Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
Most Canadian SMBs buy their systems reactively. The IT strategic planning process replaces that pattern with a documented 3-year roadmap that carries named owners and a review cadence every 90 days. I have run this 6-step sequence inside vCIO retainers since 2012, and what follows is the version I hand to Ontario and British Columbia owners in the 10 to 150 employee band.
Book an IT Business Consultation
What is IT strategic planning, and why does it matter for a Canadian SMB?
According to Innovation, Science and Economic Development Canada (2025), 1.08 million of Canada’s 1.10 million employer businesses are small firms under 100 employees. That is the population this process is built for. IT strategic planning turns business goals into a sequenced, budgeted technology roadmap an owner can actually read.
The deliverable is a short document covering a 12 to 36 month horizon. It records where the business is going, what the environment must look like to get there, and the funding order for projects and security work.
For a Canadian SMB the plan also names compliance milestones. PIPEDA sits federally. Quebec’s Law 25 and British Columbia’s Personal Information Protection Act sit provincially, and they change what Step 3 is allowed to design.
The discipline matters more than the document. A 30-page binder reviewed once a year produces less value than a 6-page plan reviewed quarterly against a live KPI dashboard. I have never watched the binder version survive its second year.
The 6-step IT strategic planning process
According to the Canadian Centre for Cyber Security (2025), its baseline control set is aimed at organizations under 500 employees and lists 13 control categories. Those categories give Step 2 a ready-made scoring sheet, which is why the assessment week rarely needs a custom framework built from scratch.
Each step has a defined output and one accountable person. The cycle compresses to roughly 6 weeks as a standalone sprint. Inside a vCIO retainer it runs continuously instead.
| Step | Activities | Output | Owner |
|---|---|---|---|
| 1. Business alignment | Leadership interviews, growth plan review, regulatory context. | Business outcomes statement (3 to 5 outcomes). | vCIO + CEO. |
| 2. Current-state assessment | People, process, technology, security review; risk register build. | Current-state report + risk register. | vCIO + MSP lead. |
| 3. Target architecture | Future-state design at 12, 24, 36 months mapped to NIST CSF 2.0. | Target-state architecture document. | vCIO + Operations lead. |
| 4. Roadmap and budget | Gap closure sequencing, dependency mapping, Run / Grow / Transform allocation. | 3-year roadmap + budget model. | vCIO + CFO. |
| 5. Governance and KPIs | RACI matrix, KPI dashboard build (Power BI), policy framework. | Governance pack + live KPI dashboard. | vCIO. |
| 6. Quarterly review | vCIO sessions, KPI review, scope changes, budget reforecast. | Updated roadmap + QBR minutes. | vCIO + Leadership. |
Step 1: Business strategy alignment
According to Statistics Canada (2024), just over one quarter of Canadian businesses, 26 percent, kept a written cyber security policy in 2023. Documentation is the exception in this market. Step 1 forces 3 to 5 business outcomes onto paper before anyone opens a vendor proposal.
Every initiative then carries a tag pointing at one of those 3 to 5 outcomes. An initiative that cannot be tagged does not belong on the roadmap. The budget splits into Run, Grow and Transform, in the shares charted above.
Across our 90+ Canadian SMB managed-IT engagements through Q2 2026, I have yet to see a plan survive its first budget cycle when the Run share was already past 70 percent. My rule is that consolidation lands before anything new gets funded.
Step 2: Current-state assessment (people, process, technology, security)
According to NIST (2024), Cybersecurity Framework 2.0 added a sixth function called Govern, which sits above Identify and Protect. Step 2 scores the current environment against all six. That change is why security posture now enters the IT strategic planning process at assessment, long before any tool gets bought.
Assessment covers 4 domains. People means roles, skill gaps and MSP coverage. Process means change management and vendor handling. Technology means asset inventory, contract audit and shadow IT. Security means posture against the 6 CSF functions.
The output is a current-state report plus a ranked risk register. Our engineers found that the contract audit surfaces more surprise cost than the hardware inventory. Most of our clients turn up an auto-renewing agreement nobody remembered signing, often a Microsoft 365 add-on licence.
Step 3: Future-state target architecture
According to the Office of the Privacy Commissioner of Canada (2026), PIPEDA’s fair information principles place accountability and safeguards on the organization holding the data, wherever that data physically sits. Target architecture is where those obligations turn into design decisions rather than policy language nobody reads.
Target architecture defines the environment at 12, 24 and 36 months. It covers identity and access, endpoint posture, network segmentation, data residency, backup and the SaaS portfolio.
Data residency commitments get recorded here. PIPEDA stops short of mandating Canadian storage, while Quebec’s Law 25 and several sector regulators expect it anyway. Recording that commitment gives Step 4 a hard vendor acceptance criterion.
Canadian compliance milestones in plain English: PIPEDA, Law 25 and Bill C-8
According to the Parliament of Canada (2026), Bill C-8 received Royal Assent on June 15, 2026 as Statutes of Canada 2026, chapter 9. It creates cyber security duties for federally regulated operators. Most SMBs sit outside its direct scope and still feel it, because enterprise customers push those requirements down the supply chain.
