I was sitting with a credit union leadership team once when the CEO asked a question that sounded simple.
“Rusty, what are we supposed to talk about in an annual technology meeting?”
It was a good question.
They already had regular IT conversations.
They reviewed help desk issues.
They approved hardware purchases.
They discussed cybersecurity when something made the news.
But they had never really stepped back and asked:
“Where is our technology going over the next year—and does it support where the credit union is going?”
That is what an annual technology strategy meeting is for.
It is not another status update.
It is not a meeting about open tickets.
And it should not become a two-hour presentation full of acronyms.
A strong annual technology strategy meeting gives leadership a clear view of risk, priorities, investments, and the roadmap for the next 12 to 36 months.
For most credit unions, I recommend setting aside 90 to 120 minutes and organizing the discussion around a simple framework.
Start With the Business Before You Talk About Technology
The biggest mistake I see is starting with equipment.
Servers.
Firewalls.
Licenses.
Laptops.
Those things matter, but they should not lead the meeting.
Start with the credit union’s business goals.
Ask:
- Are we planning to grow?
- Are we opening or consolidating branches?
- Are staffing needs changing?
- Are we introducing new member services?
- Are there major compliance or operational initiatives coming?
- Are we trying to improve employee efficiency?
- Are we preparing for a core conversion or major vendor change?
Technology should support those goals.
If you begin with the business, the rest of the agenda becomes much easier.
Agenda Item 1: Review the Previous Year’s Roadmap
Spend the first 10 to 15 minutes looking backward.
What did you plan to accomplish?
What actually happened?
What got delayed?
What changed?
Maybe the firewall replacement happened on schedule.
Maybe a Microsoft 365 project moved faster than expected.
Maybe a cloud migration was delayed because another initiative became more important.
The goal is not to assign blame.
It is to understand what changed and carry those lessons into the new plan.
Agenda Item 2: Review Your Biggest Technology Risks
Next, ask:
“What are the three to five biggest technology risks facing us right now?”
Keep the list short.
That might include:
- Cybersecurity gaps
- Aging infrastructure
- Business continuity concerns
- Key-person dependency
- Vendor risk
- Outdated documentation
- Unsupported software
- Weak recovery capabilities
A risk list with 37 items is not useful.
Leadership needs priorities.
The goal is to identify which risks deserve attention first and what actions will reduce them.
Agenda Item 3: Cybersecurity and Compliance
This should be one of the most important sections of the meeting.
But again, keep it at the leadership level.
You do not need a deep technical presentation.
You need answers to practical questions.
Discuss:
- Results of recent cybersecurity assessments
- Progress on high-priority findings
- Employee security awareness training
- Multi-factor authentication
- Endpoint and security monitoring
- Incident response readiness
- Vendor risk
- Cyber insurance readiness
- Any upcoming compliance or examination concerns
The board and leadership team should leave this section understanding where the organization is strong and where improvement is needed.
Agenda Item 4: Business Continuity and Disaster Recovery
Ask one simple question:
“If a critical system failed tomorrow morning, how confident are we that we could recover?”
Then work from there.
Review:
- Backup testing
- Recovery time objectives
- Recovery point objectives
- Critical systems
- Communication plans
- Key vendor dependencies
- Tabletop exercises
- Lessons from the last recovery test
A backup strategy that has never been tested is still an assumption.
Annual strategy meetings are a good time to make sure business continuity is part of the broader technology plan.
Agenda Item 5: Hardware and Software Lifecycle
This is where you look ahead before things become emergencies.
Review the age and support status of:
- Servers
- Firewalls
- Network switches
- Wireless infrastructure
- Employee computers
- Operating systems
- Business applications
Ask:
“What will need to be replaced in the next 12, 24, and 36 months?”
That question turns surprise expenses into planned investments.
It also makes budget conversations much easier.
Agenda Item 6: Cloud and Modernization
Not every system belongs in the cloud.
Not every system belongs on-premises.
This part of the meeting should be about fit.
Review:
- Microsoft 365 usage
- Cloud backup
- Hybrid infrastructure
- Remote access
- Legacy applications
- Opportunities to simplify operations
- Applications approaching end-of-life
The goal is not to “move to the cloud.”
The goal is to decide where modernization improves security, reliability, employee productivity, or member service.
Agenda Item 7: Artificial Intelligence and Emerging Technology
AI should now be part of the annual strategy conversation.
Not because every credit union needs a major AI project.
Because employees and vendors may already be using it.
