30-60-90 day plan for IT directors
On this page
An IT director is hired to make technology serve the business: to decide where money goes, which systems to keep, replace or retire, how the team is organized and how much risk the company is carrying. The new director arrives to a list of complaints from business leaders, a budget built by someone else, contracts on autorenewal and a team that has heard promises before. A 30-60-90 day plan for IT directors should listen widely before deciding anything, map the money and the risks, and finish with a roadmap and budget that leadership signs.
This plan is for the CIO, CFO, COO or CEO hiring an IT director to lead internal technology at a mid-size company or a division of a larger one. For a hands-on manager running infrastructure and the service desk, see the 30-60-90 day plan for IT managers. The general structure is in the 30-60-90 day plan template for new hires, and the 30-60-90 day plan for executives covers the listening tour in more depth.
Risks to check before strategy
A roadmap means little if a ransomware incident or a failed restore takes the company down in month two. In the first two weeks, ask for evidence rather than reassurance on a short list:
| Question | Evidence to ask for | Why it matters |
|---|---|---|
| Who has admin access to critical systems? | A current list, including former staff and vendors | Lingering access is a common path for incidents |
| Can we restore the most important systems? | Date and result of the last tested restore | Untested backups often fail when needed |
| What happens in an incident? | The written response plan, contacts and last exercise | Decisions made in the moment are slower and worse |
| What do contracts and laws require of us? | Customer contract security terms, cyber insurance requirements, industry obligations | Breach notice and security duties come from many sources |
| Where is sensitive data? | A rough map of customer, employee and payment data | Drives priorities for access and monitoring |
Data security and breach notification duties come from state laws, sector rules such as HIPAA for health data, industry standards such as PCI DSS for card data, customer contracts and insurance policies, and they differ by company. Confirm which apply with counsel and your security lead, as of October 2026; this is not legal advice. Many teams organize the review around the NIST Cybersecurity Framework, which gives a shared vocabulary for presenting gaps to leadership.
The 30-60-90 day plan
30-60-90 day plan — [Name], IT Director, [company / division]
Reports to: [CIO / CFO / COO / CEO] Start: [date]
Team: [N] staff in [infrastructure, apps, service desk, security]
Budget: [annual opex / capex] Main vendors: [MSP, cloud, ERP]
DAYS 1-30 — Listen and map
Goals:
- Meet every business leader: what helps, what blocks, what
they would fund
- Meet every IT team member; learn what fills their week
- Run the risk check: admin access, restore test, incident
plan, contract and insurance security terms
- Map spend: every contract with cost, owner, renewal and
notice dates; license counts against actual users
- Baseline service: ticket volume, age, satisfaction
Deliverables by day 30:
- Risk findings with owners and dates
- Spend and contract map; listening tour themes
Check-in: day 30, with [manager]
DAYS 31-60 — Fix and prioritize
Goals:
- Close or schedule the highest risks (example: remove stale
admin accounts, run a restore test, hold an incident tabletop)
- Deliver one quick improvement a business leader asked for
- Review the team structure, skills and workload
- Decide on any contracts with notice dates in the next
six months: renew, renegotiate or exit
Deliverables by day 60:
- Risk progress report; one visible quick improvement
- Draft priorities ranked with business leaders
Check-in: day 60
DAYS 61-90 — Roadmap and budget
Goals:
- Write a 12 to 18 month roadmap tied to business priorities
- Build the budget for it, including savings from the
spend map
- Propose team changes with the evidence behind them
Deliverables by day 90:
- Roadmap and budget reviewed with leadership
- Service measures against the day-30 baseline
Check-in: day 90 — full review
What to measure
Set measures with the executive sponsor and compare with the day-30 baseline. The standards below are examples only.
| Measure | Why it matters | Example standard (example only) |
|---|---|---|
| High risks open | Exposure the business carries today | Every high risk owned and dated by day 60 |
| Contracts with known renewal and notice dates | Avoids unwanted autorenewals | All contracts mapped by day 30 |
| Spend per business capability | Shows where money goes and what to cut | Mapped and shared with finance by day 60 |
| Business leader satisfaction | IT is judged by the people it serves | Short check at day 30 and day 90 |
| Ticket age and repeat issues | Daily experience of every employee | Improving against the day-30 baseline |
A filled example
IT director: Sofia Marchetti (invented), previously an infrastructure manager at a larger firm, joining a distribution company with several warehouses and a central office.
