← Hearings

Legislative Audit Committee Hearing

Wednesday, January 28, 2026·1h 26m·▶ Watch / Listen

Colorado's IT agency arrived at the Legislative Audit Committee with a stark gap on the table: of 77 cybersecurity recommendations it had self-reported as nearly all complete, state auditors found only 10 were actually implemented. OIT's new leadership conceded the disconnect even as it disagreed outright with 37 of 85 fresh recommendations.

Key Actions

·OIT Cybersecurity Resilience IT Performance AuditPassed

Notable Quotes

In the 2023 resiliency audit, OIT submitted our responses stating we had fully implemented 70 of the 77 recommendations and partially implemented the remaining seven. In short, after a strong team effort, we we felt we had come very close to achieving our goal of 100% remediation and that we had valid reasons for partial implementation status for the remaining 7. However, OSA's review concluded that we had only fully implemented 10 recommendations, partially implemented 53 and not implemented 8.

David Edinger (Executive Director, OIT) · witnessThe core disconnect that set the tone for the hearing: a wide gap between OIT's self-assessment and the auditors' findings on the prior cybersecurity audit.

+ 5 more quotes

Unlock the full summary

Subscribe to see every key action, the full discussion, amendments, and notable quotes.

Sign in to subscribe
TranscriptPreview
Good early morning. The Legislative Audit Committee will come to order. Ms. Watson, will you please call the roll? Senators and Representatives Brooks. Present. Bacon, Johnson. Here. Helton. Here. Wiseman. Good morning. Wilford. Present, Madam Vice Chair. Present, Madam Chair. Present, Madam Chair. You have a quorum. Thank you, Ms. Watson. Members, may I have a motion to release the Governor's Office of Information Technology Cybersecurity Resilience IT Performance Audit Public Report dated January 2026. So. Moved. Second. Moved by the Vice Chair, seconded by Senator Pelton. Are any opposed? The audit is now released. Mr. Devlin? Yes. Thank you, Madam Chair. Pull this a little closer and. Good morning, members of the committee. My name is Matt Devlin. I'm the Chief IT Auditor at the osa. Here with me from our team is Cindy Radke, our IT Audit Manager. This morning, as mentioned, we're going to walk you through the results of our most recent IT audit of cybersecurity resiliency that we conducted at oit. This audit was a discretionary audit that we conducted based on risk and it was a follow up audit of prior IT audit conducted back in 2023 at OIT. In summary, our audit resulted
Continue reading

Subscribe to unlock the full transcript, summary, and the assistant across all Colorado committee hearings.

Sign in to subscribe