Setting IT Goals for a New Year: A Planning Guide for Contractors

Turn a vague wish for better IT into a short list of measurable goals covering reliability, security, field support and budget for your company.

3 min readBy Ironfield Cyber Team

Most contractors set goals for revenue, backlog, safety and hiring. Technology rarely gets the same treatment. It tends to be handled reactively, with money and attention flowing to whatever broke most recently. A short planning exercise at the start of the year can change that, turning IT from a source of interruptions into something that supports the business plan.

This guide walks through a simple process that an owner, operations leader or controller can complete in a couple of hours, with or without an IT provider in the room.

Start from business plans, not technology

Ask what the company intends to do this year, and consider how technology supports it.

  • Will you grow headcount or add crews?
  • Are you opening a new office, yard or region?
  • Are you pursuing different types of work, such as defense, utility or public projects that carry security requirements?
  • Are any large projects starting in remote locations?
  • Are you planning an acquisition or changes to your accounting or project software?

Each plan creates technology needs, from licenses and devices to connectivity and compliance.

Review the past year honestly

Gather a few facts.

  • Which IT problems caused the most lost time?
  • Were there any security incidents, fraud attempts or close calls?
  • What do employees complain about most?
  • What hardware or software is aging out of support?
  • Did any customer ask security questions you struggled to answer?

If you use a managed provider, ask for a summary of tickets and trends from the past year.

Choose goals in a few categories

Aim for a small number of specific goals, perhaps one to three in each area.

Reliability and support

Examples: reduce time to resolve field issues, replace the oldest laptops, or establish a standard jobsite network kit.

Security

Examples: confirm multi-factor authentication for every user, formalize a payment verification procedure, test restores from backup, and run a staff training session.

Compliance and customer requirements

Examples: complete a gap review against NIST SP 800-171 if you handle sensitive government information, prepare standard answers to customer security questionnaires, or document an incident response plan.

Cost and value

Examples: review software licenses for waste, consolidate duplicate tools, and plan hardware replacement on a regular cycle.

People and process

Examples: write onboarding and offboarding checklists, and assign clear ownership for systems and vendors.

Make goals measurable

A good goal states what will be done, by whom and by when. Compare these.

  • Vague: "Improve cybersecurity."
  • Specific: "Enable multi-factor authentication for all employees on email and project software by the end of the first quarter, led by the controller and IT provider."

Where possible, include a way to check progress, such as the percentage of users enrolled, the date of the last successful restore test, or the number of stale accounts removed.

Estimate costs and sequence the work

For each goal, list approximate costs in money and staff time. Then sequence the work across the year, considering busy seasons. Start with quick wins that need little budget and build momentum, such as removing stale accounts and tightening payment procedures. Schedule larger projects when crews and office staff have the most capacity.

Assign owners and set review dates

Every goal needs a named person responsible. Set a short quarterly review, thirty minutes at most, to check progress and adjust. Include your IT provider in these sessions.

Communicate the plan

Share the goals with department heads in plain language. People support changes more readily when they understand why, especially for items that affect daily routines, like multi-factor authentication.

Common pitfalls

  • Setting too many goals and finishing none.
  • Leaving security entirely to the IT provider, without management decisions.
  • Ignoring the field when planning devices, connectivity and support.
  • Forgetting to leave room in the budget for surprises.

A good place to begin

If you are unsure where to start, pick three: protect payments, test backups and confirm multi-factor authentication. Those address some of the most common ways contractors lose money and time.

Ironfield Cyber works with contractors and energy companies on annual technology planning, from security reviews to budgets. If you would like help shaping your goals, we can run a planning session with your leadership team.