Skip to main content
Committee HearingJoint

Joint Technology Committee [Oct 06, 2026]

October 6, 2026 · Technology Committee · 14,694 words · 11 speakers · 202 segments

Chair Sochair

you JTC will come to order. Mr. Gravy, will you please call the roll?

Senators and Representatives, Baisley. Absent.

Ball. Here.

Kelty. Absent.

Pascal. Here.

Vice Chair Tutone. I am here.

Chair Sochair

Madam Chair. Here. Very good. I would like to welcome up members of the Office of Information Technology to get their presentation ready. We've got Sarah Thunberg, who is the CIO and Executive Director. Emily Miller, Deputy Executive Director for Digital and Delivery. Allie Terry, Interim Executive Director, Colorado Broadband. Russ Pesquil, Interim CFO and Budget Director. Casey Cook, Principal Director of Enterprise Architecture. And then Jill Frazier is our CISO. So it looks like we've got questions only for everyone but Allie Terry from the Broadband and Sarah Thunberg. And we are just having some technical things. So I just want to remind us what we're going to cover today. Um, OIT has been gracious in that the bill that we ran in this past session officially starts next year. And they have decided to give us a preview of what our quarterly updates are going to look like. And just to remind everyone, we'll do these in October, January, April, and July. and so that we'll just have the information at hand as it's current rather than in a newsletter kind of looking back. It looks like we have our slides up. We have a lot to cover, but this is all that's on the agenda today. So I would encourage committee members just to get my attention if you have a question, and we'll just kind of entertain questions as we go, if that's okay. And so I will pass to you, Director Thunberg.

Sarah Thunbergwitness

Thank you so much, Senator Marchman. Apologies. I am coming out of the tail end of a cold. Thank you for having us. As you said, we have a lot to talk about today, primarily rooted in SB 26185, the bill that passed last year. We broken the presentation out today into a number of sections how we are working within the framework of SB 26185 and our existing legislation existing statutory legislation not just that one but the others that govern our work around maturing our governance reducing our risk better stewarding taxpayer dollars and increasing resiliency So one of the key themes that we're going to speak to about today is about the importance of governance. We have a complex situation in the state of Colorado. We are not alone, but we have 18 organizations who are consolidated, which is we provide some level at OIT of oversight and authority and support for their technology in service to state employees, the agency's mission themselves, and ultimately Coloradans. That governance is an important foundation, and it's really important to have very clear policy and standards. And one of the things that's come up in our work since the reset, over the last six months really, but really since June, is that we have a lot of policy and standard debt. Much like tech debt, you can have policy debt and process debt. It all made a lot of sense when it was put in place, and now we have built sort of layer upon layer of policy, which doesn't necessarily serve and creates a lot of confusion. So we are about 20% of the way through a policy and standards evaluation, and we've created a framework to assess all of our policies and our rules and our standards. It's shown here, but the idea is that we want to ensure it is in plain language and understandable by all. It's justified. It's not just because we said so. It's really oriented around reducing risk or achieving a strategic objective. It's built in a consultative way. It's coherent. We don't want anything that is one-off. Rather, we want it to be really consistent. It's proportionate, ideally standards-based, so we enable interoperability and meeting the requirements of our other oversight bodies, our auditors, both federal and state. accountable and enforceable, that it is the least restrictive. We know our agency partners want to be able to own their own destiny in lots of ways, and we want to enable them to do that very well, but in the context of the rest of those, and that also it's relevant. We have seen that we don't retire policy. And so this is a place where we want, we are building a process by which we review and then retire where it is not appropriate. So we are in a process right now of retaining, revising, and removing policies that don't make sense for us. This is relevant. Oh, go ahead.

Chair Sochair

We have a question.

Vice Chair Titone. Thank you, Madam Chair. I think this is great to go through the policies. Tell me about how you're going about doing that. What is the criteria? Are you using artificial intelligence to review a lot of these rules Are you you know talking with your employees to see why policies were what they know about them Because there a lot of things that have been going on for a long time that maybe you weren't aware of.

Sarah Thunbergwitness

Director Thunberg. Thank you. Thank you for the question. It's a human review process at this moment. We have Casey Cook, our enterprise policy governance leader, working with a small team that includes Paige here on my left and our other rulemaking and governance folks, evaluating them. And then, yes, we are grouping them first into themes so that we can understand, for example, all of the cybersecurity policies in context with one another, all of the employee-facing ones, all of these sort of grouping together, and then trying to understand sort of what's the key ones, what might be duplicative. Also, we're seeing lots of times where they are at odds with one another, and then doing the discovery and conversation about what the right ones are for right now. And one of the things that's really important is that OIT has had historically a tribal culture, I would call it, where, to your point, Vice Chair, to tone, a lot of the knowledge was held in people's heads. rather than in clear documentation. And that made it really hard for our agency partners to know how to work with us. It made it very hard for us to show up in a consistent way. And so we're working really hard to get clear and systematic documentation of how it is we operate and why so that everybody within OIT, within the state enterprise, everyone knows sort of how we're operating. And one of the things that's important about this is that we're publishing all of this transparently in a single location. A bunch of our policy has been behind like an MFA wall, which isn't helpful if you're trying, even a vendor, trying to understand how our policies work related to cybersecurity and what you need to reach. So, yeah.

Casey Cookother

Lights, Chair, to tone. Thank you, Madam Chair. So how much interaction with the divisions are you having with this? There might be some conflicting policies on their end, and are you exploring what those are to make sure that there's smooth interaction with the divisions? Director Thunberg.

Sarah Thunbergwitness

Thank you. Yes, we're in conversation with our own internal divisions and also in deep partnership with our agency partners.

Casey Cookother

And then I have a couple of questions. The contract registry and dashboard, I know version one is up. With everything that's been going on, who owned that? Who owns that? Is that something that I just feel like we probably don't have as many folks to do that work? So I'm wondering who owns the vendor registry that we're going to get to see today?

Sarah Thunbergwitness

Thank you for the question. I'm going to move ahead a couple of slides. We're going to bounce back and forth if that's all right. So this is version one of the active contracts registry confirming that is the one you speaking to This is the one that required under SB 26185 So this will be owned by OIT procurement team in partnership with our finance team and also in partnership with DPA's offices related to the state controller and their procurement world. This is a place where it would be very helpful when you have time and capacity, V1, to look at it and see if it answers the questions in the way you had desired them. We can continue iterating, but let's take a quick tour while we're here. So it will be a dashboard that will have the ability to go deeper. At the top, you'll see the total contract value, the total number of contracts we have, the average value of a contract, and then you can explore them by date. By each of these, you'll be able to explore. Am I sharing the right thing? Yes. Okay. Great. On the left-hand side in the big box, it will have the vendor or supplier, the category. What is currently redacted is the criticality in data classification. These are secure values that we won't release publicly. This is about whether the service they provide us is related to cybersecurity. So that will be specific and available only to members and others who have a need to know. It will then talk through how many contracts we have. You'll be able to click that contracts button and see if there are multiple contracts under a single vendor and then the sort of slice and dice of dollar value. One of the things that's interesting is we have state purchasing agreements like that with Carisoft or with Insight Public Sector. These are negotiated through various procurement vehicles, and they provide access to a huge number, mostly of SAS services. So those things you procure by the month, like our Google Workspace, anything like a Jira or Zoom. So while they are under one big contract, there are hundreds of smaller ones. So you would be able to click through. As you see, we have $111 million in contract value to Karis left alone. So yes.

Chair Sochair

Vice Chair Tatone.

Casey Cookother

Thank you, Madam Chair. And I'm just going to ask this about all of the sections, and I should have prefaced this before. How much of what goes into these is actually collected and collated and processed through artificial intelligence?

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

Thank you. So this is a data linkage where we are extracting from the contracts themselves. In this case, no AI has been used.

Chair Sochair

Brett Pascal.

Thank you, Madam Chair. I'm just curious what the column add, received means. Director Thunberg.

Chair Sochair

Thank you.

