IT Strategy · 2026-07-29 (Last updated: July 2026) · 14 min read

IT Strategy for the Mid-Market 2026: Why 60 to 80 Percent of the Budget Goes into Legacy Systems — and How to Win Room Back

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

Most mid-market companies do not have an IT problem. They have a budget-allocation problem that looks like an IT problem. According to a Bitkom survey, German companies spend an average of 60 to 80 percent of their IT budget maintaining existing systems — which means that between two and four euros out of every five are already committed before a single new project is discussed. That is why so many digitalisation initiatives stall halfway: not because the technology is wrong, but because the money is tied up in a systems landscape that grew rather than was planned. This article is about getting that room back: what actually belongs in an IT strategy, the four layers to prioritise across, when to replace and when to modernise, and the three mistakes that keep budgets locked up.

The starting position in numbers

The maintenance share is the headline figure, but the pressure behind it is what makes 2026 different. The Lünendonk study on IT modernisation found that at 62 percent of companies, parts of the business-critical applications are already so outdated that they no longer meet current requirements and must be renewed. More uncomfortable still: at every second company, the operation, maintenance and further development of those legacy systems is no longer secured in the medium to long term — often for the simple reason that the people who understand them are retiring.

The market has noticed. 83 percent of the companies surveyed plan to increase their IT modernisation budget in 2026, almost a quarter of them by more than five percent. So the money is moving. The question that decides whether it produces anything is not how much you spend but in what order — and that ordering is exactly what an IT strategy is for.

Put these figures next to the AI numbers and the picture sharpens. Bitkom's 2026 survey found 41 percent of companies actively using AI, with unclear costs cited as a hurdle by 37 percent. Both things are true simultaneously: companies want to build new capability on top, while four fifths of their capacity is bound below. Anyone wondering why an AI project stalls after the pilot usually finds the answer one layer down, in the data and interfaces nobody budgeted to fix. We work through that layer specifically in AI integration in the mid-market.

Why grown IT gets more expensive than planned IT

No mid-market company decided to have a fragmented systems landscape. It happened the way such things always happen: each individual decision was reasonable at the time. The industry software came first because it had to. The CRM came later, from a different vendor, because sales needed something now. A shop system, a scheduling tool, three Excel files that quietly became business-critical. Every step solved a real problem. The cost was never in the individual step but in the connections nobody made.

That is where the compounding starts. Every system that does not talk to its neighbour produces manual work — someone copies data, reconciles it, corrects it. That work is invisible in the IT budget because it sits in personnel cost. Every non-integrated system also makes the next integration harder, so the price of change rises with each year you postpone it. And any system whose data quality nobody owns eventually becomes the reason a promising automation project fails, because an agent, a report or a forecast can only ever be as good as the data underneath. This is what technical debt actually means in a mid-market context: not bad code, but deferred connections.

The strategic consequence is simple and unpopular. You do not fix this by buying a better tool. You fix it by deciding, deliberately, which parts of the estate get renewed, which get connected, and which you knowingly keep as they are — and then funding that order. A tool bought without that decision usually becomes the next island.

The four layers of an IT strategy

An IT strategy for a company with 10 to 500 employees does not need to be a document. It needs to be a decision about four layers — what state each is in, what the first step is, and which one gets money first.

LayerTypical problem in the mid-marketSensible first step
1. InfrastructureGrown hosting, unclear responsibilities, ageing hardwareInventory: what runs where, who is responsible, what is out of support
2. DataSame customer in three systems, no single source of truthDefine the leading system per data object, then clean once
3. Processes & applicationsManual transfers between ERP, CRM and industry softwareMap the two or three highest-volume handovers, then close them
4. Security & complianceBackup untested, access rights grown, AI use undocumentedTest the restore, review access, document AI usage (Art. 4)

The order in that table is not arbitrary; it is dependency. Data quality cannot be fixed while the infrastructure underneath is unclear, process automation on top of unreliable data produces confident nonsense, and security is the layer that can invalidate all three overnight. In practice, most mid-market companies discover that their real bottleneck is layer 2 — not because it is glamorous, but because everything they want to do next quietly depends on it.

Replace, modernise, or knowingly keep

For every legacy system there are three honest options, and the skill is matching them correctly. Replace when the system performs standard tasks for which mature alternatives exist and the data can be migrated with reasonable effort — accounting, ticketing, standard CRM. Modernise when the system holds industry logic that exists nowhere else: add interfaces so its data becomes usable, extract what other systems need, renew the surface without touching the core. That is often the cheapest path for the specialised software that actually runs your business.

And then there is the third option that rarely gets stated openly: knowingly keep. Not every old system needs to be touched. A stable machine that does one job, has no growth path and costs little to run can stay exactly as it is — provided you have decided that consciously and documented who could still operate it if the one person who knows it left. What is expensive is not old software. What is expensive is old software nobody has decided about, surrounded by an ever-growing ring of point solutions built to work around it.

