Turning IT Spend Into Business Capability
CIOREVIEW >> Artificial Intelligence >> NEWS

Cardel Homes

Florin Robete, CISSP, Corporate IT Manager

Turning IT Spend Into Business Capability

Florin Robete, CISSP, Corporate IT Manager
Florin Robete, CISSP, Corporate IT Manager, Cardel Homes

Florin Robete

Technology Value Architect

Make Every Dollar Buy Capability

Early in my career, planning meant keeping systems running and projects on time. Today it starts with the business outcome, works backward to the technology and treats the budget as a strategic lever rather than a constraint. Strategic planning and financial stewardship are inseparable now. Every architectural decision is also a financial one, and the job is making sure each dollar buys capability, resilience or risk reduction.

So instead of defending a flat budget line by line, I look for moves that fund themselves: consolidating fragmented tools into a modern collaboration platform, or right-sizing cloud infrastructure like IaaS and PaaS, to cut recurring spend while strengthening security and stability. Those savings free up capital to reinvest, so the roadmap becomes self-sustaining rather than a perpetual ask for more money.

It also helps to speak "fluent geek and fluent business" at once, framing plans in terms of total cost of ownership, ROI and the spend-versus-risk trade-off.

That's what earns the trust to get strategic initiatives funded and aligns technology with growth and profitability.

Governance Creates Safe Guardrails

The mindset is to stop treating security and business enablement as opposites. Good governance is what lets you say "yes" safely.

I anchor decisions in recognized frameworks, like CIS, NIST, COBIT and ITIL, so protection is proportionate and defensible rather than reactive. I pair that with real operating discipline. A change management process controls the lifecycle of every change, while a clear IT policy is backed by regular user awareness training. Onboarding and separation workflows are built on least privilege and need-to-know, reinforced through privileged identity/access management (PIM/PAM).

When the business wants speed, governance provides the guardrails to move fast without gambling. My role is to give leadership cost-effective options and trade-offs, then let the business own the risk decision with full visibility.

Recovery Defines Real Preparedness

Resilience assumes something will eventually get through, so the real question becomes how quickly you detect, contain and recover.

That mindset drives a defense-in-depth approach; network segmentation with IPS/IDS and DoS protection, modern endpoint and identity protection, a zero-trust posture and secure edge access through SASE.

But tooling is only half of it.

  My role is to give leadership cost-effective options and trade-offs, then let the business own the risk decision with full visibility.  

The other half is a living disaster recovery and business continuity plan, with defined RTO/RPO targets, risk analysis and a communication plan, validated through tabletop exercises so you find the gaps before a real incident does. Resilience is measured by how you perform on your worst day, not your best.

Ownership Turns Strategy into Results

Execution is what actually matters; strategy on a slide changes nothing. Having worked across systems administration, business analysis and project management, I've learned that execution lives at the intersection of people, process and technology, and it holds together only when ownership and accountability are crystal clear.

Introducing formal project management and ITIL-based service practices consistently cuts delivery time and reduces missteps, largely because they force the question ‘who owns this?’ for every task, decision and risk. When each work stream has a named owner and a defined outcome they're accountable for, things stop falling through the cracks. Keeping initiatives phased reinforces that: it makes progress visible and keeps momentum alive.

A major ERP or platform migration is a good example. Rather than chase an aggressive date, the mature move is to build in enough time for training, testing and data readiness. It also means keeping sufficient overlap with the legacy system so you optimize for a low-risk outcome rather than a fast headline.

Throughout the rollout, the constant is communication and clear accountability. That means naming who owns each decision and deliverable, being explicit about what’s changing and managing the human side of the rollout so no one is guessing where responsibility sits.

Build Depth, Fluency and Versatility

Build your technical depth deliberately, but don't let it become your ceiling.

Certifications from a security foundation like CISSP through to modern cloud and AI credentials matter, but the real differentiator is a habit of continuous, hands-on learning. I still teach myself new platforms, whether that's next-generation firewalls, SASE or emerging AI tooling, because that's what keeps you credible.

At the same time, start developing the ‘softer’ skills early, because they're actually the hard ones. Learn to facilitate, persuade, plan, communicate and learn to translate technology into business value, that bilingual ability is what separates a strong engineer from a leader. Invest in it formally too; structured leadership and management development programs give you a framework to grow into the role rather than stumbling into it.

Finally, seek versatility. Wearing many hats, administrator, analyst, project manager, mentor, security specialist, is what gives you the range to manage multi-disciplinary problems. Volunteer for the messy cross-functional projects, mentor others and remember that leadership is ultimately about building a strong, collaborative team, not being the smartest person in the room.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.