About IT On Demand

IT On Demand exists because the governance layer between IT and compliance has no owner — until now.

Most firms don't find out they have a governance gap until someone official is asking questions.

By then, the conversation is not about whether the gap exists. It is about who is responsible for it.

If your name is on the DFS annual certification, you already know the answer to that question. The certification is not a filing. It is a personal legal representation to the State of New York that specific documented evidence actually exists at your firm.

Most executives sign it in good faith. Most have never been shown exactly what "documented evidence" means to an examiner — and what happens when they ask for it and it is not there.

That is the problem IT On Demand was built to solve.

I have been in this industry my entire life. I have also been on both sides of the examination table.

I grew up in IT. My father ran an IT consulting business, and I was in the work before I was old enough to fully understand what I was doing. I entered financial services at First Boston in 1994 — which became Credit Suisse First Boston, then Credit Suisse — and I have been inside regulated firms ever since.

I co-founded IT On Demand to serve New York's mid-market regulated firms. Then I stepped away from the firm for several years to serve as CIO and CISO at Allianz Risk Transfer — a reinsurance firm managing $2 billion in AUM — where I managed DFS examinations from the inside, implemented ISO 27001, and lived through GDPR from the executive seat.

That experience changed how I see this work.

When you have personally carried the liability — when you have built the program that had to hold up under regulatory scrutiny, not just describe one — you understand what "defensible" actually means. It does not mean having policies. It means having evidence. Those are different things. Most firms have one. Almost none have the other.

I came back to IT On Demand because the gap I saw from the inside of Allianz — the space between what IT providers deliver and what regulators actually examine — was still unowned in the mid-market. Twenty years later, it still is. That is the layer we own.

A few things I believe about how this work should be done.

Evidence is not documentation.

Documentation implies paperwork that satisfies a checkbox. Evidence is what survives scrutiny — a regulator's, an insurer's, a plaintiff's attorney's. Every deliverable we produce is built to survive scrutiny, not to exist.

Governance is a year-round program, not an April scramble.

Examination readiness is not something you achieve in the three weeks before a filing deadline. It is the result of maintaining evidence continuously, so that when the examiner arrives — with 30 days' notice — the answer to every request is already in a binder.

The gap is not your fault.

Your IT provider was not built to own the governance layer. Your compliance officer was not built to execute it. No single vendor in this market was built to sit at the intersection of lived regulatory experience, technical execution, and ongoing governance maintenance — until we were. You have a gap because nobody was built to fill it. We are.

The certification you sign is yours.

Not your IT provider's. Not your general counsel's. Yours. The work we do translates directly to the protection of that signature. That is not a marketing position. It is the legal reality of 23NYCRR500, and it is the reason we do not cut corners on the evidence.

The specifics, for those who want them.

Former CIO/CISO

Allianz Risk Transfer | $2B AUM reinsurance

Co-Founder

IT On Demand | 20+ years serving NY regulated firms

Regulatory frameworks

NY DFS 23NYCRR500 | SEC Cybersecurity Rules | ERISA DOL Guidance | ISO 27001 | GDPR | SOC 2

Industries served

Financial services | Insurance | Legal | Actuarial & pension | Registered investment advisors | Reinsurance

Author

Unhackd | Behind the Scenes

Featured in

Forbes | Banking & Insurance (BAI) | Safety Detectives | Karjaka

Howard Globus

If you are here because you heard Howard speak — welcome.

Security Evangelist & Owner

Howard speaks regularly to financial services associations, compliance officer groups, and industry conferences on personal executive liability, the documentation gap, and what regulated firms get wrong about cybersecurity governance.

If you attended one of those events — or if someone who did sent you here — you are in the right place. The work described on stage is the work IT On Demand delivers every day.

For speaking inquiries, event bookings, or Howard’s full keynote menu, visit howardglobus.com.

What clients say.

The first step is a Compliance Gap Assessment.

It is a private, structured diagnostic. We look at what evidence your firm has, what is missing, and what an examiner would find if they arrived next month. Thirty minutes. No pitch. No obligation.

Most people find it useful regardless of what they decide next.

Specific to your firm’s regulatory environment. 30 minutes. No obligation.