Cybersecurity
Organizations need an accurate and objective view of their cybersecurity profile to safeguard information assets and protect the organization's value.
Proactively protect and address your cybersecurity and information technology (IT) risks.
Information assets and technology investments left ungoverned and unprotected leave organizations vulnerable to compromise and loss of reputation, revenue/value, customers and intellectual property. Couple these risks with the increasing demands for transparency, accountability and compliance by regulators, government entities, shareholders and others, and you have a perfect storm of risks.
While sophisticated hacking is a valid threat to organizations, it is rarely the root cause of a data breach. The vast majority of data breaches and cybersecurity incidents are actually caused by a breakdown of basic cybersecurity processes and controls.
The Baker Tilly team provides comprehensive cybersecurity services to help organizations assess cyber risk, implement measurable security enhancements and improve control effectiveness. We will evaluate your cybersecurity controls, deliver recommended improvements and provide assurance that your cybersecurity controls are working.
Our solutions
Our clients count on our proactive, experienced cybersecurity services to manage cyber risk, helping them win now and anticipate tomorrow.

Cybersecurity and IT assessments
- System and Organization Controls (SOC) reporting
- IT and cybersecurity internal audits
- IT Sarbanes-Oxley (SOX) compliance
- Cybersecurity risk assessments: NIST CSF, ISO, CSC
- Technology due diligence
- Penetration testing and vulnerability assessment

Cybersecurity and privacy compliance
Certifications
- Cybersecurity Maturity Model Certification (CMMC)
- HITRUST
- International Organization for Standardization (ISO) certifications
Privacy compliance assessments
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
Security compliance assessments
- Cybersecurity Maturity Model Certification (CMMC)
- Health Insurance Portability and Accountability Act (HIPAA)
- Federal Risk and Authorization Management Program (FedRAMP)
- Microsoft Supplier Security & Privacy Assurance Program (Microsoft SSPA)
- New York State Department of Financial Services (NYSDFS)
- National Institute for Standards and Technology (NIST) 800-171
- National Institute for Standards and Technology (NIST) 800-53
- Payment Card Industry Data Security Standard (PCI DSS)