For firms that require full governance ownership.

Some regulatory environments are too complex for a managed program. For the right firm, IT On Demand can own the governance layer entirely — providing strategic oversight at the executive level, year-round.

If this engagement is relevant to your situation, it surfaces through the relationship. The first step is a conversation.

This is not a program tier. It is a different kind of engagement.

Cyber Liability Essentials, Cyber Watch, and Cyber Liability Manager are governance programs. They are structured, scoped, and priced to serve a defined range of regulated firms.

Governance Advisory is a strategic engagement. It is appropriate for firms where the complexity of regulatory exposure — multiple frameworks, board-level governance requirements, ongoing examination cycles, or significant personal liability concentration in one or two senior officers — warrants a governance partner, not a governance vendor.

In a Governance Advisory engagement, Howard works directly with your senior leadership. The governance layer is not managed on your behalf. It is owned on your behalf — with Howard’s expertise, judgment, and regulatory fluency operating as a function of your firm’s leadership team rather than a service delivered to it.

This is not the right fit for every firm. We do not position it as a starting point. If the scope of what we discover during your initial engagement warrants this conversation, we will have it.

The situations where advisory engagement is the right answer.

There are specific circumstances where a managed program, no matter how well built, is not sufficient for the firm’s exposure:

  • Multi-framework complexity — When a firm operates under DFS, SEC cybersecurity rules, ERISA DOL guidance, and additional frameworks simultaneously, the governance program requires continuous strategic judgment, not just maintenance.
  • Personal liability concentration — When the managing partner or CEO carries concentrated personal liability from multiple annual certifications across multiple regulatory bodies, the governance function needs to operate at a level that matches that exposure.
  • Board-level governance requirements — When the board or senior leadership requires active governance reporting, incident response leadership, or strategic oversight that a program engagement cannot provide.
  • Pre-examination or post-finding remediation — When a firm is entering a high-stakes examination cycle or has received prior findings, and the cost of a gap finding is not acceptable.
  • Risk transfer — The only engagement in this market where the governance liability moves from client to firm. When that level of risk transfer is the objective, it requires a different structure than a program engagement.

What Howard brings to an advisory engagement.

Howard Globus has managed regulatory examinations from both sides of the table — as CIO/CISO at a $2 billion AUM reinsurance firm subject to DFS oversight, and as the governance partner helping regulated firms build the programs that hold up under that same oversight.

In a Governance Advisory engagement, that experience operates as a resource available to your firm’s leadership — not as a consultant delivering a report, but as a governance function present in the room where the decisions are made.

This is not a junior associate account team. It is Howard, directly, in the engagement your firm’s exposure requires.

The right engagement surfaces through the relationship.

We do not begin with a Governance Advisory. We begin with the Compliance Gap Assessment — a 30-minute diagnostic that tells us both exactly where your firm stands and whether your situation warrants this kind of engagement.

If it does, that conversation happens then. If a managed program is the right fit, we build that instead.

Either way, the starting point is the same.