Industries

Regulated and risk-sensitive industries

Heights works in sectors where security requirements come from a regulator, a contract or a customer, and somebody has to be able to prove the organization is meeting them.

Schedule a Confidential Consultation How vCISO Leadership Works

What a sector engagement establishes

What we look at
The obligations that apply, the risks that behave differently in the sector, and who owns them today.
What leadership asks
Whether the organization can evidence its position to a regulator, an insurer or a customer.
Where it leads
A prioritized program with an accountable owner, not a list of sector findings.

What leadership raises first, whatever the sector

The vocabulary changes between a hospital, a bank and a defense supplier. The underlying questions do not.

The situations that prompt an engagement

  • Which obligations actually apply

    Regulation, contract and customer requirement overlap, and the overlap is rarely written down anywhere.

  • Whether we could evidence it

    Not whether a control exists, but whether its operation can be demonstrated on request.

  • What a customer review will find

    Questionnaires and security addenda arrive with deals, and the answers become commitments.

  • Where the third-party exposure sits

    Providers and vendors hold or reach regulated data, often under agreements nobody has reread.

  • What happens during an outage

    Sector obligations frequently set notification duties and timelines that assume a plan exists.

  • Who answers when the board asks

    Every sector on this page eventually produces a question that needs one accountable name.

  • How vCISO leadership applies

    The obligations are sector-specific. The ownership, sequencing and reporting that meet them are not.

The frameworks behind the obligations

Which of these applies to a particular organization is the first question an engagement answers. Descriptions are of the published requirements, not claims about outcomes.

How we approach regulatory readiness

NIST Cybersecurity Framework
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work. Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
ISO/IEC 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list. Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant. Technology and service companies whose enterprise customers require evidence of a controlled environment.
CMMC and NIST SP 800-171
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level. Defense contractors and their supply chain, where flow-down clauses make this an eligibility issue rather than a compliance preference.
HIPAA and the HITECH Act
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates. Covered entities and their business associates.
PCI DSS
Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available. Any organization handling payment card data, with validation effort scaled to transaction volume and method.
SOX IT general controls
Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting. Public companies, and private companies preparing for a public offering or an acquirer's diligence.
HITRUST CSF
A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence. Healthcare organizations and vendors serving them.

If your sector is not listed

These are the sectors we describe in detail, because their obligations are specific and well-documented. They are not the only organizations we work with.

The question that determines fit is not the industry label. It is whether the organization has a real security obligation, regulatory, contractual or commercial, and no CISO-level owner accountable for meeting it.

Tell us about your organization

The work these obligations usually call for

Engaged on their own, or as the execution behind a vCISO roadmap.

The complete services portfolio

Risk and governance

Risk stated in business terms, ranked by consequence, with decisions recorded and reviewed.

Third-party exposure

Responsibility boundaries stated in writing, and provider delivery reviewed against them.

When it is tested

Plans, roles and notification duties prepared before the obligation is tested rather than during it.

Bring your sector obligations to a first conversation.

Tell us what applies to your organization, what is currently in place, and what a customer, regulator or insurer has recently asked you to demonstrate.