At a glance
- Part of
- The decisions, records and oversight that turn security activity into something leadership can direct.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
Why this comes up
Risk registers fail for predictable reasons. They are written in technical language executives cannot act on, they are updated once a year for an audit, and nothing records who decided to accept a risk or on what basis.
The consequence shows up at the worst moment. A board asks what the organization's largest technology exposures are, and the answer has to be assembled from a provider report, an IT status update and a spreadsheet nobody has opened since the last assessment.
The service
What this engagement is
Who it is for
- Organizations whose risk decisions are currently made informally and recorded nowhere.
- Boards and audit committees that need a consistent view they can track between meetings.
- Companies whose existing register is technical, stale, or both.
- Leadership teams preparing for an examination, an insurance renewal or a diligence process.
A working risk process rather than a document. Risks are described by what they would disrupt, revenue, operations, patient or client data, a regulatory commitment, and rated on one scale applied the same way each cycle so movement over time is meaningful.
Every risk gets an accountable owner inside the business, not "IT" as a department. Treatment decisions are brought to the people entitled to make them and recorded with the rationale, the decision maker and the review date.
Scope
What Heights does
-
Risk identification in business terms
Risks stated by what they would disrupt, so an executive can weigh them without a translation layer.
-
A consistent assessment method
One rating scale, applied the same way each cycle, so risks can be compared to each other and to their own previous position.
-
Named ownership
An accountable owner inside the business for every risk, with the authority to act on it.
-
Treatment decisions on the record
Accept, reduce, transfer or avoid, recorded with the rationale, the decision maker and the date it is next reviewed.
-
Threat modeling where it earns its place
Structured analysis of how a specific system or process could realistically be attacked, applied to the areas where the consequence justifies the effort.
-
A review cadence that holds
A defined reassessment cycle tied to the reporting rhythm leadership already uses, rather than a separate calendar nobody keeps.
Timing
When organizations engage this
- The board has asked what the organization's top technology risks are and the answer is not consistent between people.
- An auditor, examiner or insurer has asked for evidence of a risk management process.
- Risk decisions are being made informally and are not documented anywhere.
- An incident or near miss revealed a risk nobody had formally considered.
- The organization is entering diligence for an investment, acquisition or major contract.
What you receive
- Risk register with consistent ratings and named owners
- Documented risk assessment methodology
- Risk treatment decisions with rationale and review dates
- Risk reporting format suitable for executives and the board
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- SOX
- Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
How this fits under vCISO leadership
Risk ownership is one of the core responsibilities a vCISO carries. Building the process is a discrete piece of work; running it, bringing decisions to leadership, keeping the register current, showing movement over time, is ongoing leadership.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
How is this different from a vulnerability scan?
A vulnerability scan finds technical weaknesses in systems. Risk management asks what those weaknesses, plus everything else, process gaps, third-party dependencies, single points of knowledge, could actually cost the organization, and decides what to do about it.
Scanning output feeds the risk process. It is not a substitute for it.
Who should own a cyber risk in our organization?
The person accountable for the business function the risk would disrupt, not the person who would fix it technically. A risk to patient scheduling belongs to the operations leader; a risk to financial reporting belongs to the CFO.
That distinction is what makes treatment decisions real. An owner who cannot authorize the trade-off cannot genuinely own the risk.
How often should the register be reviewed?
Quarterly works for most organizations, tied to an existing leadership meeting rather than a separate one. Individual high-rated risks often warrant a shorter cycle, and any material change to the environment should trigger a review regardless of the calendar.
Can you quantify risk in financial terms?
Where the underlying data supports it, yes, some risks have a defensible cost basis, such as contractual penalties, regulatory fines or a measurable period of downtime.
Where it does not, a fabricated number is worse than an honest qualitative rating. We are explicit about which is which, because a board that discovers a figure was invented stops trusting the whole register.
Related reading
-
Board and Executive Reporting
Preparing a Board-Level Cybersecurity Update
Directors need four things from a cyber update: what could materially hurt the organization, what is being done about it, what obligations apply, and what they are being asked to decide. Most updates deliver activity instead.
Related services
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
- Vendor, MSP and Third-Party Oversight Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
Talk through Cyber Risk Management with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.