The documented baseline. Not tools — evidence.

Cyber Liability Essentials builds the governance foundation your firm needs to demonstrate due diligence — to a regulator, an insurer, or a plaintiff's attorney — when the question arrives.

PRICE: From $529/month

Most firms have policies. Almost none have evidence.

There is a difference between a cybersecurity policy and cybersecurity evidence. A policy describes what your firm intends to do. Evidence proves that the control is operational — tested, documented, and producible on 30 days’ notice.

DFS examiners do not read policy documents. They request the evidence. Cyber insurance underwriters do the same. So do plaintiff’s attorneys, when a breach produces litigation.

Cyber Liability Essentials closes that gap. It builds the documented program that makes your firm’s cybersecurity posture defensible — before someone officially asks you to prove it.

A governance program. Not a tool subscription.

Cyber Liability Essentials is not a software platform. It is not a monitoring dashboard. It is a documented governance program — built, maintained, and kept examination-ready by IT On Demand.

What that means in practice: the policies, assessments, vendor inventories, and documentation frameworks that produce proof of due diligence exist at your firm, are current, and are organized so that when an examiner or insurer asks for them, the answer is ready.

What the program produces.

  1. Compliance Gap Assessment — A private diagnostic identifying the specific evidence your firm has, what is missing, and what a DFS examiner would find if they arrived next month. This is the starting point for every engagement.
  2. Policy and procedure development — Written governance policies aligned to your applicable regulatory frameworks (23NYCRR500, SEC cybersecurity rules, ERISA DOL guidance). Written to be implemented, not filed.
  3. Vendor risk inventory — Identification and documentation of every third party with access to your nonpublic information. The foundation of a defensible vendor risk program.
  4. Incident response plan — A written IR plan designed for your firm’s size and regulatory environment. The starting document for the tabletop testing required under 23NYCRR500.
  5. Documentation framework — An organized, maintainable structure for your governance evidence — so that when the examiner arrives with a documentation request list, you produce answers, not apologies.

Is Cyber Liability Essentials the right fit?

IT IS FOR:
  • Regulated firms that have filed their DFS certifications in good faith but have not independently verified the evidence behind them
  • Firms that have received a documentation request from an examiner and discovered gaps they did not know existed
  • Firms approaching a cyber insurance renewal that requires evidence of governance controls
  • Managing partners or CCOs who want a clear picture of what their firm could actually produce under scrutiny
IT IS NOT FOR:
  • Firms that already have a documented, tested, and current governance program and need ongoing maintenance rather than a foundation build (see Cyber Watch or Cyber Liability Manager)
  • Firms whose primary need is IT support, network monitoring, or technology infrastructure management

Testimonial Placeholder

[Note: Insert 1–2 testimonials specific to this engagement tier, or the Weekend War Room story if Howard approves its use on this page. Placeholder below.]

TESTIMONIAL PLACEHOLDER: [INSERT: Client testimonial from a firm that engaged at the Essentials level — examination result, insurance renewal outcome, or gap closed before scrutiny arrived.]

Questions about Cyber Liability Essentials.

Start with the Assessment.

The Compliance Gap Assessment takes 30 minutes and tells you specifically what your firm has, what is missing, and what it would take to close the gap. No pitch. No obligation.

30 minutes. No obligation. Specific to your firm’s regulatory environment.