Sarah Thunbergwitness

Architectural diagram, we will spell that out in future versions. Thank you very much. And because it's version one, we are still working through receiving the architectural diagrams for all of these various services. It'll take us a minute on that one.

Chair Sochair

I have a question about the 20% of the policies have been done. So that means 80% are left. Of those 80%, what kind of categories are related to security of the ones that you continue to need to look at?

Sarah Thunbergwitness

We started with security and those related to risk, and then we have sort of the long tail of others.

Chair Sochair

Okay. Thank you. Okay. I'm going to take us back in the slides for just a second, if that's okay. So we just demoed. So SB 26185, an update in our implementation status. So sharing version one of the contract registry, ta-da, we just did it, that just happened. We also have built version one of our risk and compliance reports. Again, they're not due for some time until January to you for first round of feedback. We are working on those, getting feedback from our agency partners. In addition to those being useful to you, we want to ensure that they are useful for our agency partners. We want to work in a way that everything is useful to everybody. We are continuing to iterate on the risk and compliance reports as well as the version one of the contract registry so that we deliver first version of those in January with the final, like, first final report due in November 2027, as per the legislation. So that's where we are on those. Policy and standards. All right. Let's talk for a little bit about reducing risk. So risk is the difference between our policy and standards and our reality. One of the things that we've talked about here, as well as at the audit committee, is that a lot of the historic work of the cybersecurity audit and other components were about meeting our policies and checking sort of the box rather than thinking really critically and in a risk-informed way about what the best strategies and approaches were for data protection, cybersecurity protection, all of those pieces. And so our policy and standard evaluation is really oriented around the outcomes that we need, one of those being risk reduction. Talked about the contract registry. So let's talk for a minute about where we are in the audits. So two audits that are open, is that correct?

Sarah Thunbergwitness

Yes, two. So a total of 102 findings of those 58 have been implemented, seven partially implemented, 36 pending. We continue to work closely with OSA and the audit committee to complete the implementation for all of these findings We are targeting 82% of them to be complete by the end of the calendar year, 98% by the end of the fiscal year, and then 100% by one year later. Our focus here continues to similarly be on the risk-oriented, not the admin-oriented. A huge volume of the findings are this policy debt-related, where we had multiple policies that sometimes were conflicting, and we're struggling to sort of meet these administrative ones because they together don't make sense. So it's a lot of negotiation and conversation about how do we do this, and if we retire the policy, does that meet OSA's requirements? And lots of times it's no. We have to meet it, and then we can require it. So we're in this sort of like very complicated situation with the audit findings. And I want to share an example because I think it speaks to Representative Tatone, one of your questions that you just asked, which is how are we engaging with our agency partners about this? So we have an audit finding that is oriented around did we seek feedback from agency partners about a particular policy? We said yes. We provided as our evidence that we met that finding meeting notes, screenshots of the meeting, the meeting, the attendees, notes and minutes, as well as the final outcome of that process. OSA came back and said, that's not enough. We want to see the actual document that is marked up by agency partners. We don't have that anymore because we did it in a meeting setting and then we moved forward and clicked like accept, accept, accept. And those then like erased. And so now we're in a situation where we're unable to complete that audit finding. Even though there's no risk associated with it, it's one that remains not implemented. So we continue to work with them through these. How do we document the best way that meets their needs? but also is about really meaningfully buying down risk.

Chair Sochair

Yeah. Rep. Pascal.

Thank you, Madam Chair. So was this done in, like, Google documents? Isn't there, like, a history? But then you, I don't know, maybe you can't get a delta of the two versions. I'm not sure what would satisfy that, but there is some historical information.

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

Thank you. Yes. And it's one of those situations where we created a clean version and submitted it to the audit committee and that erased it. We also have, it was attached to a meeting invite that then got erased. It's like, yes, and. We didn't expect that that was the level of evidence that would satisfy. We thought that the meeting minutes, meeting notes, and the attendees who were present would be sufficient. So we're continuing to work through those.

Chair Sochair

Yeah, Rep Haskell. Thank you Madam Chair So after having worked with the audit department do you guys have like a methodology for saving this information going forward in a way that would satisfy them Director Thunberg.

Sarah Thunbergwitness

Thank you. We're now saving everything. We continue to struggle to know always if it will satisfy the sort of rules change. and that's something we're working with them on to get to better clarity.

Chair Sochair

Vice Chair Tutan.

Casey Cookother

Thank you, Chair. So is the auditor looking at the policy and then expecting the result based on the policy they're reading? And then because there's been a change kind of administratively, like we're not doing this on a document, we're doing this in a different way, and it hasn't reflected the policy. And then I want to find out what the NA was on your.

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

Thank you. Yes, so one of the challenges is that these policies, some of them are, so the audit findings were many years ago. And so we are trying to comply with a policy that was in place many years ago and that might not make sense now. And so trying to figure those pieces out together. It's like two years ago it might have been a policy that was in our policy compendium that then now.

Chair Sochair

Vice Chair to Tom.

Casey Cookother

Thank you, Madam Chair. So just to follow up on that, a two-year finding, right? I mean, it's the same number in the new one, right? And you have two lists there. One is for an older one, one is for a newer one. Most of them are duplicates. So are they still using the same old criteria? So what's happening there? Because it doesn't make sense that the new findings should be based on the policy that's current, supposedly, I would imagine, or are they just saying that the old one is still there and it's not met? And maybe that's something that the auditor needs to go through the motion on each thing based on the policy as of today.

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

Thank you. Yes, it's the latter. And we are working through that with them to try to work on not two years ago, but what is current and truly risk-oriented. And then your question about NA. Can I phone a friend real quick? Yes.

Chair Sochair

Director Tamberg.

We tried, the finding required us to implement a login for particular devices, but we can't do it because it breaks those devices. They're operating such old operating systems and in such tech debt that they need to be to continue in their current form until we can upgrade the operating system, the code that is running within the operating system, migrate them to another device, and then deploy. But they are now not connected to the internet. They are not connected to any other systems. So it is an NA finding. That's the one.

Chair Sochair

And then I was just looking at the progress that has been made from June to September and I think I counting a couple handfuls maybe of changes and we're looking at needing to get 30 done in the next three months. Can you talk to me about some of the things that could cause those 30 to be delayed?

Sarah Thunbergwitness

Yes, there's a couple of things. So we are submitting them as they are complete, and then the auditors review them, provide us feedback, and we engage in this sort of revising process. We, in lots of instances, we are now in ones that are deeply administrative, and we don't always know the shape and the size of what will satisfy the requirements. And so that is a place where we could definitely experience delays. That example I provided before is one. We asked, for example, that that be considered partially implemented. They didn't feel like that was an appropriate outcome for now.

Chair Sochair

Vice Chair Chitone.

Casey Cookother

Thank you, Madam Chair. How have these recommendations progressed or have been delayed as a result of the restructuring that you've done? Were there people that were tasked on these that were let go, and how did that affect the progress?

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

Thank you. It's the opposite, actually. We're able to, we changed the way at the time of the reset at the end of May and the beginning of June. We changed the way we have handled the audit findings. Instead of delivering them at 5 p.m. on the day that they're due, we are delivering them in an iterative way to give the auditors the maximum amount of time to review. We have a monthly standing meeting with them. We are trying to be far more collaborative. We also have a single team that is responsible and accountable rather than sort of diffuse accountability across the organization. And we've been able to handle them far more quickly, get them out the door more quickly and with more evidence than we were able to before.

Chair Sochair

Vice Chair to Tom.

Casey Cookother

Thank you, Madam Chair. Why would you wait until the end of the day to deliver something if it was already done? Was that a policy that you had?

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

I can't speak to the answer to that question because it was not work I was involved in until I became CIO. I'm excited about this next section.

Chair Sochair

Better steward of taxpayer dollars. You're speaking my language. Thank you so much.

