Three questions most leadership teams cannot answer cleanly
Latest article
-
Who owns the cybersecurity program?
Not who runs the systems. Who is accountable for whether the program as a whole is adequate. What the vCISO owns -
What needs to be addressed first?
Not the full list of findings. The agreed order of work, and why it is in that order. How an engagement runs -
Can leadership clearly explain the risk?
In business terms, to a board, an insurer or a customer, without assembling it from three vendors. Executive and board reporting
IT staff, providers, tools and policies, and still no owner
Cybersecurity work gets done in most organizations. What is missing is the person accountable for whether the program as a whole is adequate, and for the order the work happens in.
-
Responsibility is fragmented
IT runs the systems, a provider covers part of it, vendors cover the rest. Nobody owns the whole.
-
Projects compete without priorities
Work is agreed to be important, then displaced by whatever is more urgent that week.
-
Leadership lacks meaningful reporting
The board receives metrics it cannot act on, or none at all.
-
Compliance sits apart from operations
Evidence is assembled before an assessment rather than maintained between them.
-
Vendors work without unified direction
Spending grows without a clear picture of coverage, overlap or gaps.
-
Policies do not match practice
The written program and the working practice have drifted apart.
-
The organization reacts instead of planning
Decisions are made case by case, with no stated direction to measure against.
What vCISO leadership changes
-
Clear ownership
One accountable person for the security program, with a written scope of responsibility that leadership and providers both work to.
-
Risk-based priorities
An agreed order of work, driven by business consequence and regulatory exposure rather than by whatever surfaced most recently.
-
Executive visibility
Reporting written for the audience: exposure, obligation, progress, and the decisions leadership is being asked to take.
-
Measurable program progress
A baseline, one consistent way of measuring against it, and reporting that shows movement between periods.
Flagship engagement
Executive ownership of the cybersecurity program
Heights provides ongoing strategy, governance, risk leadership, regulatory direction, vendor oversight and executive reporting. The scope of responsibility is agreed in writing at the start and reviewed as the program matures.
How vCISO engagements work Schedule a Confidential Consultation
What Heights Carries
- Security strategy and roadmap
- Governance and decision records
- Cyber risk management
- Regulatory and framework direction
- Vendor and provider oversight
- Executive and board reporting
It works alongside the people you already have. Your IT team continues to run the environment and your providers continue to deliver their services. What changes is that they receive a clear specification, an agreed order of work, and a client-side counterpart who reviews the result.
The work a strategy calls for
Each capability can be engaged on its own. More often they are how a vCISO engagement gets executed.
Risk and governance
The decisions, records and oversight that turn security activity into something leadership can direct.
Compliance and regulatory readiness
Knowing which obligations apply, and being able to evidence them when somebody asks.
Security architecture and operations
The design and running of the controls a strategy depends on.
Resilience and emerging technology
Preparedness for what goes wrong, and governance for what is arriving.
How an engagement runs
A straightforward sequence, because the value is in the judgment rather than in a named methodology.
-
Understand the current state
What the organization is responsible for, and what is actually in place to meet it, established with the people who operate the environment.
-
Establish priorities
Gaps ranked by business consequence and regulatory exposure, then agreed with executives rather than handed to them.
-
Build and coordinate the program
A phased roadmap with owners and dependencies, delivered by your team, your providers or Heights.
-
Measure and report progress
Reassessment against the original baseline using the same method, reported to leadership in a consistent format.
Regulated and risk-sensitive organizations
Sectors where security obligations are written down and somebody has to be able to evidence them.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Frameworks and regulations we work to
Which of these applies to your organization is the first question an engagement answers.
Who you would be working with
Heights Consulting Group is a strategy-first cybersecurity and technology advisory firm. Its flagship service is vCISO leadership, and the rest of the portfolio exists to help organizations execute the strategy that leadership produces.
Dr. Daniel Glauber
Founder and Managing Principal
Dr. Daniel Glauber is the founder and managing principal of Heights Consulting Group. He has more than 30 years of experience in cybersecurity and technology leadership, working with organizations to protect their digital environments, meet regulatory obligations and build resilient technology operations.
He leads the firm’s vCISO engagements, working directly with chief executives, boards, general counsel and IT leadership on security strategy, governance and risk decisions.
Written for the people who have to decide
Practical guidance on governance, risk and regulatory questions, aimed at executives and boards rather than at practitioners.
-
Regulatory Compliance
Business Associate Agreements: What Changed and What Leadership Must Verify
Recent regulatory guidance has shifted BAA oversight responsibility firmly to covered entities. Healthcare executives are now accountable for verifying that every business associate meets specific security requirements, maintains compliant agreements, and operates within defined risk tolerances. This article explains what changed, who owns oversight, and how leadership can close the gap between accountability and execution.
-
Governance
Healthcare Security Obligations: A Clear Map for Leadership
Healthcare organizations operate under a dense set of security obligations from federal regulators, state law and contractual requirements. This article maps those requirements plainly, explains who inside the organization is accountable, and sets out what adequate ownership looks like when technical leadership and executive accountability must meet.
-
Regulatory and Framework Readiness
HITRUST i1 Assurance Program: What Changed and When Healthcare Organizations Should Reassess
HITRUST introduced the i1 Assurance Program in 2024, replacing earlier certification pathways with a model that separates inherited controls from organization-specific implementation. Healthcare organizations holding e1 or r2 certifications face transition decisions with defined deadlines, requiring executive ownership of regulatory positioning and governance strategy.