BOARD IT STRATEGY
Board IT strategy: how directors govern technology without becoming technologists
You sit on a board, the technology slides go up, and you cannot tell whether you are being shown progress or being managed. This page gives you the questions to ask, the decisions that belong to the board, and the line between governing technology and running it.
Book a conversationWhat is board IT strategy?
Board IT strategy is the set of decisions a board makes to direct, control and assure technology so that it serves the organisation’s objectives and risk appetite. It is not the IT roadmap, which is management’s job. It is the layer above: deciding how much the organisation will invest in technology, which risks it will accept, how it will know the money is working, and who is accountable when something fails. Directors do not need to write code or specify systems. They need to ask the right questions and refuse to approve what they do not understand.
The distinction matters because most board technology trouble starts when these two roles blur. When a board approves a major system replacement without grasping what it is for, it has stopped governing and started rubber-stamping. When directors try to choose the database, they have stopped governing and started interfering. Good board IT strategy holds the line in between.
What a board actually needs to know about technology
A director does not need fluency in architecture. They need a working grasp of five things: where the organisation depends on technology to make money or keep promises, where it is exposed if that technology fails, how much is being spent and on what, whether the spend is producing the intended result, and who is accountable for each of these. If the board cannot answer those five from memory, the technology function is being reported badly or not at all.
The most common failure is that technology is reported as activity rather than outcome. Boards are shown projects underway, tickets closed and uptime percentages, none of which tell a director whether the organisation is safer, faster or more efficient than it was a year ago. The job of board IT strategy is to convert technology into the language the board already uses: revenue protected, cost avoided, risk reduced, capability gained. A clear IT operating model makes that translation possible, because it ties each pound of technology spend to a function the business recognises.
The questions directors should ask
Strong board oversight comes from a small number of recurring, uncomfortable questions. Asked consistently, they shape behaviour more than any policy document.
- If our most important system went down this morning, what would stop, and how long until it came back?
- What are the three technology risks most likely to put us in front of a regulator or in the press, and who owns each one?
- Of everything we spent on technology last year, what can we point to as a result?
- Where are people using tools, services or AI we have not approved, and how would we know?
- If our finance director left tomorrow, the board would notice within a day. Would we notice if our most senior technologist left? Who covers that gap?
Two of those questions deserve their own standing items. Unapproved tools, including shadow AI, are now one of the fastest-growing sources of data leakage, and a board that never asks about them is choosing not to see them. Cyber exposure belongs on the agenda every meeting, not once a year, which is why mature boards treat board cyber governance as a permanent fixture rather than an incident response.
Turning technology into board decisions
The point of board IT strategy is decisions, not awareness. A board that is merely informed about technology has done half the job. The half that counts is making the calls that only the board can make: setting the technology investment envelope, approving the risk appetite for cyber and resilience, sanctioning major changes such as a core system replacement or a move to the cloud, and holding management to account against what was promised.
To make those calls well, directors need decisions framed as choices with consequences, not as requests for sign-off. A proposal to replace a finance system should arrive with the cost of doing nothing, the risk being carried in the meantime, and the result expected, so the board is choosing between futures rather than approving a budget line. This is the discipline at the heart of fractional CIO and CISO leadership: presenting technology so that a non-technical board can decide with confidence. Where the organisation is acquiring or being acquired, the same framing drives technology due diligence, turning a technical inspection into a board-level view of value and risk.
Governing cyber, resilience and AI at board level
Three areas now reach the board directly because the consequences land there. The first is cyber. A serious breach is a board event: the IBM Cost of a Data Breach Report 2025 puts the global average cost of a breach at USD 4.44 million, and UK regulators have shown they will act, with the ICO fining British Airways £20 million in 2020 and Interserve £4.4 million in 2022. Boards that treat cyber as an IT problem learn the hard way that it is a governance problem. Practical assurance comes from knowing the organisation has a tested incident response plan and access to cyber security consulting when the in-house view is too narrow.
The second is regulatory resilience. For organisations in scope, frameworks such as NIS2 compliance place explicit duties on management bodies, which means directors can be personally accountable for oversight. The third is AI. Boards are being asked to approve AI investment faster than they can assess it, and a deliberate approach to AI governance keeps the organisation from adopting tools it cannot control or explain.
When a board needs outside technology leadership
Sometimes the gap is not in governance but in the people available to support it. A board may have no technologist among its directors, or a chief executive who needs a trusted technology counterpart who is not selling a system. This is where a virtual CISO or interim technology leader earns their place: someone who can sit in the boardroom, translate, and hold management to account without the cost of a permanent hire. If you are weighing the options, it helps to understand what a vCISO is and how the role differs from a CIO, set out plainly in CIO vs CISO. Where the need is a full leadership gap rather than advisory support, an interim CIO or CISO steps in, and our pricing shows how each engagement is scoped.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Having sat at group level in private-equity-backed and listed environments, Daniel has presented technology and security to boards in the terms directors actually decide on, which is exactly the translation board IT strategy depends on.
Frequently asked questions
What is the difference between board IT strategy and the IT strategy?
The IT strategy is management’s plan for how technology will be delivered. Board IT strategy is the board’s job of directing, controlling and assuring that plan: setting the investment envelope, agreeing the risk appetite, sanctioning major changes and holding management to account. The board governs; management runs.
Does a board need a technology expert among its directors?
Not necessarily, but it needs access to credible, independent technology judgement. Many boards meet this through a virtual CISO or interim technology leader who attends and translates, rather than appointing a permanent director, which keeps the expertise without the fixed cost.
How often should technology and cyber be on the board agenda?
Cyber and resilience should be standing items at every meeting, not an annual review, because the consequences land on the board directly. Strategic technology investment is reviewed in line with the planning cycle, but exposure is governed continuously.
What are the best questions for directors to ask about technology?
Ask what stops if the most important system fails and how long recovery takes, which technology risks could put you in front of a regulator and who owns them, what result last year’s spend produced, where unapproved tools or AI are in use, and who covers the gap if your senior technologist leaves.
Can directors be personally accountable for technology oversight?
In some cases, yes. Regulatory frameworks such as NIS2 place explicit duties on management bodies, and UK regulators have fined organisations significantly for data protection failures. Boards that treat technology and cyber purely as operational matters carry more personal exposure than they realise.
START HERE
See where your technology stands before the next board meeting
If you cannot answer what would stop, what it would cost and who owns the risk, you are governing technology in the dark. The Technology Health Check gives you a clear, board-ready picture of where you are exposed and what to decide first. Or book a conversation and we will talk it through.
Technology Health Check Book a conversation