BlackLeafwatch the watchmen
Colorado Governor's Office of Information Technology (OIT) cybersecurity oversight

Colorado's IT Office Told Auditors It Won't Fix Security Gaps

Summary

A January 2026 Colorado State Auditor follow-up found the Governor's Office of Information Technology, which runs IT security for more than 200 critical state systems across nearly every executive-branch agency, had fully implemented only 10 of the 71 cybersecurity recommendations still open from a 2023 audit -- missing the June 30, 2025 deadline its own Chief Information Officer set. For the one fix OIT had already promised once and broken -- role-based security training for the staff who manage agency systems -- OIT told auditors this year it does not plan to build it, disagreeing with 6 of the 7 new recommendations meant to force the issue.

By Frontinus · July 19, 2026

The Colorado Office of the State Auditor released a follow-up performance audit on January 21, 2026 testing whether the Governor's Office of Information Technology (OIT) -- the agency that runs IT for nearly every executive-branch department in state government -- had fixed the cybersecurity gaps a 2023 audit found. Of the 71 recommendations still open going into this follow-up, auditors found OIT had fully implemented just 10 of them (14%) by June 30, 2025, the date OIT's own Chief Information Officer told auditors, in April 2025, that all 71 would be finished.

A promise made mid-audit, and missed

The story starts with the May 2023 audit, which found OIT had not clearly defined who -- OIT, the agencies it serves, or outside vendors -- was responsible for which security tasks, had not established minimum security requirements for key activities like audit logging and account reviews, and had not built an effective way to prioritize the more than 200 critical and essential IT systems spread across Colorado's consolidated agencies. That audit made 77 recommendations; OIT agreed with 56 of them, partially agreed with 16, and disagreed with only 5.

OIT did not keep pace with its own agreements. By July 2024, OIT's own status report to the legislature's Joint Legislative Audit Committee showed 71 of the 77 recommendations still not fully implemented. Then, in April 2025 -- partway through the audit that produced this year's report -- OIT's Chief Information Officer told auditors the office planned to finish all 71 by June 30, 2025.

OIT missed its own June 2025 deadline on nearly 86% of what it still owed
Status of the 71 recommendations from the May 2023 audit still open going into the follow-up, as of June 30, 2025
Implemented
10
Partially implemented
53
Not implemented
8
Source: Colorado Office of the State Auditor, Report 2551P-IT, Report Highlights
View data as table
Of the 71 May-2023 recommendations still open when this follow-up audit began, only 10 were fully implemented by June 30, 2025 -- the date OIT's own Chief Information Officer told auditors, in April 2025, that all 71 would be finished.
Implemented10 (14%)
Partially implemented53 (75%)
Not implemented8 (11%)

The training fix OIT now says it won't build

The clearest break from that promise is in security training. In 2023, OIT agreed to build formal, role-based training explaining security responsibilities to the "Business Owners" who run agency systems and to OIT's own IT Directors, with a target date it later moved up to December 2024. By this audit, OIT reported the training still was not built by June 30, 2025 -- and told auditors it does not plan to implement what it originally agreed to.

Auditors responded with a new seven-part recommendation to force the issue. OIT disagreed with six of the seven parts, marking each one's implementation date "Not Applicable" and stating that its new security policy "does not require role-based security training." The auditor's addendum pushes back directly: OIT's own December 2024 policy, in force throughout the audit, does require exactly that training -- for both agency staff and OIT's IT Directors. In the report's other public finding, on IT governance, the auditor's addenda go further still, stating three separate times that it is plainly "unclear what OIT is disagreeing with in the recommendation."

Prior recommendations still open past deadline
61 of 71
partially implemented or not implemented at all as of June 30, 2025 -- the date OIT's own Chief Information Officer told auditors, in April 2025, that every one of the 71 would be finished
OIT's disagreement rate, 2023 audit vs. 2026 follow-up
6.5% -> 43.5%
5 of 77 recommendations disagreed with in 2023, versus 37 of 85 new recommendations disagreed with in this follow-up
New security-training fixes OIT rejected outright
6 of 7
parts of the new training recommendation OIT disagreed with, after not implementing the role-based training it had already agreed, in 2023, to build

From five disagreements to thirty-seven

This year's audit issued 85 new recommendations covering both public findings and ten additional findings the state keeps confidential because they describe specific technical vulnerabilities. OIT agreed with 18 of the 85, partially agreed with 30, and disagreed with 37 -- a 43.5% disagreement rate, up from the 6.5% rate (5 of 77) OIT posted on the original 2023 audit. Auditors warn that leaving the underlying gaps unresolved means OIT "may not be able to fully meet its statutory responsibilities to ensure that information Colorado's citizens have entrusted to state agencies is safe, secure and protected from unauthorized access, unauthorized use, or destruction."

