Colorado's IT Office Told Auditors It Won't Fix Security Gaps
Summary
A January 2026 Colorado State Auditor follow-up found the Governor's Office of Information Technology, which runs IT security for more than 200 critical state systems across nearly every executive-branch agency, had fully implemented only 10 of the 71 cybersecurity recommendations still open from a 2023 audit -- missing the June 30, 2025 deadline its own Chief Information Officer set. For the one fix OIT had already promised once and broken -- role-based security training for the staff who manage agency systems -- OIT told auditors this year it does not plan to build it, disagreeing with 6 of the 7 new recommendations meant to force the issue.
A promise made mid-audit, and missed
The story starts with the May 2023 audit⧉, which found OIT had not clearly defined who -- OIT, the agencies it serves, or outside vendors -- was responsible for which security tasks, had not established minimum security requirements for key activities like audit logging and account reviews, and had not built an effective way to prioritize the more than 200 critical and essential IT systems spread across Colorado's consolidated agencies. That audit made 77 recommendations; OIT agreed with 56 of them, partially agreed with 16, and disagreed with only 5.
OIT did not keep pace with its own agreements. By July 2024, OIT's own status report to the legislature's Joint Legislative Audit Committee showed 71 of the 77 recommendations still not fully implemented. Then, in April 2025 -- partway through the audit that produced this year's report -- OIT's Chief Information Officer told auditors the office planned to finish all 71 by June 30, 2025.
View data as table
| Implemented | 10 (14%) |
|---|---|
| Partially implemented | 53 (75%) |
| Not implemented | 8 (11%) |
The training fix OIT now says it won't build
The clearest break from that promise is in security training. In 2023, OIT agreed to build formal, role-based training explaining security responsibilities to the "Business Owners" who run agency systems and to OIT's own IT Directors, with a target date it later moved up to December 2024. By this audit, OIT reported the training still was not built by June 30, 2025 -- and told auditors it does not plan to implement what it originally agreed to.
Auditors responded with a new seven-part recommendation to force the issue. OIT disagreed with six of the seven parts⧉, marking each one's implementation date "Not Applicable" and stating that its new security policy "does not require role-based security training." The auditor's addendum pushes back directly: OIT's own December 2024 policy, in force throughout the audit, does require exactly that training -- for both agency staff and OIT's IT Directors. In the report's other public finding, on IT governance, the auditor's addenda go further still, stating three separate times that it is plainly "unclear what OIT is disagreeing with in the recommendation."
From five disagreements to thirty-seven
This year's audit issued 85 new recommendations covering both public findings and ten additional findings the state keeps confidential because they describe specific technical vulnerabilities. OIT agreed with 18 of the 85, partially agreed with 30, and disagreed with 37 -- a 43.5% disagreement rate, up from the 6.5% rate (5 of 77) OIT posted on the original 2023 audit. Auditors warn that leaving the underlying gaps unresolved means OIT "may not be able to fully meet its statutory responsibilities to ensure that information Colorado's citizens have entrusted to state agencies is safe, secure and protected from unauthorized access, unauthorized use, or destruction."
View data as table
| 2023 audit (77 recs.) | 56 agree / 16 partial / 5 disagree |
|---|---|
| 2026 follow-up (85 recs.) | 18 agree / 30 partial / 37 disagree |
The takeaway
- Only 14% of the outstanding 2023 fixes were actually finished. OIT's own Chief Information Officer told auditors in April 2025 that all 71 remaining recommendations from the May 2023 cybersecurity audit would be implemented by June 30, 2025; the follow-up found just 10 fully done, 53 partially done, and 8 not started.
- OIT now refuses to build the training it already promised. After not delivering the role-based security training it agreed to in 2023, OIT told this year's auditors it does not plan to implement what it originally agreed to -- and disagreed with 6 of 7 new recommendation parts meant to force the fix, despite its own written security policy requiring exactly that training.
- OIT's cooperation with its own auditor collapsed. OIT disagreed with 6.5% of the original 2023 audit's recommendations; in this follow-up, after years of unaddressed findings, it disagreed with 43.5% of the 85 new ones -- even as the auditor's office is the state's centralized IT provider for more than 200 critical systems across nearly every executive-branch agency.
All figures are from two Colorado Office of the State Auditor performance audits of the Governor's Office of Information Technology -- Report 2250P-IT (May 2023, conducted by contracted CPA firm Eide Bailly LLP) and Report 2551P-IT (January 21, 2026, the follow-up) -- and the follow-up's own two-page Report Highlights summary, all read in full via direct PDF fetch and pdftotext extraction. Ten additional findings in the 2026 follow-up (covering Asset Management, Contingency Planning, Identification and Authentication, Incident Response, Logging and Monitoring, Physical Access, Risk Management, Security Planning, User Access Management, and Vulnerability and Patch Management) were issued in a separate confidential report under government auditing standards for sensitive IT-security detail and are not part of this piece's sourcing. Archive.org Save Page Now captures succeeded for all three documents.
The 85.9% not-fully-resolved share, the 6.5%-to-43.5% disagreement-rate comparison, and the 37.0-percentage-point increase are this outlet's own arithmetic on the audits' own figures (methods and caveats in analysis.json); the reports state each underlying count individually but do not themselves state these derived comparisons. A blind adversarial verifier, working from the primary documents alone with no access to this draft, independently checked every itemized fact; see verification.json.
Sources(3) ▾
- Colorado Office of the State Auditor, Cybersecurity Resiliency, Governor's Office of Information Technology — IT Performance Audit, Public Report (Report 2551P-IT) (2026-01-21) — The primary document: the State Auditor's follow-up IT performance audit testing whether the Governor's Office of Information Technology (OIT) implemented the 77 recommendations from the May 2023 cybersecurity resiliency audit. Source for the 71-recommendation follow-up count and its implemented/partially-implemented/not-implemented breakdown, the June 30, 2025 self-reported completion date, the two public findings (IT Governance; Information Security Training and Awareness) and their full recommendation-and-response text, the 85 new recommendations and their Agree/Partially Agree/Disagree counts, and the OIT- April 2025 statement about finishing all 71 by June 30, 2025. content.leg.colorado.gov · original document
- Colorado Office of the State Auditor, Report Highlights: Cybersecurity Resiliency, Governor's Office of Information Technology (2551P-IT) (2026-01-21) — The auditor's own two-page public summary of Report 2551P-IT, issued alongside the full report. Source for the top-line 85 Audit Recommendations Made / 18 Agree / 30 Partially Agree / 37 Disagree box, cross-confirming the full report's disaggregated response tables. content.leg.colorado.gov · original document
- Colorado Office of the State Auditor, Audit of Cybersecurity Resiliency at the Governor's Office of Information Technology, Public Report (Report 2250P-IT) (2023-05-01) — The original May 2023 audit that Report 2551P-IT is following up on. Source for the original 77-recommendation count and its Agree (56) / Partially Agree (16) / Disagree (5) response breakdown, the original findings on IT governance and security training, and the more-than-200 critical-and-essential-systems figure describing OIT's footprint across Colorado's consolidated executive-branch agencies. content.leg.colorado.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The Colorado Office of the State Auditor⧉ released a follow-up performance audit on January 21, 2026 testing whether the Governor's Office of Information Technology⧉ (OIT) -- the agency that runs IT for nearly every executive-branch department in state government -- had fixed the cybersecurity gaps a 2023 audit found. Of the 71 recommendations still open going into this follow-up, auditors found OIT had fully implemented just 10 of them (14%) by June 30, 2025, the date OIT's own Chief Information Officer told auditors, in April 2025, that all 71 would be finished.