Three Canadian obligations belong on the roadmap as dated rows rather than as a compliance appendix at the back:
- PIPEDA breach reporting. Federal, applying to commercial activity nationwide. The roadmap needs one accountable breach-decision owner plus a logging retention period.
- Quebec Law 25. Administered by the Commission d’accès à l’information du Québec. One Quebec employee makes privacy-impact assessments a Year 1 item.
- Bill C-8. In force since June 2026 for federally regulated operators. Suppliers to banks and telecoms should expect the questionnaires inside 12 months.
I keep PIPEDA, Law 25 and the federal cyber security duties on the roadmap as dated rows with owners attached. Compliance work parked in an appendix gets funded last, and in my experience it then gets funded in a panic once a customer questionnaire lands.
“The plans that work are the ones an owner can recite from memory. Hand a 40-page strategy to a 60-person Ontario firm and it gets skimmed once and filed. Six pages with named owners and dated rows gets argued about in the boardroom, and the argument is the whole point.”
Step 4: 3-year IT roadmap and budget
According to Microsoft (2025), Windows 10 Home and Pro reached end of support on October 14, 2025. Any Canadian SMB still carrying those devices has a Year 1 hardware line whether the budget planned for it or not. A roadmap exists to make that kind of forced spend visible 24 months early.
The risk register from Step 2 sets priority order across Year 1, Year 2 and Year 3. Each initiative carries an owner, an outcome tag, a Run / Grow / Transform class and a budget envelope. Our IT budget guide for Canadian small business covers the line items.
| Horizon | Typical focus | Budget tilt |
|---|---|---|
| Year 1 | Stabilization, security baseline, vendor consolidation, quick-win automation. | Run-heavy; hold a 5 to 8 percent FX buffer for USD-billed SaaS. |
| Year 2 | Scaling capabilities, identity hardening, data platform, broader Microsoft 365 or Google Workspace optimization. | Grow-weighted. |
| Year 3 | Strategic bets: AI assistants, advanced analytics, automation platforms, new geographies. | Transform-weighted; reforecast quarterly. |
The 3-year horizon absorbs the major capital cycles, including hardware refresh and ERP renewal. Past 36 months the document stops driving budget decisions and starts driving wishful thinking.
Free download
The SMB IT Budget Template (2026)
A fillable spreadsheet with live formulas for the roadmap-and-budget step above, plus what each line item should cost a Canadian SMB. Build the 3-year budget without a blank sheet.
No sales call required. Want the plan built with you instead? Book a consultation with a CISSP-led team.
Step 5: Governance and KPI framework
According to the Canadian Centre for Cyber Security (2025), ransomware is the top cybercrime threat facing Canadian critical infrastructure, and cybercrime-as-a-service keeps lowering the barrier to entry. Governance is what keeps a plan responsive to that, because the KPI review is where a slipping security metric becomes a funded initiative.
Governance rests on three artifacts. The RACI matrix names one accountable owner per initiative. The policy framework covers acceptable use, vendor onboarding, change management and incident response. The KPI dashboard refreshes weekly in Power BI and gets reviewed quarterly.
| KPI | Target | Cadence |
|---|---|---|
| Roadmap initiative completion rate | 80 percent or better against committed quarter. | Quarterly. |
| Run cost as percent of total IT spend | Below 70 percent. | Quarterly. |
| Mean time to resolve security incidents | Quarter-over-quarter improvement. | Monthly. |
| User satisfaction | Single-question survey at QBR; trend up. | Quarterly. |
| Budget variance | Actual versus plan, reforecast quarterly. | Quarterly. |
I cap the dashboard at 5 rows on purpose. Plans tracking more than ten KPIs end up tracking none of them well, so the table above carries the whole QBR agenda. Our guide to IT metrics goes deeper on instrumenting each one.
Step 6: Quarterly review cadence (vCIO sessions)
The quarterly business review is a 60 to 90 minute working session the vCIO leads with the leadership team. The agenda is fixed: roadmap status per initiative, KPI review, risk register changes, scope additions and a rolling budget reforecast. Fusion Computing delivers managed IT services underneath that session while the vCIO owns the strategic conversation.
Without the QBR, plans go stale inside one quarter. We tracked which engagements still had a living roadmap at month 18, and the dividing line was whether the 4 QBR dates went in the calendar before signoff.
The IT strategic plan checklist: what the document needs to contain
According to Statistics Canada (2025), 12.2 percent of Canadian businesses used AI to produce goods or deliver services in the second quarter of 2025, nearly double the 6.1 percent a year earlier. That is the kind of Year 3 bet a written checklist forces an owner to fund deliberately.
A finished plan fits on 6 to 8 pages. Every row below earns its place, because a missing one shows up later as an unfunded surprise:
- 3 to 5 business outcomes in the owner’s own words.
- A current-state summary with a ranked risk register.
- Target architecture at 12, 24 and 36 months.
- A year-by-year initiative list with named owners.
- Run, Grow and Transform budget shares.
- Dated PIPEDA and provincial compliance milestones.
- A 5-row KPI table with targets.
- A RACI matrix.