Internal, external, or both: who does what

The staffing question follows the layers rather than preceding them. What belongs internally is process knowledge and decision authority — someone who understands how the company actually earns money and can say what matters first. What belongs externally is anything requiring specialist depth or availability the company cannot reasonably keep on payroll: infrastructure operation, security, software development, AI integration. For most companies between 10 and 500 employees, lean internal ownership plus a partner beats both extremes.

The failure mode worth naming is the internal all-rounder. In a lot of mid-market companies one capable person quietly runs the servers, the backups, the CRM and the website alongside their actual job. That works until it does not — until they are on holiday during an outage, or leave. It is not a criticism of the person; it is a structural risk that no strategy document mentions and every audit finds. The decision of what to build in-house versus buy is the same one we work through for software specifically in software development in the mid-market.

The three mistakes that keep budgets locked

  • Buying tools instead of deciding order. A new system bought without a place in the architecture becomes the next island — and raises the maintenance share you were trying to lower.
  • Postponing the data layer. It is the least visible work and the precondition for everything else. Every automation, report and AI project built on unowned data eventually fails, and the failure is always blamed on the new project rather than the foundation.
  • Treating modernisation as a one-off project. Systems age continuously; a single big renewal push resets the clock and then starts the same drift again. A small, permanent share of the budget for maintenance and renewal is cheaper than a replacement every seven years.

Conclusion

If 60 to 80 percent of the IT budget maintains what already exists, then the decisive strategic question is not which technology to adopt next but how to lower that share — because everything you want to do afterwards is funded from what is left. The path is unglamorous: take inventory across the four layers, fix the data layer before the automation on top of it, decide explicitly for every legacy system whether to replace, modernise or knowingly keep it, put process knowledge internally and specialist depth externally, and treat renewal as a permanent budget line rather than a project. Do that, and the same money buys progress instead of standstill. If you want that assessment done against your actual systems landscape rather than a generic maturity model, that is exactly what a first call is for — and the way we approach it is described under services and AI integration.

Frequently asked questions about IT strategy in the mid-market

What belongs in an IT strategy for a mid-market company?

Four layers: infrastructure (hosting, network, endpoints), data (where it lives, who may see it, how clean it is), processes and applications (ERP, CRM, industry software, automation), and security and compliance (backup, access, GDPR, and since 2026 the EU AI Act). An IT strategy is not a technology catalogue but the decision about the order in which these four layers get funded — and which legacy burdens you knowingly continue to carry.

Why is there so little budget left for new projects in the mid-market?

Because the existing estate costs more than it looks. According to a Bitkom survey, German companies spend an average of 60 to 80 percent of their IT budget maintaining existing systems. The Lünendonk study on IT modernisation adds that at 62 percent of companies, parts of the business-critical applications are already so outdated that they must be replaced, and at every second company the operation of legacy systems is no longer secured in the medium to long term. Change nothing, and you pay more each year for the same thing.

At what company size does an IT strategy pay off?

Practically from the point where more than one person makes IT decisions — so in the B2B mid-market, effectively always. At 10 to 50 employees a one-page target picture plus a priority list is usually enough. From roughly 50 to 500 employees the strategy matters more than individual tools, because systems start blocking each other: a CRM that does not talk to your industry software costs staff time permanently, however good it is on its own.

Should you replace legacy systems or modernise them?

Both are right, depending on the system. Replacement pays off when a system handles standard tasks for which mature alternatives exist and the migration is manageable. Modernisation (adding interfaces, extracting data, renewing the interface) makes sense when the system contains industry-specific logic that exists nowhere else. The most expensive path is the third one: leave everything as it is and keep building new point solutions around it.

What does IT consulting cost for a mid-market company?

Serious IT consulting is billed either by effort or as a project with a clearly defined outcome. More important than the day rate is what you hold at the end: a prioritised list of measures with effort and expected effect, not a presentation. An initial assessment — map the systems landscape, name the bottlenecks, set the order — is feasible within a few days and should always precede the first tool purchase.

Does the mid-market need its own IT department or is an external partner enough?

Most companies with 10 to 500 employees do best with lean internal ownership plus an external partner. Internal belongs whoever knows the processes and makes decisions; external belongs whatever requires specialist knowledge and round-the-clock availability — infrastructure, security, development, AI integration. The classic mistake is mixing the two: an internal all-rounder who runs systems on the side is a single point of failure, not a strategy.

Sources and note: Maintenance share of IT budgets (60–80% for existing systems): Bitkom survey, as widely cited in the German IT press. Legacy figures: Lünendonk study „IT modernisation between legacy, cloud and AI“ — 62% of companies report business-critical applications that are too outdated for current requirements, at every second company the operation of legacy systems is not secured in the medium to long term, and 83% plan to increase their modernisation budget in 2026 (almost a quarter by more than 5%). AI adoption context: Bitkom AI study 2026 (41% active use, 37% cite unclear costs). Layer model, first steps and failure modes reflect Vincency's own project experience, not an independent study. This article is a general overview as of July 2026. Transparency: Michael Kaiser is a co-founder of Vincency and the founder of ArkeonTech.