Citizen Portal

Get email alerts on the Audit topic

No spam. Unsubscribe anytime.

Post Audit finds nearly half of audited entities fall short on basic IT security controls

Joint Committee on Information Technology · August 25, 2026

Summary

A two-year post-audit summary presented to the committee found that 7 of 15 audited entities scored below 50% on reviewed IT security controls; common recurring weaknesses included vulnerability scans and patching, lack of disaster recovery/continuity planning and incomplete incident response plans.

The Kansas Legislative Division of Post Audit presented a two-year summary of IT security audits covering multiple state and local entities and reported repeated and widespread weaknesses.

The auditor said, "7 of the 15 entities that were audited in the past 2 years did not subsequently comply with applicable IT security standards and best practices," and noted the most common problem areas were vulnerability remediation, continuity of operations and incident response. Auditors found many entities did not perform credentialed vulnerability scans or timely patching, used unsupported software versions and lacked tested disaster recovery and business impact analyses.

The report attributed root causes to three consistent issues: insufficient management attention and oversight, inadequate IT resourcing, and poor contractor administration. The post audit presenter said follow-up audits and written responses are part of the oversight process, and that audited entities are expected to provide corrective plans and report progress in subsequent reviews.

AI generated

The text on this page is AI generated. Summaries, highlights, analysis, and video transcripts are all produced from the original source material.

AI can make mistakes, so if you spot one, and we will fix it for everyone.

Note: the source content is unaltered by us. Any content source we link to, be it a video, an audio recording, or a document, is presented exactly as its publisher released it. That publisher is usually a government body, sometimes an individual official or another organisation.

Source