How should a small or mid-size company plan its IT budget?

Short answer

Plan an IT budget bottom-up: list what it costs to run current systems, add hardware and license refresh, fund the roadmap projects leadership has approved, and set aside amounts for security, compliance and contingency. Then test the total against business growth and risk. Benchmarks based on a percentage of revenue are a weak substitute for a budget built from your actual needs.

Separate run, grow and protect

Most IT budgets mix three different kinds of spend. Keeping them separate makes the conversation with leadership much clearer.

Run costs keep the lights on: licenses, managed IT or staff, internet and phones, hosting and support contracts. Grow costs fund projects that change the business, such as an ERP, a new site or automation. Protect costs reduce risk: security tools, backup, compliance work, insurance requirements and incident readiness.

The main cost drivers

  • Headcount and hiring plans, which drive per-user licenses, devices and support
  • Number of locations, labs or plants and their network and on-site needs
  • Hardware refresh cycles for laptops, servers and network equipment
  • Software subscriptions and their renewal dates and price changes
  • Regulatory obligations such as CMMC, HIPAA or GxP, which add tooling, documentation and validation work
  • Major projects from the IT roadmap
  • Contract terms with your IT provider, including what is in scope and what is billed as projects

A practical planning method

Start with an inventory of every recurring IT cost and its renewal date; finance and your IT provider should be able to produce this together. Next, apply known changes: planned hires, devices due for replacement and announced vendor price changes.

Then price the roadmap. Each initiative should have a cost range, a quarter and a business owner. Finally, add a contingency line for unplanned work such as an urgent replacement or an incident.

NIST's Cybersecurity Framework 2.0 includes, within its Govern function, the outcome that adequate resources are allocated commensurate with the cybersecurity risk strategy, roles and policies. In budget terms, the protect line should follow from your risk decisions, not from whatever is left over.

Present it as decisions, not line items

Leadership approves budgets more readily when they can see the trade-offs. Show the run budget as the baseline, then present grow and protect items as choices: what each buys, what risk it reduces and what happens if it is deferred. Review actual spend against the plan quarterly and adjust with the roadmap.

Common budgeting mistakes

Each of the following turns into an unplanned request mid-year. A budget built from an inventory, a refresh schedule and a priced roadmap avoids most of them.

  • Budgeting only for renewals and forgetting the run costs that new projects add
  • Treating security as a one-time purchase rather than an ongoing cost
  • Ignoring end-of-life dates for servers, network gear and operating systems
  • Underestimating internal staff time needed for projects such as ERP or migrations
  • Leaving compliance work to be funded after an audit or customer demand arrives

Common follow-up questions

What percentage of revenue should we spend on IT?

There is no single right percentage. Spending depends on industry, regulation, growth stage and how much you outsource. Use benchmarks, if at all, only as a sanity check, and build the budget from your systems, headcount, roadmap and risk decisions.

Who should own the IT budget?

Finance usually owns the overall budget process, but a technology leader, such as a CIO or fractional CIO, should own the IT plan within it. That person can explain what each line buys and challenge vendor proposals with technical judgment.

How do we avoid surprise IT costs?

Keep a renewal calendar, know your provider's scope and exclusions, plan hardware refresh on a schedule, and hold a contingency line. Most surprises come from forgotten renewals, end-of-life systems and projects billed outside a managed services contract.

Need help with this?

LAN Service Group helps small and mid-size businesses build IT budgets tied to a roadmap and risk decisions as part of its IT strategy and fractional CIO-style leadership services.

Talk to LAN Service Group (888) 281-7243

Sources