IT budgets tend to fail in one of two ways: they underfund the boring, essential categories (patching, backup, identity) and overfund whatever tool a stakeholder saw in a demo; or they get set once and never revisited as the business changes.
The categories that matter
- Run — recurring costs to keep the current environment operating: licensing, connectivity, support, monitoring.
- Secure — controls and services specifically for security posture: EDR, MFA, awareness training, backup, insurance.
- Grow — projects that add capability: migrations, new tooling, automation, integration work.
- Reserve — a contingency line for incident response and unplanned hardware failure. Not optional.
Useful ratios and benchmarks
There is no universal 'IT should be X percent of revenue' rule, but two ratios tend to be more honest signals: total IT spend per employee, and the share of the budget that is 'secure' versus 'run'. Watch the direction of both over time, not the absolute number.
Forecasting as the business changes
- Tie licensing forecasts to headcount projections, not last year's totals.
- Refresh hardware on a rolling three-to-five year cycle so no single fiscal year takes the full hit.
- Reserve budget for known end-of-life dates on operating systems and critical applications.
- Revisit the budget quarterly against a short list of leading indicators, not annually.
One habit that fixes most problems
A quarterly thirty-minute review of the budget against actuals, with the person responsible for IT and the person responsible for finance in the same room.