OIT's disagreement rate with its own auditor more than tripled
How OIT responded to the auditor's recommendations, 2023 audit vs. this 2026 follow-up
2023 - Agree
72.7%
2023 - Partially agree
20.8%
2023 - Disagree
6.5%
2026 - Agree
21.2%
2026 - Partially agree
35.3%
2026 - Disagree
43.5%
Source: Colorado Office of the State Auditor, Report 2250P-IT (2023) and Report 2551P-IT (2026), Report Highlights
View data as table
In the original 2023 audit OIT disagreed with just 5 of 77 recommendations (6.5%). In this follow-up, after three years of largely unaddressed findings, OIT disagreed with 37 of 85 new recommendations (43.5%) -- including 6 of the 7 new fixes proposed for the security-training gap it had already agreed, and failed, to fix once.
2023 audit (77 recs.)56 agree / 16 partial / 5 disagree
2026 follow-up (85 recs.)18 agree / 30 partial / 37 disagree

The takeaway

  • Only 14% of the outstanding 2023 fixes were actually finished. OIT's own Chief Information Officer told auditors in April 2025 that all 71 remaining recommendations from the May 2023 cybersecurity audit would be implemented by June 30, 2025; the follow-up found just 10 fully done, 53 partially done, and 8 not started.
  • OIT now refuses to build the training it already promised. After not delivering the role-based security training it agreed to in 2023, OIT told this year's auditors it does not plan to implement what it originally agreed to -- and disagreed with 6 of 7 new recommendation parts meant to force the fix, despite its own written security policy requiring exactly that training.
  • OIT's cooperation with its own auditor collapsed. OIT disagreed with 6.5% of the original 2023 audit's recommendations; in this follow-up, after years of unaddressed findings, it disagreed with 43.5% of the 85 new ones -- even as the auditor's office is the state's centralized IT provider for more than 200 critical systems across nearly every executive-branch agency.

All figures are from two Colorado Office of the State Auditor performance audits of the Governor's Office of Information Technology -- Report 2250P-IT (May 2023, conducted by contracted CPA firm Eide Bailly LLP) and Report 2551P-IT (January 21, 2026, the follow-up) -- and the follow-up's own two-page Report Highlights summary, all read in full via direct PDF fetch and pdftotext extraction. Ten additional findings in the 2026 follow-up (covering Asset Management, Contingency Planning, Identification and Authentication, Incident Response, Logging and Monitoring, Physical Access, Risk Management, Security Planning, User Access Management, and Vulnerability and Patch Management) were issued in a separate confidential report under government auditing standards for sensitive IT-security detail and are not part of this piece's sourcing. Archive.org Save Page Now captures succeeded for all three documents.

The 85.9% not-fully-resolved share, the 6.5%-to-43.5% disagreement-rate comparison, and the 37.0-percentage-point increase are this outlet's own arithmetic on the audits' own figures (methods and caveats in analysis.json); the reports state each underlying count individually but do not themselves state these derived comparisons. A blind adversarial verifier, working from the primary documents alone with no access to this draft, independently checked every itemized fact; see verification.json.

Sources(3) ▾
  • Colorado Office of the State Auditor, Cybersecurity Resiliency, Governor's Office of Information Technology — IT Performance Audit, Public Report (Report 2551P-IT) (2026-01-21)The primary document: the State Auditor's follow-up IT performance audit testing whether the Governor's Office of Information Technology (OIT) implemented the 77 recommendations from the May 2023 cybersecurity resiliency audit. Source for the 71-recommendation follow-up count and its implemented/partially-implemented/not-implemented breakdown, the June 30, 2025 self-reported completion date, the two public findings (IT Governance; Information Security Training and Awareness) and their full recommendation-and-response text, the 85 new recommendations and their Agree/Partially Agree/Disagree counts, and the OIT- April 2025 statement about finishing all 71 by June 30, 2025. content.leg.colorado.gov · original document
  • Colorado Office of the State Auditor, Report Highlights: Cybersecurity Resiliency, Governor's Office of Information Technology (2551P-IT) (2026-01-21)The auditor's own two-page public summary of Report 2551P-IT, issued alongside the full report. Source for the top-line 85 Audit Recommendations Made / 18 Agree / 30 Partially Agree / 37 Disagree box, cross-confirming the full report's disaggregated response tables. content.leg.colorado.gov · original document
  • Colorado Office of the State Auditor, Audit of Cybersecurity Resiliency at the Governor's Office of Information Technology, Public Report (Report 2250P-IT) (2023-05-01)The original May 2023 audit that Report 2551P-IT is following up on. Source for the original 77-recommendation count and its Agree (56) / Partially Agree (16) / Disagree (5) response breakdown, the original findings on IT governance and security training, and the more-than-200 critical-and-essential-systems figure describing OIT's footprint across Colorado's consolidated executive-branch agencies. content.leg.colorado.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account