What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Regulatory Compliance
What SaaS Providers Must Now Disclose Under SEC Cyber Rules
The SEC's December 2023 cybersecurity disclosure requirements apply to all public companies, including SaaS providers. Executives must determine materiality of incidents within four days, disclose board oversight processes annually, and maintain internal controls—all requiring defined ownership and governance that many technology companies lack.
-
Compliance
What the DOJ's May 2024 Voluntary Self-Disclosure Policy for Government Contractors Means for Cybersecurity Incidents
In May 2024, the Department of Justice announced a revised voluntary self-disclosure policy for government contractors covering cybersecurity incidents and cyber fraud. Federal contractors and subcontractors face new obligations that carry real consequences: leadership must understand what qualifies for mitigation credit, what triggers mandatory disclosure, and who inside the organization owns compliance. Without clear executive ownership of cybersecurity governance and incident response, contractors risk losing mitigation credit, facing civil enforcement, or failing to meet disclosure timelines when seconds count.
-
Regulatory Compliance
What the FCC's July 2024 Data Breach Notification Rules Mean for Telecommunications and VoIP Providers
In July 2024, the FCC adopted new data breach notification rules that fundamentally change reporting obligations for telecommunications carriers and VoIP providers. The rules compress notification timelines and expand what must be disclosed. Leadership must understand who is accountable for compliance, what the new requirements demand, and how to establish the governance necessary to meet them.
-
Regulatory Compliance
What the FFIEC's November 2023 Authentication and Access Management Guidance Requires of Financial Institutions
The FFIEC issued updated authentication and access risk management guidance in November 2023. Financial institution leadership must now demonstrate layered security controls, risk-based customer authentication and continuous monitoring that examiners will assess during safety and soundness reviews. This article explains the guidance's requirements, who owns implementation and how to establish executive accountability.
-
Regulatory Compliance
What the FTC's August 2024 Data Breach Order Against Marriott Means for Data Retention and Access Controls
The FTC's August 2024 order against Marriott imposed specific data minimization, access control and retention obligations following repeated breaches. Leadership in hospitality, retail and customer-facing organizations handling large volumes of customer personal data must understand what the order signals about regulatory expectations and who inside the organization is accountable for implementation.
-
Compliance
What the Joint Commission's January 2024 Emergency Management Standard Revisions Mean for Cybersecurity and Incident Response
Joint Commission's updated emergency management standards now explicitly require accredited organizations to treat cybersecurity incidents as emergencies. This means new obligations around incident response planning, testing frequency, and executive accountability—creating a regulatory gap that many hospitals lack clear ownership to close.
-
Regulatory Compliance
What the SEC's April 2024 Identity Theft Red Flags Rule Amendments Mean for Broker-Dealers and Investment Advisers
In April 2024, the SEC expanded the Identity Theft Red Flags Rule for broker-dealers and investment advisers. Leadership must now establish formal detection and response programs where many firms previously had no systematic approach. This article explains what changed, who owns compliance, and how to move from obligation to operational readiness.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.