Back in 1789, Benjamin Franklin famously penned a note to the French scientist Jean-Baptiste Le Roy, declaring, “In this world, nothing can be said to be certain, except death and taxes.” Fast-forward more than 200 years, and many in government tech and security spheres might add auditors—who frequently deliver audit findings—to that list of certainties. This raises an intriguing question: Does the relationship between security and technology leaders and their auditors need to be contentious?
In my opinion, the answer is a resounding “no.” Auditors and Chief Information Security Officers (CISOs) can, and should, be allies. Both parties share the same overarching goal: to identify vulnerabilities, fix security issues, and ultimately prevent data breaches. This was a point highlighted in a 2021 article discussing the sometimes strained relationship between auditors and CISOs during my tenure as CISO in Michigan’s government. The disconnect often lies in their differing perspectives, but with the right approach, collaboration can thrive.
Earlier this year, I encountered Peter Ulrich, the IT Audit Manager at the Denver Auditor’s Office, at the Billington State and Local CyberSecurity Summit in Washington, D.C. Peter’s certifications, including CISA and CSX-A, underpin his impressive background across both public and private sectors, bringing a wealth of knowledge to his current position. What particularly stood out to me was his supportive relationship with Merlin Namuth, CISO for the City and County of Denver. Their rapport illustrates that cooperative relationships are not only possible but can lead to tangible improvements in cybersecurity.
In discussing his role, Peter reflected on how he found meaning in serving the public through his work in IT auditing. He explained that after thriving in a private sector role at Vantage Data Centers, he craved purpose and a connection to the community. Joining the Denver Auditor’s Office resonated with him deeply, given the scope of services and the diversity of missions to aid residents.
When asked about his working relationship with Merlin Namuth, Peter highlighted transparency and open communication as core pillars. “Maintaining independence and objectivity is essential for audits,” he noted. This independence allows him to analyze security protocols and make objective recommendations. He emphasizes the importance of working collaboratively to reach the same end goal of reducing risk and bolstering security, even if the specific pathways are sometimes up for debate.
Managing public relations surrounding audit findings is another vital aspect of Peter’s role. With the Denver Auditor’s Office, he is fortunate to have a skilled communications team to navigate press releases and media inquiries. This internal framework helps ensure that the messages conveyed to the public are accurate and constructive. Cybersecurity issues rarely garner favorable press, so assessing what information needs to remain confidential versus what should be communicated transparently is essential for maintaining public trust.
When discussing how audits can impact public perceptions, Peter responded thoughtfully. He balances the need for transparency with the potential risks associated with revealing sensitive information. The Colorado Open Records Act (CORA) provides guidelines for disclosure while protecting sensitive audit data. Following the Generally Accepted Government Auditing Standards (GAGAS), his office safeguards both the integrity of the audit process and confidential data.
Another crucial element to their effective collaboration is the mutual respect and understanding of roles. Peter and Merlin see eye-to-eye on their shared mission, even if they don’t always agree on their priorities. “Role clarity is essential,” Peter remarked, emphasizing that while Merlin’s team is in the frontlines of cybersecurity defense, his audits provide assurance on the effectiveness of the systems in place. This shared commitment to improving security allows for a productive working relationship, built on trust and professionalism.
Many CISOs struggle to view audits positively due to a misunderstanding regarding their purpose. Auditors can often be seen as adversaries seeking to expose flaws rather than partners dedicated to improving security. Peter suggests that auditors need to convey the value they bring, as their insights can effectively serve as free consulting. “We’re not here to assign blame; we’re here to improve,” Peter notes, stressing the importance of focusing on accountability rather than punishment.
For auditors, building relationships is critical. An understanding of the organization’s unique challenges allows auditors to conduct thorough assessments while fostering collaboration. This relational approach helps auditors meet professional standards while also accommodating the often-understaffed teams they are auditing.
As security and technology continue to evolve, the need for collaboration between auditors and CISOs becomes increasingly evident. The mutual goal of reducing risk and enhancing security can only be achieved when these professionals come together, leveraging their respective strengths to protect their organizations and the public they serve.

