Flagship engagement

Executive ownership of your cybersecurity program

A Heights vCISO provides the strategy, governance, risk leadership, regulatory direction and executive reporting that turn separate security efforts into one accountable program.

Schedule a Confidential Consultation What an engagement delivers

What the engagement is

Engagement type
Ongoing executive leadership, scoped in writing and reviewed as the program matures.
Works alongside
Your internal IT team, your MSP and your existing providers.
Reports to
Chief executives, boards, general counsel and compliance leadership.

What a vCISO is

A virtual Chief Information Security Officer, vCISO, is an experienced security executive who holds the CISO responsibilities for your organization on an ongoing basis without being a full-time employee: the strategy, the risk decisions, the governance, the regulatory position and the reporting to leadership.

The responsibilities it carries

The term is used loosely

The term is used loosely across the market, which makes offers hard to compare. Some firms use it for an extended assessment. Others use it for a monthly report generated from a scanning tool, or for a technician who attends a quarterly meeting.

What the role actually has to be

The version that solves the problem executives actually have is narrower and more demanding. It is not a deliverable, a checklist, a tool bundle, technical support, or a part-time administrator, and it is not a replacement for a managed service provider. It is accountability: somebody whose job is to decide what the organization should be doing about security, in what order, with what trade-offs, and to answer for that judgment when the board asks.

How Heights provides it

Heights provides that role. We work inside your leadership structure on a defined scope of responsibility, agreed in writing at the start of the engagement and reviewed as the program matures.

Why capable organizations still lack security ownership

Most organizations that need a vCISO already have IT staff, service providers, security tools and a policy document. What they do not have is a single person accountable for whether all of it adds up to an adequate program.

What usually prompts the call

It is structural, not a performance problem

This is a structural gap rather than a performance problem. An IT team is measured on availability and delivery. A managed service provider is measured against its contracted scope. A software vendor is responsible for its own product. Each of them is doing what they were engaged to do.

How the gap shows up

  • Security priorities change depending on who was in the last meeting.
  • Two providers each assume the other is handling something material.
  • A questionnaire answer is given by whoever is available, and nobody checks it against reality.
  • A risk is accepted informally, and six months later nobody can say who accepted it.
  • Budget is approved for tools without an agreed view of what problem they solve.
  • The board receives technical metrics and cannot tell from them whether the organization is in good shape.

What answering them requires

Those questions require someone with a view across the whole picture and the standing to make a call. When nobody holds that position, the decisions still get made, but they get made implicitly, by whoever happens to be closest to the problem, and nothing records why.

What the vCISO owns

Thirteen responsibilities, held by Heights inside your leadership structure. Strategy is the anchor; the rest follow from it.

Cybersecurity strategy

Deciding what the security program should achieve, over what horizon, and in what order, informed by the organization's obligations, risk profile and capacity to absorb change.

Security governance

Establishing where security decisions are made, who is entitled to make them, and how they are recorded, then running that forum.

Risk-based priorities

Maintaining a risk picture leadership can act on, and bringing accept, reduce or transfer decisions to the people with authority over the affected part of the business.

Policies and standards

Owning the policy lifecycle: approval, review, exception handling, and the judgment calls when a written rule meets an unanticipated operational reality.

Regulatory readiness

Knowing which obligations apply, keeping the evidence current between assessment cycles, and answering customer and auditor questions consistently.

Executive accountability

Being the person who answers for whether the program is adequate, rather than the person who reports what was done.

Board-level reporting

Translating the state of the program into the language directors use: exposure, obligation, progress, and the decisions being requested of them.

Security roadmaps

Maintaining a sequenced plan with owners and dependencies, and keeping it honest as circumstances change.

Incident readiness

Keeping the response plan usable and tested, and coordinating executive decision-making if an incident occurs.

Third-party risk

Assessing and re-assessing the vendors and partners whose access or data handling creates exposure for the organization.

MSP and vendor oversight

Setting expectations for providers, reviewing what they deliver against those expectations, and escalating when the service is not meeting them.

Security-awareness oversight

Directing the awareness program, what each group is trained on, how it is measured, and what happens when the same issue keeps recurring.

Continuous program improvement

Reassessing against the baseline, adjusting as the business and its obligations change, and demonstrating movement over time.

Which organizations need one

The common factor is a real security obligation with no CISO-level owner, not a particular size, sector or budget.

