Managed IT Services (MSP)
Managed IT services are the running and support of your technology environment, helpdesk, endpoints, identity administration, patching, backup and cloud administration, delivered by Heights under the same governance and reporting the security program already uses, so operations and security are directed by one owner rather than reconciled after the fact.
- Part of
- Security operations and the running of the technology itself, delivered continuously under the program's governance.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
Timing
When organizations engage this
- The person who ran IT has left, and the knowledge left with them.
- Security findings are agreed but never scheduled, because the operational calendar belongs to someone else.
- Backups have never been restored to prove they work.
- Growth has outpaced a part-time or founder-run IT arrangement.
- An insurer, customer or regulator is asking for patching and access evidence nobody can produce.
What you receive
- A written service scope with response commitments and the division of responsibility
- Managed, protected and patched endpoints with a maintained inventory
- Restoration evidence for backups on the agreed cadence
- Monthly operational reporting aligned with the security program's reporting
The problem
Why this comes up
In most organizations the people who run the technology and the people who set security direction are different parties, and the gap between them is where work falls. A patch window is agreed and never scheduled; a departed employee keeps an account for a month; a backup runs but is never restored to prove it works.
None of that is a failure of skill. It is a failure of ownership: nobody holds both the operational calendar and the security priorities, so each is negotiated against the other one ticket at a time.
The service
What this engagement is
Who it is for
- Organizations without an internal IT function, or with one person carrying it alone.
- Companies whose security program keeps stalling on operational work nobody owns.
- Businesses consolidating several providers into one accountable relationship.
- Leadership teams that want operational reporting they can read beside their security reporting.
A managed IT service run by Heights: the helpdesk, the endpoint estate, user and identity administration, patching and update cadence, backup and restoration, and the administration of the cloud services the business runs on.
What sets it apart is what it reports to. The operational work is planned against the security program, the same priorities, the same risk register, the same executive reporting, so a decision made at the leadership table is carried out on the endpoints without a handoff between providers.
Scope
What Heights does
-
Helpdesk and user support
A single place for staff to get help, with response commitments agreed in writing and reported against.
-
Endpoint management
Provisioning, configuration baselines, encryption and protection across laptops, desktops and mobile devices.
-
Identity and account administration
Accounts created, changed and removed on the timelines the security program sets, with multi-factor authentication enforced where policy requires it.
-
Patching and update cadence
Operating system and application updates on a schedule that matches the risk priorities, with exceptions recorded rather than forgotten.
-
Backup and restoration
Backups that are tested by restoring them, on a cadence that matches what the business can afford to lose.
-
Cloud and productivity administration
Administration of the email, collaboration and cloud services the business runs on, configured to the security baseline.
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
The flagship
How this fits under vCISO leadership
Managed IT keeps the environment running. The vCISO decides what the environment must achieve, sets the priorities the operational calendar follows, and answers to leadership for whether the whole holds together. Under one roof, the two never have to be reconciled.
Sectors
Where this comes up most
- Legal and Professional Services Confidentiality duties owed to every client, ethics rules that now speak directly to technology, and corporate clients who audit their law and accounting firms the way they audit any other vendor.
- Manufacturing and Industrial Production environments where downtime is measured in dollars per minute, plant systems that outlive their software support, and customers pushing security requirements down the supply chain.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Education Student records protected by federal law, financial-aid data that brings banking-grade obligations onto campus, open networks by mission, and a sector ransomware operators treat as a soft target.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Can Heights run our IT and also act as our vCISO?
Yes, and the combination is deliberate. The vCISO sets direction and answers for the program; the managed IT service carries it out. The scope of each is written down separately, so leadership can see what was decided and what was done.
Where an organization prefers an independent check on its operations, the vCISO engagement can also stand alone and oversee a different provider. Either arrangement works; what matters is that the boundary is explicit.
We already have an IT provider we like. Is this still relevant?
Then keep them. A provider that is performing well is an asset, and Heights works alongside existing providers in most engagements.
This service is for organizations that have no IT function, are losing one, or want operations and security under a single accountable owner. The vendor and third-party oversight work covers the case where the provider stays and the governance improves.
What does the helpdesk cover, and what does it not?
It covers the systems and users named in the service scope: the accounts, devices and cloud services Heights administers. What it does not cover is written in the same document, so nobody discovers a gap during an outage.
Custom line-of-business applications, specialist equipment and vendor-supported platforms are addressed case by case and recorded in the scope before the service starts.
How is a transition from our current setup handled?
It begins with an inventory: every account, device, service and credential, and who holds each. Nothing is switched until the inventory is complete and the division of responsibility is agreed.
Transitions are sequenced so that no system is between owners. The outgoing arrangement is released only once Heights has demonstrated it can operate each part.
Portfolio
Related services
- Managed Security Services (MSSP) Continuous monitoring, detection and response, and vulnerability management, run against priorities the security strategy has already set.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Penetration Testing and Vulnerability Assessment Authorized testing of your networks, applications and cloud environments, reported as findings ranked by what an attacker could actually do with them.