At a glance
- Part of
- Preparedness for what goes wrong, and governance for what is arriving.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations whose response plan has never been tested with the people named in it.
- Companies where it is unclear who has authority to declare an incident or notify customers.
- Businesses whose customer contracts or insurers require evidence of incident readiness.
- Leadership teams that have recently experienced an incident or a near miss.
A plan written so it can be followed under pressure, short, specific about roles, and explicit about who decides what, combined with an exercise that tests it against the people it names.
The notification analysis is often the most valuable component. Regulatory and contractual deadlines vary by sector, data type and jurisdiction, and identifying them while the clock is not running is materially easier than doing so while it is.
Scope
What Heights does
-
Incident response plan
Roles, declaration criteria, severity levels and escalation paths, written to be usable under pressure rather than comprehensive on paper.
-
Decision and disclosure authority
Who decides on containment, on engaging outside counsel and forensics, on customer communication and on regulatory notification.
-
Notification obligations
The regulatory and contractual notification duties and deadlines that apply to your organization, identified before they are running.
-
Tabletop exercises
Scenario-based exercises with the executive team and IT, run against the plan exactly as written.
-
Post-exercise remediation
Findings fed back into the plan, the contact lists, the contracts and the controls, the step most often skipped.
Why this comes up
The technical parts of incident response are usually the parts organizations have partly covered. The gaps are decision authority, notification obligations, legal and communications coordination, and the fact that the plan has often never been read by the people it names.
Those gaps only become visible under pressure, when the cost of resolving them is highest and the time available is shortest.
Timing
When organizations engage this
- The response plan has never been tested with the executives it names.
- A customer contract or insurer requires evidence of incident readiness.
- It is unclear who has authority to declare an incident or notify customers and regulators.
- A recent incident or near miss exposed coordination problems.
- The people named in the plan have changed roles or left the organization.
What you receive
- Incident response plan with roles, severity levels and escalation criteria
- Notification obligation summary and current contact list
- Tabletop exercise scenario and a facilitated session
- Exercise findings report with tracked remediation actions
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
How this fits under vCISO leadership
A vCISO keeps readiness current as the organization changes, new systems, new obligations, new people in the roles the plan names, and coordinates leadership if an incident actually occurs.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Who should take part in a tabletop exercise?
The people the plan actually names. That usually means the chief executive or an equivalent decision maker, IT leadership, legal or general counsel, communications, and whoever manages key customer relationships.
An exercise run only with the technical team tests the technical response and leaves the decision-making gaps, which are the ones that most often extend an incident, untested.
Does Heights respond to a live incident?
Under a vCISO engagement, Heights coordinates the leadership response: convening the right people, tracking decisions, managing notification obligations and handling executive and board communication.
Digital forensics and specialist incident response are separate disciplines, and part of readiness work is identifying which firm you would engage and establishing the relationship before you need it.
How often should the plan be exercised?
Annually is a reasonable baseline for most organizations, with an additional exercise after a significant change, a new core system, a merger, or turnover in the roles the plan names.
A plan naming people who left eighteen months ago is not a plan.
Related services
- AI and Emerging Technology Governance Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
Talk through Incident Readiness and Response Planning with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.