Plenty of businesses have an IT strategy document and no IT strategy. The document exists, it is professionally formatted, it gets presented quarterly, and year after year the same problems recur while the same initiatives stay listed as upcoming.
The tell is not length or polish. Weak plans are usually longer than good ones, because a plan that includes everything worth considering needs no prioritisation and cannot be wrong. A real roadmap makes choices, and choices can be checked.
If you work with a vCIO, are considering one, or want to test the plan you already have, these six questions surface the difference quickly. For the definitional groundwork, our explainers on what a vCIO is and what a virtual CIO does and when you need one cover the role itself.
1. What Are We Deliberately Not Doing This Year?
Ask this first, because it is the hardest question to answer with a document.
A weak plan lists everything: upgrade the servers, improve security posture, evaluate cloud options, review licensing, refresh laptops, consider AI. Everything on that list is defensible, which is the problem. Nothing has been chosen, so nothing has been committed to, and when the year ends nobody can say the plan failed because the plan never claimed anything specific would happen.
A real roadmap has exclusions and reasons for them. “We are not touching the phone system this year because the contract runs to next March and the money is going to the endpoint refresh.” That sentence is more informative than thirty pages of initiatives, because it proves somebody weighed alternatives against a finite budget.
If the answer is that everything on the list is a priority, you do not have a plan. You have an inventory of concerns.
2. Show Me the Next Four Quarters, With Owners and Money
The second question tests whether the plan is scheduled or merely aspirational. For each of the next four quarters you want three things: what is happening, who owns it, and roughly what it costs.
Missing owners are the most common gap and the most predictive. An initiative owned by “IT” or “the leadership team” is owned by nobody, and it is the first thing to slip when a busy quarter arrives. Missing money is nearly as telling, because a roadmap without cost attached has never been tested against what you can actually afford, which means the sequencing is arbitrary.
Vagueness that increases with distance is normal and fine. The next two quarters should be specific, and the following two can be directional. Vagueness in the next quarter means the plan is not operational yet. Our note on aligning IT strategy with a business growth plan covers how that sequencing should follow the business rather than the technology.
3. Which Commitments Slipped Last Quarter, and Why?
This is the question that distinguishes strategy from documentation, and a good vCIO will answer it without discomfort.
Things slip in every organisation. What matters is whether anyone tracked it. If last quarter’s commitments cannot be recalled, the plan is not being managed, it is being re-presented. A strategy with no operational follow-through is an expensive document, and it is entirely possible to have a polished roadmap sitting alongside operations that ignore it completely.
Listen for the shape of the answer as much as the content. “The migration slipped because the vendor’s timeline moved and we chose to pull the backup work forward instead” describes someone managing a plan. “We are still working through it” describes someone reporting on one.
4. Walk Me Through Your Quarterly Review Format
Ask to see the actual artefact: the agenda, the deliverables, the metrics tracked. Ask before signing if you are evaluating a provider.
A vCIO engagement is a process, not a title. If nobody can show you the format of the review, the standing deliverables, and the numbers that get reported each time, you are buying a job description. The specifics matter because they reveal what the engagement will actually consist of. A review that walks a risk register, a budget position against plan, an initiative status list, and a small set of agreed metrics is doing the job. A review that is a slide deck of industry trends is not.
Also establish cadence honestly. A useful pattern is a substantive quarterly review, lighter monthly check-ins, and availability when a real decision arises. Quarterly-only with no contact between reviews means the plan cannot respond to anything that happens in the intervening months.
5. What Does This Cost Over Three Years?
Weak plans are priced by the month, which hides most of what technology actually costs.
Three categories get left out consistently. Hardware refresh, which is a predictable cycle rather than a surprise, roughly four to five years for laptops and five to seven for servers and network equipment, and which produces a large line item whenever a fleet reaches end of support at once. Licensing escalation, since per-seat costs rise with headcount and vendors move customers up tiers. And project labour, because migrations and upgrades carry implementation and downtime costs well beyond the sticker price of the software.
A three-year view also exposes the plan’s honesty about debt. Every business defers something. A good plan names what is being deferred and when it comes due, so the eventual cost is scheduled rather than arriving as an emergency. That framing is what turns IT from an unpredictable expense into a budget line, which is one of the main reasons to bring in strategic help at all, as our overview of what IT strategy is and why it matters sets out.
6. What Breaks If We Grow By Half, or Lose Our Largest Client?
The last question tests whether the plan survives contact with the business changing, which it will.
Growth breaks things quietly. Systems sized for the current team, licensing negotiated for current headcount, support arrangements that assume a certain ticket volume. A plan built on a straight-line projection of today needs rewriting the moment you hire twenty people or open a second location, and the rewrite tends to happen under pressure.
Contraction is the harder half and is almost never addressed. If revenue dropped sharply, which commitments could be paused without leaving you exposed, and which absolutely could not? The second half of that question is the important one, because security and recovery capability are usually the first things proposed for deferral and the worst things to defer. Our piece on how your backup strategy determines your ransomware recovery outcome is a good illustration of a line item that looks optional right up until it is the only thing that matters.
What Good Answers Look Like
Across all six, the pattern that indicates a real plan is the same: specificity about trade-offs, named ownership, honest reporting on what did not happen, and numbers that extend past this quarter.
Three practical notes if you are testing an engagement:
- Agree a small number of measurable outcomes up front. Three to five is enough. Engagements that begin with objectives like “improve our IT” end in mutual frustration because nobody can tell whether they succeeded.
- Separate strategy from security ownership deliberately. These are related but distinct roles, and assuming one person covers both is a common gap. Our comparison of vCIO and vCISO roles explains how they divide.
- Give the plan a short first horizon. A focused ninety-day sprint produces evidence of whether the working relationship functions, which a twelve-month roadmap does not. Our 90-day business growth strategy sprint is built on that principle.
None of these questions require technical knowledge to ask, which is the point. They test whether somebody has made choices on your behalf and is prepared to be held to them.
If you would like to put your current plan through these six questions with someone who will answer them directly, book a free strategy call.
Frequently Asked Questions
What is the clearest sign of a weak IT strategy?
That it cannot say no. A plan listing every initiative worth considering has made no choices, commits nobody, and cannot be judged to have failed. Ask what is being deliberately deferred this year and why, and a real roadmap answers immediately.
What should a vCIO quarterly review actually contain?
A risk register, budget position against plan, status of each committed initiative including anything that slipped, and a small agreed set of metrics. If a provider cannot show you that format and its deliverables before you sign, the engagement is a title rather than a process.
How far ahead should an IT roadmap be costed?
At least three years, because the largest items are cyclical rather than monthly. Hardware refresh runs roughly four to five years for laptops and five to seven for servers and network gear, and licensing costs escalate with headcount, so a monthly view hides the biggest expenses.
Is a vCIO the same as a vCISO?
No. A vCIO owns technology strategy, roadmap, budget, and vendor decisions, while a vCISO owns security posture, risk, and compliance. They overlap and work well together, but assuming one person covers both is a common and consequential gap.
How do we know if our vCIO engagement is working?
Agree three to five measurable outcomes at the start, then check at each review whether committed initiatives shipped and whether last quarter’s slippage was tracked and explained. An engagement that reports on a plan rather than managing one shows up quickly under that test.