- The 4 QBR dates for the next 12 months.
[ORIGINAL DATA] The ranges in this playbook come from anonymized client data and an FC internal benchmark from Q2 2026 rather than a vendor survey. Want the checklist filled in against your environment? Book a consultation with Mike.
Common IT planning mistakes Canadian SMBs make
Five failure patterns repeat across our Ontario and British Columbia engagements. According to Statistics Canada’s 2024 cybercrime release, only 26 percent of businesses keep a documented security policy, which tells you how common the first pattern is: no plan exists to argue with.
Vendor-driven roadmaps justify what a rep already sold, and running the assessment before reading proposals fixes it. Initiatives owned by “IT” get fixed with a RACI matrix naming 1 person. Annual-only review produces shelfware, so the 4 QBR dates go in the calendar before signoff.
Run-cost overrun past 70 percent demands consolidation first. Compliance bolted on at the end fails audits, so PIPEDA milestones enter at Step 1 and stay dated. The plans I watch survive share 3 traits: outcomes in plain language, a roadmap readable in 10 minutes and a quarterly review the CEO chairs.
vCIO, MSP or in-house IT: how to choose who owns the plan
According to the Canadian Centre for Cyber Security (2025) baseline, an organization under 500 employees is expected to cover 13 control categories. Almost no Canadian SMB staffs that internally, which is why the practical answer for a 10 to 150 employee firm is a split.
An MSP owns the help desk, monitoring, patching and security operations. A vCIO owns the 36-month sequence and the budget conversation. An in-house IT manager can hold one role well past 100 employees, and rarely both at once. Our comparison of a virtual CIO versus a traditional CIO covers the cost side.
I ask owners one question before they decide: who is accountable when a roadmap initiative slips 2 quarters? If the answer is a committee, my read is that the plan has no owner. Fusion Computing supports both halves of that split for Canadian SMBs. Talk to a CISSP-led team first.
Start with an IT Business Consultation
Frequently asked questions
How long does the IT strategic planning process take for a Canadian SMB?
A standalone planning engagement for a 10 to 150 employee Canadian SMB typically runs 6 weeks end to end, with each of the 6 steps consuming about 1 week of working time. Within an active vCIO retainer the cycle is continuous: the document gets refreshed annually and the roadmap is reviewed quarterly. Compressing below 6 weeks thins out the assessment and the risk register.
What is the difference between an IT strategy, an IT roadmap, and an IT budget?
The IT strategy defines vision, business outcomes and target-state architecture. The IT roadmap sequences the projects that move the environment from current state to target state. The IT budget allocates dollars across Run, Grow and Transform. Built in any other order, the budget funds the wrong projects.
Do we still need an IT strategy if we already have a managed service provider?
Yes. An MSP runs operations: help desk, monitoring, patching and security operations. Strategy sets direction, meaning what the business is chasing and how the budget is sequenced over 36 months. Most Canadian SMBs pair the MSP with a vCIO retainer.
How much should a Canadian SMB budget for IT each year?
Most Canadian SMBs allocate 3 to 7 percent of revenue to technology, with regulated industries at the upper end. Within that envelope a healthy split is roughly 60 percent Run, 25 percent Grow and 15 percent Transform. When Run consumes more than 70 percent, the plan’s first job is rebalancing through consolidation rather than adding new initiatives.
What is a quarterly business review (QBR) and why does it matter?
A QBR is a 60 to 90 minute session where the vCIO and leadership review roadmap status, KPIs, risk register changes and the rolling budget reforecast. Plans with QBR discipline survive past 18 months. Plans without it become shelfware inside one quarter.
Who should own the IT strategic plan inside an SMB?
The CEO ratifies the 3 to 5 business outcomes. The vCIO, internal or external, owns the document and the cycle. Each initiative gets a single accountable owner via the RACI matrix. “IT owns it” fails in practice, because shared ownership produces no ownership.
How does compliance fit into the IT strategic planning process?
Compliance milestones get embedded in the roadmap from Step 1 onward rather than bolted on at the end. For a Canadian SMB that means PIPEDA, Bill C-8 supply-chain pressure and provincial law such as Quebec’s Law 25. The risk register scores compliance gaps like operational risks, and NIST CSF 2.0’s Govern function makes that explicit.
What KPIs should an SMB track to measure IT strategy success?
Five KPIs carry the QBR agenda. Roadmap initiative completion should hit 80 percent against the committed quarter. Run cost should stay below 70 percent of total IT spend. Mean time to resolve security incidents should improve quarter over quarter. User satisfaction and budget variance close the set.
What is the difference between a vCIO and a vCISO?
A vCIO owns the full IT strategic plan: business alignment, roadmap, budget and vendor decisions. A vCISO is security-specific, covering cybersecurity strategy, the controls roadmap and incident response readiness. Canadian SMBs in regulated sectors often engage both through one provider.
Related Resources
Keep going from here. Managed IT services is the operational layer that executes the roadmap day to day, and IT operations best practices sets the process maturity baseline used in Step 2. For Step 4 budget calibration, see managed IT services cost in Canada and cybersecurity services.