Day 30: The risk check found several administrator accounts belonging to a former managed service provider and no restore test in over a year. The spend map showed two overlapping collaboration tools and a large ERP support contract renewing in five months. Warehouse managers' main complaint was handheld scanner outages.
Day 60: Removed the stale accounts, ran a restore test that exposed a missing database backup, which was fixed, and held an incident tabletop with leadership. Replaced failing scanner access points at the worst warehouse, which cut outages there.
Day 90: Her roadmap retired one collaboration tool, renegotiated the ERP support contract and moved the savings into a phased warehouse network upgrade. Leadership approved it, along with a request for a dedicated security role.
What "on track" looks like
| Checkpoint | On track | Worth a direct conversation |
|---|---|---|
| Day 30 | Every leader met; risk check done; spend mapped | Talking only with the IT team; no view of contracts |
| Day 60 | High risks moving; one quick improvement delivered | Big plans, no visible change; risks unowned |
| Day 90 | Roadmap and budget tied to business priorities | A technology wish list with no business case |
What the company owes the new IT director
- Time with every business leader in the first month, arranged by the sponsor.
- Full contract and spend data from finance and procurement.
- Authority to act on urgent risks without waiting for the budget cycle.
- A clear decision on scope: which systems, sites and teams the role owns.
Common mistakes
| Mistake | Result | Fix |
|---|---|---|
| Strategy before the risk check | An incident derails the plan | Evidence-based risk check in the first two weeks |
| Roadmap built inside IT | Leaders do not fund or support it | Rank priorities with business leaders |
| Early restructure | Lost trust and lost knowledge | Propose changes at day 90 with evidence |
| Missing contract notice dates | Autorenewal at the old price | Contract map with notice dates by day 30 |
Turning complaints into a roadmap
The listening tour will produce a long list of complaints, many of them symptoms of the same few problems. Group them by cause: an aging network, a system that does not fit how a team works, missing training, slow support. For each cause, note who is affected, what it costs in time or money where you can estimate it, and what fixing it would take. Rank with the business leaders, not for them. A roadmap built this way is easier to fund because each item already has a sponsor outside IT.
Adapting the plan
- Heavily outsourced IT: spend more of the first month on managed service contracts, their service levels and who holds admin access.
- Regulated industries: add the compliance calendar for audits and assessments the company must pass, and meet the compliance lead in week one.
- Directors over development teams: add delivery measures and on-call practices; the 30-60-90 day plan for DevOps engineers shows what a healthy baseline looks like.
For the security side of the team, the 30-60-90 day plan for cybersecurity analysts shows how log coverage and detection ownership ramp, and the IT project manager screening questions help when the roadmap needs someone to deliver it.
Questions people ask
How is an IT director's 30-60-90 day plan different from an IT manager's?
An IT manager's first 90 days center on running systems safely: access, inventory, backups and the service desk. An IT director's center on direction and money: what the business needs from technology, where the budget goes, which contracts and vendors matter, how the team is organized and what the roadmap should be. Both need an early check on security and recovery.
What should a new IT director do in the first two weeks?
Meet each business leader and ask what technology helps or blocks them, meet every IT team lead, and confirm who holds administrative access to the most critical systems. Ask for the last incident report, the incident response plan and the date of the last tested restore, so major risks are known before strategy work starts.
How do you measure an IT director's first 90 days?
By a complete map of spend, contracts and renewal dates, an incident readiness check with gaps scheduled, a roadmap and budget leadership agrees to, and at least one visible improvement a business leader asked for. Satisfaction and service measures should be compared with the day-30 baseline.
Should a new IT director restructure the team right away?
Usually not in the first 60 days. Learn what each person does, where work queues up and which skills are missing first. A restructure proposed at day 90 with evidence is more likely to be accepted than one announced in the first month.