Cybersecurity Governance Services

IT On Demand offers structured cybersecurity governance programs for regulated firms

Every program starts with the same question: What could you hand an examiner today?

Not what policies you have filed. Not what tools your IT provider manages. What evidence — penetration test reports, vendor risk assessments, a tested incident response plan, MFA verification records — could you produce, in documented form, in 30 days?

For most regulated firms, the honest answer is incomplete. Not because they have been negligent. Because no single vendor was ever built to own that layer.

Every IT On Demand engagement begins with a Compliance Gap Assessment — a private diagnostic that answers that question specifically for your firm. From there, you choose the governance program that fits where you stand today.

What "governance" actually means in practice.

There is a layer between your IT provider and your compliance officer that almost no one owns. IT manages systems. Compliance files documents. Neither produces the evidence that regulators actually examine — and neither is built to.

That layer is what IT On Demand owns. We build the evidence, document the controls, verify the implementations, and maintain the full package year-round so that when an examination arrives, nothing needs to be created on deadline.

We operate across the four pillars that DFS, SEC, and ERISA examiners examine most closely:

Penetration testing and remediation documentation

Third-party testing with documented evidence for all high and critical findings

Vendor risk assessment and tiering

Every third party with access to nonpublic information identified, assessed, and documented

Incident response plan testing

Live tabletop exercise producing the documented proof of testing regulators explicitly require

MFA verification

Coverage audit documented across all user populations, cloud infrastructure, and privileged accounts

Three programs. One standard.

Each program is designed for a different level of governance complexity and regulatory exposure. All three are built to the same standard — examination-ready documentation that survives scrutiny, not paperwork that satisfies a checkbox.

Cyber Liability Essentials:
The defensible baseline.

From $529/month

For regulated firms that need a documented governance program and do not yet have one. Cyber Liability Essentials builds the foundational evidence — the policies, assessments, and documentation framework that produces proof of due diligence when a regulator, insurer, or incident demands it.

WHO IT IS FOR:
Firms that know they have a gap and need to close it systematically, without overpaying for complexity they do not yet need.

See full program details →

Cyber Watch:
Active posture management.

From $1,189/month

For firms that have a baseline and need ongoing assurance that it holds. Cyber Watch moves governance from a point-in-time project to a continuous program — so your firm knows where it stands before a regulator, insurer, or incident forces the question.

WHO IT IS FOR:
Firms approaching an examination cycle, renewing cyber insurance, or managing a compliance program that needs year-round maintenance rather than annual repair.

See full program details →

Cyber Liability Manager:
Full governance. Examination-ready. Year-round.

The complete governance program. 38+ framework compliance mapping. Examination-ready documentation maintained continuously. A WISP that generates in one step. The difference between scrambling in April and being ready in January.

WHO IT IS FOR:
Firms with active DFS, SEC, or ERISA exposure that cannot afford a gap finding — and whose managing partner's name is on the annual certification.

See full program details →

For firms that require full governance ownership.

Some firms reach a point where the complexity of their regulatory environment — multiple frameworks, ongoing examination cycles, board-level reporting requirements — warrants an engagement that goes beyond a managed program.

For those firms, IT On Demand can serve in a strategic governance advisory capacity: owning the governance layer entirely, providing ongoing executive-level oversight, and ensuring that risk management operates as a year-round, board-level function rather than a compliance filing exercise.

This engagement is not listed on a menu. It is not the right fit for every firm, and we do not position it as a starting point. If the complexity of what we find during your Gap Assessment warrants a deeper conversation, we will have it then.

Learn more about governance advisory →

Every engagement starts here.

The Compliance Gap Assessment is a private, structured diagnostic specific to your firm’s regulatory environment. We examine what evidence exists, what is missing, and what a DFS examiner would find if they arrived next month.

It takes 30 minutes. There is no pitch and no obligation. You leave with a clear picture of where your firm stands and what it would take to close the gap.

Most clients find it clarifying. Some find it urgent. Either outcome is useful.

30 minutes. No obligation. Specific to your firm.

We work with regulated firms —
not regulated industries in general.

Our clients are financial services firms, insurance companies, registered investment advisors, legal practices, and actuarial and pension firms operating under active DFS, SEC, or ERISA exposure. Typically 25 to 200 employees. No dedicated in-house CISO. A managing partner or CEO whose name is on the annual certification.

If that describes your firm, the governance layer we build is built for you.