Examination-ready. Not just once — year-round.
Cyber Liability Manager is the full governance program for regulated firms with active DFS, SEC, or ERISA exposure. The difference between scrambling in April and being ready in January.
PRICE: From $2,179/month
For firms at this level, "adequate" is not a defensible standard.
The firms that need Cyber Liability Manager are the firms whose regulatory exposure does not allow room for a gap finding. Financial services firms under active DFS supervision. RIAs under SEC cybersecurity rules. Pension administrators under ERISA DOL guidance.
At this level, the annual certification is not a formality — it is a personal legal representation by the managing partner or CEO. The standard is not whether the program exists. It is whether the evidence of implementation is current, complete, and organized to survive a 30-day documentation request.
For most firms at this exposure level, the gap between that standard and what they currently have is significant. Cyber Liability Manager closes it — and keeps it closed.
The complete governance program. Maintained year-round.
What Cyber Liability Manager covers.
- Full Compliance Gap Assessment — Comprehensive diagnostic across all applicable regulatory frameworks. The starting point that defines the scope of what needs to be built, verified, or maintained.
- 38+ framework compliance mapping — Your governance program mapped to every applicable framework — 23NYCRR500, SEC cybersecurity rules, ERISA DOL guidance, SOC 2, ISO 27001, and others — so that a single examination readiness posture satisfies multiple regulatory obligations simultaneously.
- WISP generation and maintenance — A firm-specific Written Information Security Program that is generated, maintained, and kept current. Not a template. Not a one-time deliverable. A living document that reflects your actual environment.
- Penetration testing, remediation, and documentation — Third-party penetration test coordinated annually. All high and critical findings remediated with documented evidence. The exam-ready paper trail that examiners request by name.
- Vendor risk program — full lifecycle — Third-party inventory built, tiered by risk, maintained as relationships change, and documented to the standard DFS examiners examine.
- Incident response plan — built, tested, documented — IR plan written for your firm’s actual environment, tested through a live tabletop exercise, and documented with the proof of testing that 23NYCRR500 explicitly requires.
- MFA verification and documentation — Complete MFA coverage audit and documentation across all user populations, cloud infrastructure, and privileged accounts. Not assumed — verified.
- Board-level reporting — Governance reporting formatted for your board or senior leadership — the documentation that demonstrates the program is operating, not just existing.
- Examiner-ready binder — A unified documentation package: policy to evidence to outcome, organized and maintainable, producible on 30 days’ notice. The answer to every item on a DFS documentation request list.
- Regulatory monitoring and program updates — Continuous monitoring of DFS, SEC, and ERISA guidance. Program updated when requirements change. You are not finding out about a new obligation at the examination.
Is Cyber Liability Manager the right fit?
IT IS FOR:
- Regulated firms with active DFS, SEC, or ERISA examination exposure that cannot afford a gap finding
- Managing partners or CEOs whose names are on annual certifications and who need independent verification of the evidence behind their signature
- CCOs managing multi-framework compliance programs who need year-round governance maintenance, not annual project work
- Firms approaching a DFS examination cycle with known documentation gaps that need to be closed before the examination arrives
- Firms that have received examination findings and need to build a remediation program that satisfies the examiner on the next cycle
- Firms that need a foundational governance build from scratch (start with Cyber Liability Essentials; Cyber Liability Manager assumes a baseline exists or is being built simultaneously)
- Firms whose complexity of regulatory exposure or board-level governance requirements warrants a dedicated advisory relationship (see Governance Advisory)
$3.5 million on the line. Four days to prove it.
When a New York actuarial firm came to us on a Thursday evening with a $3.5 million bid deadline by Monday and no compliance documentation, we ran a full governance build over the weekend: 23 policies written, management-approved, loaded into a GRC platform, employee sign-offs completed, and cybersecurity awareness training done — all anchored to a forward-looking roadmap across 23NYCRR500 and DOL frameworks.
Their submission was judged the most comprehensive of all vendors. They won the bid.
The following month, five more security questionnaires arrived from other clients. They answered all five in hours — because the evidence already existed.
A governance program does not just satisfy the examination in front of you. It answers every question that follows. That is the point.
Questions about Cyber Liability Manager.
- Q: What does "38+ framework compliance mapping" mean in practice?
- A: It means your governance program is built to satisfy multiple regulatory obligations simultaneously — not re-architected each time a new framework applies. 23NYCRR500, SEC cybersecurity rules, ERISA DOL guidance, SOC 2, ISO 27001, and others. Where frameworks overlap, the program addresses both without duplication. Where they diverge, the documentation reflects both requirements. You are not managing separate programs for separate regulators.
- Q: What is a WISP and why does it matter?
- A: A Written Information Security Program is the foundational governance document that most DFS-regulated firms are required to maintain. Most firms have a generic version — a template that was filled in once and has not been updated since. The WISP in Cyber Liability Manager is firm-specific, reflects your actual environment and regulatory exposure, and is maintained as both change. When an examiner asks for it, it is current.
- Q: How is Cyber Liability Manager different from having an internal compliance officer?
- A: A compliance officer files the documents. Cyber Liability Manager produces the evidence that the compliance officer's filings are defensible. They address different layers of the same obligation. Most of our Cyber Liability Manager clients have a compliance officer or general counsel — and those individuals find the program valuable precisely because it produces what they need to do their job under examination conditions.
- Q: What is the difference between Cyber Liability Manager and the Governance Advisory engagement?
- A: Cyber Liability Manager is a comprehensive program engagement. Governance Advisory is a strategic engagement for firms where the complexity of regulatory exposure, board-level governance requirements, or ongoing risk transfer warrants Howard's direct, senior-level involvement as a governance function rather than a vendor. Advisory engagements are not listed on a menu — they surface through the relationship when the situation warrants them.
Start with the Assessment.
The Compliance Gap Assessment identifies exactly what your firm has, what is missing, and what a DFS examiner would find if they arrived next month. It also confirms whether Cyber Liability Manager is the right fit for your situation — or whether a different engagement level makes more sense.
30 minutes. No pitch. No obligation.
30 minutes. No obligation. Specific to your firm’s regulatory environment.