Sarah Thunbergwitness

We take very seriously the budget crisis that we are in as a state and that we also recognize that technology services have gotten more expensive over the last several years, and we have been working very hard to identify places where we can reduce the cost on taxpayers and also allow you, in partnership with the Joint Budget Committee, to take resources and put them in other places. So I am going to, we'll come back to the, let's talk for a second on contractor reliance. There was a question, I'm going to change my slides here for a second. There was a question about a couple of things. The first one was asking for an inventory of all of the projects that OIT is working on in partnership with our agency partners. We provided a Tableau dashboard, which we are working through how we ensure that you have access to it from your accounts, but I'm going to walk you through it for a second because this can be helpful. So this is the inventory. It is as of September 22nd. It will get updated on a weekly basis. And you can navigate this in multiple ways. So you have the project name. You can sort by fiscal year. Is this showing up? Yes. Okay. You can sort by fiscal year that it is targeting. You can sort by the agency that the project is in support of and then the name and the project number, which you probably don't care as much about. But you can look through what all of them are. Additionally, there was a question regarding how much of the total budget was allocated for contractors versus full-time employees. You can see that split here in the inventory. Additionally, you can click over and again, by this is another tab in this Tableau experience. You can see by fiscal year. This is now all of the fiscal years. And I think it's from fiscal year 2021 is how far we've gone back. What the proportion of all of our project budgets were by contractor and full-time staff. You can navigate again. You can unclick all. And then, for example, you can click fiscal year 27 and see the distribution here. So this is what we're targeting. where we're at right now. Similarly by year you can stack them and view them in this view and then also by agency what percentage the expense of of contractor and full-time staff is. So we will ensure you have this. This is another place where we'd love some feedback about is this working for you once you have access and then is this giving you what you need yay thank you sorry it's all good I tried to get on last night and

Chair Sochair

our email doesn't quite work yet so they're gonna work to get us all access um to this and it looks great so we'll definitely look through it and give you feedback but to answer the question we'll go back again. The question about contractor versus full-time employee and the breakdown.

Sarah Thunbergwitness

Since 2023, which is when the data became sort of really robustly available, we at OIT peaked in our usage of contractors at 38%, roughly actually 39% in fiscal year 2024, and then it has been decreasing with more resourcing going to full-time employees every year since. This year we expect to significantly reduce even more our use of contractors There will always be times when we need contractors We can talk in more detail about what those are They include it very hard sometimes to hire COBOL developers or other huh

Chair Sochair

Hire me. I can do COBOL. Secret unknown facts about the members of the Joint Technology Committee. Also, surge capacity.

Sarah Thunbergwitness

but we have implemented some new evaluation criteria to ensure we are building internal state capacity wherever possible.

Chair Sochair

Appreciate that.

Sarah Thunbergwitness

So another area of incredible opportunity to be better stewards of resources is to consolidate our SAS purchases. We live in a SaaS universe where the vast majority of technology products are sold on a seat basis in a subscription model. And there is huge amounts of duplication. And we are working with haste to clean up some of this. Some examples include, we just did an evaluation of sort of cloud storage, workspace cloud storage, employee level. We are a Google workspace shop in our consolidated agencies. We get Google Drive as part of that. That is the thing that people should be using, but we see that 87,000 instances of OneDrive, which is an alternative to Google Workspace, exist, and people are using both. That means we are paying for both, and we don't need to do that. Same thing, redundant video conferencing tools. We see 33,000 instances of duplication. We are going to work to try to reduce those. Again, we get Google Workspace. That is part of what we have. We should not be using Microsoft Teams or Zoom or WebEx where at all possible. So really streamlining in those places. We see similar things across the board, project management, product management, all sorts of tools. So really trying to align on a standard and create good reasons why people should go outside of that.

Chair Sochair

I don't know why I raised my hand. I am so excited about this. I had a feeling this was going on because like my own office has a subscription to Zoom and we do. I mean, it's all over the place, but that's on my dime. But I just know that's going on a lot. do you need, like, this is mandated, right? So this is, we are now, thank you, we are going after this now. We want to save money from these savings on the, um, the SAS purchases. Is there anything that you need from our committee to, um, support you or like, do you have, how's this going to go? when you go to tell people, hey, that's neat, you have Zoom, Cisco, and Teams, but we actually use Google. We're professionals. We should all be able just to use the preferred company program. Do you need anything from us?

Sarah Thunbergwitness

Thank you for the question I imagine people are going to be a little salty that there is a little bit of a learning curve in some of these instances And so I think kindness and support. We're going to be supportive and give people plenty of notice that we're going to ask them to turn these things off

Chair Sochair

and move to the enterprise solutions. I think support as you hear from folks that they're mad about this, it would be great. Also, Senator Ball's hand is up.

Thank you. How long is it going to be until we see savings on this? We should expect to see the first round of savings this month.

Sarah Thunbergwitness

OIT is going first on a lot of these things. We are no longer going to have Microsoft Office or Microsoft Teams within OIT. It is currently, like literally at this moment, getting off computers. And then we are working with our vendor to give us the credits back so that we don't pay for it this year. That's amazing.

Chair Sochair

Senator Ball.

Ballother

Thank you, Madam Chair. And thank you, Director Tinberg. I'm sure we've all had the experience where you don't send the calendar invite, somebody sends it to you, and they send it on whatever service they use. Maybe it's Teams, maybe it's Zoom. Do these numbers capture, you know, someone who installs Zoom Workplace to dial into calls like this, or is this just paid subscriptions, not the free versions that you would use if

Chair Sochair

you're trying to connect to somebody else's room?

Sarah Thunbergwitness

Director Thunberg. Thank you. In most of these instances, it's the paid seats. And we totally know what you mean, needing to access. I need to access Zoom in this meeting so that I can present here. I have the free version installed. It is the paid version that we want to ensure that we are working towards. And that also we aren't accidentally, people aren't accidentally subscribing. that is a violation of fiscal rules and causes other problems for them. And we can see who did the installation. Correct.

Chair Sochair

Senator Ball, did you have any follow-up? I don't see your hand up, so I'll keep going.

Ballother

No, that answers my question. Thanks.

Chair Sochair

Awesome. Vice Chair Titone.

Casey Cookother

Thank you, Madam Chair. This kind of goes along with the question, Well, the information about the contractors and the vendors, Carasoft being one of the largest ones at 111 million. We have a provider of a lot of software, especially SAS stuff, through SIPA and I know we have not been really utilizing them to the extent that they could have been perhaps. So, and I know that they've got a pretty good amount there, but are there some of these software packages that you are getting from Carasoft that can be provided through SIPA? Maybe they don't have that contract yet, but maybe they can negotiate a better rate that we can do. Because SIPA doesn't charge as much, because they're not a profit entity, so theoretically they should be able to get us a better price on a lot of these things.

Chair Sochair

Is that something you planning on doing looking into those Director Thunberg Thank you for the question Yes we working really closely with SIPA to ensure so a couple of things One the procurement team is breaking apart the Kerasoft

Sarah Thunbergwitness

spending and understanding what the highest volume purchases are, and then we'll go direct to those folks and see if we can buy down and negotiate our own enterprise agreement. For example, I believe that we purchase, I'm not going to say that because I'm going to mess up which vendor it is. So one, we want to negotiate directly with those highest volume ones, Google. We go through two resellers for our Google contract. Our contract is up this year. we're working really hard to negotiate directly with them so there aren't not two folks taking a cut of taxpayer dollars, but also working really closely with SIPA so that we can negotiate better on some of those service vendors in particular. They're an incredible partner.

Chair Sochair

Very good. Thank you. Amazing. So there was another question, I believe it was Representative Kelty's question about personal computer inventory and how we were managing those and sort of what that math looked like.

Sarah Thunbergwitness

So, across the OIT-supported agencies, there are a total of 46,000 workspaces or PCs that are within our inventory. It is a big number, and there are a couple of features that make that a bigger number than the actual one-for-one employees. One is that in certain instances, we have folks who have multiple computers. So you might have a desktop computer, and then our park rangers might have a device in their vehicle. Or they might have a tablet that they use out in the field, but then one in their office. So we're not an organization that can have one for one. We also have a lot of devices that are old and still in our inventory, and they haven't been disposed of yet. So that's part of that $46,000. Of those, 17% are designated for lifecycle replacement this year. They're eligible for a refresh. We tend not to push for refresh, rather wait for folks to say I need a new computer. We're evaluating the cost benefit of that. I find personally that sometimes the agitation of my computer stopping working is perhaps not worth the productivity loss, and we might want to lean in a little bit more and get people devices that work consistently. It's an experiment we're running. but those are the stats. They're happy to answer any questions about it.

