Customer example
Virtual CIO
The Wellington Phoenix run a business far bigger than the team on the field, across multiple locations. Layer3 sits in it as virtual CIO rather than as a supplier.
Read the Wellington Phoenix case studyStrategy and governance
A roadmap your board can use.
Every managed plan includes a virtual CIO (vCIO) cadence: someone who turns technical risk into a roadmap, a budget and a board paper, and keeps all three current. Not an annual slide deck.
Established
Wellington, since 2005
Certified
ISO/IEC 27001:2022
Horizon
12–36-month roadmap
Reporting
Monthly executive, annual to quarterly review
01
The problem
Then the board finds out afterwards, usually when something needs signing.
Decisions in isolation
Systems may be selected on technical merit while commercial consequences emerge later through an unplanned renewal.
Risk you cannot see
Technical risk stays technical. Without translation it never reaches the people who decide budget, so it never gets funded.
Budget by surprise
End-of-life hardware, expiring warranties and licence changes land as unplanned capital requests instead of a forecast.
What you get
Nine things that exist whether or not there is a meeting this month. The formal governance programme sits at Sentinel; the rest run across every plan.
01
A 12–36-month plan tied to business objectives, risk appetite and growth. Reviewed, not written once.
02
Technical risk recorded, rated and tracked, in language the board can act on.
03
Monthly executive reporting on service, posture and progress, short enough to be read before the meeting rather than during it.
04
A session with your leadership and, where budget is on the agenda, your finance lead.
05
Device age, warranty expiry and licence changes forecast, so refresh is planned rather than discovered.
06
Policies drafted, kept current, and mapped to the controls they support, as part of the governance programme at Sentinel.
07
ISO/IEC 27001 and Privacy Act 2020 alignment at Sentinel, with the evidence maintained as you go instead of assembled in a panic.
08
Secure Score and tenant configuration tracked as a standing roadmap input, not a one-off audit.
09
Direct access to the people who run the environment when a decision needs technical input.
How it scales
The strategy layer is in every plan. What changes is how often it comes to the table.
01
Annual overview. Once a year the environment gets a proper look: where it is heading, what it will cost, and what needs deciding before it becomes urgent.
02
Annual. A scheduled review each year, with the roadmap and risk register brought up to date before it rather than during it.
03
Twice yearly. Two scheduled reviews a year, so network and access decisions are taken with the same roadmap in front of you.
04
Quarterly. A scheduled review with leadership and finance, with the roadmap, budget forecast and board paper refreshed each time.
The difference
The common approach
Prepared for the meeting, accurate on the day, and stale a month later. Nothing in between, so the next decision gets made without it.
What we do
The roadmap, risk register and budget forecast are live documents maintained between reviews. The review reads them; it does not invent them.
The meeting
Standing agenda
Service performance
How the service performed against its targets, with exceptions reported rather than averaged away.
Risk register
What changed, what was closed, and what is newly open.
Security posture
Movement in Microsoft 365 Secure Score and control coverage since the last review.
Roadmap progress
What shipped, what slipped, and what that does to the next two quarters.
Budget and lifecycle
Hardware, licensing and renewal forecast for the next twelve months.
Decisions needed
The short list of things only the board can decide, with the trade-offs stated.
Governance
Alignment to ISO/IEC 27001 and the Privacy Act 2020, with policies kept current and evidence maintained as you go. That formal governance, risk and compliance programme sits at the Sentinel plan. Layer3 is certified to ISO/IEC 27001:2022 and runs the same disciplines internally.
A security audit is the snapshot: a point-in-time assessment that produces a baseline, a prioritised list and a board presentation. The strategy cadence is the loop that keeps the roadmap moving afterwards. Most organisations start with the audit.
Proof
Customer example
Virtual CIO
The Wellington Phoenix run a business far bigger than the team on the field, across multiple locations. Layer3 sits in it as virtual CIO rather than as a supplier.
Read the Wellington Phoenix case studyBefore you ask
If yours is not here, ask it directly and you will get a straight answer.
Book a discovery callNext step
Thirty minutes with someone who can speak to the technical detail and the commercial reality in the same conversation.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation