What the engagement is
- Engagement type
- Ongoing executive leadership, scoped in writing and reviewed as the program matures.
- Works alongside
- Your internal IT team, your MSP and your existing providers.
- Reports to
- Chief executives, boards, general counsel and compliance leadership.
What a vCISO is
A virtual Chief Information Security Officer, vCISO, is an experienced security executive who holds the CISO responsibilities for your organization on an ongoing basis without being a full-time employee: the strategy, the risk decisions, the governance, the regulatory position and the reporting to leadership.
The term is used loosely
The term is used loosely across the market, which makes offers hard to compare. Some firms use it for an extended assessment. Others use it for a monthly report generated from a scanning tool, or for a technician who attends a quarterly meeting.
What the role actually has to be
The version that solves the problem executives actually have is narrower and more demanding. It is not a deliverable, a checklist, a tool bundle, technical support, or a part-time administrator, and it is not a replacement for a managed service provider. It is accountability: somebody whose job is to decide what the organization should be doing about security, in what order, with what trade-offs, and to answer for that judgment when the board asks.
How Heights provides it
Heights provides that role. We work inside your leadership structure on a defined scope of responsibility, agreed in writing at the start of the engagement and reviewed as the program matures.
Why capable organizations still lack security ownership
Most organizations that need a vCISO already have IT staff, service providers, security tools and a policy document. What they do not have is a single person accountable for whether all of it adds up to an adequate program.
It is structural, not a performance problem
This is a structural gap rather than a performance problem. An IT team is measured on availability and delivery. A managed service provider is measured against its contracted scope. A software vendor is responsible for its own product. Each of them is doing what they were engaged to do.
How the gap shows up
- Security priorities change depending on who was in the last meeting.
- Two providers each assume the other is handling something material.
- A questionnaire answer is given by whoever is available, and nobody checks it against reality.
- A risk is accepted informally, and six months later nobody can say who accepted it.
- Budget is approved for tools without an agreed view of what problem they solve.
- The board receives technical metrics and cannot tell from them whether the organization is in good shape.
What answering them requires
Those questions require someone with a view across the whole picture and the standing to make a call. When nobody holds that position, the decisions still get made, but they get made implicitly, by whoever happens to be closest to the problem, and nothing records why.
What the vCISO owns
Thirteen responsibilities, held by Heights inside your leadership structure. Strategy is the anchor; the rest follow from it.
Cybersecurity strategy
Deciding what the security program should achieve, over what horizon, and in what order, informed by the organization's obligations, risk profile and capacity to absorb change.
Security governance
Establishing where security decisions are made, who is entitled to make them, and how they are recorded, then running that forum.
Risk-based priorities
Maintaining a risk picture leadership can act on, and bringing accept, reduce or transfer decisions to the people with authority over the affected part of the business.
Policies and standards
Owning the policy lifecycle: approval, review, exception handling, and the judgment calls when a written rule meets an unanticipated operational reality.
Regulatory readiness
Knowing which obligations apply, keeping the evidence current between assessment cycles, and answering customer and auditor questions consistently.
Executive accountability
Being the person who answers for whether the program is adequate, rather than the person who reports what was done.
Board-level reporting
Translating the state of the program into the language directors use: exposure, obligation, progress, and the decisions being requested of them.
Security roadmaps
Maintaining a sequenced plan with owners and dependencies, and keeping it honest as circumstances change.
Incident readiness
Keeping the response plan usable and tested, and coordinating executive decision-making if an incident occurs.
Third-party risk
Assessing and re-assessing the vendors and partners whose access or data handling creates exposure for the organization.
MSP and vendor oversight
Setting expectations for providers, reviewing what they deliver against those expectations, and escalating when the service is not meeting them.
Security-awareness oversight
Directing the awareness program, what each group is trained on, how it is measured, and what happens when the same issue keeps recurring.
Continuous program improvement
Reassessing against the baseline, adjusting as the business and its obligations change, and demonstrating movement over time.
Which organizations need one
The common factor is a real security obligation with no CISO-level owner, not a particular size, sector or budget.
Fits well
- Regulated or contractually obligated organizations without a full-time CISO.
- Companies whose customers assess their security before signing.
- Businesses that have grown faster than their security program.
- Organizations where a board or audit committee has begun asking harder questions.
- Firms with capable IT teams or providers and nobody setting security direction.
- Organizations that could justify a full-time CISO eventually, but not yet.
- Companies between security leaders who need continuity rather than a pause.
The wrong answer when
- Organizations wanting somebody to operate tools day to day, that is an operational role, not an executive one.
- Companies whose security workload is genuinely continuous and full-time; at that point an internal hire is the better answer.
- Situations where leadership does not want the answers a security executive would surface. The role only works with genuine access and a willingness to act on what it finds.
What usually prompts the call
Most engagements begin with one of these. Several are usually true at once.
Audit findings
An audit or assessment produced findings that need owning and closing, not just recording.
Customer questionnaires
Security questionnaires arrive with deals and the answers have to be accurate, consistent and defensible.
Regulatory requirements
A regime applies, or newly applies, and somebody has to determine what it demands and where you stand against it.
Cyber-insurance requirements
An application or renewal asks detailed control questions, and the answers affect both coverage and price.
Board concerns
Directors have asked about cyber exposure and the current reporting does not let them answer their own question.
A security incident
Something happened, and the response exposed gaps in ownership, escalation or decision authority.
Rapid growth
Headcount, systems, data and third parties have all increased, and practices that worked at the previous size no longer hold.
New enterprise customers
A larger customer brings security terms, audit rights and expectations that the organization has not previously had to meet.
Mergers and acquisitions
Diligence is under way in either direction, and the security position has to be described accurately or assessed properly.
Leadership transitions
A security or technology leader has left and the responsibility currently has no home.
No formal security ownership
Nothing is on fire, but nobody owns the program, and leadership has recognized that this is itself the risk.
What Heights delivers
Artifacts and processes your organization owns, and would keep if the engagement ended tomorrow.
Understanding where you stand
- Current-state assessment
- A documented baseline against a chosen framework, with the evidence behind it.
- Risk register
- Risks in business terms, consistently rated, with named owners and recorded treatment decisions.
- Program metrics
- A small set of measures that show whether the program is improving, reported the same way each period.
Direction
- Cybersecurity strategy
- A stated direction for the program, tied to what the business is trying to do and what it must protect.
- Prioritized roadmap
- A phased plan with owners, dependencies and a defensible order of work.
- Governance structure
- A decision forum, defined authority, and a record of what was decided and why.
The written program
- Policy development and maintenance
- An approved, version-controlled policy set with a review schedule and an exception process.
- Regulatory-readiness planning
- Applicability analysis, control mapping and a maintained evidence base.
- Incident-response planning
- A tested plan with roles, escalation criteria and notification obligations identified in advance.
Oversight and communication
- Executive reporting
- Regular reporting to the leadership team, framed around decisions rather than activity.
- Board reporting
- A repeatable board format plus the history that shows movement between meetings.
- Third-party oversight
- Responsibility mapping, vendor tiering, and reporting expectations for each provider.
- MSP and vendor coordination
- Expectations set with providers, their output reviewed, and escalation when the service falls short.
- Security-awareness oversight
- Direction of the awareness program and follow-up on what it reveals.
- Ongoing advisory leadership
- Availability between the set pieces: architecture decisions, questionnaires, vendor selection, incidents.
How an engagement runs
Engagements begin with a confidential conversation and a written scope, move through an assessment and roadmap phase, and then settle into an operating rhythm of working sessions and scheduled reporting.
-
No cost, no obligation
A confidential conversation
What is prompting the discussion, what the organization is obliged to do, and what leadership is being asked to answer for. If we are not the right firm for what you need, we will say so.
-
Agreed in writing
Defining the responsibilities we will hold
Which responsibilities sit with Heights and which stay with you, the working rhythm, who we will work with internally, and how progress will be reported. Written down, so nothing important rests on assumption.
-
Typically the first 30 days
Discovery and assessment
A structured review of the current security posture, business objectives, compliance requirements and risk tolerance, established with the people who run the environment, not from documentation alone.
-
Typically around 60 days
Strategy and roadmap development
The findings become a strategy and a prioritized roadmap, discussed with leadership before adoption so the sequence reflects real constraints, budget cycles, capacity and contractual dates.
