Drew Baker

Senior Consultant, Wipfli Advisory LLC

As a senior risk advisory services consultant, Drew Baker performs and assists with a variety of functions in System and Organization Controls (SOC) examinations, information technology (IT) general controls reviews, cybersecurity controls reviews, cybersecurity and IT consulting, and risk assessments. He works with a variety of clients, providing IT auditing in all areas of IT controls, including IT department organization and administration computer operations, logical and physical access controls, software change management, vendor due diligence and more.

  • SOC examinations
  • Technology audits
  • Cybersecurity
  • Risk assessments

  • Information Systems Audit and Control Association (ISACA) - Member

University of Southern Maine - Gorham, Maine
  • Bachelor of science degree in information technology
Expertise and services

INDUSTRY EXPERTISE

Latest case studies, resources, and insights

  • Image of a computer demonstrating network security strength.

    ARTICLE | TECHNOLOGY INDUSTRY

    How the Cloud Controls Matrix helps protect your organization

    Be proactive about data security with the Cloud Controls Matrix. Discover how this cloud security framework can help keep your organization’s information safe.

  • Can your SOC report replace vendor questionnaires?

    ARTICLE

    Can your SOC report replace vendor questionnaires?

    Vendor questionnaires are time-consuming. If you’ve undergone a SOC audit and have an up-to-date SOC report, do you really need to fill them out?

  • How to review vendor SOC reports

    ARTICLE | RISK ADVISORY

    How to review vendor SOC reports

    Reviewing a vendor’s SOC report is a key part of performing vendor due diligence. Here’s what you should be looking for in the report.