You signed the certification.
Can you defend it?

IT On Demand builds and maintains the governance layer between your IT provider and your compliance officer — the layer DFS examiners actually examine.

Your IT provider manages your systems. No one owns your evidence.

Every regulated firm in New York has an IT provider for uptime and a compliance officer for filings.

What almost none of them have is anyone responsible for the governance layer between those two — the penetration test reports, vendor risk assessments, tested incident response plans, and MFA verification records that a DFS examiner will request by name when they arrive.

That gap is not your IT provider’s fault. They were not built to own it. No one was — until now.

When an examiner finds the gap, the finding belongs to the person who signed the certification. That is not an IT problem. It is a personal liability problem.

We own the governance layer. You get the evidence.

IT On Demand is a cybersecurity governance firm. We are not an IT support company. We do not sell tools or monitor dashboards.

We build, document, and maintain the evidence — the policies, penetration tests, vendor risk assessments, and tested incident response plans — that makes your cybersecurity posture defensible when a regulator, insurer, or plaintiff's attorney asks you to prove it.

If you can't prove it, you don't have it.

That is the standard we hold ourselves to. And the standard your examiners hold you to.

IT Provider
(systems)

IT On Demand
(governance layer)

Compliance Officer
(filings)

As seen in:

The program that fits where your firm stands today.

Every engagement starts with a Compliance Gap Assessment — a diagnostic that identifies exactly what evidence you have, what you're missing, and what a DFS examiner would find if they arrived next month. From there, you choose the level of governance support that matches your firm's current exposure.

Cyber Liability Essentials

From $529/month
The documented baseline. Not tools — a governance program that produces the evidence of due diligence when a regulator, insurer, or incident demands it.

See what's included →

Cyber Watch

From $1,189/month
Active posture management. Your firm knows where it stands before someone else forces the question.

See what's included →

Cyber Liability Manager

From $2,179/month
The full governance program. Examination-ready documentation maintained year-round. The difference between scrambling in April and being ready in January.

See what's included →

For firms that require full governance ownership.

Some firms reach a point where the complexity of their regulatory exposure warrants a deeper engagement. For the right firm, IT On Demand can own the governance layer entirely — providing ongoing strategic oversight that moves risk management from a filing exercise to a year-round, board-level program.

This is not on a menu. If it’s relevant to your situation, it surfaces through the relationship.

Learn about our advisory engagements →

Howard Globus has been on both sides of the examination table.

Most governance consultants describe what regulators look for. Howard has lived it — as CIO/CISO at Allianz Risk Transfer, a $2 billion AUM reinsurance firm, he managed DFS examinations from the inside, implemented ISO 27001, and built the programs that had to hold up under scrutiny.

He then built IT On Demand to give mid-market regulated firms access to that same governance infrastructure — without the Big 4 price tag or the junior associate account team.

Twenty years serving New York’s regulated firms. Hundreds of engagements. The standard has not changed: if you can’t prove it, you don’t have it.

  • Former CIO/CISO, Allianz Risk Transfer | $2B AUM
  • 20+ years serving NY regulated firms
  • DFS | SEC | ERISA | ISO 27001 | GDPR
  • Author, Unhackd
  • Featured: Forbes, Banking & Insurance, Safety Detectives

$3.5 million on the line. Four days to prove it.

"Their submission was judged the most comprehensive of all vendors."

A New York actuarial firm came to us on a Thursday evening. They had a $3.5 million bid deadline by Monday and no compliance documentation to show for it — with 15% of their existing revenue also at risk in the same review.

By Monday morning: 23 policies written, management-approved, and loaded into a GRC platform. Employee sign-offs completed. Cybersecurity awareness training done. A forward-looking roadmap across 23NYCRR500 and DOL frameworks assembled and ready to submit.

Their submission was judged the most comprehensive of all vendors. They won the bid.

The following month, five more security questionnaires arrived from other clients. They answered all five in hours — because the evidence already existed.

That is what a governance program actually does. It does not just satisfy the examiner in front of you. It answers every question that follows.

Two things we hear often — and what they usually mean.

They handle your systems. Uptime, speed, connectivity — that is their job, and most of them do it well. But when a DFS examiner arrives, they do not ask to see your network performance metrics. They ask for your penetration test remediation logs, your vendor risk assessment inventory, your tested incident response plan, and your MFA verification records.

That is not your IT provider’s deliverable. It has never been. That gap is what we own.

Most firms do. Policies on a shared drive, filed on time, reviewed annually. That is a good start — and it is not what DFS examiners examine.

They examine the evidence that those policies were implemented. The question is not whether the policy exists. The question is whether you can prove the control is operational. Those are different documents, and most firms do not have them.

Start with a Compliance Gap Assessment.

The Assessment is a private, structured diagnostic. We identify exactly what evidence your firm has, what is missing, and what a DFS examiner would find if they arrived next month. No pitch. No obligation. A clear picture of where you stand.

Most firms find it clarifying. Some find it urgent. Either way, you leave knowing exactly what your exposure is — and what it would take to close it.

30 minutes. No obligation. Specific to your firm’s regulatory environment.

The Governance Brief

One regulatory development. One consequence. One thing to do about it. Delivered when there is something worth saying.