-
From roughly 90 days onward
Implementation and ongoing oversight
Work carried out by your team, your providers or Heights, with expectations and acceptance criteria stated up front. Regular working sessions, scheduled reporting, and reassessment against the baseline as conditions change.
Timeframes above are indicative of how engagements typically run rather than contractual commitments. Scope and rhythm are agreed for each organization and reviewed as the program matures.
vCISO or a full-time CISO
Neither arrangement is universally better. The right choice depends on how much sustained security work the organization genuinely has, and how much internal authority the role needs to carry.
A common and healthy outcome is that an organization outgrows the arrangement. A vCISO engagement is designed to leave behind a documented program, strategy, governance, risk register, policies, evidence and reporting history, that an incoming CISO can take ownership of directly. Heights can also support that transition, including scoping the role.
vCISO
Full-time internal CISO
Organizational need
Fits when the security workload is real but intermittent, obligations, assessments, decisions and reporting rather than continuous internal demand.
Fits when security work is continuous and large enough to occupy a senior executive full time.
Scope
A defined scope of responsibility agreed in writing, focused on strategy, governance, risk and reporting.
Open-ended executive scope, typically including team building, budget ownership and organizational management.
Availability
Present on an agreed rhythm with escalation for urgent matters. Not embedded in day-to-day operations.
Present continuously, able to respond to informal signals and corridor conversations that a scheduled engagement will miss.
Internal authority
Authority is delegated and depends on visible executive backing. Works well where leadership genuinely stands behind the role.
Positional authority as an officer of the organization, with the standing that carries in internal negotiation.
Flexibility
Scope can expand or contract as the program matures, and the engagement can end cleanly when it is no longer the right shape.
A permanent hire; changing the arrangement means an organizational change.
Stage of program development
Strongest where a program is being established or rebuilt, and where breadth of experience across many organizations is more valuable than depth in one.
Strongest where a program is established and the work has shifted to running, scaling and leading a security function.
How a vCISO works alongside the people you already have
None of these relationships is a replacement. Each gains a clear specification and somebody who reviews what is delivered.
Board and executives
Receive exposure, obligation, progress and the decisions being asked of them, in one consistent format.
Board reportingHeights vCISO
Sets direction, owns the risk picture, reviews what is delivered, and answers for whether the program is adequate.
Internal IT
Keeps running the environment. Gains a clear specification, an agreed order of work and executive backing for trade-offs.
How this worksMSP and technical providers
Keep delivering their contracted scope. Gain stated expectations, defined evidence and a client-side counterpart who reviews it.
Provider oversightVendors and third parties
Assessed proportionately to the access and data involved, with responsibilities mapped in writing on both sides.
Third-party riskWith your internal IT team
A vCISO gives internal technology leaders a clear specification, an agreed order of work, and executive air cover for the decisions that follow, it does not take over their function.
In practice this makes IT's job easier in three specific ways. Priorities stop shifting with whoever asked last. Requests for budget arrive with a risk rationale attached rather than a technical one. And when a trade-off has to be made between security and delivery, somebody at executive level makes the call and records it, rather than leaving it to be absorbed quietly by the team.
With your MSP or technical provider
A vCISO provides the client-side governance that lets a managed provider do its job well: independent priorities, stated evidence requirements, review of what is delivered, and executive communication.
A vCISO occupies that position. Responsibilities are mapped and agreed by both sides. Reporting expectations are defined. Provider output is reviewed by somebody accountable to your leadership, and escalated when it does not meet the expectation. Where the provider is doing something well, that is recorded too.
Frameworks and regulations we work to
Which of these applies is one of the first questions an engagement answers. Descriptions are of the published requirements, not claims about outcomes.
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- SOX
- Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
- HITRUST
- A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence.
The work a roadmap calls for
Delivered by Heights, or by your team and providers under the same specification.
Executive cybersecurity leadership
Ownership of the security program: what it should achieve, in what order, and who answers for it.
Risk and governance
The decisions, records and oversight that turn security activity into something leadership can direct.
Compliance and regulatory readiness
Knowing which obligations apply, and being able to evidence them when somebody asks.
Security architecture and operations
The design and running of the controls a strategy depends on.
Resilience and emerging technology
Preparedness for what goes wrong, and governance for what is arriving.
