What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Governance
What Financial Institutions Must Implement Under the Interagency Guidance on Model Risk Management for AI and Machine Learning
The interagency model risk management guidance—SR 11-7 and the OCC's 2023 update—establishes governance, validation and oversight requirements when banks use AI or machine learning in credit, trading, compliance or operational decisions. This article explains what constitutes adequate model validation, who owns each component, and how to meet regulatory expectations when algorithms drive material business outcomes.
-
Regulatory Compliance
What Financial Institutions Must Implement Under the OCC's March 2024 Third-Party Risk Management Bulletin
The OCC's March 2024 bulletin establishes specific requirements for banks partnering with fintech companies, including structured due diligence, contract provisions, continuous monitoring and customer complaint oversight. Many bank executives face accountability for these security outcomes without clear ownership or a way to measure progress. This article explains what the bulletin requires, who owns each element, and how virtual CISO leadership provides the executive governance that closes this gap.
-
AI and Emerging Technology Governance
What Financial Institutions Must Implement When Using AI for Transaction Monitoring, Fraud Detection or AML Screening
Federal banking regulators and FinCEN expect financial institutions using artificial intelligence in Bank Secrecy Act compliance, fraud detection or sanctions screening to apply model risk management, maintain explainability, conduct validation testing and maintain comprehensive documentation. This article explains what adequate governance looks like, who owns each piece and how leadership should establish accountability.
-
AI and Emerging Technology Governance
What Financial Institutions Must Prepare for Under Proposed Federal AI Risk Management Requirements from Banking Regulators
Federal banking regulators have not yet published formal AI risk management requirements specific to financial institutions. However, banks and credit unions adopting AI for underwriting, fraud detection, and customer service face a governance gap: existing model risk management practices must now extend to systems that behave unpredictably, and accountability for AI governance often falls between compliance, IT, and risk functions with no clear executive owner.
-
Regulatory Compliance
What Government Contractors Must Implement Under the DoD's September 2023 Zero Trust Strategy and Reference Architecture
The Department of Defense's September 2023 zero trust reference architecture establishes mandatory security capabilities for contractors supporting DoD information systems. Defense contractor executives need to understand what zero trust implementation means for their obligations, how it intersects with CMMC requirements, and who inside their organization owns strategy versus execution.
-
Regulatory Compliance
What Government Contractors Must Implement Under the Proposed Federal Acquisition Security Council (FASC) Supply Chain Risk Information Sharing Rules
The Federal Acquisition Security Council has proposed rules requiring federal contractors to share supply chain risk information with the government. This article explains what information will be required, what protections exist for proprietary data, who owns compliance inside your organization, and how vCISO leadership closes the accountability gap between contracts, legal, and IT.
-
Compliance
What Government Contractors Must Implement When Using AI in Systems That Process Controlled Unclassified Information
Defense and federal contractors using AI tools to process CUI face specific implementation requirements for data residency, access controls, vendor due diligence and compliance documentation. Without clear executive ownership of these requirements, contractors risk non-compliance with NIST 800-171 and CMMC obligations that govern how controlled information may be handled.
-
Regulatory and Framework Readiness
What Healthcare Organizations Must Demonstrate Under the HHS Health Care Industry Cybersecurity Task Force Recommendations
The 2017 HHS Health Care Industry Cybersecurity Task Force established imperatives that continue to shape OCR enforcement expectations, now reinforced by the October 2024 Cybersecurity Performance Goals. Healthcare executives face clear accountability for security outcomes without defined ownership, sequencing or progress measures—a gap that vCISO leadership is designed to close.
-
Regulatory and Framework Readiness
What Healthcare Organizations Must Implement Under State All-Payer Claims Database Reporting and Data Security Requirements
State all-payer claims databases impose specific data security, de-identification and breach notification obligations on healthcare providers, payers and third-party administrators. These requirements create executive accountability for security outcomes that often lack clear ownership, a defined sequence or measurable progress markers. This guide explains what state APCD mandates require, who inside the organization owns compliance, and how leadership can establish governance that meets these obligations.
-
Regulatory and Framework Readiness
What Healthcare Organizations Must Implement Under the FDA's January 2024 Refuse to Accept Policy for Medical Device Cybersecurity
The FDA's October 2024 enforcement of the Refuse to Accept policy means 510(k), De Novo, and PMA submissions without documented cybersecurity design controls will not be accepted. This article explains what manufacturers must demonstrate, what belongs in a software bill of materials, and how regulatory, quality, and engineering leadership close the accountability gap.
-
Regulatory Compliance
What Healthcare Organizations Must Implement Under the FDA's May 2024 Medical Device Servicing Environment Cybersecurity Guidance
The FDA's May 2024 guidance establishes cybersecurity expectations for healthcare delivery organizations that maintain, service or operate medical devices in networked environments. Leadership faces accountability for device security without clear ownership or implementation paths. This article explains what the guidance requires, who owns each element, and how to establish the governance needed to close this gap.
-
Regulatory and Framework Readiness
What Healthcare Organizations Must Implement Under the FDA's Medical Device Cybersecurity Guidance (2023 Premarket and Postmarket)
The FDA issued updated medical device cybersecurity guidance in 2023 that fundamentally changes what device manufacturers must build into products and what purchasers must verify. Healthcare leadership is accountable for securing networked medical devices, but ownership, sequence and measurement remain unclear in most organizations. This article explains what the guidance requires, who owns the outcome, and how to establish effective governance without waiting for perfect documentation.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.