Vendor-neutral guide · 9 min read
Refreshing your IT strategy after a period of rapid change
Shape of the topic
In short
The pandemic compressed years of digital transformation into months, and many organisations adopted tools faster than they adopted the governance to match. A strategy refresh is not a one-off project triggered by crisis; it is a standing discipline of reviewing infrastructure, security posture, user experience, support capacity and automation opportunities as conditions change. This guide sets out five practical areas to work through, drawn from lessons learned by organisations that moved quickly and are now consolidating those gains.
Key takeaways
- Review infrastructure and processes together, not the technology layer in isolation.
- A zero-trust approach reduces the risk exposed by permanent remote and hybrid access.
- Applying a user-centred, incremental rollout approach beyond software teams reduces resistance to change.
- Reliable IT support and management underpins both productivity and data protection.
- Automation should target repetitive tasks and free staff time, not be sold as headcount reduction.
Why a periodic refresh matters
Static technology infrastructure, and the assumption that staff would always be in one building to use it, has been overtaken by events. The scale of change accelerated sharply from 2020, when organisations adopted cloud services in large numbers for their practicality, flexibility and scalability, precisely because those qualities were what remote collaboration demanded. Many of those decisions were made under pressure, which is a reasonable way to survive a crisis but a poor way to run a strategy indefinitely.
The task now, for most organisations, is to review what was adopted quickly and decide what should become permanent, what should be reworked, and what should be retired. That review is not a single event but a habit: infrastructure and process should be checked on a regular cycle against current and anticipated needs, not left until the next disruption forces the question.
Get the digital strategy right
A strategy refresh should cover the infrastructure and the processes built on top of it, not the visible applications alone. That means favouring agnostic solutions that work consistently across platforms, and investing in the parts of the estate that are easy to neglect because they are invisible day to day: internet bandwidth, cloud services, servers and the hardware people actually use.
Once a plan is agreed and implemented, it needs to stay under regular review rather than being treated as finished. Whatever form the plan takes, it should be communicated to and discussed with the people it affects, with training provided where a change in tools or process requires it. A strategy nobody has been told about is not being followed, it is being guessed at.
- Review infrastructure and process together, not applications in isolation
- Prefer agnostic solutions that run across platforms rather than locking into one
- Invest in bandwidth, cloud services, servers and hardware, not only visible software
- Put the strategy on a recurring review cycle
- Communicate changes and provide training before rollout, not after
Treat security as an organisation-wide discipline
The rapid shift to home working exposed gaps in systems that allowed unauthorised access, and criminals took advantage of it. The Colonial Pipeline incident, where a $4.4 million ransom was paid to restore systems taken offline in May 2021, is a widely cited example of the cost of that exposure. In response, more organisations have adopted a zero-trust approach to reduce operational and security risk, on the basis that no connection should be trusted by default regardless of where it originates.
No security measure offers complete protection, and even well-trained staff will not anticipate every method an attacker might use. Staying current with developments in the threat landscape gives an organisation its best chance of responding quickly when an incident does occur, rather than discovering the gap during the attack itself.
Cybersecurity is not a discrete project owned by one team; it runs through the whole organisation. Educating staff accordingly, so that using technology responsibly becomes an ordinary habit rather than an occasional reminder, is part of the strategy refresh rather than separate from it.
Adopt a user-centred approach to change
Agile methods, proven in software development, deliver new capability incrementally so users are not confronted with a steep learning curve all at once. Extending that mindset beyond the development team to other parts of the organisation helps those teams respond to change without it feeling sudden or unmanaged.
Putting the people who will actually use a system at the centre of planning, rather than deciding on their behalf, means understanding how they interact with existing products, systems and services before changing them. That is fundamentally a communication exercise: change only takes hold once people understand it and see the reason for it, which can require a genuine culture shift but is worth the investment.
Manage and maintain the technology people rely on
Employees need seamless access to the tools they use for work regardless of where they are working from. A high-quality, effective IT support and management capability that can deal swiftly with technical issues is essential both to maintaining productivity and to keeping confidential data safe. A remote support tool such as 247connect can play a useful role here, letting a support technician reach a user's device securely without a site visit, though the underlying discipline matters more than any single product.
Cloud services, however, are not universally appropriate. Organisations such as financial institutions, government bodies or military organisations often need to keep data on-site and within their own network for security reasons. Where that applies, any solution deployed should carry proper security safeguards, including configurable data encryption, two-factor authentication, security keys and smartcard authentication, to protect against unauthorised access. A capable set of tools that minimises downtime when problems arise also reduces cost.
