Build an IT Budget From Operating Priorities
Percentage-of-revenue benchmarks are close to useless. A category-by-category model for building an IT budget you can defend, plus the costs that are always missing.
The short answer
Build an IT budget from six categories rather than a percentage of revenue: run the business, secure the business, improve the business, hardware refresh accrual, insurance and risk transfer, and a contingency reserve of ten to fifteen percent. A defensible shape is roughly 55 to 65 percent run, 15 to 25 percent secure, and 10 to 20 percent improve.
The most common way small businesses budget for technology is to take last year's number and add a little. The second most common is to look up a percentage-of-revenue benchmark, discover that the range spans from two percent to nine percent depending on industry, and go back to the first method.
Benchmarks answer whether you spend like your peers. They do not establish whether you are buying the right things, so build the budget from operating categories.
The six categories
Run the business. Everything required to keep current operations working. Managed services or internal IT salary, connectivity, licensing, hardware refresh, backup, support. This is the largest line and the most predictable.
Secure the business. Security tooling, monitoring, assessments, training, and the compliance work your industry requires. Budget this separately from operations even though a provider may bundle them, because when a cut is needed, undifferentiated bundles get cut without anyone understanding what was removed.
Improve the business. Projects that change how you operate. A new line-of-business system, an automation initiative, an AI pilot. This is the discretionary line and the one that gets zeroed out first, which is why companies find themselves five years behind with no single decision that caused it.
Refresh. Hardware and infrastructure replacement on a schedule. Treated as a recurring accrual rather than an emergency, this stops the pattern where nothing is replaced for four years and then everything is replaced at once in the same quarter.
Insurance and risk transfer. Cyber liability premium, and any assessment or attestation your carrier or clients require.
Reserve. A contingency line, typically ten to fifteen percent of the total. Something will break, a vendor will raise prices, or an acquisition will land in your lap.
The costs that are always missing
Every budget review we do finds the same absences.
Software that never went through a budget. Departmental SaaS on credit cards, renewing annually, sometimes in duplicate. Pull twelve months of card statements and categorize every recurring charge. In a 50-person company this exercise routinely surfaces thousands of dollars a year in tools nobody is using.
License true-up at growth. If you hired twelve people, you bought twelve licenses across every per-seat tool you own, which is usually eight to fifteen tools. That multiplies faster than owners expect.
Cloud consumption drift. Metered services grow unless somebody reviews them. Storage in particular only goes up unless someone deliberately manages retention.
Project labor. A migration involves internal hours from people who have other jobs. Costing a project at the vendor quote alone understates it by a lot.
End of support timelines. Operating systems, applications, and firmware all have dates. A version reaching end of support is a scheduled expense you can see coming years in advance, and it becomes an emergency only when nobody put it on a calendar.
How to allocate between the categories
A defensible starting shape for a stable small business is roughly 55 to 65 percent on running, 15 to 25 percent on securing, 10 to 20 percent on improving, and the balance in refresh and reserve.
The shape shifts with situation. A company in a heavily regulated field carries more in the security line. A company that has deferred investment for years needs a period where improvement is larger, because the alternative is a slow accumulation of fragility. A company that just completed a major migration can run lean on improvement for a year.
The number to watch is the improvement line trending toward zero across consecutive years. That is the signal that the technology estate is aging into risk while the budget stays flat.
Making the case for the security line
Security spend is hard to defend because success is invisible. Two framings help.
Compare it to the deductible and the retention on your cyber policy, and to the operational cost of the downtime scenarios you modeled in your recovery planning. Security spend is buying down a specific quantified exposure, and it should be presented that way rather than as a general good.
Second, tie it to revenue you would lose without it. Increasingly, larger clients ask about security posture during procurement. Firms that cannot answer are removed from consideration and often never learn why. That is a sales cost, not an IT cost.
Get the model
The IT Budget Model is a workbook with the six category structure, a per-user and per-device cost breakdown, a hardware refresh schedule that accrues monthly, a software inventory sheet for catching orphan subscriptions, a three-year projection, and a variance tracker against actuals.
It is built to be filled in by a business owner or a controller. Bring the completed version to your provider and the conversation changes, because you are now discussing allocation rather than accepting a quote.
Frequently asked questions
What percentage of revenue should a small business spend on IT?
Industry benchmarks range from roughly two to nine percent, which is too wide for direct planning. They show whether you spend like your peers but cannot establish whether you are buying the right things. Build from operating categories and use the percentage as context.
What costs are usually missing from an IT budget?
Departmental software on credit cards that never went through a budget, license true-up when you hire, cloud consumption drift particularly in storage, internal project labor from people who have other jobs, and end-of-support timelines that are visible years ahead and become emergencies only when uncalendared.
How should I split my IT budget between categories?
A defensible starting shape for a stable small business is 55 to 65 percent running the business, 15 to 25 percent securing it, 10 to 20 percent improving it, and the balance in refresh, insurance, and reserve. Regulated firms carry more in security; firms recovering from deferred investment carry more in improvement.
How do I justify security spending to ownership?
Two framings work. Compare it to your cyber policy deductible and the downtime scenarios you modeled in recovery planning, so it is buying down a quantified exposure. Second, tie it to revenue: larger clients now ask about security posture in procurement, and firms that cannot answer are removed from consideration without being told why.
Related reading
- Score Your IT Provider: The 40-Point 3AM Test Audit
- Your Backups Are Not a Recovery Plan
- Run a 60-Minute Ransomware Drill With Your Leadership Team
- How to Switch IT Providers Without a Bad Month
- Read Your Cyber Policy Before You Need to Use It
- The Quarterly Technology Review Every Owner Should Demand
