IT Strategy: What to Include and How to Build One

An IT strategy is a short written document that records what your business needs technology to do, what you will spend to get there, and what you have decided not to do. It is a record of decisions rather than a list of products, and its value is that it settles arguments before they cost money.

Ask a New Zealand business owner to see their IT strategy and most will reach for a folder of quotes. What they have is a series of decisions that each made sense on the day they were made, taken by different people, at different times, under different amounts of pressure. It works, more or less, until it does not.

The problem an IT strategy solves is not that your technology is bad. It is that nobody has written down what it is for.

What Is an IT Strategy?

An IT strategy is a written document that states what the business needs its technology to do over its planning horizon, what that will cost, and which things it has decided not to pursue. It is the document the rest of your technology planning is judged against.

A strategy that names vendors on page one has usually skipped the step where somebody asked what the business needed and gone straight to what the supplier had available.

A useful one answers four questions in writing:

  • What does the business need to be able to do? Open a second site, take on twenty more staff, work from anywhere, meet a client’s security requirements, survive an audit.
  • What is in the way? The server nobody wants to touch, the application that runs on one machine, the person who is the only one who knows how any of it is wired.
  • What will you spend, and roughly when? Not to the dollar, but enough that a large cost in eighteen months is not a surprise.
  • What are you deliberately not doing? Most documents skip this, and it is what makes the rest hold up under pressure.

The fourth question does more work than it looks. A document that says yes to everything is a budget bid wearing a different cover. It earns its keep on the day somebody proposes something reasonable and you can point at the page where you agreed not to do that this year.

Why Does IT Planning Get Postponed?

Planning loses to whatever is on fire, and technology only becomes urgent when it breaks. Nothing that is currently working will ever be the most pressing item on an owner’s desk, so the strategy waits until something expensive removes the choice.

Underneath that sits a harder problem. MBIE’s Business Digital Capability report, published in May 2026 from fieldwork run in October and November 2025, surveyed 2,508 business owners and senior managers. The barrier they named most often was a low perceived return on investment, at 25%, ahead of not being able to afford the upfront cost at 22%, and lacking the skills or finding it hard to choose the right tools at 21% each. Concerns about information security and fraud stopped 16%.

Note what that measures and what it does not. It records what businesses say is holding them back on digital tools, not how many of them have written anything down, which is not something these surveys ask. But the answer at the top of that list is the one this page is about. A business that cannot see what a technology investment will return is describing the absence of a document that says what the spend is for.

Security decisions belong in the strategy rather than in a separate pile, which is the connection our guide to IT risk management works through in more detail.

What Goes Wrong in a Business With No IT Strategy?

Four things go wrong: systems stop fitting together, reliability becomes something customers notice, money leaves with nothing depending on it, and staff build their own workarounds. They overlap more often than they arrive in a fixed order, and none of them presents as a planning failure at the time.

  • Systems stop fitting together. Each tool was chosen well on its own day. Nobody was accountable for whether the set worked as a set, so staff move data between them by hand and come to regard that as the job.
  • Reliability becomes a customer problem. Internally an outage is an inconvenience. Externally it is evidence. A client who cannot reach you during a failure does not distinguish between bad luck and bad planning.
  • Money goes out with nothing depending on it. Licences assigned to people who left, subscriptions that overlap, hardware replaced in a panic at whatever price was available that week, and a support bill that grows because it is absorbing the cost of the underlying mess.
  • Good staff quietly work around it. They build spreadsheets, keep local copies, use their own tools. It looks like resourcefulness and it is, and some of it is perfectly well governed. The rest puts a piece of the business somewhere nobody is backing up or protecting, and nobody knows which is which until someone looks.

The fourth is the one owners underestimate, because it never appears on an invoice. It appears in how long things take, and in who leaves.

Four failures without an IT strategy: systems drift apart, outages reach customers, spend leaks, staff build workarounds

What Should an IT Strategy Contain?

Six sections: business context, current state, gaps and risks, priorities and ownership, indicative spend, and outcomes with a review date. It should fit in a document somebody will actually read, which for a business of this size usually means fewer than ten pages.

Section What it records Why it earns its place
Business context What the business intends to do over its planning horizon Everything below is judged against this, so it goes first
Current state What you run now, what it costs, what is near end of life You cannot plan around a server you have forgotten you own
Gaps and risks Where the current setup will not support the plan Turns vague unease into a list that can be argued about
Priorities and ownership What gets done first, second and not at all, who owns each one, and who can approve a change The part that makes it a strategy rather than a list
Spend Indicative cost and rough timing against each priority Stops large costs arriving as surprises
Outcomes and review The starting position, the improvement wanted, how it will be measured, and when it is looked at again Without a measure and a date it becomes a historical document

Notice what is mostly absent. Vendor comparisons and configuration detail belong in the work that follows rather than in the decisions themselves. Existing platforms and the dependencies that constrain a choice do belong, usually in the current state, because a gap nobody can name is a gap nobody can cost.

