Heights Consulting Group

Insights on cybersecurity leadership

Practical guidance on cybersecurity leadership, governance, risk and regulatory readiness, written to be useful whether you set the strategy, approve it or carry it out.

Written for
Anyone accountable for a security decision: executives, boards, counsel, compliance, IT and security teams.
Subjects
Governance, cyber risk, regulatory readiness and executive reporting.
Every article
Carries its author, its publication date and the date it was last substantively revised.

The archive

Every article

Cloud Security
1
Compliance
6
Compliance and Audit Readiness
1
Compliance and Governance
1
Governance
5
Governance & Compliance
3
Governance and Leadership
1
Managed Security Services
1
Regulatory Compliance
2
Regulatory and Framework Readiness
6
Risk Management
2
Published
29

Subscribe to the RSS feed

  1. Regulatory and Framework Readiness

    How NIST SP 800-171 Rev 3 Changes Assessment Methodology for Defense Contractors

    NIST SP 800-171 Revision 3 restructures assessment procedures to align with NIST SP 800-53A and introduces scoring changes that defense contractor executives must understand. Leadership accountability for controlled unclassified information protection requires clarity on what changed, who owns compliance, and how progress is measured.
  2. Regulatory and Framework Readiness

    What PCI DSS 4.0 Changed for Service Providers and When It Takes Effect

    Payment service providers face new PCI DSS 4.0 requirements with specific transition deadlines. Leadership needs clear accountability for continuous compliance, not just annual assessments.
  3. Cloud Security

    When Cloud Misconfigurations Become Reportable Breaches Under State Law

    Cloud misconfigurations can trigger breach notification obligations under state law before any threat actor touches the data. This article explains when an exposure becomes reportable, who decides, and how executive leadership should establish accountability for these determinations.
  4. Regulatory Compliance

    How HIPAA Security Rule Enforcement Changed in 2023 and 2024

    The Office for Civil Rights has shifted how it evaluates HIPAA Security Rule compliance, moving from checklist audits to outcome-based assessments tied to enterprise risk management. Healthcare executives must now demonstrate that security decisions reflect documented risk, that governance is clear, and that technical safeguards match the organization's actual risk profile.
  5. Compliance

    What SOC 2 Type II Auditors Actually Test in Access Controls

    SOC 2 Type II auditors evaluate whether access controls meet trust services criteria over a sustained period, not just on paper. Leadership must understand what evidence auditors require, who owns the control environment, and how to demonstrate operating effectiveness before the examination begins.
  6. Regulatory Compliance

    What the SEC's Cybersecurity Disclosure Rules Require in Form 8-K and Form 10-K

    Public companies must now disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality, and describe their cybersecurity risk management, governance and board oversight annually on Form 10-K. The rules assign clear accountability but create an execution problem: leadership is responsible for outcomes in a domain where they often lack technical fluency, internal ownership is fragmented, and the materiality determination requires judgment that technical staff cannot make alone.
  7. Governance and Leadership

    What an Assessor Looks for in Managed Security Services

    Security assessors evaluating managed security services focus on whether the provider can demonstrate compliance with specific regulatory requirements, such as NIST SP 800-171 for organizations handling Controlled Unclassified Information. Leadership must understand that an assessor's role is independent verification of security controls, not implementation advice, and that responsibility for compliance outcomes remains with the organization even when technical work is delegated to a managed service provider.
  8. Regulatory and Framework Readiness

    What CMMC 2.0 Requires Before Your First Assessment

    Defense contractors face CMMC certification deadlines with unclear accountability for security readiness. This article explains what must be in place before assessment, who owns certification readiness inside your organization, and how executive leadership ensures compliance without delays.
  9. Governance

    Who Owns Incident Response When a Security Event Occurs

    Incident response planning requires executive ownership of decisions that cross departments, involve regulatory obligations, and directly affect business continuity. This article explains what incident readiness and response planning entails, which leaders are accountable, and the practical steps to establish governance before an event occurs.
  10. Governance

    Identity and Access Management Strategy: What Changed and What Leadership Must Know

    Identity and access management has shifted from a technical implementation detail to a board-level governance question. This article explains what executives are now accountable for, who should own the strategy, and the practical decisions required to meet regulatory and operational expectations.
  11. Governance & Compliance

    What Current Regulation Requires Around Cloud Security Architecture and Governance

    U.S. organizations moving to cloud infrastructure face regulatory requirements that demand clear governance structures, defined security architectures and documented accountability. No single regulation prescribes cloud security architecture in detail, but sector-specific frameworks impose enforceable obligations around access controls, data protection, audit trails and vendor management. Leadership is accountable for establishing the governance function, even when technical execution is delegated. This article explains what compliance actually requires, who owns what inside the organization, and how to establish the executive control that regulators expect.
  12. Governance & Compliance

    What to Put in Place First for Regulatory and Framework Readiness

    Regulatory and framework readiness is the work of aligning your organization's cybersecurity practices with external requirements and recognized standards. Without clear executive ownership, this work stalls, accountability fragments, and leadership cannot measure progress toward outcomes that auditors, regulators and boards expect. This article explains what regulatory and framework readiness means in practical terms, why it matters to the business, who should own it, and what leadership should do next.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.