Examination-ready. Not just once — year-round.

Cyber Liability Manager is the full governance program for regulated firms with active DFS, SEC, or ERISA exposure. The difference between scrambling in April and being ready in January.

PRICE: From $2,179/month

For firms at this level, "adequate" is not a defensible standard.

The firms that need Cyber Liability Manager are the firms whose regulatory exposure does not allow room for a gap finding. Financial services firms under active DFS supervision. RIAs under SEC cybersecurity rules. Pension administrators under ERISA DOL guidance.

At this level, the annual certification is not a formality — it is a personal legal representation by the managing partner or CEO. The standard is not whether the program exists. It is whether the evidence of implementation is current, complete, and organized to survive a 30-day documentation request.

For most firms at this exposure level, the gap between that standard and what they currently have is significant. Cyber Liability Manager closes it — and keeps it closed.

The complete governance program. Maintained year-round.

Cyber Liability Manager is the most comprehensive governance engagement IT On Demand offers on a program basis. It covers the full scope of documentation, testing, verification, and ongoing maintenance required to maintain examination-ready posture across 38+ compliance framework mappings.
It includes a WISP (Written Information Security Program) that generates in one step — not a generic template, a firm-specific program aligned to your regulatory environment and kept current as that environment changes.
This is the engagement for firms that cannot afford the alternative.

What Cyber Liability Manager covers.

  1. Full Compliance Gap Assessment — Comprehensive diagnostic across all applicable regulatory frameworks. The starting point that defines the scope of what needs to be built, verified, or maintained.
  2. 38+ framework compliance mapping — Your governance program mapped to every applicable framework — 23NYCRR500, SEC cybersecurity rules, ERISA DOL guidance, SOC 2, ISO 27001, and others — so that a single examination readiness posture satisfies multiple regulatory obligations simultaneously.
  3. WISP generation and maintenance — A firm-specific Written Information Security Program that is generated, maintained, and kept current. Not a template. Not a one-time deliverable. A living document that reflects your actual environment.
  4. Penetration testing, remediation, and documentation — Third-party penetration test coordinated annually. All high and critical findings remediated with documented evidence. The exam-ready paper trail that examiners request by name.
  5. Vendor risk program — full lifecycle — Third-party inventory built, tiered by risk, maintained as relationships change, and documented to the standard DFS examiners examine.
  6. Incident response plan — built, tested, documented — IR plan written for your firm’s actual environment, tested through a live tabletop exercise, and documented with the proof of testing that 23NYCRR500 explicitly requires.
  7. MFA verification and documentation — Complete MFA coverage audit and documentation across all user populations, cloud infrastructure, and privileged accounts. Not assumed — verified.
  8. Board-level reporting — Governance reporting formatted for your board or senior leadership — the documentation that demonstrates the program is operating, not just existing.
  9. Examiner-ready binder — A unified documentation package: policy to evidence to outcome, organized and maintainable, producible on 30 days’ notice. The answer to every item on a DFS documentation request list.
  10. Regulatory monitoring and program updates — Continuous monitoring of DFS, SEC, and ERISA guidance. Program updated when requirements change. You are not finding out about a new obligation at the examination.

Is Cyber Liability Manager the right fit?

IT IS FOR:

  • Regulated firms with active DFS, SEC, or ERISA examination exposure that cannot afford a gap finding
  • Managing partners or CEOs whose names are on annual certifications and who need independent verification of the evidence behind their signature
  • CCOs managing multi-framework compliance programs who need year-round governance maintenance, not annual project work
  • Firms approaching a DFS examination cycle with known documentation gaps that need to be closed before the examination arrives
  • Firms that have received examination findings and need to build a remediation program that satisfies the examiner on the next cycle
IT IS NOT FOR:
  • Firms that need a foundational governance build from scratch (start with Cyber Liability Essentials; Cyber Liability Manager assumes a baseline exists or is being built simultaneously)
  • Firms whose complexity of regulatory exposure or board-level governance requirements warrants a dedicated advisory relationship (see Governance Advisory)

$3.5 million on the line. Four days to prove it.

When a New York actuarial firm came to us on a Thursday evening with a $3.5 million bid deadline by Monday and no compliance documentation, we ran a full governance build over the weekend: 23 policies written, management-approved, loaded into a GRC platform, employee sign-offs completed, and cybersecurity awareness training done — all anchored to a forward-looking roadmap across 23NYCRR500 and DOL frameworks.

Their submission was judged the most comprehensive of all vendors. They won the bid.

The following month, five more security questionnaires arrived from other clients. They answered all five in hours — because the evidence already existed.

A governance program does not just satisfy the examination in front of you. It answers every question that follows. That is the point.

Questions about Cyber Liability Manager.

Start with the Assessment.

The Compliance Gap Assessment identifies exactly what your firm has, what is missing, and what a DFS examiner would find if they arrived next month. It also confirms whether Cyber Liability Manager is the right fit for your situation — or whether a different engagement level makes more sense.

30 minutes. No pitch. No obligation.

30 minutes. No obligation. Specific to your firm’s regulatory environment.