IT Strategy: What It Is and Why Your Business Needs One

An IT strategy is a short written document that records what your business needs technology to do, what you will spend to get there, and what you have decided not to do. It is a record of decisions rather than a list of products, and its value is that it settles arguments before they cost money.

Ask a New Zealand business owner to see their IT strategy and most will reach for a folder of quotes. What they have is a series of decisions that each made sense on the day they were made, taken by different people, at different times, under different amounts of pressure. It works, more or less, until it does not.

The problem an IT strategy solves is not that your technology is bad. It is that nobody has written down what it is for.

What Is an IT Strategy?

An IT strategy is a written document that states what the business needs its technology to do over its planning horizon, what that will cost, and which things it has decided not to pursue. It is the document the rest of your technology planning is judged against.

A strategy that names vendors on page one has usually skipped the step where somebody asked what the business needed and gone straight to what the supplier had available.

A useful one answers four questions in writing:

  • What does the business need to be able to do? Open a second site, take on twenty more staff, work from anywhere, meet a client’s security requirements, survive an audit.
  • What is in the way? The server nobody wants to touch, the application that runs on one machine, the person who is the only one who knows how any of it is wired.
  • What will you spend, and roughly when? Not to the dollar, but enough that a large cost in eighteen months is not a surprise.
  • What are you deliberately not doing? Most documents skip this, and it is what makes the rest hold up under pressure.

The fourth question does more work than it looks. A document that says yes to everything is a budget bid wearing a different cover. It earns its keep on the day somebody proposes something reasonable and you can point at the page where you agreed not to do that this year.

Why Do So Few Businesses Have an IT Strategy?

Planning loses to whatever is on fire, and technology only becomes urgent when it breaks. Nothing that is currently working will ever be the most pressing item on an owner’s desk, so the strategy waits until something expensive removes the choice.

Security worry sits underneath a lot of that hesitation. MBIE’s Business Digital Capability Monitor, published in July 2024 from fieldwork run between November 2023 and January 2024, surveyed 2,356 New Zealand businesses of all sizes. It found concerns about information security and fraud to be the most frequently identified barrier to going further with digital tools, named by 49% of businesses overall and by 50% of small businesses, up from 42% of small businesses the year before.

Note what that measures and what it does not. It records what businesses say is holding them back. It says nothing about how many of them have written anything down, because nobody asks that question in a national survey. Our own experience is that the businesses most worried about security are frequently the ones with no document setting out what they have decided to do about it, and worry without a decision behind it is just a recurring meeting.

Security decisions do belong in the strategy rather than in a separate pile, which is the connection our guide to IT risk management works through in more detail.

What Goes Wrong in a Business With No IT Strategy?

Four things go wrong: systems stop fitting together, reliability becomes something customers notice, money leaves with nothing depending on it, and staff build their own workarounds. They arrive in roughly that order, and none of them presents as a planning failure at the time.

  • Systems stop fitting together. Each tool was chosen well on its own day. Nobody was accountable for whether the set worked as a set, so staff move data between them by hand and come to regard that as the job.
  • Reliability becomes a customer problem. Internally an outage is an inconvenience. Externally it is evidence. A client who cannot reach you during a failure does not distinguish between bad luck and bad planning.
  • Money goes out with nothing depending on it. Licences assigned to people who left, subscriptions that overlap, hardware replaced in a panic at whatever price was available that week, and a support bill that grows because it is absorbing the cost of the underlying mess.
  • Good staff quietly work around it. They build spreadsheets, keep local copies, use their own tools. It looks like resourcefulness and it is, but every workaround puts a piece of the business somewhere you cannot see, back up or protect.

The fourth is the one owners underestimate, because it never appears on an invoice. It appears in how long things take, and in who leaves.

Four failures without an IT strategy: systems drift apart, outages reach customers, spend leaks, staff build workarounds

What Should an IT Strategy Contain?

Six sections: business context, current state, gaps and risks, priorities, indicative spend, and a review date. It should fit in a document somebody will actually read, which for a business of this size usually means fewer than ten pages.

