What a sector engagement establishes
- What we look at
- The obligations that apply, the risks that behave differently in the sector, and who owns them today.
- What leadership asks
- Whether the organization can evidence its position to a regulator, an insurer or a customer.
- Where it leads
- A prioritized program with an accountable owner, not a list of sector findings.
What leadership raises first, whatever the sector
The vocabulary changes between a hospital, a bank and a defense supplier. The underlying questions do not.
-
Which obligations actually apply
Regulation, contract and customer requirement overlap, and the overlap is rarely written down anywhere.
-
Whether we could evidence it
Not whether a control exists, but whether its operation can be demonstrated on request.
-
What a customer review will find
Questionnaires and security addenda arrive with deals, and the answers become commitments.
-
Where the third-party exposure sits
Providers and vendors hold or reach regulated data, often under agreements nobody has reread.
-
What happens during an outage
Sector obligations frequently set notification duties and timelines that assume a plan exists.
-
Who answers when the board asks
Every sector on this page eventually produces a question that needs one accountable name.
-
How vCISO leadership applies
The obligations are sector-specific. The ownership, sequencing and reporting that meet them are not.
The sectors we describe in detail
Each page sets out that sector's environment, risks, obligations, triggers and the services that apply.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
The frameworks behind the obligations
Which of these applies to a particular organization is the first question an engagement answers. Descriptions are of the published requirements, not claims about outcomes.
- NIST Cybersecurity Framework
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work. Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
- ISO/IEC 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list. Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant. Technology and service companies whose enterprise customers require evidence of a controlled environment.
- CMMC and NIST SP 800-171
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level. Defense contractors and their supply chain, where flow-down clauses make this an eligibility issue rather than a compliance preference.
- HIPAA and the HITECH Act
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates. Covered entities and their business associates.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available. Any organization handling payment card data, with validation effort scaled to transaction volume and method.
- SOX IT general controls
- Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting. Public companies, and private companies preparing for a public offering or an acquirer's diligence.
- HITRUST CSF
- A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence. Healthcare organizations and vendors serving them.
If your sector is not listed
These are the sectors we describe in detail, because their obligations are specific and well-documented. They are not the only organizations we work with.
The question that determines fit is not the industry label. It is whether the organization has a real security obligation, regulatory, contractual or commercial, and no CISO-level owner accountable for meeting it.
The work these obligations usually call for
Engaged on their own, or as the execution behind a vCISO roadmap.
Establishing what applies
Every sector engagement starts here: which obligations bind this organization, what they actually require, and where the program stands against them today.
Risk and governance
Risk stated in business terms, ranked by consequence, with decisions recorded and reviewed.
Third-party exposure
Responsibility boundaries stated in writing, and provider delivery reviewed against them.
When it is tested
Plans, roles and notification duties prepared before the obligation is tested rather than during it.
Bring your sector obligations to a first conversation.
Tell us what applies to your organization, what is currently in place, and what a customer, regulator or insurer has recently asked you to demonstrate.
Or reach us directly at (407) 908-7001 or info@heightscg.com.