Back to blog
DecisionsSMEsManaged Service

Prioritising IT investments: what comes first

NDVDL Team8 min read
Network and server infrastructure as the foundation for IT investments

IT investments should be prioritised in a clear order: first close the risks that could bring the business to a standstill, then strengthen the technical foundation, and only then invest in new features and convenience. Missing or untested backups and security gaps therefore come before new software. A roadmap spanning several years stops the budget from flowing into one-off purchases decided by urgency rather than impact.

Why are IT investments in SMEs often prioritised wrongly?

In many businesses the order of IT spending comes out of daily life: whoever asks loudest, or whose device has just failed, gets the budget. Add to that offers from vendors and resellers who naturally put their own product first. The result is visible purchases like new laptops or a new app, while invisible foundations such as backup, updates or network structure are left behind.

Invisible gaps only show up once they become expensive. A business notices a missing working backup during an outage, an unpatched firewall during an attack. Prioritising therefore means deliberately setting the order by risk and impact rather than by visibility.

Risk or benefit – which comes first?

A simple method is to place every planned investment against two questions: what happens if we don't do it? And what do we gain if we do? Investments that close a high risk come before investments that mainly add benefit. Benefit can still be gained later, but a total outage or data loss cannot be undone.

  • High risk, high benefit: tackle immediately, for example a working, tested backup
  • High risk, little visible benefit: still plan early, for example replacing systems without vendor updates
  • Low risk, high benefit: implement after the foundations, for example automation or an interface between two systems
  • Low risk, low benefit: postpone or drop

Which gaps should be closed first?

At the top of the list are the points where a single incident could shut the business down for a long time or destroy data for good. These gaps are usually not expensive to close but are often overlooked because nothing seems wrong day to day.

  • Backup: is all important data backed up, is a copy kept separate from the main system, and has restoring actually been tested?
  • Updates: are servers, firewall, network devices and workstations running versions that still receive security updates?
  • Access: are admin accounts protected, is multi-factor authentication enabled for email and remote access, are accounts of departed staff disabled?
  • Documentation: does anyone other than a single person know how the IT is set up and where credentials are kept?
  • Emergency: is it defined who does what during an outage and in which order systems are restored?

From practice: a backup only counts as existing once a restore has been successfully tested. Some businesses are convinced they have a backup and discover on the first test that important data is missing or that restoring takes longer than expected.

Want to know where your IT stands today? The IT self-check uses typical everyday situations to show where things are stuck and what to tackle first.

Start the IT check

Why foundations before extras?

After the acute risks comes the technical foundation: a stable, sensibly segmented network, orderly user management, a clear decision between cloud and on-premise servers, and traceable documentation. New software, automation or AI applications build on this foundation. Introducing them first means building on ground that gives way later under the extra load.

This applies to AI in particular. An AI assistant meant to search internal documents needs organised, findable data and clear access rights. Without them, AI starts at the wrong end. The extras have their place in the roadmap, but after the foundation.

How do one-off purchases become an IT roadmap?

An IT roadmap spreads planned investments over several years and shows what depends on what. It makes visible when devices and licences expire, which projects build on each other and where budget can be bundled. Instead of deciding anew each year what feels urgent, the business works through a plan and adjusts it regularly.

  1. 01Inventory: record devices, software, licences, contracts and their terms in one place.
  2. 02Assess risks: check backup, updates, access, documentation and emergency planning honestly.
  3. 03Clarify dependencies: which projects require others first, for example the network before a new phone system.
  4. 04Rank projects by risk and benefit and spread them across years and quarters.
  5. 05Prepare a short decision paper for management for every larger project.
  6. 06Review the roadmap at least once a year and after major changes in the business.

What belongs in a decision paper for management?

A good decision paper fits on one page and is understandable without technical knowledge. It shows which problem is being solved, which options exist and what happens if nothing is done. That lets management assess IT investments in the same way as any other investment in the business.

  • Situation: which problem or risk exists today, in plain words
  • Options: two or three realistic variants, including doing nothing
  • Costs: one-off costs and running costs over the planned lifetime
  • Impact: which risk falls, which process improves, who in the business notices
  • Dependencies and timing: what has to be done first and when implementation makes sense
  • Recommendation: which option is proposed and why

What mistakes do SMEs make when planning IT budgets?

  • Budgeting only for the purchase and forgetting ongoing licences, maintenance and support
  • Replacing devices only when they fail instead of planning the replacement
  • Starting a project before its foundation is in place, such as moving to the cloud without an adequate internet connection
  • Treating security as a one-off project instead of an ongoing task
  • Deciding purely on the cheapest offer without comparing total costs over the lifetime

Running costs are often underestimated in prioritisation. Every new piece of software, every additional cloud service and every new device brings licences, updates and support effort with it. A roadmap should therefore show not only what is being bought but also how running costs change as a result – and which old systems can be switched off in return.

Whether a project is better run in the cloud or on your own servers is not a matter of belief but of requirements, connectivity and cost over the lifetime. That decision should be made before the purchase, not after. Whether ongoing support then stays in-house or goes to a provider as a managed IT service also belongs in the roadmap.

How NDVDL takes this on for you

NDVDL starts by taking stock in your business: we look at the network, servers, backup, access and processes, and talk to the people who work with them every day. You then receive a prioritised roadmap with decision papers your management can assess without any IT background. What comes first is usually the risks found in that review, such as an untested backup.

We then implement the projects in the agreed order and, if you wish, operate and maintain the infrastructure on an ongoing basis. We keep the roadmap up to date with you, so the next investment is not decided on gut feeling again. You have one fixed contact person who knows your setup.

Tell us which IT purchases you have planned, whether written down as a list or only in your head. We look at your infrastructure and put that list in order with you, by risk and benefit.

Discuss the order

Frequently asked questions

An SME should first invest in what prevents a standstill or data loss: a tested backup, up-to-date systems with security updates and protected access. Next comes the technical foundation such as the network and user management. New features and convenience come after that.

IT projects can be prioritised by placing each one against risk and benefit: what happens if we don't do it, and what do we gain if we do? Projects that close a high risk take precedence. Dependencies between projects also shape the order.

An IT roadmap is a plan that spreads IT investments over several years and makes dependencies visible. SMEs benefit too, because budget is spent by impact rather than urgency. The roadmap should be reviewed at least once a year.

An IT decision paper describes on one page the situation, two or three options including doing nothing, one-off and running costs, the impact and a recommendation. It should be understandable without technical knowledge. That way an IT investment can be judged like any other investment.

Backup comes before new software because data loss cannot be undone, while the benefit of new software can still be gained later. A backup only counts once a restore has been tested. New software on an unprotected foundation adds to the risk.

Questions about your IT infrastructure?

Talk directly to our team — no obligation, no detours.