At a glance
- Part of
- The decisions, records and oversight that turn security activity into something leadership can direct.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
Why this comes up
Managed service providers, managed security providers and software vendors carry out real and necessary security work, usually competently. Problems arise from unstated boundaries rather than from capability: both sides assume the other is handling patch exceptions, log retention, offboarding or alert triage.
The gap is invisible until a questionnaire asks who is responsible, or an incident makes it obvious that nobody was.
The service
What this engagement is
Who it is for
- Organizations relying on several providers with overlapping or unclear responsibilities.
- Companies where nobody internally reviews the security reporting providers send.
- Businesses whose customers now ask how third-party risk is managed.
- Leadership teams renewing, replacing or expanding a significant provider relationship.
Client-side governance of provider relationships. This is not an audit of your providers and it is not an attempt to displace them, it is the counterpart function that lets them do their job well, because expectations, evidence requirements and acceptance criteria are stated rather than assumed.
It covers the relationships you already have and the process for the ones you take on next, scaled to the access and data involved rather than applied uniformly to every supplier.
Scope
What Heights does
-
Responsibility mapping
A written split of security responsibilities between your organization and each provider, agreed by both sides rather than inferred from a contract.
-
Contract and service-level review
What existing agreements genuinely commit each provider to, including notification duties, evidence obligations and retention terms.
-
Evidence and reporting expectations
What each provider reports, how often, and in what form, so performance can be assessed rather than assumed.
-
Proportionate vendor assessment
An intake and reassessment process for new and existing vendors, scaled to the access and data each one has.
-
Recurring service review
A regular review with providers, chaired on your side, with actions tracked to closure.
Timing
When organizations engage this
- Several providers are involved and the responsibility boundaries between them are unclear.
- Nobody on your side reviews the security reporting providers send.
- A customer questionnaire or an audit asked how third-party risk is managed.
- A provider relationship is coming up for renewal, replacement or expansion.
- An incident or service failure exposed an assumption that turned out to be wrong.
What you receive
- Responsibility assignment matrix covering internal teams and every provider
- Vendor inventory with risk tiering
- Provider reporting and evidence requirements
- Recurring service review agenda with action tracking
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
How this fits under vCISO leadership
This is where a vCISO is most often the missing piece. Providers execute; somebody accountable to your leadership has to set the expectation, review what arrives, and escalate when the service is not meeting it. That role is the vCISO's.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Will this damage our relationship with our MSP?
In our experience it improves it. Most friction between organizations and their providers comes from unstated expectations, and providers generally welcome a client who states clearly what is wanted and reviews what is delivered.
The work is about defining the boundary, not challenging competence. Where a provider is doing something well, that gets recorded too.
How many vendors should we be assessing?
Far fewer than the total number you have contracts with. Assessment effort should follow access and data: a provider with administrative access to core systems warrants real scrutiny; a supplier with no access to your data warrants very little.
Tiering the inventory first is usually what makes the program sustainable.
What if a provider will not supply the evidence we ask for?
That is itself useful information, and it is a decision for leadership rather than a technical impasse. Sometimes the request is disproportionate and should be reduced; sometimes the provider genuinely cannot evidence something material.
Either way it becomes a documented risk with an owner, rather than an unresolved email thread.
Related services
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
Talk through Vendor, MSP and Third-Party Oversight with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.