Heights Consulting Group

Virtual CISO leadership. Clear priorities. Executive accountability.

Heights brings cybersecurity risk, compliance, vendors, and security initiatives into one governed program leadership can understand and act on.

Schedule a Confidential Consultation How vCISO Leadership Works

02 Before

IT staff, providers, tools and policies, and still no owner

Cybersecurity work gets done in most organizations. What is missing is the person accountable for whether the program as a whole is adequate, and for the order the work happens in.

  • Responsibility is fragmented

    IT runs the systems, a provider covers part of it, vendors cover the rest. Nobody owns the whole.

  • Projects compete without priorities

    Work is agreed to be important, then displaced by whatever is more urgent that week.

  • Leadership lacks meaningful reporting

    The board receives metrics it cannot act on, or none at all.

  • Compliance sits apart from operations

    Evidence is assembled before an assessment rather than maintained between them.

  • Vendors work without unified direction

    Spending grows without a clear picture of coverage, overlap or gaps.

  • Policies do not match practice

    The written program and the working practice have drifted apart.

  • The organization reacts instead of planning

    Decisions are made case by case, with no stated direction to measure against.

03 After

What vCISO leadership changes

Nothing here is a promise about attackers. It is a description of what becomes true once the program has an owner.

  1. Clear ownership

    One accountable person for the security program, with a written scope of responsibility that leadership and providers both work to.

  2. Risk-based priorities

    An agreed order of work, driven by business consequence and regulatory exposure rather than by whatever surfaced most recently.

  3. Executive visibility

    Reporting written for the audience: exposure, obligation, progress, and the decisions leadership is being asked to take.

  4. Measurable program progress

    A baseline, one consistent way of measuring against it, and reporting that shows movement between periods.

Everything a vCISO engagement delivers

04 Flagship engagement

Executive ownership of the cybersecurity program

Heights provides ongoing strategy, governance, risk leadership, regulatory direction, vendor oversight and executive reporting. The scope of responsibility is agreed in writing at the start and reviewed as the program matures.

How vCISO engagements work Schedule a Confidential Consultation

What Heights carries

  1. Security strategy and roadmap
  2. Governance and decision records
  3. Cyber risk management
  4. Regulatory and framework direction
  5. Vendor and provider oversight
  6. Executive and board reporting

It works alongside the people you already have. Your IT team continues to run the environment and your providers continue to deliver their services. What changes is that they receive a clear specification, an agreed order of work, and a client-side counterpart who reviews the result.

05 Sequence

How an engagement runs

A straightforward sequence, because the value is in the judgment rather than in a named methodology.

  1. Understand the current state

    What the organization is responsible for, and what is actually in place to meet it, established with the people who operate the environment.

  2. Establish priorities

    Gaps ranked by business consequence and regulatory exposure, then agreed with executives rather than handed to them.

  3. Build and coordinate the program

    A phased roadmap with owners and dependencies, delivered by your team, your providers or Heights.

  4. Measure and report progress

    Reassessment against the original baseline using the same method, reported to leadership in a consistent format.

How the phases are scoped and timed

08 Who you would be working with

Dr. Daniel Glauber

Founder and Managing Principal

About Heights Consulting Group

Heights Consulting Group is a strategy-first cybersecurity and technology advisory firm. Its flagship service is vCISO leadership, and the rest of the portfolio exists to help organizations execute the strategy that leadership produces.

Dr. Daniel Glauber is the founder and managing principal of Heights Consulting Group. He has more than 30 years of experience in cybersecurity and technology leadership, working with organizations to protect their digital environments, meet regulatory obligations and build resilient technology operations.

He leads the firm’s vCISO engagements, working directly with chief executives, boards, general counsel and IT leadership on security strategy, governance and risk decisions.

09 Insights

Written for the people who have to decide

All insights

Business Associate Agreements: What Changed and What Leadership Must Verify

Recent regulatory guidance has shifted BAA oversight responsibility firmly to covered entities. Healthcare executives are now accountable for verifying that every business associate meets specific security requirements, maintains compliant agreements, and operates within defined risk tolerances. This article explains what changed, who owns oversight, and how leadership can close the gap between accountability and execution.

Healthcare Security Obligations: A Clear Map for Leadership

Healthcare organizations operate under a dense set of security obligations from federal regulators, state law and contractual requirements. This article maps those requirements plainly, explains who inside the organization is accountable, and sets out what adequate ownership looks like when technical leadership and executive accountability must meet.

HITRUST i1 Assurance Program: What Changed and When Healthcare Organizations Should Reassess

HITRUST introduced the i1 Assurance Program in 2024, replacing earlier certification pathways with a model that separates inherited controls from organization-specific implementation. Healthcare organizations holding e1 or r2 certifications face transition decisions with defined deadlines, requiring executive ownership of regulatory positioning and governance strategy.

Executive cybersecurity leadership, delivered as a service.