What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Regulatory and Framework Readiness
GLBA Safeguards Rule 2023: What Changed for Financial Institutions and What Leadership Now Owns
The June 2023 amendments to the Gramm-Leach-Bliley Act Safeguards Rule introduced incident response planning, annual reporting, and explicit board accountability requirements. Financial services leadership is now responsible for cybersecurity outcomes without always having clear ownership, measurement, or governance. This creates a structural gap that virtual CISO leadership is designed to close.
-
Regulatory and Framework Readiness
ISO/IEC 27001:2022: What Changed in the Revision and What It Means for Certified Organizations
ISO/IEC 27001:2022 introduced material changes to control requirements and management obligations. Organizations certified under the 2013 edition must transition by October 2025. This article details what changed, what the deadline requires, and how leadership should approach reassessment.
-
Regulatory and Framework Readiness
NIST SP 800-171 Revision 3: What Changed and What Defense Contractors Must Reassess
NIST SP 800-171 Revision 3 introduces substantive changes to the security requirements that defense contractors must meet to handle Controlled Unclassified Information. With CMMC enforcement linking contract awards to verifiable compliance, these changes create immediate reassessment obligations. This article explains what changed, the timeline under CMMC, and who inside the organization must own the response.
-
Regulatory Compliance
NYDFS Cybersecurity Regulation: The 2023 Amendments and What They Require of Leadership
The November 2023 amendments to New York's 23 NYCRR 500 place direct accountability for cybersecurity outcomes on boards and senior executives. For financial institutions operating in or serving New York, these requirements establish governance obligations, access controls, and third-party oversight standards that cannot be delegated to IT alone. This article explains what the regulation requires, who is accountable, and how leadership can establish the ownership and measurement needed to demonstrate compliance.
-
Regulatory Compliance
SEC Cyber Disclosure Rules: What Financial Services Firms Must Now Report and When
The SEC's December 2023 cybersecurity disclosure rules require public companies to report material incidents within four business days and disclose board oversight and risk management practices annually. Compliance demands clear executive ownership of materiality determination, incident response governance, and regulatory reporting—functions that typically fall outside both technical IT and legal counsel's core expertise.
-
Regulatory and Framework Readiness
SOC 2 Trust Services Criteria 2022: What Changed and What SaaS Leadership Must Reassess
The 2022 update to SOC 2 Trust Services Criteria introduced substantive language changes that affect how SaaS organizations design controls, evaluate compliance, and report to stakeholders. For leadership, this represents more than a technical audit matter—it's a governance question with board-level accountability implications.
-
Regulatory and Framework Readiness
Texas Data Privacy and Security Act (HB 4): What It Requires of Organizations Operating in Texas from July 2024
Texas House Bill 4 imposes consumer rights, controller obligations, and data security requirements on organizations handling Texas residents' personal data. The Act creates compliance obligations that require executive ownership, governance structures, and ongoing risk decisions—capabilities that virtual CISO leadership provides.
-
Governance
Vendor, MSP and Third-Party Oversight: What Executive Teams Must Decide
Third-party relationships introduce cybersecurity and privacy risks that belong to the organization, not the vendor. Leadership must decide who owns ongoing oversight, what acceptable risk looks like, and how to demonstrate governance when examined by regulators or boards.
-
Regulatory Compliance
What Broker-Dealers Must Now Report Under Regulation S-P and SCI
The SEC's May 2023 amendments to Regulation S-P impose new incident notification and safeguard requirements on broker-dealers. Compliance officers and executives are now accountable for security outcomes that many firms lack clear ownership structures to deliver. This article explains what changed, who is responsible, and how strategic vCISO leadership provides the executive ownership necessary to meet these obligations.
-
Regulatory Compliance
What Community Banks Must Now Implement Under the FDIC's 2023 Computer-Security Incident Notification Rule
The FDIC's November 2021 final rule requires banks to notify regulators within 36 hours of a computer-security incident that materially disrupts or degrades operations. Chief executives are accountable, but many banks lack clear ownership of the strategy, governance and regulatory position needed to comply.
-
Regulatory and Framework Readiness
What Controlled Unclassified Information (CUI) Handling Rules Mean for Government Contractors Beyond NIST 800-171
Government contractors handling CUI face two distinct compliance obligations: NIST 800-171 technical controls and the marking, storage, transmission, and destruction requirements in 32 CFR Part 2002. Leadership is accountable for both, but most organizations lack clear ownership of the regulatory position, the sequence of implementation, or a method to measure progress. Without executive-level governance, contractors operate under contractual risk they cannot quantify.
-
Regulatory Compliance
What Credit Unions Must Now Implement Under the NCUA's 2023 Cybersecurity and Incident Response Rule
The NCUA's November 2021 final rule requires federally insured credit unions to maintain incident response plans, report cybersecurity incidents to their boards, and notify the NCUA within 72 hours of substantial incidents. Leadership must establish clear governance: someone must own strategy, someone must execute, and the board must receive reportable information. Most credit unions lack the executive owner needed to translate regulatory obligation into defensible practice.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.