- Ensure support can resolve issues remotely and quickly, wherever staff are working
- Assess whether cloud or on-site storage is appropriate for the data involved
- Where data must stay on-site, insist on strong encryption and multi-factor authentication
- Track downtime reduction as a direct cost saving, not just a convenience
Look for the right places to automate
Automation is often met with concern that it will displace jobs, but its more realistic role is removing repetitive, low-value activity such as data entry or routing requests to the correct department. That frees staff time for more creative work or for training in areas where the organisation has skills gaps, which benefits both the individual and the organisation's productivity.
Any automation decision should be informed by data and analytics rather than assumption, and staff should be brought into the change and given the chance to buy in before it is implemented. It is worth being explicit about what automation cannot replace: people skills, human interaction and creative thinking, and demonstrating that those things remain valued as specific functions are automated.
Best-practice checklist
1. Audit what was adopted under pressure
List every tool, platform and process change made during the last period of rapid change and assess whether each should be kept, reworked or retired, based on evidence rather than habit.
2. Set a recurring strategy review cadence
Put the IT strategy on a fixed review cycle, such as every six or twelve months, so it is revisited on schedule rather than only after the next disruption.
3. Move towards zero trust incrementally
Identify the highest-risk access points, such as remote administrative access, and apply stronger verification there first rather than attempting a single organisation-wide switch.
4. Bring users into rollout planning
Involve a representative group of the people who will use a new system before it is deployed, and communicate the reasoning behind the change, not just the mechanics of it.
5. Confirm support coverage matches the working pattern
Check that IT support can reach staff wherever they are working, including securely accessing a device remotely when a site visit is not practical.
6. Identify one automation candidate with measurable benefit
Pick a single repetitive task, measure the time it currently costs, automate it, and use the result to build the case for further automation with evidence rather than assertion.
Common pitfalls
- Treating a strategy refresh as a one-off project rather than a recurring discipline
- Investing in visible applications while neglecting bandwidth, servers and underlying infrastructure
- Rolling out zero trust or new tools without communicating the reasoning to staff
- Assuming cloud services are appropriate for every data type without checking regulatory or contractual constraints
- Presenting automation as a threat to jobs rather than involving staff in deciding what gets automated
What to measure
| Strategy review frequency | Should be fixed and recurring, not reactive |
|---|---|
| Proportion of access under zero-trust controls | Should rise steadily for remote and admin access |
| Staff training completion for new tools | Track before and after rollout |
| IT support response time for remote staff | Should match or beat on-site response time |
| Hours saved per automated task | Measure before and after automation |
Select any column heading to sort.
Frequently asked questions
- How often should an organisation review its IT strategy?
- There is no universal figure, but treating it as a recurring exercise, at least annually and after any major operational shift, is more reliable than waiting for a crisis to prompt the review. Lessons learned from rapid changes such as the pandemic shift to remote work show that decisions made under pressure need deliberate revisiting once conditions stabilise.
- What does zero trust mean in practice for a mid-sized organisation?
- It means no connection or device is trusted automatically because of its location on the network. Every access request is verified, typically through strong authentication and least-privilege permissions, which reduces the exposure created by widespread remote and hybrid access compared with older perimeter-based security models.
- Why involve staff in a technology rollout rather than just deploying it?
- Change only sticks once people understand and accept it. A user-centred, incremental approach, similar to agile development practice, reduces resistance and surfaces practical problems early, rather than after a full rollout when they are expensive to fix.
- Is cloud infrastructure always the right choice for an IT strategy refresh?
- No. Cloud services suit many organisations for their flexibility and scalability, but sectors such as financial services, government and military organisations often need to keep data on-site within their own network for regulatory or security reasons, provided strong safeguards such as encryption and multi-factor authentication are in place.
Sources
Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.
- Five Strategies To Revamp Your IT Strategy In An Ever-Changing World
Forbes Technology Council
Original article by Al Kingsley MBE, Forbes Technology Council, September 2022.
- Guide to Enterprise Telework, Remote Access and BYOD Security (SP 800-46 Rev. 2)
NIST
Underpins recommendations on securing remote and hybrid access as part of a strategy refresh.
- Zero Trust Architecture
NIST
Reference definition and design principles for zero-trust approaches mentioned in the source article.
- Zero trust guidance
NCSC
UK government guidance on adopting zero-trust principles, supporting the security section of this guide.
Putting it into practice
This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.
More best-practice guides
Making technology choices
A vendor-neutral guide to evaluating new business technology properly: structured trials, stakeholder feedback, case studies, reviews and evidence.
Flexible technology strategy
A vendor-neutral guide to planning an organisation's technology landscape for hybrid working: auditing assets, building security in from the start, and involving staff at every level.
Managing hybrid workplace technology
A vendor-neutral guide to the day-to-day discipline of running hybrid workplace technology: cybersecurity vigilance, tracking constant change, and delivering a frictionless user experience.