Fits well

  • Regulated or contractually obligated organizations without a full-time CISO.
  • Companies whose customers assess their security before signing.
  • Businesses that have grown faster than their security program.
  • Organizations where a board or audit committee has begun asking harder questions.
  • Firms with capable IT teams or providers and nobody setting security direction.
  • Organizations that could justify a full-time CISO eventually, but not yet.
  • Companies between security leaders who need continuity rather than a pause.

The wrong answer when

  • Organizations wanting somebody to operate tools day to day, that is an operational role, not an executive one.
  • Companies whose security workload is genuinely continuous and full-time; at that point an internal hire is the better answer.
  • Situations where leadership does not want the answers a security executive would surface. The role only works with genuine access and a willingness to act on what it finds.

What usually prompts the call

Most engagements begin with one of these. Several are usually true at once.

Discuss your situation

Audit findings

An audit or assessment produced findings that need owning and closing, not just recording.

Customer questionnaires

Security questionnaires arrive with deals and the answers have to be accurate, consistent and defensible.

Regulatory requirements

A regime applies, or newly applies, and somebody has to determine what it demands and where you stand against it.

Cyber-insurance requirements

An application or renewal asks detailed control questions, and the answers affect both coverage and price.

Board concerns

Directors have asked about cyber exposure and the current reporting does not let them answer their own question.

A security incident

Something happened, and the response exposed gaps in ownership, escalation or decision authority.

Rapid growth

Headcount, systems, data and third parties have all increased, and practices that worked at the previous size no longer hold.

New enterprise customers

A larger customer brings security terms, audit rights and expectations that the organization has not previously had to meet.

Mergers and acquisitions

Diligence is under way in either direction, and the security position has to be described accurately or assessed properly.

Leadership transitions

A security or technology leader has left and the responsibility currently has no home.

No formal security ownership

Nothing is on fire, but nobody owns the program, and leadership has recognized that this is itself the risk.

What Heights delivers

Artifacts and processes your organization owns, and would keep if the engagement ended tomorrow.

Talk through what you would need first

Understanding where you stand

Current-state assessment
A documented baseline against a chosen framework, with the evidence behind it.
Risk register
Risks in business terms, consistently rated, with named owners and recorded treatment decisions.
Program metrics
A small set of measures that show whether the program is improving, reported the same way each period.

Direction

Cybersecurity strategy
A stated direction for the program, tied to what the business is trying to do and what it must protect.
Prioritized roadmap
A phased plan with owners, dependencies and a defensible order of work.
Governance structure
A decision forum, defined authority, and a record of what was decided and why.

The written program

Policy development and maintenance
An approved, version-controlled policy set with a review schedule and an exception process.
Regulatory-readiness planning
Applicability analysis, control mapping and a maintained evidence base.
Incident-response planning
A tested plan with roles, escalation criteria and notification obligations identified in advance.

Oversight and communication

Executive reporting
Regular reporting to the leadership team, framed around decisions rather than activity.
Board reporting
A repeatable board format plus the history that shows movement between meetings.
Third-party oversight
Responsibility mapping, vendor tiering, and reporting expectations for each provider.
MSP and vendor coordination
Expectations set with providers, their output reviewed, and escalation when the service falls short.
Security-awareness oversight
Direction of the awareness program and follow-up on what it reveals.
Ongoing advisory leadership
Availability between the set pieces: architecture decisions, questionnaires, vendor selection, incidents.

How an engagement runs

Engagements begin with a confidential conversation and a written scope, move through an assessment and roadmap phase, and then settle into an operating rhythm of working sessions and scheduled reporting.

  1. No cost, no obligation

    A confidential conversation

    What is prompting the discussion, what the organization is obliged to do, and what leadership is being asked to answer for. If we are not the right firm for what you need, we will say so.

  2. Agreed in writing

    Defining the responsibilities we will hold

    Which responsibilities sit with Heights and which stay with you, the working rhythm, who we will work with internally, and how progress will be reported. Written down, so nothing important rests on assumption.

  3. Typically the first 30 days

    Discovery and assessment

    A structured review of the current security posture, business objectives, compliance requirements and risk tolerance, established with the people who run the environment, not from documentation alone.

