Mastering KPIs in Your IT Strategic Plan (Part 4)
How to Measure What Matters and Track IT's Strategic Progress
“What gets measured gets done.”
- Peter Drucker
If you've been following along from the beginning, you’ve already done some heavy lifting. By now you've set your goals, aligned them with your organization's broader strategic vision, and prioritized projects to achieve them. Now comes one of the most critical steps: defining and measuring success through Key Performance Indicators (KPIs).
Why KPIs Matter
Key Performance Indicators (KPIs) are the quantifiable indicators of progress toward an intended result. (KPI.org)
KPIs aren't just checkboxes; they're vital signs of your strategic health. Simply put, if you can't measure your success, how will you know when you've achieved it? Every strategic goal in your IT plan should have quantifiable KPIs that clearly indicate progress toward completion.
Let's say one of your goals is improving system reliability to enhance organizational productivity. Your KPIs might include:
Reduction in system downtime (e.g., from 2% to 0.5%).
Decrease in helpdesk tickets related to system outages.
Increased user satisfaction ratings from periodic surveys.
By tracking these metrics regularly, you gain clarity about your team's progress and can proactively address issues before they become major problems.
Selecting Effective KPIs
Not every metric is created equal. Effective KPIs are SMART: Specific, Measurable, Achievable, Relevant, and Time-bound.
Here's a quick test for your KPIs:
Specific: Is the goal clear? Instead of "improve cybersecurity," try "reduce security incidents by 30% annually."
Measurable: Can it be quantified or tracked? If you can't measure it, rethink it.
Achievable: Is it realistic given your resources and constraints?
Relevant: Does it align clearly with strategic objectives?
Time-bound: Do you have a clear timeframe?
A Real-Life Example from My 2021 Strategic plan
Goal 1: Ensure reliable, secure, high performing information technology services to support business needs
Objective 1.1 Enhanced Security
The Office of Information & Technology Management (OITM) will include enterprise security management, continuous monitoring, and identity and access management which includes single-sign-on.
We will assess current security risk policy for alignment with acceptable security risk thresholds and devise cloud security requirements to determine the security services and level of protection required for client data and information in the cloud.
We will focus on implementing the latest in proven cybersecurity techniques and technologies including upgrading to a Zero Trust Architecture (ZTA). [S]
Goal 1 Strategic Initiative
Objective 1.1 Enhanced Security - Transition 100% of the organization’s network architecture to Zero Trust Architecture by the end of FY2024 [R, T]
Goal 1 Key Performance Measure
Objective 1.1 Enhanced Security - 100% of the organization’s network architecture will be transitioned to a Zero Trust Architecture as represented by the progress against the CISA ZTA Maturity Model v2 [A, M]
(The letters at the end represent the areas of the strategic goal that align with the SMART KPIs.)
In developing each strategic goal, I had approximately 3 objectives under each associated with initiatives and key performance measures. Here, I trimmed it down for clarity.
KPIs Are Not “Set-It-and-Forget-IT”
Your KPIs should evolve with your environment. Real-time data can (and should) shape your strategy. That means regularly reviewing, updating, and sometimes even scrapping a KPI if it no longer serves your mission.
Strategic plans should breathe. KPIs are how you check the pulse.
Aren’t these Numbers just a Formality?
Absolutely not. KPIs are the currency of credibility. They translate your IT vision into tangible, measurable outcomes that your stakeholders can understand.
Mastering KPIs and ROI demonstrates that IT isn’t just supporting the business—IT is the business. And when you show clear progress with hard data, you're not just building dashboards, you’re building trust.
Next week, Part 5 – Communicating Your IT Strategic Plan Effectively.
Because the best plan in the world won’t matter if no one understands it.
Read the How to Develop Your IT Strategic Plan Series from the beginning
Why CIOs Must Be in the Room: Strategic IT Planning That Actually Works
It is that time again. Time to draft my four-year Information Technology Strategic Plan.