Chair Sochair

Yeah. So that seems like a lot of things to replace, but it's only like 20%, 17%. Do you feel like the budget that's forthcoming is going to cover that, or will there be a supplemental or anything for this type of, um, I'm assuming there won't be a supplemental. for lifecycle replacement of PCs. Can you confirm?

Sarah Thunbergwitness

Can I phone a friend? Yes, of course.

No, we are not asking for any additional. This is the budget. Thank you.

Chair Sochair

Please proceed. Okay. Additional question Rep. Kelty asked was about end of support.

Sarah Thunbergwitness

network devices. This is not the individual work units that people use, but rather the network equipment, Wi-Fi spots, switches, routers, firewalls. We have a lot of end-of-life devices that we are currently in the process of refreshing. We have been funded to do this already. We are well on our way. We are prioritizing our 24-7 facilities and ensuring they are getting upgraded network equipment first and then moving from there. The 48 firewalls, so glad to see that those are a part of being upgraded. I'm curious if we have any

Chair Sochair

security issues that are related to these 48 firewalls that need to be updated. It's probably hard to speak so categorically, but I just wonder.

Sarah Thunbergwitness

No, we do not. Okay, good. They are end of life and we want to just continue. I think historically in the sort of traditional IT model, it was sort of like you said it and you forget it. And we are working towards this product model, and our network equipment is similarly thought of this way. We want to have care and feeding and ensuring we're managing it moving forward so things don't turn into tech debt. But, no, we don't feel there are any risks related to our firewalls or our switches or our access points.

Chair Sochair

Good. Please proceed.

Sarah Thunbergwitness

Great. Hold on. I need a sip of water. So the next one in the asset refresh category is about servers. We are moving to a fully cloud first is where we are now, cloud forward for all of our server assets. We have a very small number. We actually are ahead as a state. I think qualitatively we should look at this, but as compared to our peer states, we are the farthest along that I know of in moving to the cloud and getting off legacy on-prem servers, which is better from a security perspective, cost perspective, and allows us to keep them up to date. So we have significantly reduced our physical server reduction. We're down 24% over the last year alone. Continuing to target that sort of long tail reduction of moving things to the cloud. There are a couple of instances where we will not move them to the cloud. Those largely are within our Department of Corrections and Department of Public Safety use cases. There are special rules CJIS specialized security public safety and correctional operational requirements that require them to be on those similarly change This is a place where governance and policy is really important. We don't want to always assume that just because it was once required to be on-prem, it needs to stay that way forever, and we will continue to work through and see as those rules change, can we move them to the cloud, which gives us more efficiency.

Chair Sochair

Vice Chair Tatan.

covered with plastic because there's leaks in around or something like that. Director Thunberg, are you familiar with this in the Department of Veteran Military Affairs?

Sarah Thunbergwitness

I am not familiar with this. I would love to look into it and report back.

We'd appreciate that. And pictures would be great, too. No kidding. We don't need to see pictures of plastic. So keep going. Thank you.

Chair Sochair

Okay.

Sarah Thunbergwitness

The next thing, a little bit of a shift. We've been engaged in conversations with you all. There's been a request that IT capital requests come with greater detail when they come to you all for consideration and evaluation. So based upon our conversations and our collaboration, we are revamping our capital technical evaluation. This is our proposal. We would love your feedback. There is a smaller number this year appropriate for the budget. You received the first version of those IT capital requests from the Office of State Budget and Planning last week. We will then, this month, augment those requests with the technical assessment shown on this slide. So for each request, we will evaluate the investment in parallel with a number of priorities, what we understand from legislation, also governor's office executive priorities. We will employ the guide-don't-gate philosophy, which is one really that we think is really important that we want to guide towards success. And that we will rank the projects using a scoring mechanism that is shown on the right-hand side. We're going to assess in five areas. The first is architectural alignment. alignment. We have enterprise IT frameworks and we want to reduce duplication. We have a problem in the state where we have not done this work very well in the past and so we have created sort of lots of custom solves for similar situations across many agencies. For example, permitting and and grants management. We have as many permitting solutions as we have permits that are required where those could have been built on an enterprise framework and saved a bunch of resources We want to reduce duplication by having standards in our architectural guidance. The second is really essential obviously is the security posture and risk tiering. We are leveraging existing risk and security frameworks including the FedRAMP, GovRAMP evaluation, which we can talk more, and then really reviewing in detail before they come. Director Thunberg, we have a question on architectural alignment. Yes.

Chair Sochair

Vice Chair Titone.

Casey Cookother

Thank you, Madam Chair. How much, I'd like to see a little bit more of some direct feedback from the agency you're working with on a lot of this architectural alignment to be sure, because I know in the past they have been a bit frustrated that they haven't gotten what they were asking for. So having the agency actually have that say and some words about it to be sure that everybody's in alignment on what they're going to get.

Sarah Thunbergwitness

Director Thunberg.

Casey Cookother

That sounds great.

Sarah Thunbergwitness

How would it be helpful to share that back with you?

Casey Cookother

I think that the way that we get this information is the departments come and make their pitch to us in our December meetings. So theoretically, I'm wondering if you don't have your scoring rubric ready to go prior to the evaluation of these in December, and then we can hear feedback from the departments.

Chair Sochair

Vice Chair Tatone.

Casey Cookother

Thank you, Madam Chair. I think, you know, because a lot of the procurement is done mostly through OIT, and in the past, and I'm not saying that this is how it's going forward, but in the past they have been sort of, OIT is like, well, this is how you're going to do it. And the agency doesn't really, I don't know, maybe they're not, they don't feel empowered to say on the microphone that they're not really happy with it and they're just going along with it. And I think that, you know, that's something that we, and I don't know how to solve that problem if the agency doesn't have the courage to say this isn't what we want, but we're getting it anyway. I don't know how to solve that problem. That's a culture problem, perhaps. But, you know, we want to make sure that everybody is getting what they want. And maybe that's a further discussion of how we accomplish that.

Sarah Thunbergwitness

Yeah, Director Thunberg. My experience is that it's largely the opposite experience, that agencies are procuring solutions independent of OIT, and we are brought in at the very end, at the point oftentimes at which the CIO or the CFO is asked to sign the procurement. And so I think what that speaks to is that then if we raise concerns, that ship has sailed. And then that's real salty. It would make me very, very upset as an agency ED if my team had just spent a huge amount of time drafting a scope of work, going through a procurement and then you have an award and then you give it to somebody and they like whoa whoa whoa that a bad Don do that I can appreciate why that would make them very very frustrated And I think a lot of what we trying to do here is move way farther upstream so that we are clear from the start. For example, if you're going to build on Salesforce, which is we're a Salesforce state. So if you're going to build on Salesforce, here are the security requirements, the access management requirements, here's what you're going to need to do from a custom code versus just a configuration basis. And if we can set those standards in advance, then when they go to procure, they can procure from vendors who they know can meet that. And we've avoided all of that like heartache. Do you have another question?

Chair Sochair

Vice Chair Taton, follow up.

Casey Cookother

Yeah, thank you, ma'am. And that's fine. I mean, whatever, none of this should be happening in a vacuum on one side or the other. I mean, this all needs to be a collaborative effort to be sure if you're going to deliver services and sign off on procurement for something, you can't, none of that should happen that way. So it should be a collaborative effort. And I don't want what you said could have been happening before to continue to happen because it should be collaborative even though, as the statute says, procurement is with OIT. The agency needs to have that feedback and understand what they want and how they want to do it and not necessarily have something forced on them that is not going to work well.

Chair Sochair

Very good.

Sarah Thunbergwitness

Let's move on to vendor and contract integrity.

Chair Sochair

Is that where we are on the third?

