
Knowledge base
September 30, 2026
Your IT Budget for 2027: Three Questions to Include
You don’t draw up your IT budget for 2027 in December. You sign the contracts that take effect in January in November. You request quotes for those contracts in October. And you should ask yourself the questions you’ll need to answer for that process right now.
In most budgets, security is listed as a single line item under IT—an expense, somewhere between software licenses and hardware. This blog post is about what should come before that line item: three questions that determine how large the budget should be—and whether it actually requires new funding.
Our answer in one sentence: Start with what you’re already paying, not with what you still want to buy.
What am I paying for twice?
In virtually every environment we review, there are paid licenses with no assigned users. Employees who have left, test accounts that were left active, a subscription that continued after a relocation. No one intentionally left them active. Nor did anyone cancel them.
In addition, we see duplicate tools. A paid email filter alongside the filtering that’s already built into Microsoft 365. Two backup products for the same mailbox. A separate antivirus scanner on laptops that already have Defender. Each of those decisions was a good one at the time. Taken together, they make up the first security budget for 2027, and it’s already on the books.
Gather this year’s IT invoices and note, for each line item, who uses it and what it does. That’s all there is to it. To learn how to match licenses to users, check out the blog post about the inner workings of Microsoft 365.
What can I prove?
Until last year, providing proof was something only certified companies had to do. Now every supply chain questionnaire asks for it, and so does the insurer. “MFA is in effect” is a statement. A list with a date, showing for whom MFA has been enforced and under which regulation, is proof.
By 2027, verifiability should be a permanent line item in the budget, not a project. Think of an annual recovery test of your backup with a brief report, a semiannual cleanup of accounts and licenses, one documented training session, and the maintenance of your core documents. The cost is minimal. What it requires is a recurring commitment.
The reason this is happening now is explained in the report “One Month of the Cybersecurity Act”: the law enforces itself through contracts, and the questionnaires are getting smarter with each round.
How much does a week of downtime cost?
This is the figure that doesn’t appear in any budget. Take the revenue for an average week. Add the labor costs for a team that can’t work. Add the time spent on repairs outside of business hours, and the customers you can’t help that week.
Compare that amount to the annual costs of the basic package: MFA, a tested backup, and automatic updates. For every client with whom we run this calculation, the result is the same. The basic package costs a fraction of what a single bad week would cost. And that same basic package is included in the requirements insurers set before they pay out.
The calendar for October through January
A few Microsoft deadlines fall right in the middle of this budget season. Each of those deadlines requires a decision that will either cost money or save money.
Mailbox. Starting October 1, Microsoft will begin phasing out Exchange Web Services on a tenant-by-tenant basis for organizations that have not configured it themselves. It will be permanently shut down in April 2027. Any legacy connections to your mailbox will stop at that time. Ask your vendors if they use Microsoft Graph.
Laptop. Starting in October 2025, Windows 10 will only receive security updates through the paid ESU program. Whether to continue paying or replace the device is a budgetary decision. Count your devices, including the laptop you use for working from home and the PC at the front desk.
Sign In. On February 1, 2027, Microsoft will stop using SMS codes for sign-in for most users; for Global Administrators and external users, this will take effect on July 1, 2027. Anyone who wants to continue using SMS will need to pay their own telecommunications provider. The passkey is free.
Grant. The “My Cyber-Resilient Business” program runs through November 30, 2026. First, you complete the Digital Trust Center’s CyberVeilig Check; then, you purchase a security measure; and finally, you submit your application to RVO. Any purchases or payments made before September 7 do not count toward the program.
Two things you can do in ten minutes
List your licenses alongside your users. The Tenant Check requires an administrator account and does not count PIM-eligible administrators. However, in two minutes, it shows which paid licenses do not have a user assigned to them, along with your MFA coverage and your administrator accounts. It does not save anything from your tenant.
Check your external security. The Security Check only measures what’s publicly visible; it doesn’t look at anything inside your environment. But in just thirty seconds, it shows you what your client can already see: your email security, DNS, certificates, and your website’s security headers.
How ALTA-ICT helps
During a budget meeting, we compare three lists side by side: what you’re paying, what you’re getting in return, and what’s coming up next year. First, we streamline things; then we lay the groundwork—which costs nothing; and only then do we discuss investments. Bring your current IT contract with you, and we’ll give you a fair assessment. If you want to switch providers, read the blog post about switching first. We operate in accordance with ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024.
Frequently Asked Questions
Should security be allocated its own line item in the budget?
Yes, but only after the cleanup. The unclaimed licenses and duplicate tools you find are often enough to cover the basics. The rule itself is then for accountability and for any remaining investments.
What is the difference between “regular” and “demonstrable”?
“Regular” refers to what you do. “Verifiable” refers to what you can demonstrate, along with a date. A client or insurer will ask for the latter.
Should I continue paying for Windows 10 or replace it?
That depends on the device’s age and whether it can run Windows 11. Check first. With a list for each device, the decision is easy to make.
Can I get a grant for the basics?
Some of the measures are available through My Cyber-Resilient Business through November 30. You must first complete the CyberVeilig Check. Funding is allocated on a first-come, first-served basis.
If I could do only one thing, what should I do first?
Compare this year’s invoices side by side. Just take a look. You’ll automatically see what you’re paying twice for.
Conclusion
An IT budget for 2027 doesn’t start with what you want to buy. It starts with three questions: what am I paying for twice, what can I account for, and what does a week of downtime cost? Those who answer these questions in October will sign contracts in November that make sense. Those who wait will have to budget based on a hunch in December.
Would you like to go through the three questions together? Schedule a budget meeting with ALTA-ICT in October. Please bring your current IT contract.
Want to know more?

Related
blogs
Tech Updates: Microsoft 365, Azure, Cybersecurity & AI – Wekelijks in je Mailbox.



