Templates

30-60-90 day plan for IT directors

On this page
  1. Risks to check before strategy
  2. The 30-60-90 day plan
  3. What to measure
  4. A filled example
  5. What "on track" looks like
  6. What the company owes the new IT director
  7. Common mistakes
  8. Turning complaints into a roadmap
  9. Adapting the plan
  10. Questions people ask

An IT director is hired to make technology serve the business: to decide where money goes, which systems to keep, replace or retire, how the team is organized and how much risk the company is carrying. The new director arrives to a list of complaints from business leaders, a budget built by someone else, contracts on autorenewal and a team that has heard promises before. A 30-60-90 day plan for IT directors should listen widely before deciding anything, map the money and the risks, and finish with a roadmap and budget that leadership signs.

This plan is for the CIO, CFO, COO or CEO hiring an IT director to lead internal technology at a mid-size company or a division of a larger one. For a hands-on manager running infrastructure and the service desk, see the 30-60-90 day plan for IT managers. The general structure is in the 30-60-90 day plan template for new hires, and the 30-60-90 day plan for executives covers the listening tour in more depth.

Risks to check before strategy

A roadmap means little if a ransomware incident or a failed restore takes the company down in month two. In the first two weeks, ask for evidence rather than reassurance on a short list:

QuestionEvidence to ask forWhy it matters
Who has admin access to critical systems?A current list, including former staff and vendorsLingering access is a common path for incidents
Can we restore the most important systems?Date and result of the last tested restoreUntested backups often fail when needed
What happens in an incident?The written response plan, contacts and last exerciseDecisions made in the moment are slower and worse
What do contracts and laws require of us?Customer contract security terms, cyber insurance requirements, industry obligationsBreach notice and security duties come from many sources
Where is sensitive data?A rough map of customer, employee and payment dataDrives priorities for access and monitoring

Data security and breach notification duties come from state laws, sector rules such as HIPAA for health data, industry standards such as PCI DSS for card data, customer contracts and insurance policies, and they differ by company. Confirm which apply with counsel and your security lead, as of October 2026; this is not legal advice. Many teams organize the review around the NIST Cybersecurity Framework, which gives a shared vocabulary for presenting gaps to leadership.

The 30-60-90 day plan

30-60-90 day plan — [Name], IT Director, [company / division]
Reports to: [CIO / CFO / COO / CEO]    Start: [date]
Team: [N] staff in [infrastructure, apps, service desk, security]
Budget: [annual opex / capex]    Main vendors: [MSP, cloud, ERP]

DAYS 1-30 — Listen and map
Goals:
- Meet every business leader: what helps, what blocks, what
  they would fund
- Meet every IT team member; learn what fills their week
- Run the risk check: admin access, restore test, incident
  plan, contract and insurance security terms
- Map spend: every contract with cost, owner, renewal and
  notice dates; license counts against actual users
- Baseline service: ticket volume, age, satisfaction
Deliverables by day 30:
- Risk findings with owners and dates
- Spend and contract map; listening tour themes
Check-in: day 30, with [manager]

DAYS 31-60 — Fix and prioritize
Goals:
- Close or schedule the highest risks (example: remove stale
  admin accounts, run a restore test, hold an incident tabletop)
- Deliver one quick improvement a business leader asked for
- Review the team structure, skills and workload
- Decide on any contracts with notice dates in the next
  six months: renew, renegotiate or exit
Deliverables by day 60:
- Risk progress report; one visible quick improvement
- Draft priorities ranked with business leaders
Check-in: day 60

DAYS 61-90 — Roadmap and budget
Goals:
- Write a 12 to 18 month roadmap tied to business priorities
- Build the budget for it, including savings from the
  spend map
- Propose team changes with the evidence behind them
Deliverables by day 90:
- Roadmap and budget reviewed with leadership
- Service measures against the day-30 baseline
Check-in: day 90 — full review

What to measure

Set measures with the executive sponsor and compare with the day-30 baseline. The standards below are examples only.

