Layer3 Logo

Strategy and governance

IT strategy and governance

A roadmap your board can use.

Every managed plan includes a virtual CIO (vCIO) cadence: someone who turns technical risk into a roadmap, a budget and a board paper, and keeps all three current. Not an annual slide deck.

Established

Wellington, since 2005

Certified

ISO/IEC 27001:2022

Horizon

12–36-month roadmap

Reporting

Monthly executive, annual to quarterly review

01

The problem

Technology decisions get made in isolation

Then the board finds out afterwards, usually when something needs signing.

Decisions in isolation

IT chosen without the business in the room

Systems may be selected on technical merit while commercial consequences emerge later through an unplanned renewal.

Risk you cannot see

Nothing the board can act on

Technical risk stays technical. Without translation it never reaches the people who decide budget, so it never gets funded.

Budget by surprise

Refresh arrives as a shock

End-of-life hardware, expiring warranties and licence changes land as unplanned capital requests instead of a forecast.

What you get

What the strategy layer includes

Nine things that exist whether or not there is a meeting this month. The formal governance programme sits at Sentinel; the rest run across every plan.

01

Technology roadmap

A 12–36-month plan tied to business objectives, risk appetite and growth. Reviewed, not written once.

02

Risk register

Technical risk recorded, rated and tracked, in language the board can act on.

03

Board reporting

Monthly executive reporting on service, posture and progress, short enough to be read before the meeting rather than during it.

04

Scheduled review

A session with your leadership and, where budget is on the agenda, your finance lead.

05

Budget and lifecycle

Device age, warranty expiry and licence changes forecast, so refresh is planned rather than discovered.

06

Policy and governance

Policies drafted, kept current, and mapped to the controls they support, as part of the governance programme at Sentinel.

07

Compliance alignment

ISO/IEC 27001 and Privacy Act 2020 alignment at Sentinel, with the evidence maintained as you go instead of assembled in a panic.

08

Microsoft 365 posture

Secure Score and tenant configuration tracked as a standing roadmap input, not a one-off audit.

09

Advisory access

Direct access to the people who run the environment when a decision needs technical input.

How it scales

The cadence follows your plan

The strategy layer is in every plan. What changes is how often it comes to the table.

01

Manage

Annual overview. Once a year the environment gets a proper look: where it is heading, what it will cost, and what needs deciding before it becomes urgent.

02

Protect

Annual. A scheduled review each year, with the roadmap and risk register brought up to date before it rather than during it.

03

Secure Edge

Twice yearly. Two scheduled reviews a year, so network and access decisions are taken with the same roadmap in front of you.

04

Sentinel

Quarterly. A scheduled review with leadership and finance, with the roadmap, budget forecast and board paper refreshed each time.

The difference

Most IT strategy is an annual event

The common approach

A deck once a year

Prepared for the meeting, accurate on the day, and stale a month later. Nothing in between, so the next decision gets made without it.

What we do

A roadmap that stays current

The roadmap, risk register and budget forecast are live documents maintained between reviews. The review reads them; it does not invent them.

The meeting

What a review covers

Standing agenda

Service performance

How the service performed against its targets, with exceptions reported rather than averaged away.

Risk register

What changed, what was closed, and what is newly open.

Security posture

Movement in Microsoft 365 Secure Score and control coverage since the last review.

Roadmap progress

What shipped, what slipped, and what that does to the next two quarters.

Budget and lifecycle

Hardware, licensing and renewal forecast for the next twelve months.

Decisions needed

The short list of things only the board can decide, with the trade-offs stated.

Governance

Compliance you can evidence

Alignment to ISO/IEC 27001 and the Privacy Act 2020, with policies kept current and evidence maintained as you go. That formal governance, risk and compliance programme sits at the Sentinel plan. Layer3 is certified to ISO/IEC 27001:2022 and runs the same disciplines internally.

A security audit is the snapshot: a point-in-time assessment that produces a baseline, a prioritised list and a board presentation. The strategy cadence is the loop that keeps the roadmap moving afterwards. Most organisations start with the audit.

Proof

Who we already look after

Customer example

Virtual CIO

The Wellington Phoenix run a business far bigger than the team on the field, across multiple locations. Layer3 sits in it as virtual CIO rather than as a supplier.

Read the Wellington Phoenix case study

Before you ask

Questions about IT Strategy and Governance

If yours is not here, ask it directly and you will get a straight answer.

Book a discovery call

No. The strategy layer is part of every managed plan. What changes between plans is the cadence, not whether you get one.

Someone who works on your environment, not an account manager. Reviews are with your leadership, and with your finance lead when budget is on the agenda.

No — it sits alongside them. On co-managed plans the vCIO works with your IT lead rather than around them, and the roadmap is built jointly.

We align your environment, policies and evidence to ISO/IEC 27001 and keep them current. Certification itself is issued by an external auditor, not by us.

12 to 36 months, reviewed as things change rather than rewritten once a year.

A security audit. It produces the assessment and the prioritised roadmap that the cadence then maintains.

Next step

Bring the board a plan, not a surprise

Thirty minutes with someone who can speak to the technical detail and the commercial reality in the same conversation.

Layer3

Book a discovery call - 30 minutes, no obligation