Discuss:
- Which AI tools are already in use
- Whether an acceptable-use policy exists
- Data privacy concerns
- Vendor AI features
- Possible low-risk pilot projects
- Training needs
You do not need to predict the future.
You do need a way to evaluate new technology before it quietly enters the organization.
Agenda Item 8: Vendor Management
Most credit unions rely on a large technology ecosystem.
Core provider.
Internet providers.
Cloud vendors.
Security vendors.
Phone systems.
Fintech partners.
Your annual strategy meeting is a good time to ask:
- Which vendors are critical?
- Which contracts are coming up for renewal?
- Are there overlapping services?
- Are we paying for tools we no longer need?
- Which vendors create the greatest operational or cybersecurity risk?
- Who owns each relationship?
Someone needs to see the whole picture.
Otherwise, technology slowly becomes a collection of disconnected contracts.
Agenda Item 9: Build the Budget
Now you are ready to talk about money.
Notice how late this comes in the meeting.
That is intentional.
By this point, leadership understands the business goals, risks, lifecycle needs, security priorities, and major projects.
Now the budget has context.
Organize spending into four categories:
Keep the lights on.
Managed services, licensing, connectivity, and everyday support.
Reduce risk.
Cybersecurity, compliance, business continuity, and resilience.
Improve operations.
Productivity, modernization, automation, and member experience.
Prepare for tomorrow.
Strategic projects, emerging technology, and long-term infrastructure.
That makes technology spending easier to explain to the board.
Agenda Item 10: Leave With Five Priorities
Do not leave the meeting with 25 initiatives.
Leave with five.
For each one, define:
- The objective
- The owner
- The expected timeframe
- The estimated investment
- The business reason
- The next action
A strategy meeting should create decisions.
Not just discussion.
A Simple 120-Minute Agenda
If you want a starting point, here is one:
0–15 minutes: Business goals and prior-year review
15–30 minutes: Top technology risks
30–45 minutes: Cybersecurity and compliance
45–60 minutes: Business continuity and disaster recovery
60–75 minutes: Hardware/software lifecycle
75–90 minutes: Cloud, AI, and modernization
90–105 minutes: Vendor management and budget priorities
105–120 minutes: Finalize top five initiatives and next steps
That is enough structure to keep the meeting focused without turning it into a marathon.
Final Thoughts
The best technology strategy meetings do not make leadership feel more technical.
They make leadership feel more confident.
You should leave knowing:
Where your biggest risks are.
What needs to be replaced.
Which projects matter most.
What the next year will cost.
What the next three years may require.
And how technology supports the mission of the credit union.
After more than 26 years working with organizations, I have learned that the best technology decisions rarely happen during emergencies.
They happen during calm, intentional conversations long before the emergency ever arrives.
That is why an annual technology strategy meeting matters.
It creates a place to stop reacting.
Look ahead.
Ask better questions.
And make sure your technology is helping the credit union become stronger, safer, and better prepared for what comes next.
Need Help Building Your Credit Union’s Technology Strategy Meeting?
At CTG, we help credit union leadership teams turn complicated technology issues into clear, practical roadmaps.
We can help you review cybersecurity, business continuity, hardware lifecycle, cloud strategy, AI readiness, vendor relationships, and future investments—then organize those priorities into a strategy your leadership team and board can understand.
For more than 26 years, CTG has helped organizations make thoughtful technology decisions, backed by a team with more than 200 years of combined experience.
If your next annual planning session is coming up, we can help you build the agenda, assess the environment, and create a clear 12-to-36-month technology roadmap.
Talk with CTG
Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net
Let’s make your next technology meeting less about problems—and more about where your credit union is going next.
Recent Blog Posts...
How Should an Ohio Credit Union Build an Annual Technology Strategy Meeting Agenda?
What Every Ohio Credit Union Board Should Know About Cybersecurity
How Should an Ohio Credit Union Prepare for a Cyber Insurance Renewal?
The AI Receptionist for Legal Practices: Automating Client Intake Without Losing the Human Touch
Artificial Intelligence for Ohio Credit Unions: Where Should You Start?
- AI6
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud58
- Collaboration18
- Communication20
- Compliance4
- Contact Center1
- Credit Unions12
- Cyber Liability Insurance2
- Cybersecurity37
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure26
- Managed Network Services20
- Managed Services19
- Microsoft Teams2
- Network Performance29
- Network Security34
- News11
- Phishing1
- Press Release2
- Risk Assessment3
- security1
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx7
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