Sarah Thunbergwitness

We're going to speak a moment, I think, slide 16. The current status update for the existing IT capital projects, those in flight.

Chair Sochair

We interrupted you after number two, and so we were thinking you might go through the vendor and contract integrity.

Sarah Thunbergwitness

Apologies. Yes, yes, yes, yes, yes. So, we want to ensure, to your point, Vice Chair, to tone that the contracts make sense in the context of what we're delivering. That looks like prioritizing pre-approved state vehicles, those, for example, that are available through SEPA or other places, so that we have already worked through contracts and negotiations. You will see when we do an update on IT capital projects, contract negotiation is a very common place where projects get delayed. It causes us all sorts of problems. So using pre-approved vehicles and contract models that we know are successful and yield better outcomes, ensuring that there are appropriate service level agreements, responsiveness targets, and also appropriate consequences when a vendor cannot meet that. We want to, in all of these cases, be good stewards of public resources by avoiding vendor lock-in, by avoiding bad outcomes from bad contracts. The original sin of bad technology in government is a bad procurement and a bad contract. So we need to make sure we have these things tight and we know how they're going to get structured before we fund them.

Chair Sochair

Advice Chair Tatum.

Casey Cookother

Thank you, Madam Chair. I don't know if you're going to cover this later or whatever, but just for presenting us with these requests, the one thing that I've always been frustrated with is that, you know, there's no vendors that have actually put in bid requests and there's still like this number that says how much it's going to cost. And how do you justify that cost? You don't have any bids from anything, and that's something that however that needs to be presented is some justification of the cost of how you got to this number because what I'm afraid of is that when we come up with these numbers before we even go out to bid, that these vendors know exactly how much to bid on and what their target's going to be. And maybe we don't even say. Maybe we're not ready to say how much it is in some cases when we're not ready to actually get the request funded, or we keep that in executive session, because why does a vendor need to know how much something we're estimating it to cost before we send it out to bid? Let them tell us and see how far away they come from our mark. So that's just something that maybe we can come up with a better system, because it feels like we're putting this number out there, and then the vendors are like, oh, $20 million, okay, well. All right, I really want that one, and maybe I'll just do 21 million and see where they go. But I don't even know how you can get to that number to begin with. So I don't even know how realistic it is because we never see that information. So that's just something I wanted to throw out.

Sarah Thunbergwitness

Director Team Break. Sounds good. Sign me up. Let's work with it. somewhat related to that I think because these three and four are very connected iterative delivery we have a problem in government partially related to what you just mentioned which is all of the money comes in one big pot and then we assign it and we make it that we have this big bang problem where we set out $20 million, $50 million, $100 million, and we say we're going to use it over the next five years, and then poof, it's going to launch. And what we know is that almost none of those work. 13% of them ultimately become functional software on time, within scope, and on budget. So we want to see in a place we would like to partner with you as well as JBC is more iterative pools of funding. So things like take a smaller amount at the start, build an MVP, and if you can be successful, then come back and ask for more. I think there is a scarcity mindset that we're all going to face, which is people feel like if they don't ask for the full amount now, they're never going to get it. I don't know how we counter that. This is a bigger problem. But the nature of saying, yes, here's $20 million and then feeling pressure to commit that $20 million increases the likelihood that we lose that $20 million and don't have the good outcomes. And so I think we are going to try to provide more feedback on the likelihood of the way this work is going to get done of being done in an iterative way that yields better success So that something we really invested in because we have got to do this better as a whole of government And then the next one is ensuring that we are prioritizing tech debt mitigation and retirement. It is way more interesting and fun to build something new than it is to retire technical debt. but our systems then grow upon one another. And then if we have the foundational element, for example, being an on-prem server in a storage closet wrapped in plastic, I hope to God that's not happening, but then we build something new, a new web application on top of that, we are setting ourselves up for failure. So ensuring that the tech debt that is associated with the project is surfaced surfaced and is appropriately costed and mitigated to achieve that additional outcome will be part of our assessment.

Chair Sochair

Very good.

Sarah Thunbergwitness

So these next budgets and actuals are these 13 projects, the ones that we approved last year, and this is the status of them.

Chair Sochair

This is the status of them. I am unsure if they are last year or they are last year.

Sarah Thunbergwitness

They are last year. So 10 of the 13 are on track. I am happy to provide information about them. I want there's more details in all of them. I think the three that are off track or at risk that we're talking about, all three of them are facing timeline risk related to contract negotiation. and contract-related work. So the CDPHE health facilities and EMS modernization, again, the contract is taking a long time, so the schedule is going to take longer. The statewide procurement system, this is the e-procurement module here, too, a contractual dependency needing to ensure the vendor is using the right cooperative agreement and they've signed on to it and that there are, we're in the sort of like red line period with that.

Chair Sochair

Vice Chair Tatum.

Casey Cookother

Just a question about, you mentioned contractors and if there is something with a contractor where there's a delay and we have contract employees that are working on that project, and then there's essentially a work stoppage. What happens to that contract employee during that time? Are we paying them? Are they not getting paid? Are they pulled to go work someplace else because they're idle? And then do we get them back or do we get somebody different? and then now they're not familiar with it? Do you kind of see where I'm going? Tell me a little bit about that process.

Sarah Thunbergwitness

Director Thunberg. Thank you. So it depends. In these instances, the contracts are with the vendors who are providing the service, and in these instances there aren't contractors, separate contractors, that are supporting the work. But in instances where there are instances where we had vendor delays for whatever reason that we have had opportunity cost losses full and contractors where we had vendors being unable to do whatever the work is And we have state employees who sit by and need the vendor to do their stuff. I think, yeah, anytime you have a delay, it's more expensive. And I think important to the iterative model that ideally we don't do these big bangs that five years in we're discovering that the requirements that we set four years ago don't meet the moment. Vice Chair Titone.

Chair Sochair

Thank you, Madam Chair.

Casey Cookother

So I understand like if you have a major project and you have employees working on a major project like all the time, I mean they shouldn't be sitting around doing nothing. I mean are they being assigned to do something else in the interim? Because like that seems very inefficient.

Sarah Thunbergwitness

Director Thunberg. Thank you. I can speak only for OIT. Yes, wherever possible, we pull people to do other work, and we don't have people sitting idly by. Yes.

Chair Sochair

Can you help me understand why the CDPS vendor procurement took so long?

Sarah Thunbergwitness

Yeah, they kept saying it was really important, and then it just last month got, I think, solidified.

Chair Sochair

So can you just help me understand what's going on with CDPS?

Sarah Thunbergwitness

I don't have a ton of information aside from what is here, which is the contract, the negotiation with the vendor that they selected is taking a very long time, that the work hasn't even started yet. there in negotiating what will be done in the contract.

Chair Sochair

Okay, thank you. And you can go on to resiliency now.

Sarah Thunbergwitness

Oh, hold up.

Chair Sochair

Vice Chair Tatum.

Casey Cookother

Thank you, Madam Chair. They've spent $1.9 million and they haven't got a contract yet? Or is that what's left on that contract?

Sarah Thunbergwitness

They've spent about $600,000.

Chair Sochair

Director Thunberg.

Sarah Thunbergwitness

We might need to ask the department.

Chair Sochair

Okay.

Sarah Thunbergwitness

Good question for the department, but here is what we have more information on. It is a multi-phase project. Phase one is complete. It was completed in July of 2025, which is the design, blueprint, and roadmapping. Phase two is the part, the e-citation component. That is one of the places that I think was delayed. The contract was fully approved and executed just as approved. Don't quote me on the executed part. September 9th, 2026, and they've started initial implementation. And then phase three, that is another procurement that is currently running. So yeah an eight delay in one of those procurement components and the department will have more information about it

Chair Sochair

Thank you. That's really helpful. And Mr. Gravy did remind us, too, that we got an update from the department in June as part of their quarterly update, so we could probably go back and look at that, too. But thank you for sharing that.