MeasureWhy it mattersExample standard (example only)
High risks openExposure the business carries todayEvery high risk owned and dated by day 60
Contracts with known renewal and notice datesAvoids unwanted autorenewalsAll contracts mapped by day 30
Spend per business capabilityShows where money goes and what to cutMapped and shared with finance by day 60
Business leader satisfactionIT is judged by the people it servesShort check at day 30 and day 90
Ticket age and repeat issuesDaily experience of every employeeImproving against the day-30 baseline

A filled example

IT director: Sofia Marchetti (invented), previously an infrastructure manager at a larger firm, joining a distribution company with several warehouses and a central office.

Day 30: The risk check found several administrator accounts belonging to a former managed service provider and no restore test in over a year. The spend map showed two overlapping collaboration tools and a large ERP support contract renewing in five months. Warehouse managers' main complaint was handheld scanner outages.

Day 60: Removed the stale accounts, ran a restore test that exposed a missing database backup, which was fixed, and held an incident tabletop with leadership. Replaced failing scanner access points at the worst warehouse, which cut outages there.

Day 90: Her roadmap retired one collaboration tool, renegotiated the ERP support contract and moved the savings into a phased warehouse network upgrade. Leadership approved it, along with a request for a dedicated security role.

What "on track" looks like

CheckpointOn trackWorth a direct conversation
Day 30Every leader met; risk check done; spend mappedTalking only with the IT team; no view of contracts
Day 60High risks moving; one quick improvement deliveredBig plans, no visible change; risks unowned
Day 90Roadmap and budget tied to business prioritiesA technology wish list with no business case

What the company owes the new IT director

  • Time with every business leader in the first month, arranged by the sponsor.
  • Full contract and spend data from finance and procurement.
  • Authority to act on urgent risks without waiting for the budget cycle.
  • A clear decision on scope: which systems, sites and teams the role owns.

Common mistakes

MistakeResultFix
Strategy before the risk checkAn incident derails the planEvidence-based risk check in the first two weeks
Roadmap built inside ITLeaders do not fund or support itRank priorities with business leaders
Early restructureLost trust and lost knowledgePropose changes at day 90 with evidence
Missing contract notice datesAutorenewal at the old priceContract map with notice dates by day 30

Turning complaints into a roadmap

The listening tour will produce a long list of complaints, many of them symptoms of the same few problems. Group them by cause: an aging network, a system that does not fit how a team works, missing training, slow support. For each cause, note who is affected, what it costs in time or money where you can estimate it, and what fixing it would take. Rank with the business leaders, not for them. A roadmap built this way is easier to fund because each item already has a sponsor outside IT.

Adapting the plan

  • Heavily outsourced IT: spend more of the first month on managed service contracts, their service levels and who holds admin access.
  • Regulated industries: add the compliance calendar for audits and assessments the company must pass, and meet the compliance lead in week one.
  • Directors over development teams: add delivery measures and on-call practices; the 30-60-90 day plan for DevOps engineers shows what a healthy baseline looks like.

For the security side of the team, the 30-60-90 day plan for cybersecurity analysts shows how log coverage and detection ownership ramp, and the IT project manager screening questions help when the roadmap needs someone to deliver it.

Questions people ask

How is an IT director's 30-60-90 day plan different from an IT manager's?

An IT manager's first 90 days center on running systems safely: access, inventory, backups and the service desk. An IT director's center on direction and money: what the business needs from technology, where the budget goes, which contracts and vendors matter, how the team is organized and what the roadmap should be. Both need an early check on security and recovery.

What should a new IT director do in the first two weeks?

Meet each business leader and ask what technology helps or blocks them, meet every IT team lead, and confirm who holds administrative access to the most critical systems. Ask for the last incident report, the incident response plan and the date of the last tested restore, so major risks are known before strategy work starts.

How do you measure an IT director's first 90 days?

By a complete map of spend, contracts and renewal dates, an incident readiness check with gaps scheduled, a roadmap and budget leadership agrees to, and at least one visible improvement a business leader asked for. Satisfaction and service measures should be compared with the day-30 baseline.

Should a new IT director restructure the team right away?

Usually not in the first 60 days. Learn what each person does, where work queues up and which skills are missing first. A restructure proposed at day 90 with evidence is more likely to be accepted than one announced in the first month.