Section What it records Why it earns its place
Business context What the business intends to do over its planning horizon Everything below is judged against this, so it goes first
Current state What you run now, what it costs, what is near end of life You cannot plan around a server you have forgotten you own
Gaps and risks Where the current setup will not support the plan Turns vague unease into a list that can be argued about
Priorities What gets done first, second and not at all The part that makes it a strategy rather than a list
Spend Indicative cost and rough timing against each priority Stops large costs arriving as surprises
Review date When it will be looked at again, and by whom Without a date it becomes a historical document

Notice what is absent. There are no product names, no vendor comparisons and no configuration detail, all of which belong in the work that follows rather than in the decisions themselves.

How Is an IT Strategy Different From a Roadmap or a Budget?

The strategy decides, the roadmap sequences, and the budget funds. Those are three documents doing three jobs, and most of the confusion in technology planning comes from asking one document to do all three.

An IT strategy states what matters and what does not. An IT roadmap takes those decisions and puts them in an order with dates attached. IT budget planning then turns that order into numbers a financial year can carry.

Run them backwards and you get the pattern most owners recognise on sight. The budget is set first, from last year’s figure plus a percentage. The roadmap is written to fit the budget. The strategy, where one exists, is assembled afterwards to explain what was always going to happen anyway.
Strategy decides what matters, roadmap puts it in order, budget pays for it, and the reverse order most businesses follow

What Does an IT Strategy Change About How You Spend?

An IT strategy changes the order of the questions. Without one, the question is whether a given purchase is affordable. With one, the question is whether it is the next thing, which is harder to answer and considerably more useful.

The national picture is worth a glance for context, with a clear warning about what it is. Stats NZ’s productivity statistics for the year ended March 2025, released in April 2026, cover the measured sector, meaning the market industries that make up over 80% of New Zealand’s GDP. In that year capital inputs rose 1.5% while output fell 1.5%, and capital productivity fell 3.0%.

Be careful how you read that. Capital inputs are the flow of services a business gets from the capital it already holds, not the amount it spent that year. Capital productivity is output per unit of capital, not financial return. The series covers firms of every size, it does not separate technology from buildings, plant or vehicles, and it says nothing whatsoever about businesses that plan compared with businesses that do not.

So it is not evidence that an IT strategy works. It is a description of the conditions you are buying in, and the direction is unhelpful enough to make unplanned spending a worse bet than it was five years ago. That is the strongest honest claim available, and any supplier telling you the national numbers prove they can improve your productivity is overreaching.

Who Should Write the IT Strategy?

Somebody who understands the business and somebody who understands the technology should write it together, with the owner or general manager in the room while the decisions are made. In most businesses between ten and a hundred staff there is no internal person whose job this is, so the technical half comes from an external adviser.

The failure at each end is predictable. Written by the business alone, an IT strategy becomes a list of frustrations with no idea what fixing them costs. Written by a supplier alone, it becomes a quote with a cover page.

Who holds the pen matters less than who is accountable for what is in it. Two rules keep that honest:

  • The person who signs it must be able to explain it. If the owner cannot say in their own words why the second item is second, it has been accepted rather than agreed.
  • Whoever advises should be willing to write down what not to buy. Advice that only ever adds is not advice.

Some businesses formalise this with vCIO services rather than carrying the role internally.

How Often Should an IT Strategy Be Reviewed?

An IT strategy should be reviewed once a year as a standing commitment, and immediately whenever something material changes in the business. The annual review keeps it alive and the triggered review keeps it accurate.

The triggers are easy to list and easy to miss in the moment: taking on or losing a significant number of staff, opening or closing a site, a merger or acquisition, a new client arriving with security requirements attached, a serious incident, or a core system reaching end of support.

Any one of those changes what the business needs technology to do, which is the first line of the document. If that line has changed and nothing below it has been revisited, the rest is now describing a business you no longer run.

How Do You Tell a Real IT Strategy From a Shopping List?

Look for the decisions that cost something. A real IT strategy contains at least one thing the business wanted, is not getting this year, and the reason why. A shopping list contains only purchases.

