When the IT job becomes the risk job
“I’m the sort of person if I get 24 out of 25 on a test, I will challenge it because that’s just not acceptable,” says Jennifer Hutton, vice-president of information technology and risk and chief privacy officer at Steele Auto Group.
Hutton is one of two finalists for the 2026 CanadianCIO Fawn Annan Memorial Award, given each year to a woman in IT leadership by the CIO Association of Canada.
She never planned a career that would put her up for it.
That refusal to leave the last mark on the table is how a job about technology and cybersecurity became one about everything that could go wrong at the company.
Hutton was hired to run IT and look after cybersecurity. Now, she also runs insurance, privacy, health and safety, and she’s responsible for managing risk across the whole business.
The job kept growing, and she kept saying yes.
She joined Steele in late 2022, her first job in the car business. The auto group is based in Dartmouth, Nova Scotia, and runs about 60 dealerships across the four Atlantic provinces and in Texas, with an IT team of nine.
Steele is her first job in the car business. Her earlier career was in B2B, running technology at a legal-services firm and, before that, in consumer products and food manufacturing. Selling cars means selling to the public, and that changed what she had to protect.
A dealership holds the kind of personal and financial information a bank does, and the industry was slow to treat it that way.
The industry was made up largely of small, independently owned dealerships until recently. Small enough that looking after computers and customer data was often a part-time job for whoever was handy.
“I called another dealership on P.E.I. and I said, ‘Hey, we’re getting some spam from your domain and do you have an IT department or somebody who looks after IT that I can speak to,’” says Hutton. “And the receptionist said, ‘I don’t know, I think our owner’s nephew helps us on weekends, but I don’t think he’s available during the week.’”
Because that was normal, the software companies dealerships buy from were used to easygoing customers. When Hutton pushed them for stronger security, the managers and directors she first dealt with told her to back off.
“I was met with things like, ‘That’s not the way we do it. You came from outside the auto world, that’s not how we do it here. Relax. It’ll be fine. Go away,’” says Hutton.
She went over their heads and built relationships with those companies’ senior executives, explaining what she needed and why. The result is relationships that now work as partnerships, with both sides openly sharing their plans.
Steele also grows by buying other dealerships, and Hutton won’t let a newly acquired store run on its old systems for even a day.
“If the deal’s closing on Sunday morning, the store closes 5:00 Saturday night. By 5:00 Sunday morning, they have all of our infrastructure, all of our systems, everything switched over,” says Hutton.
She also sits on an advisory committee with the Nova Scotia Automobile Dealers Association, the group that represents car dealers in the province, and helps smaller and independent dealers set up their own security and privacy programs.
That help goes to the shops still relying on somebody’s nephew.
Preparing for the outage before it happens
In 2024, a company called CDK Global was hit by ransomware, a kind of attack that locks up an organization’s computer systems until it pays to get them back.
CDK’s software runs the daily operations of thousands of car dealerships across North America, so when its systems went down, the dealerships that depend on it were locked out too — some for weeks.
Steele was ready when it happened. Hutton and her team were at the Keg the night the attack hit, prepping a tabletop exercise, a walkthrough of how the company would respond to an emergency.
The scenario she’d planned was the dealer management system going down, the software that runs a dealership’s sales, service and payments. Losing it means the dealership can’t sell a car, book a service, or take a payment.
“We actually got to deal with the real scenario and the made-up scenario all in the same week,” says Hutton.
The attack affected nine Steele dealerships for about two and a half weeks. They managed to keep taking payments the whole time, using backup systems the team had set up before anyone needed them.
“The insurance company kept asking me, are you sure you’re not making a claim for business loss,” says Hutton.
She told them no.
Paying for that kind of preparation means keeping the technical detail out of the conversation with the board.
“Don’t walk into a boardroom and ask them if you can buy a new firewall, because number one, they don’t know what a firewall is,” says Hutton. “Number two, we don’t want them to touch our firewalls.”
What moves a board is the effect on the business. She turns every request into a plain question. How would the company run payroll if the systems went down? What would a shutdown of the dealer management system cost the group?
When Nova Scotia Power, the province’s electricity utility, had a breach that exposed customer information, she used it as an example because her own customers had started paying closer attention to how their personal data gets handled.
Why she won’t block shadow AI
Hutton treats AI as part of the company’s overall risk.
“An AI strategy is not something that’s owned by your IT department,” says Hutton. “This is enterprise risk.”
Her approach runs against what she hears from peers. In her CIO association chapter, she says, the common line is to block shadow AI, the tools employees use on their own without company approval, until the rules and safeguards are ready.
Hutton allows it.
“I’m probably one of the few CIOs that will tell you I don’t block shadow AI,” she says.
Her reasoning is that people will use these tools no matter what, on a phone or a personal device if they have to, so she is focused on teaching them to use them safely.
About three-quarters of the AI at Steele is already built into software the group uses every day, from its customer records to the main system that runs the dealerships. The rest goes through one approved paid tool, with smaller AI helpers built inside it for different departments.
An internal AI task force coordinates how new tools roll out. When someone finds something that works, they show it to the group, and if it holds up it gets shared with everyone else.
The career she didn’t plan
Hutton spent most of her career as the only woman in the room, or one of two. She’s led technical teams made up of men for more than 20 years. Steele is the first place she’s had women on her own IT staff.
She says she thinks the field stays lopsided because women don’t apply, and they don’t apply because nobody showed them it was an option.
“I remember the first time I saw a female airline pilot, and I went, huh, well, I would have done that if I had known girls could do that,” says Hutton.
The Fawn Annan nomination makes her that example for someone else. It caught her off guard. The career grew a step at a time while she was busy doing the work, and she never aimed at anything like this.
“When I really look back on the work that I’ve done, and my impact on people, I think is still what surprises me the most,” says Hutton.
Hutton has built a career being described as someone who manages through crisis and change. Systems that fail, industries that lag, a board that needs convincing. She has a method for all of it.
Then the last year handed her something no method covers. She lost her mother and her husband within months of each other.
“This is one of the ones that I thought might knock me down and it didn’t,” says Hutton.
Final shots
- Cybersecurity gets bigger than IT when the same risks touch privacy, insurance, safety, and whether the business can keep running.
- The value of backup systems shows up when something breaks. Steele kept taking payments through a two-and-a-half-week CDK outage because the fallback was already there.
- Hutton’s approach to shadow AI starts from a practical assumption: people will use it anyway, so the job becomes giving them safer ways to do it.
This article is part of a series profiling the finalists for the 2026 CanadianCIO of the Year Awards, presented by the CIO Association of Canada. The winner will be announced Oct. 1 in Toronto. Digital Journal is the national media partner for the CIO Association of Canada.
When the IT job becomes the risk job
#job #risk #job