For most not-for-profit organisations, technology isn't the mission. It's what sits behind the mission.
It helps your people communicate, manage information, support clients and communities, collaborate across locations, protect sensitive data and keep essential services running. When technology works well, much of that happens quietly in the background. When it doesn't, the effects can reach well beyond the IT team.
A system that's difficult to use creates more work for employees. Ageing infrastructure consumes time and resources. Disconnected applications lead to manual processes and duplicated effort. A cyber incident can interrupt services as well as compromise information. And when technology decisions are continually postponed or made reactively, small problems can gradually become much bigger ones.
That's why it can be useful to periodically conduct an IT reality check. Not to ask whether your organisation has the newest technology, but something much more practical: Is technology genuinely helping your organisation deliver its mission — or is it quietly creating unnecessary work, cost and risk?
Here are six questions worth considering.
1. Is your IT team spending most of its time keeping things running?
There's always going to be day-to-day IT work. Users need support. Accounts need managing. Devices need maintaining. Applications need updating. Security alerts need investigating. New employees need onboarding.
But when most available IT capacity is consumed by keeping the existing environment operational, longer-term improvements can become difficult to progress. Projects get postponed, documentation falls behind, systems remain in place longer than intended and security improvements compete with support requests. Strategic planning becomes something the team will get to when things quieten down — except things rarely do.
This isn't necessarily a reflection on the capability of an internal IT team. In many organisations, capable technology staff are simply being asked to manage an increasingly complex environment with limited time.
The more useful questions are:
- How much IT capacity is currently spent reacting to problems?
- Which recurring tasks consume disproportionate amounts of time?
- What important improvements keep being postponed?
- Where could additional expertise, automation or external support free the internal team to focus on higher-value work?
A healthy technology environment shouldn't require constant intervention just to remain operational.
2. Have temporary technology fixes become permanent?
Technology environments rarely become complicated overnight. Complexity tends to accumulate.
A temporary workaround is introduced to solve an immediate problem. A new application is added without fully integrating it with existing systems. Older infrastructure remains because replacing it isn't yet a priority. Manual processes develop between systems that were never designed to work together.
Individually, these decisions may be entirely reasonable. Over several years, however, they can create technology debt. Employees may find themselves entering the same information into multiple systems. Important processes may depend on spreadsheets or individual knowledge. Older applications can become difficult to support or secure. Integrations become fragile. IT teams spend increasing amounts of time maintaining an environment that has evolved incrementally rather than intentionally.
For not-for-profits, replacing everything at once is rarely practical — nor is it necessarily desirable. The objective should instead be to understand where accumulated technology debt is having a meaningful impact.
Ask:
- Which systems create the most support issues?
- Where are employees relying on manual workarounds?
- Which applications or infrastructure are approaching end of support?
- Are there systems that only one or two people really understand?
- Which technology limitations are affecting service delivery or employee productivity?
Once those pressure points are visible, modernisation can become a prioritised roadmap rather than an expensive transformation project.
3. Could you continue delivering services if a critical system became unavailable?
Cybersecurity conversations often focus on preventing incidents. Prevention matters enormously, but it is only part of resilience.
Even organisations with strong security controls need to consider what happens if a critical application, Microsoft 365 environment, server, internet connection or other technology service becomes unavailable. That interruption could result from a cyber incident, hardware failure, software problem, supplier outage or human error. The cause matters, but to the people relying on your organisation's services, so does the outcome.
That's why an IT reality check should include some practical continuity questions:
- Which systems are genuinely critical to service delivery?
- How long could the organisation operate without them?
- Is important information backed up appropriately?
- Are those backups isolated and protected?
- Has the recovery process actually been tested?
- Who needs to be involved if a significant technology outage occurs?
- Are critical third-party technology dependencies understood?
This is especially important for organisations supporting clients or communities who may depend on timely and reliable access to services. Resilience isn't simply about preventing something from going wrong. It's also about knowing how the organisation will continue when it does.
4. Does technology work equally well for people outside head office?
The traditional picture of an organisation's IT environment — employees sitting at desks in one central office — increasingly bears little resemblance to how many not-for-profits actually operate. Your workforce might include people working across multiple offices, community locations, client sites or from home. Some employees may spend most of their day away from a traditional workplace altogether.
