Heights Consulting Group

Virtual CISO Leadership. Clear priorities. Executive accountability.

Heights brings cybersecurity risk, compliance, vendors, and security initiatives into one governed program leadership can understand and act on.

Clear priorities and executive accountability for security, built for regulated, risk-sensitive organizations: healthcare, financial services, defense supply chains, manufacturing, legal, insurance, aviation and technology.

Schedule a Consultation How vCISO Leadership Works

  1. Who owns the cybersecurity program? Not who runs the systems. Who is accountable for whether the program as a whole is adequate.
  2. What needs to be addressed first? Not the full list of findings. The agreed order of work, and why it is in that order.
  3. Can leadership clearly explain the risk? In business terms, to a board, an insurer or a customer, without assembling it from three vendors.
Dr. Daniel Glauber, Founder and CEO of Heights Consulting Group

The principal

Led by Dr. Daniel Glauber

Every Heights engagement is led by its founder: Doctor of Management, adjunct professor of cybersecurity, three decades across defense, government and enterprise security, and the virtual CISO at the table in every engagement. He is the author of Cybersecurity in the Age of Artificial Intelligence.

The person at your table The evidence: three engagements

02 Before

IT staff, providers, tools and policies, and still no owner

Cybersecurity work gets done in most organizations. What is missing is the person accountable for whether the program as a whole is adequate, and for the order the work happens in.

  • Responsibility is fragmented

    IT runs the systems, a provider covers part of it, vendors cover the rest. Nobody owns the whole.

  • Projects compete without priorities

    Work is agreed to be important, then displaced by whatever is more urgent that week.

  • Leadership lacks meaningful reporting

    The board receives metrics it cannot act on, or none at all.

  • Compliance sits apart from operations

    Evidence is assembled before an assessment rather than maintained between them.

  • Vendors work without unified direction

    Spending grows without a clear picture of coverage, overlap or gaps.

  • Policies do not match practice

    The written program and the working practice have drifted apart.

  • The organization reacts instead of planning

    Decisions are made case by case, with no stated direction to measure against.

03 After

What vCISO leadership changes

Nothing here is a promise about attackers. It is a description of what becomes true once the program has an owner.

  1. Clear ownership

    One accountable person for the security program, with a written scope of responsibility that leadership and providers both work to.

  2. Risk-based priorities

    An agreed order of work, driven by business consequence and regulatory exposure rather than by whatever surfaced most recently.

  3. Executive visibility

    Reporting written for the audience: exposure, obligation, progress, and the decisions leadership is being asked to take.

  4. Measurable program progress

    A baseline, one consistent way of measuring against it, and reporting that shows movement between periods.

Everything a vCISO engagement delivers

04 Flagship engagement

Executive ownership of the cybersecurity program

Heights provides ongoing strategy, governance, risk leadership, regulatory direction, vendor oversight and executive reporting. The scope of responsibility is agreed in writing at the start and reviewed as the program matures.

How vCISO engagements work Schedule a Confidential Consultation

What Heights carries

  1. Security strategy and roadmap
  2. Governance and decision records
  3. Cyber risk management
  4. Regulatory and framework direction
  5. Vendor and provider oversight
  6. Executive and board reporting

05 Sequence

How an engagement runs

  1. Understand the current state

    What the organization is responsible for, and what is actually in place to meet it, established with the people who operate the environment.

  2. Establish priorities

    Gaps ranked by business consequence and regulatory exposure, then agreed with executives rather than handed to them.

  3. Build and coordinate the program

    A phased roadmap with owners and dependencies, delivered by your team, your providers or Heights.

  4. Measure and report progress

    Reassessment against the original baseline using the same method, reported to leadership in a consistent format.

How the phases are scoped and timed

07 Where we work

Regulated and risk-sensitive organizations

Sectors where security obligations are written down and somebody has to be able to evidence them.

Frameworks and regulations we work to

Which of these applies to your organization is the first question an engagement answers.

How we establish which obligations apply

  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • SOC 2
  • CMMC and NIST SP 800-171
  • HIPAA and the HITECH Act
  • PCI DSS
  • SOX IT general controls
  • HITRUST CSF

08 Who you would be working with

Dr. Daniel Glauber

Founder and CEO

About Heights Consulting Group

Heights Consulting Group is a strategy-first cybersecurity and technology advisory firm. Its flagship service is vCISO leadership, and the rest of the portfolio exists to help organizations execute the strategy that leadership produces.

Dr. Daniel Glauber is the founder and CEO of Heights Consulting Group. He holds a Doctor of Management in Organizational Leadership with a specialization in Information Systems and Technology, as well as an MBA, and has spent three decades in information technology, cybersecurity, enterprise architecture and organizational leadership. His doctoral research examined the relationship between leadership, organizational decision-making and technology adoption, including knowledge management work presented at the 18th International Conference on Information and Knowledge Management in Barcelona.

His background includes more than fifteen years supporting United States government, defense and national security missions, with assignments connected to Afghanistan, Bogota, Guantanamo Bay, U.S. Central Command, U.S. Southern Command, the National Ground Intelligence Center, the National Security Agency and NATO. That work is where technology, security, leadership and mission continuity had to hold together at once.

He is the author of Cybersecurity in the Age of Artificial Intelligence, published in 2025: eighteen chapters across five security domains on how artificial intelligence is changing both attack and defense, grounded in more than fifty real-world case studies. He also serves as an adjunct professor of cybersecurity at Keiser University in Orlando.

Before founding Heights, he founded MSP PRO, created the Cyber Health Check assessment platform, and served as CEO of Kintek Cybersecurity. He leads the firm’s vCISO engagements today, working directly with chief executives, boards, general counsel and IT leadership on security strategy, AI governance and risk decisions.

09 Insights

Written for the people who have to decide

All insights

What Cyber Incident Response Plans Must Contain to Satisfy Regulators

Regulated organizations are accountable for documented incident response plans that meet specific technical and governance requirements. This article explains what every plan must include, who approves it, how often it must be tested, and where executive ownership typically breaks down.

When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2

SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome.

GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024

The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.