Why Do Quarterly Technology Reviews Matter More Than Annual IT Planning for Credit Unions?

I was sitting with a leadership team once reviewing their technology plan when somebody said:

“Rusty, didn’t we just do this last year?”

Technically, yes.

We had built a good plan.

We reviewed the budget.

We talked about cybersecurity.

We identified equipment that needed to be replaced.

We discussed several projects for the coming year.

Then life happened.

A vendor changed its pricing.

A cybersecurity concern moved up the priority list.

A project took longer than expected.

A few employees left.

Microsoft introduced new capabilities.

And leadership started talking about an initiative that wasn’t even on the radar when we created the original plan.

The annual technology plan wasn’t bad.

The world around it had changed.

That’s why I believe credit unions should have both an annual technology strategy meeting and quarterly technology reviews.

Think of the annual meeting as deciding where you’re going.

The quarterly review makes sure you’re still heading in the right direction.

For most credit unions, I recommend a 60-to-90-minute technology review every quarter, built around five questions:

  1. What changed?
  2. What risks need our attention?
  3. Are our projects on track?
  4. What decisions are coming?
  5. What should we do next?

That’s a much better technology strategy than putting a plan in a folder and opening it again 12 months later.

1. Start Every Quarter With: What Changed?

Technology doesn’t wait for your annual planning cycle.

Neither does your business.

Start every quarterly review with one simple question:

What’s different today than it was 90 days ago?

Maybe you hired employees.

Maybe a critical vendor changed.

Maybe you’re planning a branch project.

Maybe your cyber insurance renewal identified a concern.

Maybe a security assessment uncovered a gap.

Maybe Microsoft 365 has changed.

Maybe employees have started experimenting with artificial intelligence.

Sometimes the biggest technology risks weren’t on last year’s roadmap because they didn’t exist yet.

Quarterly reviews give leadership a regular place to identify those changes before they become surprises.

2. Review Your Top Technology and Cybersecurity Risks

I don’t think leadership needs a spreadsheet containing 75 technical vulnerabilities.

Leadership needs priorities.

Every quarter, ask your IT team or technology partner:

“What are the three biggest technology risks we should know about right now?”

Then discuss each one.

What is the risk?

What could happen?

How likely is it?

What are we doing about it?

Does leadership need to make a decision?

Those risks might involve cybersecurity, aging equipment, vendor access, Microsoft 365, backup and recovery, employee training, or unsupported software.

The list can change.

That’s the point.

Cybersecurity isn’t an annual conversation anymore.

3. Check Your Roadmap Before Projects Drift

Here’s another thing I’ve learned.

Technology projects rarely fail because somebody intentionally ignores them.

They drift.

A server replacement gets pushed three months.

A security project waits for a vendor.

A cloud initiative loses momentum.

Documentation never quite gets finished.

One quarter becomes another.

Suddenly, you’re discussing the same project at next year’s annual meeting.

Quarterly reviews create accountability without turning leadership into project managers.

For each major initiative, use a simple status:

Green: On schedule.

Yellow: Something needs attention.

Red: Leadership intervention or a decision is required.

Then ask:

What’s the next milestone?

Who’s responsible?

What could delay it?

Does the budget still make sense?

You don’t need 40 slides.

You need visibility.

4. Review Cybersecurity and Recovery Readiness

Cybersecurity deserves a standing place on every quarterly agenda.

Not because you need to scare everyone with the latest cyberattack.

Because security requires continuous attention.

Review areas such as:

  • Significant security events
  • Employee security awareness
  • Identity and access
  • Microsoft 365 security
  • Vulnerability or risk findings
  • Backup status
  • Recovery testing
  • Incident response readiness
  • Vendor concerns

And periodically ask one of my favorite questions:

“When did we last prove we could recover?”

That’s a much stronger question than:

“Are the backups running?”

Your quarterly review can also track improvements identified during cybersecurity assessments, examinations, insurance renewals, and tabletop exercises.

That keeps security work moving between major events.

5. Look at Your Technology Lifecycle

Technology usually gives you warning before it becomes a problem.

The trouble is we’re often too busy to listen.

Quarterly reviews are a good time to look ahead 12 to 36 months.

What’s approaching end-of-life?

Which computers are due for replacement?

When does the firewall need attention?

Are servers still appropriately supported?

Are warranties expiring?

Are software platforms changing?

Instead of saying:

“The server failed. We need $40,000.”

I’d rather see leadership saying:

“We know this investment is coming next year, and it’s already part of the roadmap.”

That’s the difference between technology spending and technology planning.

6. Review Vendors Before Renewal Dates Surprise You

Credit unions depend on a lot of outside organizations.

Core providers.

Microsoft.

Cybersecurity companies.

Internet carriers.

Backup providers.

