Be On The Record
BlogSign inSubscribe
HearingsBillsAlerts
← Hearings

Legislative Audit Committee Hearing

Wednesday, January 28, 2026·1h 26m·▶ Watch / Listen

The Colorado Legislative Audit Committee received a follow-up IT performance audit of the Governor's Office of Information Technology (OIT) on cybersecurity resilience, revealing that OIT had failed to fully implement the vast majority of 71 open recommendations from a May 2023 audit — producing 12 new findings and 85 new recommendations — while OIT disagreed outright with 37 of those 85 recommendations, prompting sharp questioning from committee members about accountability, documentation failures, and the adequacy of OIT's cybersecurity posture. The committee released the public audit report by voice vote and then voted to go into executive session to hear the confidential portion of the audit, with the chair confirming that two-thirds of the committee membership was present and stating the ayes had it; no legislative action was taken on the audit recommendations, and no outcome of the executive session could be determined as the transcript ends when public recording stopped.

Key Actions

·OIT Cybersecurity Resilience IT Performance Audit – Public Report (January 2026)No Vote

+ 1 more action

Controversies

Whether OIT's disagreements with audit recommendations reflect substantive disagreement or documentation/communication failure

Matt Devlin (OSA) stated that OIT's responses 'seem to align with our recommendations even though they're disagreeing,' making it 'really unclear... in what regard OIT is disagreeing.' David Ettinger agreed in his opening with the documentation/communication framing, yet the audit shows OIT disagreed outright with 37 of 85 recommendations. The Chair directly raised this tension, stating: 'your statement is that you agree, yet in looking at the audit results, there's a lot of partially agrees and several disagrees with the recommendations. So I'm trying to reconcile that.'

+ 4 more controversies

Notable Quotes

“I'm much more confident in our cybersecurity posture itself than I am in our ability to implement cybersecurity audits. But you would never know that from the audit results.”

David Ettinger (Executive Director, OIT) — Ettinger made this remark to explain the gap between OIT's self-assessment of its cybersecurity work and the audit's finding that OIT could not sufficiently document implementation of 71 open recommendations from the 2023 audit.

+ 4 more quotes

Votes

Motion to release the Governor's Office of Information Technology Cybersecurity Resilience IT Performance Audit Public Report dated January 2026Passed
Yes (2)Vice Chair (name not recorded in transcript), Senator Pelton (first name unclear — transcript states 'Senator Pelton'; both Rod Pelton and Byron Pelton are on the roster)
Motion to go into executive sessionPassed
Yes (2)Representative Dusty Johnson (mover), Representative Jenny Willford (seconder — transcript renders as 'Representative Willford')
Unlock the full summary

Subscribe to see all key actions, controversies, quotes, and what's next.

Sign in to subscribe
TranscriptPreview
Good early morning. The Legislative Audit Committee will come to order. Ms. Watson, will you please call the roll? Senators and Representatives Brooks. Present. Bacon, Johnson. Here. Helton. Here. Wiseman. Good morning. Wilford. Present, Madam Vice Chair. Present, Madam Chair. Present, Madam Chair. You have a quorum. Thank you, Ms. Watson. Members, may I have a motion to release the Governor's Office of Information Technology Cybersecurity Resilience IT Performance Audit Public Report dated January 2026. So. Moved. Second. Moved by the Vice Chair, Seconded by Senator Pelton. Are any opposed? The audit is now released. Mr. Devlin? Yes. Thank you, Madam Chair. Pull this a little closer and. Good morning, members of the committee. My name is Matt Devlin. I'm the Chief IT Auditor at the osa. Here with me from our team is Cindy Radke, our IT Audit Manager. This morning, as mentioned, we're going to walk you through the results of our most recent IT audit of cybersecurity resiliency that we conducted at oit. This audit was a discretionary audit that we conducted based on risk and it was a follow up audit of prior IT audit that we conducted back in 2023 at OIT. In summary, our…
Continue reading

Subscribe to unlock the full transcript, summary, and search across all Colorado committee hearings.

Sign in to subscribe