Sarah Thunbergwitness

Fantastic. The next one is a quick update on what is called CORE, which is the state's accounting system. A reminder that CORE is a delegated service to the Department of Personnel and Administration. So it is managed and operated by DPA. We're providing a light update. If you have more questions, it is totally for them to answer in more detail. An iterative, again, trying to run this in a product model. The team continues to ship new features with good feedback. Three large-scale feature sets were released. That includes upgrading the homepages, deploying Google multi-factor authentication, and then having more accessibility within the platform itself. Deploying communications support to the employees who access it. Core is an employee-facing tool. It's the accounting system that we use. The project is currently operating on time and on budget.

Chair Sochair

any other details, DPA are your people.

Sarah Thunbergwitness

And with that, I would love to hand it over to Allie to speak to Broadband.

Chair Sochair

Does that work for you all, or is there anything else you want to ask? You can always circle back. Sounds good. Great. The floor is yours, Ms. Terry, Director Terry,

interim executive director of the Colorado Broadband Office. Thank you, and thank you for having me today for my first meeting, so I really appreciate it. I wanted to give you a brief update. I think you all had asked for more frequent updates, sort of in-progress updates, so I wanted to offer some of those today. As a quick reminder, we're working towards 99% broadband coverage. Clarification, the denominator for that, so we've got about 2.9 million households in Colorado. Every 1% is about 30,000 locations. We're making slow but steady progress. we see those changes in the points of percentages sadly instead of the big percentages but we're really excited we've got some projects coming online and so we'll talk a little bit about some of those in the next couple of slides so BEAT is our largest program this is a program that's funded by the NTIA right now the funding that we have available for on-site last mile services This is about $420.6 million. And as an update, just in the last couple of months, we've got 55 grant agreements executed. Not a lot of spending on that yet because those grant agreements are just now getting executed. But we're really excited. Almost all of the projects right now are in the middle of their NEPA compliance. So that's because there's a federal nexus for this particular program. They have to go through environmental requirements. significant environmental review so they're almost all of our grantees are still in that process right now we only have one that's ready to submit to the feds for for their environmental there's no ground disturbing activity that's allowed prior to their their approval by the feds and so construction hasn't started but they're working in the background so these are programmatic updates not bringing people online updates but a couple of updates on this We have been waiting for release of the additional funding to be able to reach out and do some additional work. We're waiting for guidelines from NDIA. We thought it was coming, but in September they issued new guidance for deployment. So we have some additional work to do. They've put some new locations on the list, about 8,000 of them. We'll be looking at those to get those locations served as well. So those are 8,000 unserved locations that were either misclassified on the original maps, on the FCC maps that have been cleaned up by the FCC, or there are locations that a federal program has maybe defaulted and they're back on our map. So we're going to be able to use bead money to serve those. So we're working on that now. That's going to be about a six-month process to get those locations, grants, and out the door. Next slide. So CPF program, if you think of these as sort of like baby bear, mama bear, papa bear, this is our mama bear program. It's right in the middle, sort of a sweet spot of $112 million. We have spent about 55% of those funds. So these programs are all in construction right now. And all of them have passed through their or are working through their permitting and make ready and actually have shovels in the ground. some exciting updates we do have eight projects that have already completed construction ahead of schedule and are starting their closeout the majority of these projects end this december so when we do our report to you next year we'll be able to show some locations that are actually coming and they're being lit and people are getting service it's going to be a really exciting update Right now, just as some background on what closeout looks like for our grantees, we require speed tests to make sure that the speeds that they've said and that we have paid for are accurate and that that's what entities, I'm sorry, that's what households are getting, that they're getting the speeds that they're promised. They also do narrative reports, some of the financial reconciliation too for closeout. We do have 12 grants that Treasury granted extensions to. The majority of the reasons for the extensions were permitting or make ready. This is just run really slow. They run really slow in every state. Our state is no different. But we do have additional challenges in terms of construction seasons that some states don't have. And so Treasury's extended 12 of our programs to the end of June to be able to get a little bit more of a construction season. And right now, we're feeling pretty good about those remaining programs. Some of the programs that are closing out now didn't use all their money. So they were able to be really efficient about their costs and they gave us some money back And so we have taken that money and with Treasury permission created a digital connectivity program It is a program that is running really hot There's only three months to get it done. The feds gave us permission a couple of months ago. And this is really around the adage, if we build it, they will come. Yes, they will come if they know how to use it, right? And this is the they know how to use it part. So we're really excited to be able to support this. through federal funds. This is, it's still a capital project, right? So these are, this is not for ongoing operating costs, it's for routers and equipment and laptops for people to be able to access three things. So education, healthcare, and work improvement in their work. We got over $2.5 million of requests for $900,000. It's a rolling application. We have issued provisional awards for six grants for about 610,000. We've got a little bit of money. Actually some programs are in review this week. So we anticipate in getting to that 900,000 very, very quickly.

Chair Sochair

Yes.

Rep. Pascal.

Chair Sochair

Thank you, Madam Chair.

So I'm curious, who are the grantees? Like, what kind of entities are the grantees, and how did they even know this thing was there? Director Terry.

Thank you, Madam Chair, and thank you for the question. So we publicized through some of our other agency partners, so CDLE and other programs, but we have – I'll get you more information for our next update. I know that there have been a couple of recovery programs that have been included. There's some school systems that have, particularly some rural school systems, that have applied for these. In addition to our newsletter and all of those things, we have really been working with some of our, collaboratively with some of our other state agencies to get the word out about these programs, where sometimes it fits a little bit more within their normal constituency, where ours tend to be ISPs. Please.

Chair Sochair

So talking.

Yes.

Chair Sochair

Thank you.

So the advanced state and local grant program is in flight right now. So this is the high cost. This is funded by the high cost support mechanism funds. We have two tiers. 60% of our money goes to middle mile per legislative requirements, and the remainder goes to this tier two, which is last mile, short-term construction, and digital equity. Our middle mile tier one applications have been provisionally awarded, so that's the one that we ran first. We've got nine projects, six different grantees, and about $22 million that are awarded. Those grant agreements haven't been signed yet. They're provisionally awarded, and we're working through all of the sort of pre-grant agreement paperwork, if you will, to get those wrapped up. and out the door. And then tier two is we have 40% of the funds available

Chair Sochair

to split across last mile, short term construction

and digital equity. We received applications under every category. They're in review right now. And we anticipate getting those provisional awards out by the end of the year Very good Slide

Chair Sochair

And so our baby bear program,

or at least our baby bear federal program is SLFRF, which we thought was so big when we first got it. It was so exciting. So our SLFRF program is funded by ARPA,

Chair Sochair

which is a federal funding source. We have 17 grants in that and about $35 million that we funded. These are last mile projects. These are the projects that connect people at the very end of the line. We're at about 83% of our grant funds are spent for these programs. All of these programs end, have a very firm end date of December 31st. So we're excited that we've got a number of projects in the closeout process now. Again, same as the other ones. We've got speed tests that are required. So the closeout process is a little bit long, but construction has to be completed by December 31st. So far, we've got about 5,000 locations on the map from this project. And by December 31st, we anticipate that we'll have the remaining locations to be able to present to you. Very good. Vice Chair Tatum.

Thank you, Madam Chair. And I'm sorry I was out of the room when you were going over the BED grant program overview. Spending update, you say 0.1% of the grant funds have been spent. I mean, that's like a very, very small amount. And I wasn't here, maybe you went over that, but I mean, it's a lot of money that's kind of sitting there. What's the holdup on that?

Chair Sochair

Yes, you can go ahead, Director Terry.

Director Terryother

Thank you, Madam Chair, and thank you for the question. Yes, so the $420 million is both our admin funds and our construction funds. This program is a milestone-based program, And right now, the grant agreements were just signed over the last couple of months. And so all of our programs are in NEPA compliance. So they can't do any ground-disturbing activity until they've completed their environmental reviews. And none of our grantees have passed that milestone yet, unfortunately.

Vice Chair Tatan. Thank you, Madam Chair. So I know that when the administration shifted a couple years ago, a lot of the funding was reduced and a lot of the implementation went away from fiber more to satellite based. So how many less miles of fiber are we anticipating putting in compared to what we had anticipated when we first applied for all this money?

