Corsica’s breadth—spanning managed IT, managed cybersecurity, and the kind of vCISO-level guidance that translates technical risk into board-ready business language—meant JSA could lean on one partner instead of stitching together point solutions. As Santos notes, leadership doesn’t want dashboards; it wants clarity, fewer metrics, and better narratives.
Results:
24/7 Support. Internal IT Augmented. Seamless Compliance Processes.
The partnership delivered exactly what a scaling, audit-bound business needs: predictability and peace of mind.
The help desk became a standout. “What surprised me most,” Doioka said, “was that the help desk team consistently exceeded our expectations”—a result validated by positive feedback from JSA’s own users. With reliable 24/7 IT support in place, JSA’s internal team was freed from day-to-day firefighting.
“Our IT team can now confidently shift focus away from day-to-day help desk responsibilities and dedicate more time to higher-level, strategic initiatives.”
—John Doioka | Manager, Information Systems
Audits became uneventful—the highest compliment in a regulated business. With a documented evidence queue, clear task ownership, and a steady cadence, JSA walks into internal and external audits ready, with the metrics to prove it. “Silence is golden,” as Santos puts it.
“Success in an audit is making it business as usual. We built a custom queue for audit evidence, so when the auditors arrive, we’re ready—and we have the metrics to prove it.”
—Jonathan Santos, Senior Vice President & Head of IT
Just as important, the model eliminated the “vacation-risk nightmare.” By offloading help desk operations and documenting processes with a trusted partner, JSA no longer depends on any single person’s knowledge to keep the business running. The broader business benefits most of all—with dependable global support enabling the company to scale with fewer surprises.
“What gives me peace of mind is that our users are fully satisfied with their IT needs and the level of support we provide them.”
—John Doioka, Manager, Information Systems
Lessons for Leaders Scaling IT Internationally
JSA’s journey offers a practical playbook for CIOs and senior operators guiding their organizations through international growth. The throughline: scaling globally isn’t really about technology at all. It’s about process, ownership, and partnership.
- Design for scale with boring, well-owned systems. Point solutions are fast but don’t scale; repeatable operating models do.
- Delegate execution, never accountability. A trusted MSP augments the team—but direction, risk appetite, and ownership must stay with leadership.
- Treat compliance as a daily routine, not an event. Documentation and an established cadence help make audits a regular part of operations rather than panic-inducing scenarios.
- Translate risk into business language. The job isn’t to teach the board cybersecurity—it’s to explain risk like any other business decision.
“When you scale internationally, you’re not really scaling technology—you’re scaling judgment, discipline, and clarity. Growth isn’t about shiny new IT systems; it’s about fewer surprises.”
—Jonathan Santos, Senior Vice President & Head of IT
After more than a decade of expansion, the relationship endures for one simple reason—one that defines the kind of partner Corsica aims to be.
“Trust can’t be dictated; it has to be earned. We’re fortunate to have Corsica as a trusted partner.”
—Jonathan Santos | Senior Vice President & Head of IT