Annual IT Planning for Organizations That Aren't Tech Companies
A Gartner-style planning cycle scaled for SMB operators, budget, risk, roadmap, and governance without a 50-person IT department.
Large enterprises run annual IT planning cycles: current-state assessment, demand forecast, architecture review, budget allocation, and a roadmap tied to business outcomes. SMB operators skip this, not because they don't need it, but because nobody packaged it for a leadership team that runs clinical programs, not datacenters.
You can run a credible planning cycle in two half-days with the right prep. Here's the structure we facilitate for clients across Rhode Island, Connecticut, and Massachusetts.
Why annual planning beats reactive IT
Without a plan, technology spend follows:
- Renewal dates (Microsoft auto-renews the wrong SKUs)
- Crises (ransomware, failed audit, key person departure)
- Loudest voice in the room (new tool for one department)
With a plan, spend follows business priorities: admissions capacity, new location, compliance gap, staff retention through better tools.
The output isn't a 100-slide deck. It's a one-page roadmap, a budget range leadership agrees on, and a risk register everyone understands.
Phase 1: Current-state snapshot (pre-work)
Before the planning session, document:
| Domain | Questions |
|---|---|
| People | Headcount, remote/on-site mix, roles joining/leaving in next 12 months |
| Applications | Line-of-business systems, shadow IT, integrations |
| Infrastructure | Cloud platforms, network sites, backup status |
| Security | MFA coverage, EDR, last phishing test, incidents in past year |
| Spend | MSP, licenses, telecom, projects, total IT-adjacent monthly |
Your MSP should deliver most of this in a environment summary, if they can't, that's finding zero.
Phase 2: Business demand intake (half-day, leadership)
Bring operations, finance, and program leadership. Ask:
- What must work flawlessly in the next 12 months? (Admissions season, audit, new site opening)
- What breaks today that we've normalized? (Workarounds, manual re-entry, downtime)
- What growth or change is planned? (M&A, new program, headcount +30%)
- What external pressure is coming? (Funder requirements, cyber insurance renewal, regulatory survey)
Map each answer to a technology dependency. "Open second location" implies network, identity, EHR access, phones, not just "more laptops."
Phase 3: Risk and compliance alignment
Rank risks honestly:
- Existential, ransomware without tested backup, no MFA on email
- Operational, single person knows the network, no documented runbooks
- Strategic, aging intake portal losing referrals to faster competitors
- Compliance, gaps an auditor or funder would flag
Allocate budget to existential and operational first. Strategic projects get slotted if capacity allows, not because they're shiny.
Phase 4: Build the roadmap (three horizons)
Translate demand and risk into initiatives:
0–6 months (run the business)
Renewals, security gaps, backup verification, critical replacements
6–18 months (change the business)
New location network, portal modernization, automation pilots, cloud optimization
18+ months (transform selectively)
Platform migrations, multi-site architecture, advanced analytics, only with business sponsor
Each initiative needs: owner, rough cost band, dependency, and success metric.
Phase 5: Budget and governance
Present leadership three numbers:
- Run, managed IT, licenses, telecom (predictable monthly)
- Grow, approved projects and pilots (quarterly release valve)
- Reserve, incident and opportunistic spend (10–15% of IT budget for SMBs)
Governance doesn't require a committee bureaucracy:
- Monthly ticket trend review with MSP
- Quarterly business review with roadmap check
- Annual plan refresh tied to fiscal calendar
Common planning mistakes
Planning tools instead of outcomes, "We need new CRM" before "referrals take 48 hours to assign."
Ignoring license true-ups, M365, EDR, backup seats creep; plan for true-ups explicitly.
No exit criteria for pilots, trials that never end consume budget and attention.
IT plans in a vacuum, admissions and clinical sign-off prevents built-but-unused systems.
Deliverables you should expect from your IT partner
After planning, you should have:
- One-page roadmap with horizons
- Budget run/grow/reserve breakdown
- Updated risk register
- Radar (adopt/trial/watch/hold) for emerging tech
- Named owners for each initiative
If your MSP only sends ticket stats, you're getting helpdesk metrics, not strategic partnership.
We run this cycle with clients as part of managed engagements. Start with a free audit if you want a current-state snapshot before your next fiscal year.