At a glance
- Part of
- Preparedness for what goes wrong, and governance for what is arriving.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations where teams are already using AI tools without a stated position.
- Companies whose customers have started asking how AI use is governed.
- Businesses whose existing vendors have enabled AI features that process their data.
- Boards that have asked what the organization's AI exposure actually is.
A governance position that permits useful adoption without losing track of where regulated or confidential data ends up. The question is not whether to allow AI, that decision has usually already been made by the people using it, but under what conditions.
The work is deliberately proportionate. A heavyweight review process applied to every use case gets bypassed; one scaled to the sensitivity of the data and the consequence of an error gets followed.
Scope
What Heights does
-
Acceptable use position
A clear statement of permitted, restricted and prohibited uses, written so staff can apply it without a legal reading.
-
Data handling boundaries
Which categories of data may be used with which systems, including third-party and vendor-embedded AI features.
-
Review before deployment
A proportionate review step for new use cases, sized to the sensitivity of the data and the consequence of an error.
-
Vendor and feature assessment
Assessment of AI capabilities arriving inside software you already use, which is where most unmanaged exposure appears.
-
Accountability for output
Who remains responsible for decisions informed by an AI system, and what human review applies before those decisions take effect.
Why this comes up
AI adoption rarely arrives as a project. It arrives as individual teams using tools already available to them, often with data that carries handling obligations, and usually without anyone having stated a position.
It also arrives inside software you already license. Vendors enable AI features on existing products, which means data can begin flowing to new processing without a procurement decision ever being made.
Timing
When organizations engage this
- Teams are already using AI tools and no position has been stated.
- A customer security questionnaire has asked how AI use is governed.
- Existing software vendors have enabled AI features that process your data.
- The board or an investor has asked what the organization's AI exposure is.
- A regulated data type is involved and nobody has confirmed whether current use is permissible.
What you receive
- AI acceptable use policy and data handling standard
- Use-case intake and review process
- Inventory of AI systems and AI-enabled vendor features in use
- Executive briefing on AI exposure and the decisions required
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
How this fits under vCISO leadership
AI governance is not a one-time policy. A vCISO keeps the position current as tools, vendor features and regulatory expectations change, and brings the decisions that need executive input to the table rather than making them by default.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Should we just prohibit AI tools?
A blanket prohibition usually produces unmonitored use rather than no use, and it forfeits genuine benefit. It is also difficult to enforce when AI features are embedded in software the organization already runs.
A stated position with clear boundaries is generally more effective than a ban, because it gives staff a way to comply that does not require them to work around it.
What is the risk we should actually be worried about?
For most organizations it is data leaving a controlled environment, regulated, confidential or contractually restricted information entering a system whose data handling has never been assessed.
Second is unreviewed reliance: decisions taken on AI output without a human accountable for the result. Both are governance problems rather than technical ones.
How do we find out what is already in use?
A combination of asking and looking. Teams generally answer honestly when the purpose is establishing a workable position rather than assigning blame, and vendor license and configuration reviews surface the embedded features nobody explicitly adopted.
The inventory is usually longer than leadership expects, and the vendor-embedded portion is usually the larger part of it.
Related services
- Incident Readiness and Response Planning A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
Talk through AI and Emerging Technology Governance with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.