Direct · Service 08

Advisory & vCIO

The person who can walk into your board meeting and explain what the technology spend bought, what the risks are and what happens next, in the language your directors already use.

A technology review in a boardroom, with reporting on the wall screen
The problem

Technology decisions made one invoice at a time

Between roughly fifty and fifteen hundred staff, most Australian organisations sit in an awkward gap. Too large to run on goodwill and whoever is best with computers, and still too small to justify a full-time chief information officer, a security lead and a solutions architect on the payroll at the same time.

What fills the gap is a sequence of individually reasonable decisions — a renewal here, an urgent replacement there — each pulling in its own direction. Three years later the architecture is an archaeology of expiring contracts.

A vCIO is a fractional version of the missing role: someone accountable for whether the plan was right, and held to that same plan next quarter.

Deliverables

Six things you can actually hold

Advisory work earns its fee in artefacts. These are documents that outlive the meeting.

Three-year technology roadmap
What changes, in what order, and why. Sequenced around contract expiry, hardware end-of-life, growth plans and the risks the assessment found, then reviewed and revised each quarter.
Defensible annual budget
Operating and capital, split into committed, planned and discretionary, with the consequence of deferring each item stated. Built so you can defend any line to a board or a finance committee on your own.
Risk register
Technology and security risks with owners, ratings, treatments and review dates. The register is the thing an auditor asks for, and the thing that turns “we should probably fix that” into a decision somebody made.
Quarterly business review
Ninety minutes with your leadership: performance against the commitments you set, security posture, spend against budget, roadmap progress, and the decisions we need from you before the next one.
Board & audit reporting
A one-page technology and cyber summary in the language directors use, plus the supporting evidence pack for audit committees, insurers and client due-diligence questionnaires.
Vendor & contract register
Every technology contract, its renewal date, its notice period and its exit cost. Reviewed ahead of each expiry so every renewal is a deliberate decision.
The roadmap, the budget and the reviews over three years The assessment produces the first roadmap and budget. Every quarterly review then revises the roadmap, so it stays current for all three years.
  1. Technology assessmentProduces the first roadmap and budget
  2. Three-year roadmapRevised each quarter
  3. Annual budgetOperating and capital, for each year
  4. Quarterly business reviewNinety minutes, pack three working days ahead

Reviews run quarterly on the Complete tier and monthly on Fortified.

The meeting

What a quarterly review actually covers

Same agenda every quarter, so you can see movement. It runs ninety minutes and you get the pack three working days beforehand.

  • Service performance. Ticket volume by category, how we tracked against the response times you set, and the three issues that generated the most support time.
  • Security posture. Essential Eight movement, incidents and near-misses, phishing simulation results, and control drift.
  • Spend. Actual against budget, licence changes, and anything trending in a direction you should know about well before renewal.
  • Roadmap. What we said we would do last quarter, what we did, and what moved — including things we got wrong.
  • Risk register. New entries, changed ratings, and treatments completed or overdue.
  • Decisions required. A short list of things only you can decide, with a recommendation and a cost against each.

Included quarterly on the Complete tier and monthly on Fortified. Available as a standalone engagement if your IT is managed elsewhere and you want an independent view.

Also available

Project-based advisory

Engagements with a defined question and a defined end, whoever manages your IT.

Technology due diligence

Pre-acquisition review of a target's technology, security posture, contracts and integration cost.

Provider review

An independent assessment of your current MSP against what you are paying for. We will tell you if they are doing fine.

Tender & RFP support

Writing the requirements, evaluating responses, and sitting on your side of the table, as adviser only.

Merger integration

Tenant consolidation, identity merging, licence rationalisation and a sequenced cutover plan.

Questions

What people ask

Is the vCIO just a sales role with a better title?

It is at some providers, and it is a fair thing to be suspicious of. The test is whether the roadmap ever recommends something that reduces what you pay them. Ours regularly does — licence consolidation, retiring a service, extending hardware life — and those recommendations are in the pack in writing.

Can we engage a vCIO and keep our current provider?

Yes, and it is a genuinely useful arrangement. You get an independent technical voice reviewing your existing provider's work. We are explicit upfront about the conflict of interest, and we will put in writing that we are not bidding for the managed services contract during the engagement.

How is it priced?

Included in the managed services agreement at the Complete tier and above. As a standalone engagement it is a fixed monthly retainer based on your size and meeting cadence. We price it that way because hourly billing discourages exactly the conversations you should be having.

Who attends from our side?

Whoever holds the budget and whoever feels the pain — usually a managing director or general manager, a finance lead, and an operations manager. If you have internal IT, they should be in the room and part of the conversation.

Get a technology plan you can defend

The assessment produces the first version of the roadmap and budget. From there it is a living document, revised each quarter.