All Guides
Strategy

What Should Be on an IT Roadmap?

A proper IT roadmap covers hardware, security, compliance, projects, and budget on a rolling 3-year view. Here is how to build one and present it to leadership.

Last reviewed September 2026

Overview

An IT roadmap is a 3-year forward view of what the business needs from technology. Not a wish list. Not a shopping list. A structured plan aligned to business strategy, covering what to keep, what to change, what to retire, and how much it costs.

What an IT Roadmap Covers

Business alignment

Strategy, growth targets, new sites, new products, M&A. Technology must serve the direction.

Infrastructure lifecycle

Servers, networks, storage, endpoints, cloud footprint. Refresh cycles and end-of-life dates.

Security posture

Essential Eight maturity target, security programme, insurance readiness, training.

Compliance obligations

Industry regulations, customer contracts, certifications (ISO, SMB1001, IRAP).

Software portfolio

Core platforms, upcoming migrations, retiring legacy, licence negotiations.

People and skills

Headcount for IT, training, capability gaps, partner strategy.

Projects pipeline

Prioritised list with size, risk, dependencies, and outcome.

Budget

OpEx and CapEx split, rolling 3 years, benchmarked.

Hardware Lifecycle

  • Laptops: 3-4 years, rolling refresh
  • Monitors and peripherals: 5-7 years
  • Network equipment: 5-7 years, security firmware throughout
  • Servers: 5 years or cloud migration
  • Phones and mobile: 2-3 years
  • Document and track every asset in a register (RMM exports, Intune, asset management tool)

Security Planning

  • Essential Eight maturity trajectory (ML1 now, ML2 year 2, etc.)
  • Insurance renewal requirements
  • Staff training programme
  • Incident response plan, tested annually
  • Third-party risk reviews
  • Planned penetration test cadence

Compliance Obligations

  • Australian Privacy Act obligations
  • Industry-specific (APRA CPS 234, healthcare, education, legal)
  • Customer contract requirements (enterprise customers, government)
  • Certification pathways (ISO 27001, SMB1001, IRAP, ACSC partner)
  • Overseas obligations if applicable (GDPR, NIS2, CMMC)

Budget Structure

Run (BAU)

Licences, managed services, support, connectivity, insurance. Predictable OpEx.

Grow

New systems, new sites, new capabilities. Funded by business growth.

Transform

Larger strategic shifts. Cloud migration, ERP replacement, office fit-outs. Funded discretely.

Refresh

Hardware and software refresh. Rolling CapEx or DaaS lease.

Contingency

10-15% of the total for unplanned events. Always needed, never planned for.

Presenting to Leadership

  • One-page executive summary with the 3-year picture
  • Risks and dependencies called out clearly
  • Budget expressed in dollars, not licence SKUs
  • Linked to business outcomes (growth, risk reduction, compliance, cost out)
  • Review cadence (quarterly with exec, annually with board)
  • Clear decisions needed from leadership, each time

Common Mistakes

No roadmap at all

Every decision becomes a fire drill. Budget is reactive. Risk accumulates.

Roadmap that is a wish list

Too long, too detailed, not prioritised. Board switches off.

Technology-led, not business-led

Lists Microsoft licences and Cisco gear but not outcomes. Board cannot approve.

Never revisited

Written in January, forgotten by March. Quarterly reviews keep it alive.

No budget discipline

"Strategy" with no numbers. Leadership cannot allocate.

Build a Proper IT Roadmap

We run IT strategy workshops and produce board-ready roadmaps, risk registers, and budgets for Australian SMBs.