Heights Consulting Group

Insights on cybersecurity leadership

Practical guidance on cybersecurity leadership, governance, risk and regulatory readiness, written to be useful whether you set the strategy, approve it or carry it out.

Written for
Anyone accountable for a security decision: executives, boards, counsel, compliance, IT and security teams.
Subjects
Governance, cyber risk, regulatory readiness and executive reporting.
Every article
Carries its author, its publication date and the date it was last substantively revised.

The archive

Every article

Cloud Security
1
Compliance
6
Compliance and Audit Readiness
1
Compliance and Governance
1
Governance
5
Governance & Compliance
3
Governance and Leadership
1
Managed Security Services
1
Regulatory Compliance
2
Regulatory and Framework Readiness
6
Risk Management
2
Published
29

Subscribe to the RSS feed

  1. Risk Management

    Cyber Risk Management: What Leadership Is Now Expected to Own

    Cyber risk management has moved from a technical IT function to an enterprise-level accountability that sits with senior leadership. This shift reflects changing regulatory expectations and the integration of cybersecurity into broader organizational risk management. For executives without a clear internal owner or roadmap, this article explains what is required, who should be accountable, and how to establish effective governance.
  2. Governance

    Vendor, MSP and Third-Party Oversight: What Leadership Must Decide

    Vendor and third-party oversight is now a regulatory and operational requirement that leaves executives accountable for outcomes they cannot see clearly. This article explains what the obligation entails, who should own it, and how to establish effective governance without replacing existing technical controls.
  3. Compliance and Governance

    What Assessors Look for in Security Policy, Standards and Awareness Programs

    Security policy, standards and awareness requirements appear in nearly every regulatory and compliance assessment. Assessors evaluate whether an organization has defined how it protects sensitive information, translated those rules into operational standards, and built understanding across the workforce. Many executives discover gaps only when an assessment deadline arrives. This article explains what assessors examine, who is accountable, and what constitutes adequate ownership.
  4. Governance

    What Current Regulation Requires Around Security Program Assessment

    Federal regulations mandate regular security assessments for organizations handling controlled unclassified information (CUI). Executives are accountable for demonstrating that security controls are implemented correctly and operating as intended, but many organizations lack clear ownership of the assessment process. This guide explains the regulatory requirements, what leadership must oversee, and how to establish accountability.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.