What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Compliance
What SaaS Providers Must Implement Under ISO/IEC 27001:2022 Annex A Controls 5.23, 8.10 and 8.11 for Data Loss Prevention and Information Deletion
ISO/IEC 27001:2022 introduced material changes to how SaaS providers must prevent data loss and ensure secure deletion. Controls 5.23, 8.10 and 8.11 now require specific governance, technical safeguards and documented procedures that certification auditors will verify. Many SaaS organizations lack clear executive ownership of these requirements, creating compliance gaps and audit risk.
-
Compliance and Governance
What SaaS Providers Must Implement Under SOC 2 Criteria CC6.6, CC6.7 and CC7.2 for Logging, Monitoring and Incident Response
SOC 2 Type II attestation requires specific, auditable controls for logging completeness, log retention, security monitoring and incident response. This article explains what the 2022 Trust Services Criteria demand under CC6.6, CC6.7 and CC7.2, what auditors test, and who inside a SaaS organization is accountable for these outcomes.
-
Compliance
What SaaS Providers Must Implement Under the California Consumer Privacy Act's Right to Delete and Verification Requirements
California's CPRA establishes specific obligations for SaaS providers handling deletion requests from California consumers. This article explains what constitutes a verifiable consumer request, which data must actually be deleted versus retained, and who inside the organization is accountable for building and maintaining compliant processes.
-
Regulatory and Framework Readiness
What SaaS Providers Must Implement Under the FTC's Standards for Safeguarding Customer Information
The FTC's Standards for Safeguarding Customer Information require specific technical safeguards from non-financial companies that collect or handle consumer financial data. This article explains when the rule applies, what it requires, who is accountable, and how vCISO leadership provides the executive ownership needed to meet regulatory obligations.
-
AI and Emerging Technology Governance
What State AI Transparency and Impact Assessment Laws Require of Organizations Deploying Automated Decision Systems
Connecticut SB 2, Colorado SB 205, and similar state frameworks impose algorithmic impact assessment, documentation, and public disclosure obligations on organizations using AI for consequential decisions in hiring, credit, insurance, housing, and healthcare. Leadership is accountable for compliance outcomes that span legal, technical, and risk functions, yet most organizations lack a clear owner for governance strategy and regulatory positioning.
-
Regulatory and Framework Readiness
What State Consumer Health Data Privacy Laws Mean for Organizations That Collect Biometric, Genetic or Reproductive Health Information
Washington's My Health My Data Act, Nevada SB 370 and Connecticut SB 3 create consent, disclosure and deletion obligations for consumer health data that go beyond HIPAA and apply to apps, platforms and services outside traditional healthcare. Organizations that collect health data from consumers now face overlapping state requirements without clear internal ownership or a reliable way to measure compliance progress.
-
Regulatory and Framework Readiness
What State Health Data Privacy Laws Now Require Beyond HIPAA
Washington, Nevada, and Connecticut have enacted health data privacy laws that extend far beyond HIPAA's scope, covering consumer health apps, wellness platforms, telehealth services, and other digital health technologies. Chief executives and general counsel in these sectors face new compliance obligations with significant penalties, but often lack clear ownership and accountability structures to address them. This article explains what these laws require, who is responsible, and what leadership should do next.
-
Regulatory Compliance
What State Insurance Commissioners Now Require Under the NAIC Model Cybersecurity Law for Health Insurers
The NAIC Insurance Data Security Model Law establishes cybersecurity governance, risk assessment, third-party oversight and incident response requirements for state-regulated health insurers. It differs from HIPAA by requiring board-level accountability, annual risk assessments and written third-party vendor programs. Health plan executives face compliance timelines and regulatory examination without necessarily having clear internal ownership of the security strategy these laws require.
-
Regulatory and Framework Readiness
What Technology Providers Must Implement Under the EU's Cyber Resilience Act for Products with Digital Elements
The EU Cyber Resilience Act imposes enforceable security-by-design, vulnerability handling and reporting requirements on technology providers selling products with digital elements into European markets. Leadership must assign clear ownership of regulatory position, establish compliance governance and demonstrate adequate security controls before enforcement begins in 2027.
-
Regulatory Compliance
What the ECRA Enhanced Cybersecurity Standards for Medicare and Medicaid Providers Mean for Access Controls and Monitoring
The Emergency Cybersecurity Requirements Act directs HHS to establish cybersecurity performance requirements for healthcare providers that participate in Medicare and Medicaid. While proposed standards have not yet been published, the statute establishes clear congressional intent that security will become a condition of participation. This article explains what is known about the framework, the governance gap most organizations face when accountability is assigned without executive ownership, and what preparation is prudent now.
-
Regulatory Compliance
What the EU AI Act Means for Organizations Deploying AI Systems
The EU AI Act, enforceable from August 2024, classifies AI systems by risk and imposes obligations on deployers and providers. Leadership must determine whether systems in use fall within scope, assign accountability, establish governance and meet compliance deadlines. Without clear ownership, organizations face regulatory exposure and reputational consequences.
-
Regulatory and Framework Readiness
What the FDA's March 2024 Cybersecurity in Medical Devices Quality System Regulation Proposal Means for Device Manufacturers
The FDA's proposed amendments to the Quality System Regulation would, if finalized, make cybersecurity controls a required design input throughout the product lifecycle. Leadership at medical device manufacturers would become accountable for documented risk management, secure design controls, and continuous post-market monitoring—responsibilities that currently lack clear ownership at most organizations.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.