Heights Consulting Group

Insights on cybersecurity leadership

Practical guidance on cybersecurity leadership, governance, risk and regulatory readiness, written to be useful whether you set the strategy, approve it or carry it out.

Written for
Anyone accountable for a security decision: executives, boards, counsel, compliance, IT and security teams.
Subjects
Governance, cyber risk, regulatory readiness and executive reporting.
Every article
Carries its author, its publication date and the date it was last substantively revised.

The archive

Every other article

Cloud Security
1
Compliance
6
Compliance and Audit Readiness
1
Compliance and Governance
1
Governance
5
Governance & Compliance
3
Governance and Leadership
1
Managed Security Services
1
Regulatory Compliance
2
Regulatory and Framework Readiness
6
Risk Management
2
Published
29

Subscribe to the RSS feed

  1. Compliance and Audit Readiness

    When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2

    SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome.
  2. Regulatory and Framework Readiness

    GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024

    The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.
  3. Governance

    What Security Documentation an Assessor Requests First and Why It Matters

    Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like.
  4. Compliance

    When Privileged Access Management Becomes an Audit Requirement

    SOC 2, PCI DSS and CMMC assessments increasingly test for privileged access controls, not as a checkbox but as evidence of governance. This article explains which frameworks mandate PAM, what constitutes compliance for audit purposes, and how leadership can establish accountability before the assessment begins.
  5. Compliance

    How FedRAMP Authorization Works and What It Requires Before You Apply

    FedRAMP authorization allows cloud service providers to sell to federal agencies through a standardized security assessment process. Leadership must understand the timeline, evidence requirements and internal ownership structure before committing to an authorization effort that typically spans twelve to eighteen months and requires continuous executive oversight.
  6. Managed Security Services

    What Changes When Your MSP Also Provides Security Monitoring

    When a managed service provider takes on security monitoring, the lines of accountability blur unless leadership explicitly defines who decides risk tolerance, who speaks to regulators, and who owns the security program. This article explains what shifts, what stays internal, and how executive ownership closes the gap.
  7. Regulatory and Framework Readiness

    What GDPR Requires of US Companies and When It Applies

    The General Data Protection Regulation applies to US companies that process personal data of individuals in the European Union, regardless of where the company is located. This article explains the territorial scope, core obligations, leadership accountability and practical steps for compliance.
  8. Compliance

    What Sarbanes-Oxley IT General Controls Actually Require and How They Are Tested

    Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap.
  9. Compliance

    When Log Retention Becomes a Legal Obligation and What That Means for Cloud Accounts

    Organizations face legal and regulatory requirements to preserve specific system logs for defined periods, but cloud environments create complexity around who is responsible for which records. This article explains what log retention obligations exist, where the shared responsibility model leaves gaps, and how to establish clear ownership so the organization can meet its compliance duties without ambiguity.
  10. Compliance

    When Multi-Factor Authentication Is Legally Required and What Counts as Compliant

    Federal regulations now mandate multi-factor authentication in specific contexts, but determining what qualifies as compliant and who owns implementation remains unclear in many organizations. This guide explains which regulations require MFA, what technical approaches satisfy those requirements, and how leadership should allocate accountability.
  11. Risk Management

    What Counts as a Security Incident Under Your Cyber Insurance Policy

    Cyber insurance policies require prompt notification of security incidents, but defining what qualifies is complicated. Many organizations lack clear decision protocols, creating delays that can invalidate claims. This article explains how incidents are defined, who should make the determination, and how to establish the governance needed to respond within policy timeframes.
  12. Regulatory and Framework Readiness

    What HITRUST CSF r11 Requires That HIPAA Does Not

    HITRUST CSF r11 is a contractual security certification increasingly required by health plans, business associates and investors. It builds on HIPAA's regulatory baseline with prescriptive technical controls, third-party validation and annual audits. Leadership must understand what the standard adds, who owns the work and how to demonstrate progress.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.