Dr. Daniel Glauber
Founder and CEO of Heights Consulting Group, with more than 30 years of experience in cybersecurity and technology leadership.
- Role
- Founder and CEO
- Credentials
- Doctor of Management, Organizational Leadership (Information Systems and Technology). MBA, Business Administration.
- Author of
- Cybersecurity in the Age of Artificial Intelligence
- Writes on
- Executive and board-level security leadership. Cybersecurity governance and program strategy.
Profile
Background
The experience behind the firm's engagements, and the standard its published writing is held to: every article under this byline is attributed, dated and sourced.
Dr. Daniel Glauber is the founder and CEO of Heights Consulting Group. He holds a Doctor of Management in Organizational Leadership with a specialization in Information Systems and Technology, as well as an MBA, and has spent three decades in information technology, cybersecurity, enterprise architecture and organizational leadership. His doctoral research examined the relationship between leadership, organizational decision-making and technology adoption, including knowledge management work presented at the 18th International Conference on Information and Knowledge Management in Barcelona.
His background includes more than fifteen years supporting United States government, defense and national security missions, with assignments connected to Afghanistan, Bogota, Guantanamo Bay, U.S. Central Command, U.S. Southern Command, the National Ground Intelligence Center, the National Security Agency and NATO. That work is where technology, security, leadership and mission continuity had to hold together at once.
He is the author of Cybersecurity in the Age of Artificial Intelligence, published in 2025: eighteen chapters across five security domains on how artificial intelligence is changing both attack and defense, grounded in more than fifty real-world case studies. He also serves as an adjunct professor of cybersecurity at Keiser University in Orlando.
Before founding Heights, he founded MSP PRO, created the Cyber Health Check assessment platform, and served as CEO of Kintek Cybersecurity. He leads the firm’s vCISO engagements today, working directly with chief executives, boards, general counsel and IT leadership on security strategy, AI governance and risk decisions.
The engagements this experience supports
Cybersecurity in the Age of Artificial Intelligence, on Amazon
Expertise
Areas of focus
- Executive and board-level security leadership
- Cybersecurity governance and program strategy
- Cyber risk management
- Regulatory and framework readiness
- AI and emerging technology security
Research
Published research
Knowledge Management Strategies within a Corporate Environment
ICIKM 2016, 18th International Conference on Information and Knowledge Management, Barcelona, 2016.
Writing
Published insights
-
Governance & Compliance
What Cyber Incident Response Plans Must Contain to Satisfy Regulators
Regulated organizations are accountable for documented incident response plans that meet specific technical and governance requirements. This article explains what every plan must include, who approves it, how often it must be tested, and where executive ownership typically breaks down.
-
Compliance and Audit Readiness
When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2
SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome.
-
Regulatory and Framework Readiness
GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024
The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place.
-
Governance
What Security Documentation an Assessor Requests First and Why It Matters
Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like.
-
Compliance
When Privileged Access Management Becomes an Audit Requirement
SOC 2, PCI DSS and CMMC assessments increasingly test for privileged access controls, not as a checkbox but as evidence of governance. This article explains which frameworks mandate PAM, what constitutes compliance for audit purposes, and how leadership can establish accountability before the assessment begins.
-
Compliance
How FedRAMP Authorization Works and What It Requires Before You Apply
FedRAMP authorization allows cloud service providers to sell to federal agencies through a standardized security assessment process. Leadership must understand the timeline, evidence requirements and internal ownership structure before committing to an authorization effort that typically spans twelve to eighteen months and requires continuous executive oversight.
-
Managed Security Services
What Changes When Your MSP Also Provides Security Monitoring
When a managed service provider takes on security monitoring, the lines of accountability blur unless leadership explicitly defines who decides risk tolerance, who speaks to regulators, and who owns the security program. This article explains what shifts, what stays internal, and how executive ownership closes the gap.
-
Regulatory and Framework Readiness
What GDPR Requires of US Companies and When It Applies
The General Data Protection Regulation applies to US companies that process personal data of individuals in the European Union, regardless of where the company is located. This article explains the territorial scope, core obligations, leadership accountability and practical steps for compliance.
-
Compliance
What Sarbanes-Oxley IT General Controls Actually Require and How They Are Tested
Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap.
-
Compliance
When Log Retention Becomes a Legal Obligation and What That Means for Cloud Accounts
Organizations face legal and regulatory requirements to preserve specific system logs for defined periods, but cloud environments create complexity around who is responsible for which records. This article explains what log retention obligations exist, where the shared responsibility model leaves gaps, and how to establish clear ownership so the organization can meet its compliance duties without ambiguity.