Ask most businesses between 10 and 100 employees how their IT budget gets set, and the honest answer is usually some version of “we take last year’s number and adjust it a bit.” Not because anyone’s being careless, but because IT budgeting is genuinely hard to do well without someone whose job includes actually owning the process, and most businesses this size don’t have a CIO or IT Director on staff to do it.
The result is a budget that’s more a reflection of accumulated commitments than a deliberate plan. Here’s a more useful way to approach it.
Start by separating “run” from “change”
Most IT budgets blur two very different categories of spend. “Run” costs are what it takes to keep the current environment operating: MSP fees, existing software licences, hosting, connectivity, hardware refresh cycles. “Change” costs are new investment: a system migration, a security uplift, a new platform to support growth.
When these two categories aren’t separated, run costs tend to quietly expand year over year (see: software sprawl) while change investment gets whatever’s left over, rather than being planned deliberately. Separating them forces a clearer question for each: is this necessary to keep operating, or is this a choice we’re making to move the business forward?
Build from actual need, not last year’s number
Rolling last year’s IT budget forward with a small adjustment feels efficient, but it locks in whatever inefficiencies were already there, including the unused licences and overlapping tools most businesses are quietly carrying. A better starting point is a proper review: what do we actually have, what does it cost, and what does the business actually need over the next 12-18 months.
This is more work upfront, but it’s the only way to catch the gap between what you’re paying for and what you’re using.
Map spend to business priorities, not vendor categories
Most IT budgets are organised by vendor or category: MSP fees, software, hardware, cloud hosting. That’s useful for accounting, but it doesn’t answer the question leadership actually cares about, which is whether IT spend is supporting where the business is going.
A more useful lens is to map spend against business priorities. If growth depends on a new location opening, what does IT need to support that. If a compliance requirement is coming, what does that cost. If the current setup is a security risk, what does closing that gap look like. This reframes IT budget conversations from “here’s what things cost” to “here’s what the business needs and what it costs to get there,” which is a much easier conversation to have at the leadership table.
Plan renewals ahead of time, not on the day the invoice lands
One of the most common patterns in businesses without dedicated IT leadership is that vendor and licence renewals get decided by default: the invoice arrives, nobody’s reviewed whether the tool is still needed or whether pricing is competitive, and it gets paid because stopping it feels riskier than continuing it.
A functioning IT budget process tracks renewal dates well ahead of time, so there’s a genuine decision point rather than a default renewal. This alone is often where the first real savings show up.
Build in a risk and compliance line, even if it feels abstract
It’s easy for IT budgets to focus entirely on operational costs and skip risk. But cyber insurance requirements, compliance obligations, and basic security hygiene (backups, access reviews, patching cadence) all have a cost, and if they’re not budgeted for deliberately, they tend to get deprioritised until something forces the issue. Budgeting for this proactively is cheaper than budgeting for it reactively, almost every time.
Review quarterly, not annually
IT budgets set once a year and then left alone tend to drift, because circumstances change faster than the annual cycle. A quarterly review, even a light one, keeps the budget aligned with what’s actually happening in the business and catches problems while they’re still small.
Who should be doing this
In businesses large enough to have a CIO or IT Director, this process has an owner. In businesses that aren’t, it usually falls to whoever’s available, which often means it doesn’t happen with much rigour at all. This is one of the more concrete pieces of what an IT Director actually does, whether full-time or fractional: bringing a deliberate, business-aligned process to a budget that would otherwise just be inherited from last year.
If your IT budget currently looks more like an inherited number than a plan, that’s a reasonable thing to bring to a conversation.