About

Joy Floresca Knox

Knox Technology Advisors is a technology and cybersecurity consulting practice founded by Joy Floresca Knox, who spent twenty-five years running enterprise technology, security, data, and risk as the executive accountable when something went wrong.

Background

Through July 2026, Joy was Managing Director of Information Systems and Security at Gradient Learning, a national education nonprofit, where she served as the organization's senior technology executive. She owned enterprise technology strategy across IT operations, engineering, data, cybersecurity, enterprise risk, and AI enablement, leading a blended organization of internal staff, contractors, and offshore partners spread across a fully distributed workforce.

The work she is proudest of there is unglamorous. Over several years the technology function changed from something people submitted tickets to into a capability the organization made decisions with, which took governance structures and service standards, modernized platforms, a privacy and compliance program built under FERPA, COPPA, SOPPA, and CCPA, and the decoupling of identity and core infrastructure through an organizational separation carried out with no service interruption and full long-term portability of platforms and data as hard requirements.

Before that, Joy spent nearly two decades in the venture capital ecosystem, as VP of IT and Operations at Wildcat Venture Partners and Mohr Davidow Ventures, Director of IT at ONSET Ventures, and through consulting and CTO advisory work with other firms. She ran the firms' own technology while advising portfolio companies on security architecture and operational scaling as they grew.

At Wildcat, the fund's AUM and investment strategy meant SEC registration was never actually required, but like most venture firms in that period the firm did the work to evaluate the requirements and confirm where it stood rather than assume. Joy built the data governance and security controls that determination called for, which meant understanding exactly where an exempt reporting adviser's obligations end and a registered adviser's begin, and what that distinction demands of a firm's systems, access controls, and documentation. At Mohr Davidow she reduced IT expenditure by more than half through vendor and contract work. Earlier in her career she spent several years at Stanford University and the Stanford University School of Medicine.

Joy also co-founded VCPEIT and served as its President for a decade. The organization is a nonprofit professional community of more than 200 technology leaders and decision-makers across venture capital and private equity, and running it taught her more about how technology decisions actually get made than any single operating role did.

Point of view

Most compliance programs fail on operability rather than on design. The controls are usually right; what tends to be missing is an honest accounting of what it costs a real team to execute them every week, which is why programs stop being followed somewhere around month four. A control that requires heroics will be skipped during precisely the incident it was written for.

The industry oversells frameworks and undersells judgment. A clean SOC 2 report means an auditor found evidence that controls operated during a defined window, which is a considerably narrower claim than most buyers hear, and treating it as a verdict on security does clients real harm.

With AI, the risk is rarely the technology itself. It is governing the technology after an organization has already adopted it. Knox Technology Advisors builds enterprise AI governance frameworks, acceptable use policies, risk assessment models, and phased adoption plans, and then does the harder half of the work, which is deploying the tooling and getting people to change how they work. Policy without enablement produces shadow adoption, and shadow adoption is worse than whatever the policy was written to prevent.

Regulatory breadth is usually a claim rather than a capability. Control architecture transfers across regimes; regulation-specific judgment does not. We would rather tell you exactly where that line falls than present a logo wall of frameworks, which is why the services page sets out what this practice knows cold and what it doesn't.

How the work goes

Direct, and on the record. You get an actual read on your program, including the read that says it is in better shape than you think and the money would do more good elsewhere. Knox Technology Advisors would rather lose the follow-on engagement than produce a report that flatters the person who commissioned it.

The approach is built on transparency and partnership rather than on gatekeeping, which in practice means giving your team options and an honest picture of the risk instead of handing over a finding and a deadline.

Credentials

CCNA, MCSE, and advanced SQL database management, alongside NIST-aligned risk practice and control disciplines that map to SOC 2 and ISO 27001 domains. AI governance work modeled to ISO/IEC 42001 guidelines. Working environments have included Salesforce, Okta, Google Workspace, Microsoft 365, Canvas LMS, Snowflake, Tableau, Zendesk, Jira, Omnissa Workspace ONE, and enterprise deployments of ChatGPT Enterprise, Gemini, and NotebookLM.

Get in touch LinkedIn