Heights Consulting Group

Managed IT Services (MSP)

Managed IT services are the running and support of your technology environment, helpdesk, endpoints, identity administration, patching, backup and cloud administration, delivered by Heights under the same governance and reporting the security program already uses, so operations and security are directed by one owner rather than reconciled after the fact.

What you receive

Part of
Security operations and the running of the technology itself, delivered continuously under the program's governance.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

Timing

When organizations engage this

  • The person who ran IT has left, and the knowledge left with them.
  • Security findings are agreed but never scheduled, because the operational calendar belongs to someone else.
  • Backups have never been restored to prove they work.
  • Growth has outpaced a part-time or founder-run IT arrangement.
  • An insurer, customer or regulator is asking for patching and access evidence nobody can produce.

What you receive

  • A written service scope with response commitments and the division of responsibility
  • Managed, protected and patched endpoints with a maintained inventory
  • Restoration evidence for backups on the agreed cadence
  • Monthly operational reporting aligned with the security program's reporting

The problem

Why this comes up

In most organizations the people who run the technology and the people who set security direction are different parties, and the gap between them is where work falls. A patch window is agreed and never scheduled; a departed employee keeps an account for a month; a backup runs but is never restored to prove it works.

None of that is a failure of skill. It is a failure of ownership: nobody holds both the operational calendar and the security priorities, so each is negotiated against the other one ticket at a time.

The service

What this engagement is

Who it is for

  • Organizations without an internal IT function, or with one person carrying it alone.
  • Companies whose security program keeps stalling on operational work nobody owns.
  • Businesses consolidating several providers into one accountable relationship.
  • Leadership teams that want operational reporting they can read beside their security reporting.

A managed IT service run by Heights: the helpdesk, the endpoint estate, user and identity administration, patching and update cadence, backup and restoration, and the administration of the cloud services the business runs on.

What sets it apart is what it reports to. The operational work is planned against the security program, the same priorities, the same risk register, the same executive reporting, so a decision made at the leadership table is carried out on the endpoints without a handoff between providers.

Scope

What Heights does

  • Helpdesk and user support

    A single place for staff to get help, with response commitments agreed in writing and reported against.

  • Endpoint management

    Provisioning, configuration baselines, encryption and protection across laptops, desktops and mobile devices.

  • Identity and account administration

    Accounts created, changed and removed on the timelines the security program sets, with multi-factor authentication enforced where policy requires it.

  • Patching and update cadence

    Operating system and application updates on a schedule that matches the risk priorities, with exceptions recorded rather than forgotten.

  • Backup and restoration

    Backups that are tested by restoring them, on a cadence that matches what the business can afford to lose.

  • Cloud and productivity administration

    Administration of the email, collaboration and cloud services the business runs on, configured to the security baseline.

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.

The flagship

Managed IT keeps the environment running. The vCISO decides what the environment must achieve, sets the priorities the operational calendar follows, and answers to leadership for whether the whole holds together. Under one roof, the two never have to be reconciled.

Read about vCISO leadership

First steps

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

FAQ

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

Can Heights run our IT and also act as our vCISO?

Yes, and the combination is deliberate. The vCISO sets direction and answers for the program; the managed IT service carries it out. The scope of each is written down separately, so leadership can see what was decided and what was done.

Where an organization prefers an independent check on its operations, the vCISO engagement can also stand alone and oversee a different provider. Either arrangement works; what matters is that the boundary is explicit.

We already have an IT provider we like. Is this still relevant?

Then keep them. A provider that is performing well is an asset, and Heights works alongside existing providers in most engagements.

This service is for organizations that have no IT function, are losing one, or want operations and security under a single accountable owner. The vendor and third-party oversight work covers the case where the provider stays and the governance improves.

What does the helpdesk cover, and what does it not?

It covers the systems and users named in the service scope: the accounts, devices and cloud services Heights administers. What it does not cover is written in the same document, so nobody discovers a gap during an outage.

Custom line-of-business applications, specialist equipment and vendor-supported platforms are addressed case by case and recorded in the scope before the service starts.

How is a transition from our current setup handled?

It begins with an inventory: every account, device, service and credential, and who holds each. Nothing is switched until the inventory is complete and the division of responsibility is agreed.

Transitions are sequenced so that no system is between owners. The outgoing arrangement is released only once Heights has demonstrated it can operate each part.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.