Fintech platforms.

Software companies.

Managed technology partners.

Every quarter, look ahead at significant contract renewals and vendor decisions.

Ask:

Are we getting what we’re paying for?

Are services overlapping?

Has the vendor’s role changed?

Does the vendor have appropriate access?

Is a renewal approaching?

Do we need to evaluate alternatives?

Vendor management becomes much easier when you’re making decisions six months before a contract expires instead of six days.

7. Talk About AI and Emerging Technology

This is exactly the kind of topic that demonstrates why annual planning alone isn’t enough.

Artificial intelligence is changing too quickly for a once-a-year conversation.

Your employees may discover new tools.

Microsoft may introduce new AI capabilities.

Existing vendors may add AI to products you’re already using.

Quarterly reviews give leadership a place to ask:

What are employees using?

What are our vendors introducing?

Are there privacy or cybersecurity concerns?

Do our policies need updating?

Is there a business problem AI could actually help solve?

You don’t need to chase every trend.

But you shouldn’t be surprised by them either.

8. Connect Technology to the Budget

A quarterly technology review shouldn’t become a financial meeting.

But budget belongs in the conversation.

Compare what you planned against what is actually happening.

Have project costs changed?

Did an unexpected expense appear?

Is next year’s capital planning beginning to take shape?

Are there security improvements that should move forward?

A three-to-five-year technology roadmap, supported by quarterly reviews, helps make IT spending more predictable.

Instead of asking:

“Why is IT so expensive this year?”

leadership can ask:

“Which business risks and strategic priorities are these investments addressing?”

That’s a much healthier conversation.

A Simple 60-to-90-Minute Quarterly Technology Review

You don’t need to make this complicated.

Here’s a framework I like:

First 10 minutes: What changed in the business?

Next 15 minutes: Top technology and cybersecurity risks.

Next 15 minutes: Roadmap and project status.

Next 10 minutes: Business continuity, backup, and recovery.

Next 10 minutes: Infrastructure lifecycle and vendor decisions.

Next 10 minutes: Budget and upcoming investments.

Final 10–20 minutes: AI, strategic opportunities, decisions, owners, and next actions.

Every meeting should end with something concrete.

What are our top three priorities before the next quarterly review?

Give each one an owner.

Give it a target date.

Then revisit it in 90 days.

Annual Planning Still Matters

I’m not suggesting you eliminate your annual technology strategy meeting.

You need it.

That’s where leadership should step back and look at the next 12 months, three years, and eventually five years.

Quarterly reviews serve a different purpose.

Annual planning sets the strategy.

Quarterly reviews keep the strategy alive.

You need both.

Without an annual plan, quarterly meetings can become reactive.

Without quarterly reviews, annual plans can become irrelevant.

Together, they create a rhythm.

Plan.

Execute.

Review.

Adjust.

Repeat.

The Question Every CEO and Board Should Ask

At your next leadership or board meeting, ask:

“When was the last time we reviewed our technology strategy—not our IT problems, but our strategy?”

There’s a big difference.

If the only time leadership talks about technology is when something breaks, a contract needs approval, or a cybersecurity incident makes the news, you’re managing technology reactively.

Your members deserve better than that.

Final Thoughts

The best technology strategies I’ve seen aren’t necessarily the most complicated.

They’re the ones people actually use.

A five-year roadmap doesn’t help if nobody looks at it.

A cybersecurity assessment doesn’t help if findings aren’t addressed.

A business continuity plan doesn’t help if nobody tests it.

And an annual IT plan doesn’t help much if the organization changes six months later and the plan doesn’t.

That’s why I like quarterly technology reviews.

Every 90 days, stop.

Look around.

Ask what’s changed.

Review the risks.

Check the roadmap.

Make decisions.

Then keep moving.

After more than 26 years in technology, I’ve learned that good technology leadership isn’t about predicting everything that’s going to happen.

It’s about building a process that helps you adjust when it does.

When Was Your Credit Union’s Last Technology Strategy Review?

If your technology conversations happen mainly when something breaks, a contract expires, or the annual budget comes around, CTG can help you build a more proactive approach.

We help credit unions develop practical quarterly technology reviews, annual strategy meetings, cybersecurity roadmaps, business continuity plans, infrastructure lifecycle plans, Microsoft 365 strategies, vendor reviews, AI planning, and three-to-five-year technology roadmaps.

CTG has been helping organizations make better technology decisions for more than 26 years, backed by a team with more than 200 years of combined experience.

And because we’re vendor-agnostic, the conversation starts with your credit union’s goals and risks—not with a product we want you to buy.

Talk with CTG

Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net

Let’s turn technology planning from an annual event into an ongoing strategy—and make sure your next 90 days move your credit union in the right direction.


Share:

Recent Blog Posts...