Heights Consulting Group

Strategy, governance, and execution, connected

Heights leads the cybersecurity program through a vCISO engagement, and provides the risk, compliance, security and technology work required to put that strategy into operation.

Flagship
vCISO leadership: ownership of the program, its priorities and its reporting.
Supporting
Risk and governance, regulatory readiness, architecture and operations, resilience and AI governance.
Engaged as
Ongoing leadership, a defined piece of work, or delivery under an existing roadmap.

Flagship engagement

vCISO leadership

Ongoing executive ownership of the security program: strategy, governance, risk decisions, regulatory position and reporting to leadership.

Everything else on this page is work a security strategy calls for. This is the engagement that decides what the strategy should be, in what order, and who answers for the result.

What the engagement covers Schedule a Confidential Consultation

What the engagement owns

  • Cybersecurity strategy and a prioritized roadmap
  • Security governance and the decisions behind it
  • Risk ownership, in business terms
  • Regulatory position and the evidence behind it
  • Executive and board reporting
  • Oversight of internal teams and providers

A Security Program Assessment is how most engagements begin: a measured picture of where the program stands before anything is sequenced. How the assessment works.

The portfolio

The work that puts the strategy into operation

Each capability can be engaged on its own. More often they are how a vCISO engagement gets executed.

How an engagement sequences the work

Risk and governance

The decisions, records and oversight that turn security activity into something leadership can direct.

Compliance and regulatory readiness

Knowing which obligations apply, and being able to evidence them when somebody asks.

Security architecture and operations

The design and running of the controls a strategy depends on.

Resilience and emerging technology

Preparedness for what goes wrong, and governance for what is arriving.

Structure

How the work connects to the program

Leadership sets the direction. Everything beneath it exists to assess, build, operate or evidence what that direction requires.

The Heights service architecture. vCISO leadership governs the program; supporting services in Risk and governance, Compliance and readiness, Security and technology put that strategy into operation, and each can be engaged on its own.
Leads the program vCISO Leadership Ongoing executive ownership of the security program: strategy, governance, risk decisions, regulatory position and reporting to leadership.

Each supporting capability can be engaged independently where that is the right answer.

Scope

Ways an engagement is structured

Scope is agreed in writing before work starts. Which of these fits is one of the things a first conversation settles.

  1. Ongoing vCISO leadership

    Heights holds the CISO responsibilities on a continuing basis, inside your leadership rhythm, with reporting on an agreed cadence.

  2. A defined piece of work

    One service with a stated scope, a stated output and an end: an assessment, a policy set, a readiness review, a response plan.

  3. Execution under an existing roadmap

    Your team or your providers deliver, and Heights supplies the specification, the acceptance criteria and the client-side review.

  4. Leadership support for a specific event

    A customer security review, a regulatory deadline, an audit, diligence, or a decision that needs a security position stated accurately.

Heights does not publish rates. Scope, cadence and commitment differ by organization, and quoting a number before understanding the obligations would be guesswork.

Ownership

Why most of this works better with an owner

A deliverable only changes something if somebody owns what happens next.

Any of these services can be delivered as a standalone piece of work, and sometimes that is exactly right, a specific gap, a fixed deadline, a defined output.

Without an owner to sequence it, fund it, hold providers to it and report on it, the same findings tend to reappear in the next assessment. That is the role a vCISO engagement fills.

How that ownership works in practice

Insights

Related reading

Written for the people who have to decide what the program does next.

All insights
  • Governance & Compliance

    What Cyber Incident Response Plans Must Contain to Satisfy Regulators

    Regulated organizations are accountable for documented incident response plans that meet specific technical and governance requirements. This article explains what every plan must include, who approves it, how often it must be tested, and where executive ownership typically breaks down.

  • Compliance and Audit Readiness

    When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2

    SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome.

  • Regulatory and Framework Readiness

    GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024

    The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.