Questions we hear most often — answered directly.
If you have a question that is not here, the Compliance Gap Assessment is the fastest way to get an answer specific to your firm's situation.
The DFS Annual Certification
A: The annual certification is a formal attestation filed with the New York Department of Financial Services by a senior officer of a covered entity — typically the CEO, managing partner, or president. The certification states that the firm’s cybersecurity program is in compliance with the requirements of 23NYCRR500 as of December 31 of the prior year. It is not an administrative filing — it is a personal legal representation to the State of New York. If an examination finds that the certified program does not match the evidence of implementation, the liability for that discrepancy belongs to the person who signed the certification.
A: DFS examiners work from a documentation request list that consistently includes: the firm’s Written Information Security Program (WISP); a third-party penetration test report with documented remediation evidence for all high and critical findings; a vendor risk assessment inventory covering every third party with access to nonpublic information; a tested incident response plan with documented proof of testing; MFA verification records documenting coverage across all user populations and privileged accounts; and board-level reporting showing the program is actively managed. The examination is a documentation audit, not a technology audit.
A: A documented finding results in a formal DFS response requirement — typically a remediation plan with defined timelines and a follow-up examination to verify the remediation. In cases of significant or repeated non-compliance, DFS has issued consent orders that name individual senior officers, imposing monetary penalties and, in some cases, restrictions on future industry conduct. The Silvergate Bank enforcement action, in which the CEO and Chief Risk Officer were personally named and fined, is the most prominent recent example of the personal liability exposure the annual certification carries.
A: DFS typically provides 30 days’ notice before a cybersecurity examination. That is 30 days to produce documentation that must reflect your program as of December 31 of the prior certification year — not documentation created in the 30 days following the notice. Firms that receive examination notice and then attempt to build their documentation package are, in most cases, already in a difficult position.
A: DFS has a process for amended filings, but filing an amended certification after an examination has been scheduled — or after an examiner has identified a discrepancy — does not eliminate the exposure created by the original filing. The defensible approach is to ensure that the evidence behind the certification exists and is current before the certification is signed, not after the examination begins.
Governance Documentation — The Basics
A: The documentation gap is the difference between what a firm’s cybersecurity policies say will be done and what documented evidence proves has been done. Most regulated firms have policies — a Written Information Security Program, an incident response plan, a vendor management policy. Almost none have the evidence that those policies are implemented: the penetration test remediation logs, the vendor risk assessment inventory, the proof that the incident response plan was tested, the MFA verification records. The gap between those two categories is the documentation gap. The Compliance Gap Assessment is specifically designed to identify whether your firm has one and how significant it is.
A: A WISP is the foundational governance document required by most cybersecurity regulations — including DFS 23NYCRR500 — that describes a firm’s cybersecurity policies and the controls implemented to protect nonpublic information. A WISP is not a generic template. It is a firm-specific document that reflects the firm’s actual technology environment, risk posture, and regulatory obligations. A WISP that was accurate when it was written but has not been updated since is not a defensible document — it is a record of a prior state.
A: Vendor risk tiering is the process of identifying every third party with access to your firm’s nonpublic information, assessing the risk each one represents, and documenting both. Under 23NYCRR500, covered entities are required to implement a third-party service provider security policy — and examiners request the vendor risk assessment documentation as part of the examination. For firms with many vendor relationships, the inventory can be extensive and is one of the most commonly found gaps in examination readiness assessments.
A: An IT provider typically performs ongoing vulnerability scanning — automated tools that identify known vulnerabilities in your environment. A penetration test is a structured, third-party exercise that simulates an actual attack on your systems to identify exploitable vulnerabilities that scanning may not catch. DFS 23NYCRR500 requires regulated entities to conduct periodic penetration testing by a qualified third party. The examination asks for the penetration test report and the documented remediation evidence for all high and critical findings — not a vulnerability scan summary.
A: Multi-factor authentication (MFA) is a security control requiring users to verify their identity through more than one method before accessing systems. DFS 23NYCRR500 requires covered entities to implement MFA for access to nonpublic information and privileged accounts. MFA verification is the documented confirmation that MFA is configured and operational across all required user populations — including cloud infrastructure, remote access, and privileged accounts. Many firms have MFA deployed in some environments but not others. The examination asks for documentation of coverage. “We think we have it everywhere” is not a defensible answer.
A: A tabletop exercise is a structured, facilitated simulation in which a firm’s key personnel work through a hypothetical cybersecurity incident scenario — following the firm’s incident response plan — to test whether the plan is operational and understood by the people responsible for executing it. DFS 23NYCRR500 explicitly requires that covered entities test their incident response plans annually. The tabletop exercise produces the documented proof of that testing. An incident response plan that has never been tested is not an operational control — it is a document.
About IT On Demand and How We Work
A: IT On Demand is a cybersecurity governance firm — not an IT provider and not a security technology vendor. IT providers manage systems. Security vendors sell tools and monitoring. Neither is built to produce the governance documentation that regulators examine. IT On Demand owns the layer between those two functions — building and maintaining the penetration test documentation, vendor risk assessments, tested incident response plans, MFA verification records, and WISP that constitute examination-ready governance evidence. That layer is what we were built to own.
A: The Compliance Gap Assessment is a private, structured diagnostic specific to your firm’s regulatory environment. We examine what governance evidence your firm currently has — policies, penetration test reports, vendor risk documentation, incident response plan, MFA verification records — and identify what is missing relative to the standards your applicable regulators examine. The Assessment takes approximately 30 minutes and produces a specific readout of your firm’s documentation gap. Every IT On Demand engagement begins with the Assessment. There is no pitch and no obligation.
A: Howard works directly in client engagements. IT On Demand does not operate an account team model where clients meet Howard and then work with junior staff. The governance expertise that clients engage when they work with IT On Demand is the expertise they interact with throughout the engagement.
A: Our primary focus is New York-based firms operating under DFS supervision, SEC cybersecurity rules, and ERISA DOL guidance. Many of those frameworks apply nationally — SEC-registered investment advisors operate across the country, and ERISA obligations are not geographically limited. We work with firms outside New York where the regulatory framework and the nature of the governance work is consistent with our practice. The Compliance Gap Assessment is the right starting point to determine whether IT On Demand is the right fit for your firm’s specific situation.
A: A virtual CISO (Chief Information Security Officer) is a senior governance professional who serves in a CISO capacity on an outsourced basis — providing the strategic oversight, board-level reporting, and ongoing governance leadership that a full-time CISO would provide, calibrated to the firm’s size and regulatory exposure. For regulated firms with 25 to 200 employees and no dedicated internal CISO, a governance advisory engagement with IT On Demand can provide that function — owning the governance layer at the executive level rather than managing a program at the service level. This engagement is not appropriate for every firm. If your situation warrants it, that conversation happens through the relationship.
A: IT On Demand offers three governance programs at defined starting prices: Cyber Liability Essentials from $529/month, Cyber Watch from $1,189/month, and Cyber Liability Manager from $2,179/month. Specific pricing for each engagement is determined by the Compliance Gap Assessment, which establishes the scope of what needs to be built or maintained. We do not quote final pricing before understanding your firm’s specific documentation gap and regulatory exposure.
Still have a question?
The fastest way to get an answer specific to your firm is the Compliance Gap Assessment. Thirty minutes. We look at your firm’s specific regulatory environment and documentation, and you leave with a clear picture of where you stand.
30 minutes. No pitch. No obligation.