Frequently asked questions
If your question is not here, ask it directly. We will answer plainly, including when the answer is that you do not need what you came to ask about.
Maintained by Dr. Daniel Glauber.
What does a vCISO do?
A vCISO holds the executive responsibilities for an organization's security program: setting the strategy, owning the risk picture, running security governance, maintaining the policy set, keeping the regulatory position defensible, overseeing providers, and reporting to executives and the board.
The defining characteristic is accountability over time rather than the depth of any single deliverable. A consultant produces a report and leaves; a vCISO owns what happens next.
Does a vCISO replace our IT team?
No. Your IT team continues to run the environment, systems, identity, change management, availability and support.
What changes is that the security requirements they work to become explicit rather than implied, priorities stop shifting between meetings, and trade-offs between security and delivery are decided at executive level rather than absorbed quietly by the team.
Does a vCISO replace our MSP?
No. A managed service provider operates and supports the environment under a contracted scope. A vCISO works on your side of that relationship: defining what is expected, reviewing what is delivered, and escalating when the two do not match.
The two roles are complementary. Provider work generally becomes easier and more effective when the client has somebody senior enough to specify what is wanted and to assess what arrives.
How involved is a vCISO?
Engagements are structured around a defined scope of responsibility and a working rhythm, regular sessions with IT and leadership, plus scheduled executive and board reporting, rather than a fixed number of hours.
Between those sessions the vCISO remains available for the things that do not wait: a customer questionnaire, an architecture decision, a vendor issue or an incident. The scope is agreed in writing at the start and reviewed as the program matures.
Can a vCISO communicate with executives and the board?
Yes, that is a core part of the role rather than an add-on. Reporting is built for a governance audience: material exposures, progress against an agreed plan, applicable obligations, and the specific decisions leadership is being asked to take.
The format stays consistent between meetings, because directors build their judgment from the change between periods rather than from any single report.
Can a vCISO help with security questionnaires?
Yes, and this is one of the fastest returns for technology and service companies. Questionnaire answers are representations that become contractual commitments, so they need to be accurate, consistent between customers, and defensible later.
The practical approach is a maintained set of canonical answers with named owners, which turns each new questionnaire from a research exercise into a review.
Can a vCISO help prepare for audits and assessments?
Yes. Preparing for assessments, coordinating evidence and handling assessor findings are ordinary parts of the role.
Heights prepares organizations for assessment; it does not perform the audit, examination or certification itself. That separation is deliberate, an adviser assessing their own work would not produce a credible result.
How does an engagement begin?
With a confidential conversation about what is prompting the enquiry, what the organization is obliged to do, and what leadership is being asked to answer for. There is no cost or obligation attached to it.
If it makes sense to continue, scope is agreed in writing, and the engagement opens with a discovery and assessment phase that typically runs about thirty days.
What information do we need to get started?
For the first conversation, nothing prepared. What helps is knowing what triggered the enquiry, which obligations you are working to, roughly what is in place today, and who currently makes security decisions.
Detailed material, policies, previous assessments, provider contracts, system inventories, is gathered during discovery, and we work with whatever exists rather than requiring it to be assembled in advance.
Is this appropriate for an organization without a formal security program?
Yes, and that is one of the most common starting points. Organizations without a formal program are usually not starting from nothing, they have controls, tools and practices that were never assembled into a coherent whole.
The first phase establishes what genuinely exists, which is almost always more than leadership expects in some areas and less in others.
Where vCISO leadership is most often needed
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
More on the role
-
Board and Executive Reporting
Preparing a Board-Level Cybersecurity Update
Directors need four things from a cyber update: what could materially hurt the organization, what is being done about it, what obligations apply, and what they are being asked to decide. Most updates deliver activity instead.
-
Governance
Answering Customer Security Questionnaires Without Slowing Down Sales
Security questionnaires arrive with enterprise deals and the answers become contractual representations. Treating them as a sales task produces inconsistency; treating them as a governance task produces answers you can stand behind and reuse.
Discuss whether a vCISO is the right answer.
Sometimes it is not, and we will say so. Bring your obligations, your current arrangements and the questions leadership is asking.
Or reach us directly at (407) 908-7001 or info@heightscg.com.