The firm

A strategy-first cybersecurity and technology advisory firm

Heights Consulting Group provides executive cybersecurity leadership. Our flagship service is vCISO leadership, and everything else we do exists to help organizations execute the strategy that leadership produces.

Schedule a Confidential Consultation How vCISO Leadership Works

Who we work with

Leadership
Chief executives, boards, presidents and COOs, CFOs and general counsel.
Functions
Compliance leaders and IT leadership carrying security obligations without a CISO-level owner.
Organizations
Regulated and risk-sensitive, where the obligation is real and the accountability is unclear.

Position

What we are, and what we are not

Heights is an advisory firm. Dr. Daniel Glauber founded it to combine strategic advisory with hands-on execution, helping organizations reduce risk, meet their compliance obligations, and align technology with what the business is actually trying to do.

The work we lead with is executive: deciding what a security program should achieve, in what order, with what trade-offs, and being accountable for the answer when a board asks.

We also deliver program and operational work, because a strategy nobody executes is not worth much. But the sequence matters. Tools and services bought before the direction is set tend to produce activity rather than progress.

We are not a managed service provider competing for your IT contract. Where an organization already has an MSP or an internal IT team, our role is to give them clear expectations and to verify that what was agreed is actually happening.

Approach

Why we lead with strategy

Most organizations do not have a security problem that a product solves. They have an ownership problem: capable people doing sensible things, with nobody accountable for whether the whole adds up to enough.

That is why the order of work matters. An organization that buys monitoring before deciding what would constitute an incident gets alert volume. One that writes policies before understanding how it operates gets a documented gap between what it says and what it does. One that pursues a framework before establishing which obligations apply spends against requirements that were never theirs.

Establishing direction first is not slower. It is what makes everything after it cheaper, because the work is aimed at something.

How vCISO leadership works

How we work

Working with clients, teams and providers

Engagements are structured around a scope of responsibility agreed in writing, and a working rhythm that fits the leadership calendar the organization already has.

With client leadership

Regular working sessions and scheduled reporting, framed around exposure, obligation, progress and the decisions leadership is being asked to take. Decisions are recorded with their rationale, so a risk accepted in March can still be explained in November.

With internal technology teams

IT continues to run the environment. What we add is a clear specification, an agreed order of work, and executive backing for the trade-offs that follow. In practice it also gives technology leaders a route for concerns they have often been raising for some time, a departmental opinion becomes a governed risk with an owner.

How the vCISO works with internal IT

With managed and technical providers

Providers do real work, usually competently. What is frequently missing is somebody on the client side senior enough to specify what is wanted, review what arrives, and decide what happens when something falls outside the contracted scope. We occupy that position, and we record what providers do well as readily as what they do not.

How we structure provider oversight

Principles

Commitments we hold to

Operating commitments rather than values statements, each one is something a client could hold us to.

  1. Say what we actually think

    Including when the honest answer is that an organization does not need what it came to ask for, or needs less of it than expected.

  2. Write it down

    Scope, decisions, rationale and residual risk are recorded. A security program that exists only in conversation cannot be governed, evidenced or handed over.

  3. Prioritize by consequence

    Work is sequenced by what it would cost the organization to get wrong, not by control numbering or by what is easiest to demonstrate.

  4. Work with the people already there

    Internal teams and existing providers usually know the environment better than any incoming adviser. Our job is direction and verification, not displacement.

  5. Claim only what we can support

    No invented statistics, no borrowed client names, no guarantees that an incident cannot happen and no suggestion that passing an assessment means an organization is secure.

  6. Leave something transferable

    The documented program belongs to the client. If they hire a full-time CISO, that person should be able to pick it up and continue without starting again.

Leadership

Who leads the work

Dr. Daniel Glauber

Founder and Managing Principal

Dr. Daniel Glauber is the founder and managing principal of Heights Consulting Group. He has more than 30 years of experience in cybersecurity and technology leadership, working with organizations to protect their digital environments, meet regulatory obligations and build resilient technology operations.

He leads the firm’s vCISO engagements, working directly with chief executives, boards, general counsel and IT leadership on security strategy, governance and risk decisions.

In practice that experience shows up in the judgment calls an engagement turns on: which obligations genuinely apply, which risks are worth the cost of treating, what a board needs to hear, and when the honest advice is to do less than the client expected.

Areas of focus

  • Executive and board-level security leadership
  • Cybersecurity governance and program strategy
  • Cyber risk management
  • Regulatory and framework readiness

Full profile and published writing

Find us

Contact details

Office

504 W. Plant Street
Winter Garden, FL 34787

Telephone

(407) 908-7001