  4. Typically around 60 days

    Strategy and roadmap development

    The findings become a strategy and a prioritized roadmap, discussed with leadership before adoption so the sequence reflects real constraints, budget cycles, capacity and contractual dates.

  5. From roughly 90 days onward

    Implementation and ongoing oversight

    Work carried out by your team, your providers or Heights, with expectations and acceptance criteria stated up front. Regular working sessions, scheduled reporting, and reassessment against the baseline as conditions change.

Timeframes above are indicative of how engagements typically run rather than contractual commitments. Scope and rhythm are agreed for each organization and reviewed as the program matures.

vCISO or a full-time CISO

Neither arrangement is universally better. The right choice depends on how much sustained security work the organization genuinely has, and how much internal authority the role needs to carry.

A common and healthy outcome is that an organization outgrows the arrangement. A vCISO engagement is designed to leave behind a documented program, strategy, governance, risk register, policies, evidence and reporting history, that an incoming CISO can take ownership of directly. Heights can also support that transition, including scoping the role.

vCISO

Full-time internal CISO

Organizational need

Fits when the security workload is real but intermittent, obligations, assessments, decisions and reporting rather than continuous internal demand.

Fits when security work is continuous and large enough to occupy a senior executive full time.

Scope

A defined scope of responsibility agreed in writing, focused on strategy, governance, risk and reporting.

Open-ended executive scope, typically including team building, budget ownership and organizational management.

Availability

Present on an agreed rhythm with escalation for urgent matters. Not embedded in day-to-day operations.

Present continuously, able to respond to informal signals and corridor conversations that a scheduled engagement will miss.

Internal authority

Authority is delegated and depends on visible executive backing. Works well where leadership genuinely stands behind the role.

Positional authority as an officer of the organization, with the standing that carries in internal negotiation.

Flexibility

Scope can expand or contract as the program matures, and the engagement can end cleanly when it is no longer the right shape.

A permanent hire; changing the arrangement means an organizational change.

Stage of program development

Strongest where a program is being established or rebuilt, and where breadth of experience across many organizations is more valuable than depth in one.

Strongest where a program is established and the work has shifted to running, scaling and leading a security function.

How a vCISO works alongside the people you already have

None of these relationships is a replacement. Each gains a clear specification and somebody who reviews what is delivered.

The vCISO coordinates between the board and executives, internal IT, managed service providers and third-party vendors. It replaces none of them; it gives each a clear specification and reviews what is delivered.

Board and executives

Receive exposure, obligation, progress and the decisions being asked of them, in one consistent format.

Board reporting

Heights vCISO

Sets direction, owns the risk picture, reviews what is delivered, and answers for whether the program is adequate.

Internal IT

Keeps running the environment. Gains a clear specification, an agreed order of work and executive backing for trade-offs.

How this works

MSP and technical providers

Keep delivering their contracted scope. Gain stated expectations, defined evidence and a client-side counterpart who reviews it.

Provider oversight

Vendors and third parties

Assessed proportionately to the access and data involved, with responsibilities mapped in writing on both sides.

Third-party risk

With your internal IT team

A vCISO gives internal technology leaders a clear specification, an agreed order of work, and executive air cover for the decisions that follow, it does not take over their function.

In practice this makes IT's job easier in three specific ways. Priorities stop shifting with whoever asked last. Requests for budget arrive with a risk rationale attached rather than a technical one. And when a trade-off has to be made between security and delivery, somebody at executive level makes the call and records it, rather than leaving it to be absorbed quietly by the team.

With your MSP or technical provider

A vCISO provides the client-side governance that lets a managed provider do its job well: independent priorities, stated evidence requirements, review of what is delivered, and executive communication.

A vCISO occupies that position. Responsibilities are mapped and agreed by both sides. Reporting expectations are defined. Provider output is reviewed by somebody accountable to your leadership, and escalated when it does not meet the expectation. Where the provider is doing something well, that is recorded too.

How we structure provider oversight

Frameworks and regulations we work to

Which of these applies is one of the first questions an engagement answers. Descriptions are of the published requirements, not claims about outcomes.

How we approach regulatory readiness

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
PCI DSS
Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
SOX
Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
HITRUST
A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence.

The work a roadmap calls for

Delivered by Heights, or by your team and providers under the same specification.

The complete services portfolio

Risk and governance

The decisions, records and oversight that turn security activity into something leadership can direct.