Chair Sochair

Director Terry.

Director Terryother

Thank you, Madam Chair. Thank you for the question. I don't know an exact number on the miles of fiber, but we do have about half of our locations. So we had around 100,000 locations that were eligible for bead funding, and about 50,000 of them are going to be served at this point by bead funding, by satellite instead of by fiber or even fixed wireless, which would be a 50% reduction in our locations. So I'm not answering the exact same question that you're asking. We have prioritized pushing fiber as far out as we possibly can and it sort of part of the middle mile construction strategy where those locations are so expensive that the feds have the right to choose that to say that those locations would be too expensive to serve using federal dollars and that's the decision that they made that said with this middle mile strategy our goal is to push fiber and middle mile out as far as it can so that connecting those locations with high quality fiber internet becomes less expensive and there's more of a business case to be able to do them. So we did have a significant decrease in what we had hoped to be able to serve with fiber.

Brett Paschal. Yeah, that made me curious about the environmental studies for fiber versus satellite. Do satellite have environmental studies, and how does that work?

Chair Sochair

Director Terry.

Director Terryother

Thank you for the question. It's a great question. So we, technically, actually, satellite does have some environmental studies, but they're very minimal. So we do have to submit. They have to submit on their behalf. We have to submit their NEPA approval. But because there are no land stations in Colorado, there is very little. There's almost no paperwork on their side. Now, those are two grant agreements. We have two LEO providers, two low-Earth orbit satellite providers in Colorado that won provisional awards, Amazon and SpaceX. Neither of those grant agreements have been signed yet. We're still in negotiations around some of the requirements. The Fed's made some changes to their location list, and we're working through this with them. They've been great partners. They will likely go very fast because their NEPA is like a checkbox. Yeah.

Okay. Thanks for going backwards a little bit for us.

Chair Sochair

I think we are on slide 27, is that right? Let me take that. Sorry, I was talking so long, my computer went quiet. Thank you. So, thank you, that's perfect.

Director Terryother

A quick update on Middle Mile. So our Middle Mile initiative is in progress right now. We opened the middle mile report, the road map report for public comment. Public comment was closed on August 7th, and so we've taken all of the public comment back and we're sort of reviewing, encapsulating, and deciding whether or not we need to make any changes to our stakeholders, to our initial report based on our stakeholder feedback. In general, there are three things to know really about our middle mile program. One is figuring out where we have statewide inventory and doing the gap analysis. The second is figuring out what are the most appropriate strategies to really, like I was talking about, push that middle mile out so that we've got, we're creating business cases for ISPs and our public sector partners to really be able to lean in to support our rural areas. and then also just creating this strategic plan and framework around implementation. And it's just in review right now. So one of the questions that we had from you all last meeting was around federal risk, and so I wanted just to talk a little bit about what things are looking like now. We don't feel like there are significant risks necessarily to the funding that has been obligated by the feds to this point with one exception. So our full allotment, and Rep to Tony, you were referencing this, is actually $826 million. We've only got access to about $421 million of it right now. Those remaining funds, we're waiting for guidance from the feds on. We don't know what that guidance is going to look like. In June 6, they pivoted once for the benefit of the bargain round. As it happens, last month they pivoted again for a second benefit of the bargain round. That's the additional 8,000 locations that I was talking about. And we are still waiting for guidance on the remaining money where we may be able to use those for other initiatives that support broadband infrastructure in the state of Colorado. We, as I think you all know, we ended up having to rescind all of our original preliminary BEAT awards. We had to go through a grant agreement process again and reissue. That process is done, and those are the grant agreements that we're sending out now. This new September 3rd notice doesn't undo anything. it just sort of decreases the additional funding that we have available, and the feds are saying that we should be using it for deployment on these 8,000 locations rather than the initiatives that maybe would have been coming out in guidance afterwards. So the funding, I don't, oh, I'm sorry.

Casey Cookother

Vice Chair, to tone. Thank you, Madam Chair. So the extra money that's still on the table, it seems to me from what I'm hearing, and maybe this is something you can back up, is that there has been more of a push to get as many of the unserved people onto satellite and to really not focus on a lot of the broadband. And it's that kind of where you're seeing when people can't afford it, the money will be going towards them getting the equipment so that way they can get the Internet through that method instead of doing it through the ground-based. And that is a very expensive endeavor to buy all that equipment for people who don't have it and to kind of get them hooked on that satellite and the vendors that the administration carefully picked for political purposes. Wouldn't you agree, Dr. Terry or Director Terry?

Chair Sochair

Thank you.

Director Terryother

Thank you for the question and the comment. We're still in negotiations with our LEO providers, but I did want to highlight one of the things that you had mentioned. And currently in the negotiations, and I anticipate that we're going to land here, for the areas that are not now going to get fiber and are going to be funded by satellite, those locations actually will have subsidized customer premise equipment, equipment, which I do think, while it may not have been our original vision for the state of Colorado, I do think in some areas where household expenses are really high and income is really low, that that is helpful to have customer premise equipment. That's something that they don't have to pay for and that they only have to pay for service. So, yeah. Very good. Yep And so we talked about I talked about this a little bit already got ahead of my slides But we are waiting still on guidance for that remaining, you know, $300,000. We're looking forward to it. I mean, we keep hearing rumblings. It was supposed to be out this summer. We're hearing rumblings that it's still going to be coming out sometime soon and probably that we're not going to have the luxury of being able to run the second Bob round and non-deployment separately that we may be running them all at the same time. But the team is certainly prepared for that. So I do think we don't know what the guidelines are going to look like for that additional money. And that additional money has the capacity to really help states like Colorado, Mountain Region states in general, but Colorado specifically as well, if we're able to use those funds for things like Middle Mile, where we really can push hardened infrastructure farther out into our more rural areas, that would be really incredible. MakeReady is a very expensive proposition in Colorado as well. If we're able to get funding to be able to support some of our electrical co-ops, that's also very helpful because they can't raise their rates because of broadband deployments. and we find that broadband ISPs either pull out or they switch from fiber to fixed wireless, even for their backbone to be able to address some of those make-ready costs. So the longer we have the delays in the guidance, the harder it is for us to plan, even to plan our state programs to really capitalize on what the feds are doing. So, yeah, we're just looking forward to it. have no control over. We're really looking forward to that guidance coming out. I think that's my last slide. I'm happy to take any other questions before I hand it back to Sarah.

Chair Sochair

Back to you. Thank you.

Sarah Thunbergwitness

Thank you, Madam Chair. I wanted to follow on. There was the question about federal funding risk writ large. So Allie spoke to it regarding broadband. No news to any of you, but OIT is also would be impacted by HR1 penalties related to Medicaid and SNAP. Our key benefits are all delivered digitally. That's the way the vast majority of Coloradans access these programs and systems, so they are at risk related to the various new compliance mechanisms described within HR 1 and would be deeply problematic, not just for the loss of the technology, but the service that is delivered via the technology is the real problem here. But just wanted to acknowledge that that would be an impact for Coloradans, for the agencies who administer them as well as OIT.

Do we have any idea when we'll find out? I mean, I've heard that there, I mean, do we know this already? In terms of the cuts in funding, in terms of like COBie's is replacing CBMS, and CFBMS is funded by this money. So if this money goes away what happens to COBie and CBMS in general So I going to answer thank you for the question I going to say something first and then talk speak to that The risk that we have under HR1 is related to error rates

Sarah Thunbergwitness

And so our SNAP error rate must be under a particular threshold. And if we as an entire state can't hit that target, then we are penalized. And those penalties then eat into our SNAP budget and we are less able to administer. So that is a little different. That's the real big elephant in the room risk. Separately, building better systems and better technology to administer reduces challenges related to error rate and to fraud, waste, and abuse and those sorts of things. I don't believe that anything related to H.R. 1 penalties itself threatens Kobe's and the rebuild, though there would be catastrophic consequences if we had these penalties, error rate penalties. And we would, together as a state, you at the legislature in partnership with CDHS in particular, on the SNAP side, we would have to figure out what we do.