How Do You Build an IT Strategy?

In five steps, and the order matters more than the polish. The first two are the ones businesses skip, because they are the ones that cannot be answered by looking at the equipment.

  • Agree the business goals and constraints. What the business intends to do, what it can fund, what risk it is willing to carry, and how much change it can absorb at once.
  • Establish the current position. The systems, costs, dependencies and gaps that bear on those goals, including anything near end of support.
  • Compare the options against each priority. Including improving what you already run, and including what it costs to defer the decision another year.
  • Record the priorities and who owns them. The reasoning, the indicative resources, the outcome expected, and who can approve a change to any of it.
  • Build the delivery plan, then review against the outcome. Sequencing and funding are the next two jobs, and the measure you set in step four is what the review is actually for.

How Is an IT Strategy Different From a Roadmap or a Budget?

The strategy decides, the roadmap sequences, and the budget funds. Those are three jobs, and most of the confusion in technology planning comes from asking one of them to do all three. They can be three documents or three sections of one working plan, and in a smaller business one plan is usually enough. What matters is that each job gets done, and that they keep informing each other as costs, risks and business needs become clearer.

An IT strategy states what matters and what does not. An IT roadmap takes those decisions and puts them in an order with dates attached. IT budget planning then turns that order into numbers a financial year can carry.

Run them backwards and you get the pattern most owners recognise on sight. The budget is set first, from last year’s figure plus a percentage. The roadmap is written to fit the budget. The strategy, where one exists, is assembled afterwards to explain what was always going to happen anyway.
Strategy decides what matters, roadmap puts it in order, budget pays for it, and the reverse order most businesses follow

What Does an IT Strategy Change About How You Spend?

An IT strategy changes the order of the questions. Without one, the question is whether a given purchase is affordable. With one, the question is whether it is the next thing, which is harder to answer and considerably more useful.

Four questions do most of that work, and none of them needs a national statistic behind it:

  • What outcome is this meant to produce? Stated as something the business would notice, not as a system being replaced.
  • What happens if nothing changes? Price the status quo, because that is what every option is really being compared against.
  • Which options fit the constraints? Including improving what you already run, and including waiting a year.
  • How will you know afterwards? What you will measure, against what starting point, and when you will look at it.

Any supplier telling you that national productivity figures prove they can improve yours is overreaching. Those series cover firms of every size, do not separate technology from buildings, plant or vehicles, and say nothing at all about businesses that plan compared with businesses that do not.

A strategy is what lets you answer the fourth question twelve months later, because it is the only place the starting point was written down.

None of that is a reason to spend more. It is a reason to know what each thing is for before you spend anything.

Who Should Write the IT Strategy?

Somebody who understands the business and somebody who understands the technology should write it together, with the owner or general manager in the room while the decisions are made. Plenty of businesses of this size have nobody internally whose job this is, in which case the technical half comes from an external adviser.

The risk at each end is worth naming. Written by the business alone, an IT strategy can turn into a list of frustrations with no idea what fixing them costs. Written by a supplier alone, it can turn into a quote with a cover page. Neither is inevitable, and a capable internal team or an independent adviser will avoid both; what makes the difference is whether both halves of the conversation are in the room.

Who holds the pen matters less than who is accountable for what is in it. Two rules keep that honest:

  • The person who signs it must be able to explain it. If the owner cannot say in their own words why the second item is second, it has been accepted rather than agreed.
  • Whoever advises should be willing to write down what not to buy. Advice that only ever adds is not advice.

Some businesses formalise this with vCIO services rather than carrying the role internally.

How Often Should an IT Strategy Be Reviewed?

An IT strategy should be reviewed once a year as a standing commitment, and immediately whenever something material changes in the business. The annual review keeps it alive and the triggered review keeps it accurate. A lighter progress check in between, at whatever cadence suits the business, lets an owner act on a slipping priority rather than discovering it twelve months later.

The triggers are easy to list and easy to miss in the moment: taking on or losing a significant number of staff, opening or closing a site, a merger or acquisition, a new client arriving with security requirements attached, a serious incident, or a core system reaching end of support.

Any one of those changes what the business needs technology to do, which is the first line of the document. If that line has changed and nothing below it has been revisited, the rest is now describing a business you no longer run.