Yet technology and support models can still be designed around the assumption that everyone is sitting in the same building. That disconnect can create friction. Remote employees may experience unreliable access to applications. Frontline workers may develop workarounds because systems don't fit naturally into their day-to-day roles. Devices outside the office can be harder to manage consistently, while employees may struggle to access IT support when and where they need it.
Security also becomes more complicated when people, devices and information are distributed across different locations. It's worth asking:
- Can employees securely access the information and applications they need wherever they work?
- Is the experience consistent across offices, remote locations and frontline environments?
- Can devices be managed and secured remotely?
- Is IT support accessible to people outside the main office?
- Are employees adopting unofficial tools because approved systems aren't meeting their needs?
Technology should follow the way your organisation actually works — not force your people to work around the technology.
5. Do you know how AI is already being used across your organisation?
For many organisations, the AI conversation is still framed around a future decision: Should we adopt AI?
But that question increasingly misses what's already happening. Employees have access to tools such as ChatGPT, Microsoft Copilot and AI capabilities embedded inside many everyday applications. Some may already be using them to draft documents, summarise information, analyse data, prepare communications or reduce administrative work.
That creates genuine opportunities for organisations looking to make limited resources go further. It also creates new questions. What information are employees entering into AI tools? Which platforms have been approved? How is sensitive client or organisational information handled? Do employees understand what constitutes appropriate use? Does the organisation have visibility over the AI services being accessed?
Simply blocking AI is unlikely to be a sustainable strategy. Equally, adopting AI without appropriate governance can introduce unnecessary risk. A useful starting point is understanding what is already happening:
- Which AI tools are employees currently using?
- What tasks are they using them for?
- What organisational or client information could be involved?
- Are approved tools and expectations clearly communicated?
- Where could AI genuinely remove administrative burden or improve productivity?
- Where should human oversight always remain?
Responsible AI adoption starts with visibility — not assumptions.
6. Are technology decisions part of organisational planning — or made when something needs replacing?
One of the clearest indicators of technology maturity isn't the age of an organisation's hardware or the number of applications it uses. It's when technology enters the planning conversation.
In a reactive environment, technology investment is often triggered by events. A server reaches end of life. A contract expires. An application no longer meets requirements. A security issue appears. A new site opens. An employee needs something the existing environment can't provide.
Each issue is addressed individually, but over time that can lead to technology spending without necessarily creating a coherent technology strategy. A more strategic approach starts with the organisation's plans.
If services are changing, what technology will be required to support them? If the workforce is becoming more distributed, does the current environment support that model? If the organisation expects to use AI more extensively, are its data, security and governance foundations ready? If an important system will require replacement in two years, can that investment be planned now rather than becoming an urgent expense later?
This doesn't require predicting every future technology requirement. It means connecting technology decisions with broader organisational priorities early enough to make deliberate choices.
For organisations where expenditure is rightly scrutinised, that can be particularly valuable. Good technology planning isn't about spending more. It's about making sure the money, time and resources you do invest are directed towards the things that matter most.
The goal isn't more technology. It's technology that earns its place.
An IT reality check isn't an argument for replacing everything. In fact, the outcome may be that some systems are working perfectly well and don't need attention.
The purpose is to identify where technology is helping the organisation — and where it may be creating unnecessary friction, risk or cost. Perhaps the biggest issue is resilience. Perhaps it's accumulated technical debt. Perhaps the internal IT team needs more capacity. Perhaps employees need better technology outside the office. Perhaps AI use has moved faster than governance. Or perhaps individual technology decisions are being made without a longer-term roadmap connecting them together.
The priorities will be different for every organisation. What matters is understanding them.
For a not-for-profit, successful technology shouldn't be measured by how many new systems have been implemented or how quickly the latest technology has been adopted. It should be measured by whether technology helps people work effectively, protects the information entrusted to the organisation, supports the continuity of important services and makes responsible use of available resources.
Ultimately, technology should make it easier for your organisation to focus on what it exists to do: protect trust, maintain essential services, make limited resources go further and support your organisation's mission — rather than getting in its way.
Tags:
Not For Profit
25 September 2026, 14:40:55 ACST
Comments