What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Regulatory Compliance
What the FTC's September 2024 Consent Order Against Amazon Ring Means for IoT Device Manufacturers
The FTC's enforcement action against Amazon's Ring division found that employees and contractors were granted unrestricted access to consumer video recordings without business justification, violating privacy commitments. IoT device manufacturers handling consumer data now face clear regulatory expectations: implement role-based access controls, maintain audit logs, restrict access to legitimate business purposes, and establish executive accountability for these controls. This article explains what the consent order requires and what product leadership must do to avoid similar findings.
-
Regulatory Compliance
What the GSA's IT Modernization Centers of Excellence Supply Chain Risk Management Guidance Means for Federal Contractors
The General Services Administration's IT Modernization Centers of Excellence have issued guidance requiring federal contractors to demonstrate supply chain risk management for IT products and services. This guidance affects vendor risk assessment, component transparency, and documentation requirements. For contractors selling to civilian agencies, the business question is not whether to comply, but who owns the strategy and evidence that compliance exists.
-
Governance
What the NIST Cybersecurity Framework 2.0 Govern Function Means for Executive and Board Oversight
NIST Cybersecurity Framework 2.0 introduces Govern as a new, standalone function that defines organizational leadership responsibilities for cybersecurity risk management. This article explains what the Govern function establishes for board and executive accountability, how it differs from version 1.1, and what adequate ownership looks like in practice.
-
Compliance
What the NIST Post-Quantum Cryptography Standards Mean for Organizations That Handle Federal Data
In August 2024, NIST published three post-quantum cryptography standards (FIPS 203, 204, 205) to protect encrypted data from future quantum computing threats. Federal agencies and contractors face migration timelines beginning in 2025. This article explains what leadership must inventory now, who owns the transition, and how executive governance prevents costly delay.
-
Regulatory and Framework Readiness
What the October 2024 HHS Cybersecurity Performance Goals Mean for Healthcare Organizations
In October 2024, the U.S. Department of Health and Human Services published voluntary cybersecurity performance goals for the healthcare sector. These goals create new leadership decisions around security prioritization, resource allocation and regulatory positioning—without specifying who owns them or how progress should be measured. This article explains what changed, which goals apply to different organization types, and what executive ownership looks like in practice.
-
Governance
What to Put in Place First for AI and Emerging Technology Governance
AI and emerging technology governance requires establishing clear accountability, risk assessment processes, and oversight structures before deployment. This article explains what executive leadership must put in place first: identifying who owns governance decisions, defining risk tolerance, establishing evaluation criteria, and creating reporting mechanisms that address both strategic opportunity and regulatory exposure.
-
Leadership
Who Evaluates Your Security Program When No One Owns It Full Time
Most regulated organizations are accountable for security outcomes without clear executive ownership. This creates a gap between regulatory expectation and operational reality. This article explains what adequate oversight looks like, who should own it, and how leadership can close the accountability gap.
-
Regulatory Compliance
CCPA and CPRA Enforcement in 2024: What the California Privacy Protection Agency Has Prioritized and What That Means for SaaS Providers
The California Privacy Protection Agency began enforcement of the California Privacy Rights Act in 2023. SaaS providers selling to California consumers face clear obligations around data collection disclosure, consumer rights mechanisms, and security practices. Without executive ownership of privacy compliance, organizations cannot answer basic regulatory questions or demonstrate adequate controls. This article explains the enforcement landscape through mid-2024, what the CPPA has prioritized, and what leadership must verify.
-
Regulatory and Framework Readiness
CMMC 2.0 Final Rule: What Defense Contractor Leadership Must Decide Now
The October 2024 CMMC 2.0 final rule creates binding cybersecurity requirements for defense contractors. Leadership must now decide who owns the regulatory position, how to demonstrate compliance at the required level, and how to translate technical obligations into accountable governance.
-
Regulatory Compliance
DFARS 7012 and Cyber Incident Reporting: What Contractors Must Report and to Whom
Defense contractors face binding incident reporting obligations under DFARS 252.204-7012. This requirement creates executive accountability for deciding what constitutes a reportable incident, who receives the report, and how quickly it must be filed. The obligation exists whether or not the organization has appointed someone to make those decisions.
-
Regulatory Compliance
Executive Order 14110 and Federal AI Requirements: What Contractors and Regulated Entities Must Prepare For
Executive Order 14110, issued in October 2023, directs federal agencies to establish binding requirements for AI systems used by contractors and in regulated sectors. This article explains what the order requires, who inside your organization is accountable, and the practical steps leadership must take to demonstrate compliance as agency-specific rules take effect.
-
Compliance
FedRAMP and the 2024 Authorization Process Changes: What Cloud Providers Must Now Demonstrate
Recent changes to FedRAMP authorization have shifted expectations toward continuous monitoring and ongoing governance. Cloud service provider executives now face sustained accountability for security outcomes without always having clear internal ownership. This article explains what the authorization process now requires, who inside the organization must own these obligations, and how strategic leadership closes the gap between compliance milestones and operational reality.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.