At a glance
- Part of
- The decisions, records and oversight that turn security activity into something leadership can direct.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
Why this comes up
Downloaded policy templates create a documented gap between what an organization says it does and what it does. That gap is the first thing an assessor finds, and the last thing anyone wants to explain after an incident.
The second failure is quieter. Policies exist, are technically accurate, and nobody outside the IT team has read them, so the behaviors they describe never actually change.
The service
What this engagement is
Who it is for
- Organizations whose policies were inherited, downloaded or written for a single audit.
- Companies where an assessment identified missing, unapproved or unenforced policies.
- Leadership teams that want a briefing built around governance decisions rather than a technical presentation.
- Organizations whose staff have no consistent guidance for handling sensitive data or suspected incidents.
Policy work that starts from current operating reality and closes the distance to the intended state deliberately, rather than declaring a target state and hoping practice catches up.
Alongside the documents, the governance that keeps them alive: who approves, how often they are reviewed, how an exception is requested and recorded, and who decides when a policy meets an operational reality nobody anticipated.
Awareness work is scoped by role. The judgment an executive needs about disclosure and escalation is not the judgment a billing clerk needs about handling a suspicious email.
Scope
What Heights does
-
A policy set scoped to your organization
A library sized to the organization and its obligations, rather than a generic enterprise set nobody will maintain.
-
Standards and procedures
The operational detail beneath each policy, so a requirement can be followed in practice and evidenced afterwards.
-
Review, approval and version control
Who approves, how often policies are reviewed, and how changes are tracked, the trail an assessor asks for.
-
Exception handling
A route for the cases a policy did not anticipate, so exceptions are recorded and time-bounded rather than becoming undocumented practice.
-
Executive and board briefings
Sessions built around the decisions leadership makes: oversight, funding, disclosure and escalation.
-
Workforce awareness programs
Role-relevant training covering the scenarios each group is most likely to encounter, with oversight of completion and follow-up.
Timing
When organizations engage this
- Policies exist but do not describe how the organization actually operates.
- An assessment or audit identified missing or unapproved policies.
- A customer contract or framework requires a documented, approved policy set.
- Staff have no consistent guidance for handling sensitive data or reporting a suspected incident.
- The executive team has asked for a briefing suited to the decisions they actually make.
What you receive
- Approved policy set with version control and a review schedule
- Supporting standards and procedures
- Policy exception process and exception register
- Executive briefing materials and a workforce training plan
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
How this fits under vCISO leadership
A vCISO owns the policy lifecycle rather than just its creation: annual review, exception decisions, and the judgment calls that arise when a written rule meets an operational reality nobody anticipated.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
How many policies do we actually need?
Fewer than most template sets suggest. The right number is the smallest set that covers your obligations and that you will genuinely maintain, typically somewhere between eight and twenty documents for a mid-sized organization.
A library of sixty unmaintained policies is worse than a dozen accurate ones, because it creates documented commitments the organization is demonstrably not meeting.
Can you use policies we already have?
Usually, yes. Existing policies often need reworking rather than replacing, most commonly to reflect how the organization actually operates, to add the supporting standards that make them actionable, and to establish approval and review that has never been formalised.
How do we know whether awareness training is working?
Completion rates tell you very little on their own. More useful signals are whether staff report suspected incidents, whether reports arrive early enough to matter, and whether the same category of mistake keeps recurring.
We set out what will be measured before the program starts, so it is not judged retrospectively on whichever number looks best.
Related services
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Vendor, MSP and Third-Party Oversight Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
Talk through Security Policy, Standards and Awareness with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.