Compliance and regulatory readiness

Knowing which obligations apply, and being able to evidence them when somebody asks.

Security architecture and operations

The design and running of the controls a strategy depends on.

Resilience and emerging technology

Preparedness for what goes wrong, and governance for what is arriving.

Frequently asked questions

If your question is not here, ask it directly. We will answer plainly, including when the answer is that you do not need what you came to ask about.

Maintained by Dr. Daniel Glauber.

What does a vCISO do?

A vCISO holds the executive responsibilities for an organization's security program: setting the strategy, owning the risk picture, running security governance, maintaining the policy set, keeping the regulatory position defensible, overseeing providers, and reporting to executives and the board.

The defining characteristic is accountability over time rather than the depth of any single deliverable. A consultant produces a report and leaves; a vCISO owns what happens next.

Does a vCISO replace our IT team?

No. Your IT team continues to run the environment, systems, identity, change management, availability and support.

What changes is that the security requirements they work to become explicit rather than implied, priorities stop shifting between meetings, and trade-offs between security and delivery are decided at executive level rather than absorbed quietly by the team.

Does a vCISO replace our MSP?

No. A managed service provider operates and supports the environment under a contracted scope. A vCISO works on your side of that relationship: defining what is expected, reviewing what is delivered, and escalating when the two do not match.

The two roles are complementary. Provider work generally becomes easier and more effective when the client has somebody senior enough to specify what is wanted and to assess what arrives.

How involved is a vCISO?

Engagements are structured around a defined scope of responsibility and a working rhythm, regular sessions with IT and leadership, plus scheduled executive and board reporting, rather than a fixed number of hours.

Between those sessions the vCISO remains available for the things that do not wait: a customer questionnaire, an architecture decision, a vendor issue or an incident. The scope is agreed in writing at the start and reviewed as the program matures.

Can a vCISO communicate with executives and the board?

Yes, that is a core part of the role rather than an add-on. Reporting is built for a governance audience: material exposures, progress against an agreed plan, applicable obligations, and the specific decisions leadership is being asked to take.

The format stays consistent between meetings, because directors build their judgment from the change between periods rather than from any single report.

Can a vCISO help with security questionnaires?

Yes, and this is one of the fastest returns for technology and service companies. Questionnaire answers are representations that become contractual commitments, so they need to be accurate, consistent between customers, and defensible later.

The practical approach is a maintained set of canonical answers with named owners, which turns each new questionnaire from a research exercise into a review.

Can a vCISO help prepare for audits and assessments?

Yes. Preparing for assessments, coordinating evidence and handling assessor findings are ordinary parts of the role.

Heights prepares organizations for assessment; it does not perform the audit, examination or certification itself. That separation is deliberate, an adviser assessing their own work would not produce a credible result.

How does an engagement begin?

With a confidential conversation about what is prompting the enquiry, what the organization is obliged to do, and what leadership is being asked to answer for. There is no cost or obligation attached to it.

If it makes sense to continue, scope is agreed in writing, and the engagement opens with a discovery and assessment phase that typically runs about thirty days.

What information do we need to get started?

For the first conversation, nothing prepared. What helps is knowing what triggered the enquiry, which obligations you are working to, roughly what is in place today, and who currently makes security decisions.

Detailed material, policies, previous assessments, provider contracts, system inventories, is gathered during discovery, and we work with whatever exists rather than requiring it to be assembled in advance.

Is this appropriate for an organization without a formal security program?

Yes, and that is one of the most common starting points. Organizations without a formal program are usually not starting from nothing, they have controls, tools and practices that were never assembled into a coherent whole.

The first phase establishes what genuinely exists, which is almost always more than leadership expects in some areas and less in others.

More on the role

  • Board and Executive Reporting

    Preparing a Board-Level Cybersecurity Update

    Directors need four things from a cyber update: what could materially hurt the organization, what is being done about it, what obligations apply, and what they are being asked to decide. Most updates deliver activity instead.

  • Governance

    Answering Customer Security Questionnaires Without Slowing Down Sales

    Security questionnaires arrive with enterprise deals and the answers become contractual representations. Treating them as a sales task produces inconsistency; treating them as a governance task produces answers you can stand behind and reuse.

Discuss whether a vCISO is the right answer.

Sometimes it is not, and we will say so. Bring your obligations, your current arrangements and the questions leadership is asking.