Four further tests, none of which need any technical knowledge:

  • Can you find the business reason for the largest line? If the justification is that the current one is old, that is a replacement schedule.
  • Is there a number against doing nothing? Good documents price the status quo, because that is what every option is really being compared with.
  • Does it name who decides? Not who installs. Who decides.
  • Would it still make sense if your supplier changed? A document written around one provider’s product set is that provider’s plan.

The NCSC Cyber Security Framework makes a similar point from the security side. Its stated audience is government and large organisations, though the NCSC says it can be used by organisations in any sector, so treat it as a structure worth borrowing rather than a standard you are expected to meet. Two of its objectives read directly onto this: prioritise security investment towards real threats to the systems that matter, and know who you can get help from before an incident happens. Both are decisions taken in advance and written down.

Frequently Asked Questions

What is an IT strategy?

An IT strategy is a written document stating what a business needs its technology to do, what it will spend to get there, and what it has decided not to do. It records decisions rather than products, so that technology spending can be judged against something other than the urgency of whoever is asking.

Which document does a given decision belong in, the strategy or the roadmap?

If the decision is about whether something is worth doing, it belongs in the strategy. If it is about when it happens and in what order, it belongs in the roadmap. A useful test: if changing your mind would alter what the business is trying to achieve, that is strategy, and if it only alters the sequence, that is the roadmap.

How much does an IT strategy cost to produce?

It is normally a few days of work rather than a project, and it is often included in an existing advisory arrangement rather than quoted separately, so the answer depends on how you are already buying advice. Two questions settle it with any provider: what is the day rate, and does the fee include the review in twelve months. Our IT consulting page sets out how we price this work.

Does a business with twenty staff really need an IT strategy?

Yes, and arguably more than a large one does, because a smaller business has less room to absorb a bad technology decision. The document can be proportionately shorter. What it cannot be is absent, because the alternative is not having no strategy but having an unwritten one that changes depending on who is asked.

What is the first step if we have never had one?

Write down what the business intends to do over the next two years, in plain language and on one page, before anyone looks at the technology. Almost every bad IT strategy starts with an audit of the equipment, because that is the easy part, and then quietly becomes a replacement schedule.

Can our managed IT provider write our IT strategy?

They can, and many do it well, but ask one question first: are they willing to write down what you should not buy? A provider whose advice only ever adds to its own scope is not giving you a strategy. The practical test is whether the document would still make sense if you changed suppliers next year.

How do we know whether our current IT strategy is working?

Compare the last twelve months of technology spending against what the document said the priorities were. If most of the money went on things that are not in it, either the strategy was wrong or it is being ignored, and both of those are worth knowing before the next budget round.

What is the difference between an IT strategy and a digital transformation programme?

The strategy is the decision-making document and a transformation programme is one possible outcome of it. A business can have a perfectly good IT strategy whose conclusion is that this is not the year to change how anything works, which is a legitimate answer that a transformation programme cannot reach.

Should the IT strategy cover cyber security, or should that be separate?

It should cover it, because security decisions compete for the same money as everything else and separating them is how they end up unfunded. The detailed threat work can live in a separate risk assessment, but what the business has decided to protect, and what it has accepted, belongs in the main document.

How does Exodesk help with IT strategy?

We run the review, write the document with you, and price the options including the option of doing nothing, working with businesses from our Christchurch and Dunedin offices. Where a business already has a strategy, the more useful exercise is usually checking whether the last twelve months of spending actually matched it.

NEXT STEP

Could you say what last year’s technology spend bought?

If the answer is not really, that is the gap an IT strategy closes. We help New Zealand businesses write one that is short enough to use and specific enough to argue with.

Or read more about our IT consulting services.

Start typing and press Enter to search

Social engineering banner: an impersonated call and video request alongside a separate phone used to verify it independentlyBCDR vs backup for NZ businesses -- flat vector iceberg showing backup as small visible tip and full BCDR strategy as large hidden foundation below waterline Call Us Now