At a glance
- Part of
- Ownership of the security program: what it should achieve, in what order, and who answers for it.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations that have never established a documented security baseline.
- Leadership teams that have inherited a program and need to know what they actually have.
- Companies where security spending has grown without a coherent picture of coverage.
- Boards or investors asking for an independent view of the program.
A structured review of the security program as it actually operates, not as documentation describes it. Findings are validated with the people who run the environment, internal IT, outside providers, the staff who handle exceptions, rather than inferred from a document review.
The output is a baseline you can measure against later, a gap list ranked by what it would cost the organization to get wrong, and a roadmap sequenced against real constraints: budget cycles, capacity, contractual dates.
Scope
What Heights does
-
Framework-based current state
Your program is assessed against a framework appropriate to your obligations, commonly the NIST Cybersecurity Framework, NIST SP 800-171, or the trust services criteria behind SOC 2.
-
Control and coverage review
Existing controls are reviewed for what they genuinely cover, who operates them, and how their effectiveness is evidenced.
-
Interviews with the people who run it
Findings are validated with IT leadership, operations staff and outside providers, because the gap between documented and actual practice is usually where the risk sits.
-
Prioritized gap analysis
Gaps are ranked by business risk and regulatory exposure rather than by control number order, so leadership can see what genuinely matters first.
-
Roadmap and sequencing
A phased plan with owners, dependencies and a realistic order of work, discussed with leadership before it is adopted.
Why this comes up
Most organizations have more security capability than they can describe and less coverage than they assume. Tools were bought at different times for different reasons, policies were written to satisfy an audit, and responsibility is spread across an internal IT team, an outside provider and a handful of software vendors.
The result is not usually negligence. It is that nobody has ever assembled the whole picture in one place, so questions like "are we covered for that?" get answered by whoever is in the room rather than by evidence.
Timing
When organizations engage this
- A customer, insurer or investor has asked how the security program is governed.
- A new regulatory or contractual obligation applies and nobody can confirm where you stand.
- Leadership has changed and needs an accurate baseline rather than an inherited assumption.
- Security spending has grown steadily without a corresponding picture of coverage.
- A previous assessment produced findings that were never closed, and nobody knows which still apply.
What you receive
- Current-state assessment report mapped to the selected framework
- Prioritized gap register with a business-risk rating for each item
- Phased remediation roadmap with owners, dependencies and sequencing
- Executive summary written for a non-technical audience
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
How this fits under vCISO leadership
An assessment is normally the opening phase of a vCISO engagement. On its own it produces an accurate plan. Under ongoing vCISO leadership that plan is owned, sequenced against the business calendar, and reported on until the work is finished.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
How long does an assessment take?
For most mid-sized organizations the discovery and assessment phase runs about thirty days, with the strategy and roadmap taking shape over the following weeks. Complexity, the number of outside providers involved and how much documentation already exists all move that.
The timeline is agreed at scoping so it fits around your operating calendar rather than interrupting it.
Which framework should we be assessed against?
That depends on what you are obliged to do. If a customer contract names SOC 2, or federal work brings NIST SP 800-171 and CMMC into scope, the choice is made for you.
Where nothing is mandated, the NIST Cybersecurity Framework is usually the most useful starting point: it is widely understood, it maps reasonably onto other requirements, and it produces a baseline you can measure movement against.
Will this disrupt our IT team?
The demand on internal staff is mostly interviews and document requests, scheduled in advance. We work around operational commitments rather than through them.
Where an outside provider holds part of the picture, we go to them directly rather than routing every question through your team.
What happens if the findings are worse than expected?
That is a normal outcome and it is better discovered here than during an audit or an incident. The report says what is true, and the roadmap sequences the response so the most consequential gaps are addressed first.
An accurate baseline is more useful than a flattering one, particularly if you will later have to describe your position to a customer, an insurer or a regulator.
Related reading
-
vCISO Leadership
What a vCISO Is Responsible For, and What It Does Not Replace
A vCISO carries the accountability for a security program: strategy, risk decisions, governance, regulatory position and reporting. Understanding where that responsibility starts and stops is what makes the arrangement work alongside an IT team or a managed provider.
Related services
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
- Vendor, MSP and Third-Party Oversight Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.
Talk through Security Program Assessment with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.