The DFS certification your firm signs every April is a personal legal representation. We build the evidence behind it.

IT On Demand serves New York financial services firms operating under 23NYCRR500 — building and maintaining the governance documentation that makes the annual certification defensible.

What 23NYCRR500 actually requires — and what most firms don't have.

New York’s cybersecurity regulation for financial services firms does not require tools. It requires evidence — documented proof that specific controls are implemented, tested, and operational at your firm.

The annual certification filed with DFS is not an administrative filing. It is a personal attestation by the covered entity’s senior officer that the firm’s cybersecurity program meets the requirements of the regulation. When an examiner arrives and finds a gap between what was certified and what the evidence shows, the liability belongs to the person who signed it.

Most DFS-covered firms have IT providers managing their systems and compliance officers filing on time. What they do not have is anyone producing the evidence that sits between those two functions — the penetration test remediation logs, vendor risk assessments, tested incident response plans, and MFA verification records that an examiner will request by name.

That is the documentation gap. And it is the gap IT On Demand was built to close.

When a DFS examiner arrives, here is what they ask for.

A DFS examination of a financial services firm under 23NYCRR500 is not a technology audit. It is a governance audit. Examiners work from a documentation request list. The items they request — consistently, across examinations — include:

  • Third-party penetration test report with remediation evidence for all high and critical findings
  • Vendor risk assessment inventory — every third party with access to nonpublic information, tiered by risk
  • Tested incident response plan — including documented proof that the plan was tested, not just written
  • MFA verification records — coverage documentation across all user populations, cloud infrastructure, and privileged accounts
  • Written Information Security Program (WISP) — current, firm-specific, not a generic template
  • Board-level governance reporting — evidence that the program is actively managed, not just filed
If your firm cannot produce these documents in 30 days, the examination will find a gap. The finding belongs to the person who signed the certification.

We own the governance layer. Your IT provider owns the systems. Your compliance officer owns the filings.

IT On Demand does not replace your IT provider or your compliance officer. We fill the gap between them — the layer that is unowned in most financial services firms and is exactly what DFS examiners examine.

We build, document, and maintain the evidence your firm needs to certify with confidence: the penetration test documentation, the vendor risk program, the tested IR plan, the MFA verification records, and the WISP that reflects your actual environment and regulatory exposure.

Year-round. Not on a deadline.

The firms we know best.

Our financial services clients are typically mid-market firms — 25 to 200 employees, $10 million to $500 million in AUM or revenue, operating under active DFS supervision with no dedicated in-house CISO.

The decision-maker is usually the managing partner or CEO whose name is on the DFS annual certification, or the CCO or General Counsel managing the compliance program. In most cases, neither has had a clear picture of what specific evidence exists behind the certification they file. The Compliance Gap Assessment changes that.

Questions we hear from financial services firms.

Find out exactly what your firm could produce under examination today.

The Compliance Gap Assessment is a 30-minute, private diagnostic. We look at your firm’s specific regulatory exposure, what evidence exists, and what a DFS examiner would find if they arrived next month. No pitch. No obligation. A clear picture of where you stand.