What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
AI and Emerging Technology Governance
What Must Be in Place Before Using AI to Analyze, Summarize or Route Information Protected Under Attorney-Client Privilege
General counsel and chief legal officers evaluating AI tools for legal document review face a governance problem: who owns the decisions that preserve privilege when vendor systems process confidential communications? This article explains the risks AI creates for privileged material, what controls must be established before deployment, and who inside the organization is accountable for those decisions.
-
AI and Emerging Technology Governance
What Must Be in Place Before Using AI with Customer or Patient Data
Before AI processes protected data, organizations need clear governance, defined accountability, documented legal positions on regulation, vendor contracts that allocate risk appropriately, and technical controls that enforce policy. This article explains what executives must put in place, who owns each component, and how virtual CISO leadership closes the gap between technical implementation and executive accountability.
-
AI and Emerging Technology Governance
What Must Be in Place Before Using Generative AI to Draft, Review or Summarize Legal, Regulatory or Compliance Documentation
Generative AI tools present confidentiality, privilege, accuracy, and unauthorized practice of law risks when applied to contracts, policies, filings, or legal research. This article explains the controls, approval workflows, and executive ownership required before using large language models in legal or compliance work.
-
Compliance
What Organizations Must Implement for Privileged Access Management Under NIST 800-53 Rev. 5 Control AC-6
NIST 800-53 Rev. 5 Control AC-6 requires organizations to enforce least privilege principles for privileged access, define what counts as privileged, and implement specific logging and monitoring. Federal contractors must demonstrate compliance through governance, documented decisions, and executive accountability. This article explains what the control requires, who owns it, and how to establish measurable progress.
-
Governance
What Organizations Must Implement Under NIST AI 600-1 for Generative AI Risk Management and Documentation
NIST's AI Risk Management Framework establishes a structured approach to identifying, documenting and governing AI systems. This guidance creates new executive accountability for transparency, testing and risk decisions in organizations deploying generative AI. Without clear ownership, these requirements become unmanaged compliance exposure.
-
Compliance and Governance
What Organizations Must Implement Under OMB M-24-10 Zero Trust Architecture Requirements
OMB M-24-10 requires federal civilian agencies to implement zero trust architecture across five pillars: identity, devices, networks, applications and data. Organizations that connect to federal systems or process federal data face significant implications. This article explains the requirements, implementation deadlines, accountability structures, and what leadership must do now.
-
AI and Emerging Technology Governance
What Organizations Must Implement When Employees Use Generative AI to Draft or Respond to Customer Service Requests Containing Personal Information
When customer service teams use generative AI tools to draft or respond to requests containing personal information, organizations face data handling obligations, vendor accountability gaps, and training requirements without clear ownership. This article explains what risks arise, what controls are required, who is accountable, and how vCISO leadership closes the governance gap.
-
Emerging Technology Governance
What Organizations Must Implement When Using AI to Generate or Modify Software Code in Production Systems
When engineering teams use AI-assisted development tools, leadership becomes accountable for outcomes without clarity on who owns what. This article explains what must be in place: code review protocols, testing requirements, intellectual property controls, security scanning obligations and the documentation framework needed to demonstrate adequate governance. It identifies who is accountable and what practical next steps look like.
-
AI and Emerging Technology Governance
What Organizations Must Implement When Using Generative AI with Source Code or Proprietary Technical Documentation
Development teams using AI coding assistants and documentation tools with proprietary code create intellectual property, data handling, and regulatory obligations that span legal, technical, and governance domains. This article explains what technology and SaaS leadership must implement to protect proprietary assets, comply with privacy obligations, and establish clear accountability when generative AI enters the software development lifecycle.
-
AI and Emerging Technology Governance
What Organizations Must Implement When Using Large Language Models to Summarize, Classify or Route Customer Communications
Before deploying LLMs to handle customer communications, organizations face specific data handling obligations, accuracy verification requirements, and disclosure duties. This article explains the governance, accountability and verification structures that must be in placeāand what leadership must do when models produce incorrect output.
-
AI and Emerging Technology Governance
What Organizations Must Prepare for When Implementing Generative AI in Customer Service and Support
Generative AI in customer-facing systems introduces accountability questions that many organizations have not yet answered: what customer data may be used for training or inference, what must be disclosed, and who owns the risk decisions. Leadership must resolve governance gaps before deployment, not after.
-
Regulatory Compliance
What Organizations Using AI for Employment Decisions Must Implement Under EEOC Guidance and State AI Employment Laws
The EEOC has issued guidance on bias in AI hiring systems, and states including New York, California and Illinois have enacted laws requiring bias testing, disclosure and record-keeping when AI is used in employment decisions. Leadership must establish clear ownership, comply with overlapping requirements and document governance to manage both compliance risk and the underlying fairness concerns.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.