How Do You Tell a Real IT Strategy From a Shopping List?

Look for the decisions that cost something. A strategy that has made real choices usually shows its trade-offs: something the business wanted that is waiting, and the reason it is waiting. A shopping list contains only purchases.

Four further tests, none of which need any technical knowledge:

  • Can you find the business reason for the largest line? Age on its own is not a business case, though support expiry, reliability and lifecycle cost can be. If nothing more than age is written down, that is a replacement schedule.
  • Is there a number against doing nothing? Good documents price the status quo, because that is what every option is really being compared with.
  • Does it name who decides? Not who installs. Who decides.
  • Would it still make sense if your supplier changed? A document written around one provider’s product set is that provider’s plan.

The NCSC Cyber Security Framework makes a similar point from the security side. Its stated audience is government and large organisations, though the NCSC says it can be used by organisations in any sector, so treat it as a structure worth borrowing rather than a standard you are expected to meet. Two of its objectives read directly onto this: prioritise security investment towards real threats to the systems that matter, and know who you can get help from before an incident happens. Both are decisions taken in advance and written down.

Frequently Asked Questions

What is an IT strategy?

An IT strategy is a written document stating what a business needs its technology to do, what it will spend to get there, and what it has decided not to do. It records decisions rather than products, so that technology spending can be judged against something other than the urgency of whoever is asking.

Which document does a given decision belong in, the strategy or the roadmap?

If the decision is about whether something is worth doing, it belongs in the strategy. If it is about when it happens and in what order, it belongs in the roadmap. A useful test: if changing your mind would alter what the business is trying to achieve, that is strategy, and if it only alters the sequence, that is the roadmap. They can be two documents or two sections of one plan, as long as both jobs actually get done.

How much does an IT strategy cost to produce?

It depends on how many systems and sites are in scope, how much is already documented, and whether the work stops at the strategy or carries on into a roadmap and ongoing advice. We scope the work and quote a fixed fee before it starts rather than selling it by the day, and our IT consulting page sets out the engagement options. Whoever you ask, check what the quote covers and whether the review in twelve months is included.

Does a business with twenty staff really need an IT strategy?

Yes, though the document should be proportionate. A simple business with few systems may need only a couple of pages, while multiple sites, complex systems or regulatory obligations justify deeper work. What it cannot be is absent, because the alternative is not having no strategy but having an unwritten one that changes depending on who is asked.

What is the first step if we have never had one?

Write down what the business intends to do over the next two years, in plain language and on one page, before anyone looks at the technology. An equipment audit is useful input and a poor starting point, because a plan that begins with the inventory tends to end as a replacement schedule.

Can our managed IT provider write our IT strategy?

They can, and many do it well, but ask one question first: are they willing to write down what you should not buy? A provider whose advice only ever adds to its own scope is not giving you a strategy. The practical test is whether the document would still make sense if you changed suppliers next year.

How do we know whether our current IT strategy is working?

Check the outcomes as well as the spending. Against each priority, compare where the business started, what improvement was wanted and where it has got to. Spending to the plan is useful discipline, but it does not prove the investment delivered anything. If most of the money went on things that are not in the document, either the strategy was wrong or it is being ignored, and both are worth knowing before the next budget round.

What is the difference between an IT strategy and a digital transformation programme?

The strategy is the decision-making document and a transformation programme is one possible way of implementing it. A business can have a perfectly good IT strategy whose conclusion is that this is not the year to change how anything works. A programme already under way can also be paused or reconsidered when the strategy is reviewed, which is one of the reasons for having one.

Should the IT strategy cover cyber security, or should that be separate?

It should cover it, because security decisions compete for the same money as everything else and separating them is how they end up unfunded. The detailed threat work can live in a separate risk assessment, but what the business has decided to protect, and what it has accepted, belongs in the main document.

How does Exodesk help with IT strategy?

We run the review, write the document with you, and price the options including the option of doing nothing, working with businesses from our Christchurch and Dunedin offices. Where a business already has a strategy, the more useful exercise is usually checking whether the last twelve months of spending actually matched it.

NEXT STEP

Could you say what last year’s technology spend bought?

If the answer is not really, that is the gap an IT strategy closes. We help New Zealand businesses write one that is short enough to use and specific enough to argue with.

Or read more about our IT consulting services.

Start typing and press Enter to search

Social engineering banner: an impersonated call and video request alongside a separate phone used to verify it independentlyProduction servers, an application and cloud services on one side of a dashed line, with a locked backup copy set apart on the other Call Us Now