Strategy, governance, and execution, connected
Heights leads the cybersecurity program through a vCISO engagement, and provides the risk, compliance, security and technology work required to put that strategy into operation.
- Flagship
- vCISO leadership: ownership of the program, its priorities and its reporting.
- Supporting
- Risk and governance, regulatory readiness, architecture and operations, resilience and AI governance.
- Engaged as
- Ongoing leadership, a defined piece of work, or delivery under an existing roadmap.
Flagship engagement
vCISO leadership
Ongoing executive ownership of the security program: strategy, governance, risk decisions, regulatory position and reporting to leadership.
Everything else on this page is work a security strategy calls for. This is the engagement that decides what the strategy should be, in what order, and who answers for the result.
What the engagement covers Schedule a Confidential Consultation
What the engagement owns
- Cybersecurity strategy and a prioritized roadmap
- Security governance and the decisions behind it
- Risk ownership, in business terms
- Regulatory position and the evidence behind it
- Executive and board reporting
- Oversight of internal teams and providers
A Security Program Assessment is how most engagements begin: a measured picture of where the program stands before anything is sequenced. How the assessment works.
The portfolio
The work that puts the strategy into operation
Each capability can be engaged on its own. More often they are how a vCISO engagement gets executed.
Executive cybersecurity leadership
Risk and governance
The decisions, records and oversight that turn security activity into something leadership can direct.
Compliance and regulatory readiness
Knowing which obligations apply, and being able to evidence them when somebody asks.
Security architecture and operations
The design and running of the controls a strategy depends on.
Resilience and emerging technology
Preparedness for what goes wrong, and governance for what is arriving.
Structure
How the work connects to the program
Leadership sets the direction. Everything beneath it exists to assess, build, operate or evidence what that direction requires.
- Risk and governance Establishes the baseline and the priorities
- Compliance and readiness Establishes what is required and how it is evidenced
- Security and technology Addresses the risks and runs the controls
Each supporting capability can be engaged independently where that is the right answer.
Scope
Ways an engagement is structured
Scope is agreed in writing before work starts. Which of these fits is one of the things a first conversation settles.
-
Ongoing vCISO leadership
Heights holds the CISO responsibilities on a continuing basis, inside your leadership rhythm, with reporting on an agreed cadence.
-
A defined piece of work
One service with a stated scope, a stated output and an end: an assessment, a policy set, a readiness review, a response plan.
-
Execution under an existing roadmap
Your team or your providers deliver, and Heights supplies the specification, the acceptance criteria and the client-side review.
-
Leadership support for a specific event
A customer security review, a regulatory deadline, an audit, diligence, or a decision that needs a security position stated accurately.
Heights does not publish rates. Scope, cadence and commitment differ by organization, and quoting a number before understanding the obligations would be guesswork.
Ownership
Why most of this works better with an owner
A deliverable only changes something if somebody owns what happens next.
Any of these services can be delivered as a standalone piece of work, and sometimes that is exactly right, a specific gap, a fixed deadline, a defined output.
Without an owner to sequence it, fund it, hold providers to it and report on it, the same findings tend to reappear in the next assessment. That is the role a vCISO engagement fills.
Insights
Related reading
Written for the people who have to decide what the program does next.
-
Governance & Compliance
What Cyber Incident Response Plans Must Contain to Satisfy Regulators
Regulated organizations are accountable for documented incident response plans that meet specific technical and governance requirements. This article explains what every plan must include, who approves it, how often it must be tested, and where executive ownership typically breaks down.
-
Compliance and Audit Readiness
When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2
SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome.
-
Regulatory and Framework Readiness
GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024
The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.