I shared to Tom. Thank you, Madam Chair. Do you have any idea about what our error rate is and how other states' error rates are? I'm just kind of contemplating. Is the rate that they've chosen to have a threshold a realistic number to begin with? And is it actually obtainable? Because most of the errors that I'm hearing happen are not necessarily on our end, but it's on the end of someone else who's applying that's not providing the correct information. And so do we know where the error rate is coming from? and if it is on the person who's applying for its side, is that where we need to focus our efforts on more so than the actual giving the benefit out? Because I think that's where there's missing information perhaps on their end.

Chair Sochair

Director Thunberg, there are states that are not in jeopardy

Sarah Thunbergwitness

because their error rates are not at the place that ours are, is the way I understand it. Right? That is correct. I think I would recommend this be a conversation with the Department of Human Services.

Chair Sochair

Their program is doing some pretty exceptional work to reduce our error rate

Sarah Thunbergwitness

and to control as much as is controllable both at the state level and partnership with the county. I think you can look at some of the states with far lower error rate. It's an interesting exercise to look at the states with lower error rate and see how much SNAP benefit they provide Rep Haskell

So I'm trying to follow that reasoning. It's a percentage, right? So why would delivering less SNAP benefit cause you to have a lower percentage? Less human error.

Sarah Thunbergwitness

Hmm?

Less human error. Yeah, I don't quite follow that.

Sarah Thunbergwitness

Because there's less touches.

If you have less ends, I don't know. If you have less ends, then there are less chances to make a mistake. So if we have one million and they have 500,000, we only have 500,000 ways to make a mistake, whereas we have one million ways. But it's a percentage. Yeah.

Chair Sochair

So that doesn't make sense to me.

Sarah Thunbergwitness

Director Toon-Brain. The complexity of operating programs increases the chances for error. You see, this is me speaking in my personal capacity, if I'm allowed to do that. um you see states that where their priority is to get snap benefit to residents as quickly and reduced with as reduced amount of friction so emergency snap getting it out the door much more quickly um increases the number of touch points because we will get the benefit out then come back and get more data come back and get more data as is allowable under the program where in other jurisdictions you see far smaller number and that all of the work is done in the upfront before any benefit is administered. And there are, it's just a different, it's a different strategy.

Vice Chair Tatan. Yeah, just on this, I think, I think what could be happening is that a lot of the states with lower rates are being more selective as who they give it out to. And maybe Maybe just looking at a certain demographic where they're sure they're not going to have any kind of error to eliminate the error. And therefore, if you're denying a lot of those benefits, then you're not giving out as many because you're being selective as to which ones you're giving out and therefore you would have less of a rate. But if you're looking at people who are on the threshold of having the benefit and their income might fluctuate in that period of time, then maybe that's where the error rates are coming from because you're trying to help the people who are on the fringe. And if you're only trying to affect the people who are at the bottom and not even close to the threshold, then you're not going to have as much of an error. That would be my guess. I made a note that we'll make sure to have the DHS folks come talk to us real early on

Chair Sochair

about this. So, okay, sneak peek. I want to finish in 15 minutes. Fantastic. That's it for a must. Overall, we are working hard to make meaningful progress, improving our governance, reducing our risk, and really trying to store public resources.

Sarah Thunbergwitness

Also, as evidenced by this meeting, getting way out over our skis talking about things like snap error rate. I apologize to my colleagues at CDHS. Vice Chair Titone.

Casey Cookother

Thank you very much. While we have you here, could you tell me a little bit about the real-time billing and how that's been going for, you know, keeping that fund on track and getting the rates? I would love for you to answer that, but I will just say that is we are going to be talking about that, too, between now and our next meeting.

Chair Sochair

We're just going to have an opportunity for JTC members to have direct conversation about real-time billing because that's come up, and I felt like we might need that opportunity. So I just share that because we will get a chance, but I'm also going to pitch to you if you have anything, but we will have a chance to talk before our December meetings, if that's all right with you guys.

Sarah Thunbergwitness

Thank you, Senator Marchman and Representative Titone. Yes, continuing. One of the changes we're deploying is in partnership with our agency colleagues, changing the invoice and the way that the bill is actually delivered to be far more human readable, less OIT speak, much more easy to understand. That is one of the things we're really focused on in innovating, and innovating is a strong word, iterating on in partnership with the agencies so that it is a lot clearer and gives the fidelity and detail that agencies want in an easy-to-understand way.

Chair Sochair

Okay, so I have a question. We got a list of the CCHE priorities Colorado Commission on Hire and by statute they have to submit an annual prioritized capital IT list to us JBC and OSPB Part of me is wondering if it shouldn We shouldn say it has to go to OIT at some point too My question is this We already have these lists They prioritized I mean I'm just going to go ahead and say they've got four projects tied for 100%. So that tells me already the rubric is challenging. But that said, it's $25 million of new capital IT projects that fall through the universities. Now, the way they get on this list is they get the group of folks to basically, it's five criteria. And one of them is like, you can vote for your own, basically. And so that's why we get like four of them are tied for 100%. But I do think it would be helpful for us to have a conversation about how do we handle these? Because we get a list from OSPB that you're going to look into, which is fantastic. But my concern is we've got this whole separate list and this whole separate process. And that's a whole separate conversation, but I would still value OIT's five pillar look at those projects. So just curious on your thoughts on that. Were you aware that we do that?

Sarah Thunbergwitness

Thank you. No, I was not aware and I have not looked at it. Happy to engage in a conversation with the right and appropriate thing is. Also happy to make available our evaluation criteria to you to give to them, if nothing else.

Chair Sochair

They not the ones to do it So you going to have like the presidents and those people saying we really need this Well those are not necessarily the people who are looking at the five specific techie things So we'll put a pin in it. We kind of had a, we, you know, yeah, Rep. Pascal. But nonetheless, we'll put a pin in it and come back.

Rep. Pascal. Thank you, Madam Chair. I am waiting for the definition of techie thingies. In the meantime, so we have in the bundle of stuff in our box, we have the Office of Information Technology 2026 Customer Feedback Survey, which was done in May 2026, which would have been before the restructuring. So I'm curious, what is the future for this? Is there going to be another survey done to see how things have changed, et cetera?

Sarah Thunbergwitness

Thank you for the question. Two things. One, we'll continue the annual survey. So we'll continue that cadence with similar questions, continue that. Additionally, we're launching a quarterly survey with our customer user group. So those people who we interact with most frequently, that will launch. It's a lighter survey with a smaller set of people, not everyone in state government. We'll do it quarterly starting in October. So next time we come, we'll be able to share the first iteration. Really sorry about that.

I was trying to get the definition of techie things. I think I nailed it.

Chair Sochair

Okay. Okay, seeing no other questions or business before us, we are going to adjourn. But before we do that I just want to say thank you so much This was really great I really appreciate all of the efforts Welcome And we will meet again in December. Let's try to set up a time where we can invite JTC members to come have a conversation about real-time billing. I would do it here, but it's just so formal. I feel like we need to sit around a table and ask questions and have just a little more, I don't know, we might ask a lot of questions. So we'll set something like that up between now and December. And then we will also set up a conversation about the higher ed. One thing that Mr. Gravy pointed out is that higher ed sends all their stuff October 1. but then OSPB does a little bit of massaging, again, not the techie things, but a little bit of massaging to make it a priority by November 1. So we do get a little bit of information, but again, it's not that tech stuff. It's the we approve and want this project from the governor's office. So all of that to say, Ms. Falco.

Samantha Falcoother

Samantha Falco, legislative council staff. I just, for the members, wanted to point out that last week I sent out from Diva Hari, Vivek, her draft AI assessment tool that we have had ongoing conversations about. So if everyone can review that draft and let us know if you have any feedback, that would be great.

Chair Sochair

I missed that. So thank you. Nice work. And we will commit to reviewing that. So thank you. And with that, we will adjourn JTC. Thank you.

Source: Joint Technology Committee [Oct 06, 2026] · October 6, 2026 · Gavelin.ai