The Security You Need.
The Compliance to Succeed.

We help innovative technology and cloud service providers simplify the path to security and compliance.


Join Us At HIMSS Global Health Conference & Exhibition

Find us in the Cybersecurity Command Center at the leading healthcare technology conference March 14-18 in Orlando.


BARR Certifications Earns Prestigious Accreditation for Certification to ISO/IEC 27001

Together, BARR Certifications and BARR Advisory are one of only nine firms in the nation that meet requirements of the ANAB and AICPA to issue both ISO/IEC 27001 certifications and SOC 2 audit reports


Diversity In Tech

Why we need it, how BARR is leading the charge, and how you can join us.


A Simple Introduction to the 18 CIS Controls

Explore the 18 CIS Controls and how you can easily implement them into your cybersecurity program.


Introducing People & Culture Services

Now offering personalized HR and talent solutions for your growing business.


Our Approach: Simplify and Customize

We go beyond the compliance checklist and assess all aspects of your organization’s unique environment, identifying risks, areas for improvement and simplifying the processes and controls needed to turn compliance into a strategic asset. 2.svg

Plan and Scope

We believe in determining the why before proposing the how and that careful planning is imperative to achieve your business objectives. We simplify complex projects by defining roles, responsibilities
and setting clear expectations
over project scope. .svg


We take a comprehensive approach toward assessment. By identifying business issues and opportunities at every level, we simplify solutions and turn risks and complex compliance requirements into a competitive advantage for your organization.

Report and Comply

Whether we are performing a compliance examination, risk assessment or CISO advisory services, we deliver the highest quality reports. To ensure accuracy, our technical writing team reviews all reports prior to distribution.


Our approach enables organizational alignment, integration of business processes and continuous improvement. Our commitment to you extends far beyond our final deliverables. We follow up to ensure our work infuses value in your organization.

Cybersecurity Risk Management, Compliance, and Advisory Services

At BARR, we simplify compliance across multiple regulatory and customer requirements in a wide range of industries including technology, financial services, healthcare and government. Explore our services below.

SOC Examinations

Differentiate your organization by providing your stakeholders with a System and Organization Controls (SOC) report that demonstrates your commitment to confidentiality, integrity and availability. BARR is here to assist you with the following audit reports:


Focuses on controls that are relevant to an audit of your clients’ financial statements.

SOC 2 and SOC 3

Reports apply more broadly to operational controls covering security, availability, confidentiality, processing integrity, and/or privacy across a variety of systems.

SOC for Cybersecurity

Demonstrates that effective processes and controls are in place to detect, mitigate, and recover from breaches and other security events.

Healthcare Compliance

From HIPAA to HITRUST compliance challenges, our service professionals can help you navigate the complex healthcare rules and risks associated with business associates who handle e-PHI.

Certification to ISO Standards

ISO 27001, ISO 27017, and ISO 27018 are internationally accepted standards that demonstrate your organization’s commitment to information security risk management. Let us help you with your ISMS.

Government Assessments

As an accredited Third-Party Assessment Organization (3PAO), we provide independent assessment services to cloud providers. We follow the ‘do once, use many times’ framework to help organizations streamline complicated government mandates.

Payment Card Industry (PCI) Services

If you store, process, or transmit credit card data either as a merchant, processor, or service provider, then the Payment Card Industry Data Security Standard (PCI DSS) applies to you. Our focus is helping your organization achieve PCI compliance.

Penetration Testing and Vulnerability Assessments

Whether it’s an Infrastructure as a Service (IaaS), Platform as a Service (PaaS) or Software as a Service (SaaS), our specialists have extensive experience in penetration testing for cloud-based environments.

IT Governance Risk and Compliance (GRC) Advisory

BARR Advisory provides governance, risk and compliance (GRC) services to help clients improve risk management, streamline information security processes and reduce cost.

Who We Serve

BARR is a trusted cybersecurity advisor to some of the fastest growing cloud service providers (IaaS, PaaS, SaaS) from around the world operating in the most regulated industries.

We are very impressed with BARR. We felt confident during our SOC 2 audit, knowing that BARR had the right competence and would help us along the way.

ANNA BURMANCOO and Data Protection Officer, 84codes

It’s odd to say that it was a pleasure doing business with an auditor. However, that was definitely our experience with BARR Advisory. We give BARR our highest recommendation.

EDITH HANEYEVP, General Counsel & Compliance Officer, Fogo Data Centers

BARR Advisory ran a very efficient process that used my time in a very efficient way. I would recommend their services to everybody looking for an efficient SOC 2 certification process.


The work with BARR Advisory has proven to be an asset to our company and our clients; we are truly appreciative.

DOLLY KRISHNASWAMYGlobal IP Strategist & Security, Alphaserve Technologies

BARR's friendly and professional auditors led us through two audit periods, and helped us affect lasting security measures while increasing company efficiency. We highly recommended them.


Everyone who met with Brad and his team said they loved spending time with them, which is the weirdest reaction to an auditor interview I’ve ever gotten.


BARR Advisory ran a highly structured and transparent process with a clear articulation of what was needed to achieve date-driven milestones. They are the definition of professional, thorough, and high-quality. It also helped enormously to do the readiness report with them first to understand the journey ahead.

ROGER ARNEMANNChief Operating Officer, Nomis Solutions

The audit process is perfectly painless and I truly enjoy working with the team at BARR. We have worked with several auditors from BARR and each one has been organized, clear in their requests and a pleasure to work with. I am looking forward to next year's audit (hard to believe, I know!).

ABBY HORNDirector of Operations, INOC Data Centers

This was the first SOC 2 audit for Mylo, and BARR Advisory made the process very smooth and understandable. We gained a lot of benefit by doing a Readiness Assessment with them first, so that when the audit started, we were well prepared. We are very happy with the content of the report and look forward to working with BARR again.

ANGELA ROBERTSONSecurity and Compliance Director, Mylo

BARR Advisory is a critical component for suggestions and accountability towards continuous improvements in our platform's security and privacy controls.

JAMES METZGERDirector of Compliance, HealthTap Technologies, Inc.

Save Yourself Time By Using Salient

Handling how you manage payments online is very important. Salient is a new innovative and easy to use method of sending & receiving money online. It’s fast, secure and free to sign up.

  • Top Customer Support
  • Most Liked Company
  • Best In Class 2016
  • Friendliest Group
  • Innovative Brand

Security Automation: Tips on How to Do More with Less

| Automation | No Comments

Automation at its core is about combining the manual with mechanics. Even before the invention of the computer, humans have automated the production processes with external tools. When the wheel…

Everything You Need to Know About the SOC Audit Process: Part 1—Readiness Assessment 

| Uncategorized | No Comments

Many organizations choose to complete a readiness assessment prior to their System and Organization Controls (SOC) examination. The readiness period of your SOC audit prepares your organization’s policies and procedures…

How Much Should We Spend on Cybersecurity?

| Company Culture, Security | No Comments

Data breaches can have disastrous consequences, particularly for startups or small to medium-sized businesses. According to Cybercrime Magazine, 60 percent of small companies go out of business within six months…

Data from vulnerability scanning.

Vulnerability Scans vs. Penetration Tests: Differences, Benefits, Limitations, and BARR’s Distinctive Approach

| Cyber Hygiene, Data Privacy, Risk Management, Security, Vulnerability Management | No Comments

Vulnerability scans and penetration tests—they sound similar, right? Some use them interchangeably, but the truth is these terms are quite different when it comes to how they are carried out,…

Contact Us for a Free Consultation

We’re here to help you! Speak with a BARR specialist about your security and compliance needs.