Skip to content

Blog

205 posts.
Every one of them here.

Licensing mechanics, audit defence, cloud waste, SaaS sprawl and shadow AI. Written for the people who answer for them, and detailed enough to use in a renewal.

Start with these

The pieces we would hand you first if you asked what is actually changing right now.

  • Featured

    CerteroX: What the Certero AI Assistant Means for Your Business

    The Certero AI Assistant lets authorised users ask plain-English questions of live asset, software and licence data. It is off until an administrator enables it, and it can never return data the person asking is not already entitled to see.

    Liam Mcbride 7 min read
    • ITAM
    • AI
    • Governance
The library

Everything, newest first.

All 205 posts, covering hardware, licensing, subscriptions, cloud spend and the governance that has to sit over all of it. Search it, filter it or read straight down.

Topic

Year

40 of 44 posts · Security · Vulnerability, exposure and control.

2026 6 posts

  1. Shadow AI: The New Shadow IT Problem (And Why Visibility Comes First)

    Shadow AI moves faster than Shadow IT and carries a wider blast radius. What it is, why the old playbooks do not cover it, and the discovery standard you need before any policy can hold.

    • SaaS
    • AI
    • Governance
    • Security
    8 min
  2. ITAM & SAM: The foundations of modern cyber security

    Security tools only protect what they can see. ITAM and SAM close the visibility gaps that leave legacy machines, unsupported software and mixed-platform hardware outside your defences.

    • ITAM
    • SAM
    • Governance
    • Security
    5 min
  3. Security needs visibility: The defence value of ITAM

    Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.

    • ITAM
    • Governance
    • Security
    5 min
  4. Changing ITAM from a tick-box job to business enabler

    IT asset management stopped being an audit chore some time ago. Here is what it now does for finance, security, procurement and the service desk — and what changes the moment the data becomes trustworthy.

    • ITAM
    • Security
    • FinOps
    6 min
  5. Shadow AI: finding the opportunities and reducing the risks

    Most AI use inside large organisations never reaches IT. Here is why it happens, what it actually risks, and how to get control of it without banning the tools your teams have already found useful.

    • SaaS
    • AI
    • Governance
    • Security
    8 min
  6. UK businesses sitting on a Shadow AI 'data and privacy disaster'

    Microsoft's research found 71% of UK employees using unapproved AI tools at work — and most of them untroubled by the risk. Without visibility of what is running, GDPR compliance becomes impossible to evidence.

    • SaaS
    • AI
    • Governance
    • Security
    5 min

2025 10 posts

  1. The hidden cost of a software-only mindset

    Cloud and SaaS dominate the budget conversation, but every workload still lands on a physical machine. When hardware visibility drifts, security, finance and IT all start working from numbers nobody trusts.

    • ITAM
    • Security
    6 min
  2. Is your ITAM function ready for Coronavirus?

    A business continuity checklist for ITAM and SAM leaders — licensing when staff work from personal devices, temporary rights changes that are never reversed, unsanctioned software, and keeping sight of machines that no longer touch the corporate network.

    • ITAM
    • SAM
    • Governance
    • Security
    7 min
  3. How ITAM, SAM, SaaS and Cloud Solutions Can Give You Visibility Over Remote Workforces

    Remote and hybrid working scattered devices, licences and cloud instances well beyond the corporate network. A walk through the four problems that creates — visibility, security, licensing and cloud cost — and what it takes to close each one.

    • ITAM
    • SAM
    • SaaS
    • Cloud
    • Security
    10 min
  4. Top IT Asset Management Trends of 2025 (So Far)

    Eight shifts reshaping ITAM through 2025 — from the gap between MDM and true lifecycle management, to multi-cloud visibility, compliance automation, security convergence and workflow orchestration. What each one means, and what to do about it.

    • ITAM
    • SAM
    • Cloud
    • Security
    • FinOps
    7 min
  5. The real cost of Shadow IT (and how to bring it under control)

    Shadow IT is not a discipline problem, it is a friction problem. What unapproved tools actually cost in wasted spend, security exposure and compliance risk — and the five steps that bring them back under governance without slowing teams down.

    • SaaS
    • AI
    • Governance
    • Security
    9 min
  6. Top 10 IT Compliance Mistakes (And How to Avoid Them)

    The ten compliance failures that show up again and again in mature IT functions — manual tracking, hybrid blind spots, misread licence terms, unmanaged SaaS — and the controls that close each one.

    • ITAM
    • SAM
    • SaaS
    • Governance
    • Security
    8 min
  7. The Overlooked Link Between SaaS Visibility, FinOps and Cybersecurity

    SaaS visibility stopped being a procurement problem some time ago. It is now the control that finance and security both depend on — and neither can enforce a policy against an application they cannot see.

    • SaaS
    • Security
    • FinOps
    6 min
  8. 5 Ways Software Asset Management Improves Your Business

    SAM is usually sold as audit insurance. It is also a security control, a cost-reduction programme, due diligence for an acquisition, and the only reliable basis for rationalising your applications.

    • SAM
    • Governance
    • Security
    7 min
  9. Why SaaS Sprawl Is Killing Your IT Budget (And What to Do About It)

    The average enterprise now runs 305 SaaS applications and leaves 46% of its licences unused. Here is where the money actually goes, why the risk is not only financial, and the six controls that stop the bleed.

    • SaaS
    • Governance
    • Security
    • FinOps
    6 min
  10. Windows 11 migration: why it matters

    Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.

    • ITAM
    • Governance
    • Security
    8 min

2024 0 posts

2023 2 posts

  1. SaaS Discovery: Turning Unknown SaaS Into the Known

    Shadow SaaS is what happens when buying software stops needing IT. What it costs you in security, compliance and spend — and the three converging discovery signals that now find it, including the AI tools nobody declared.

    • SaaS
    • AI
    • Governance
    • Security
    8 min
  2. Software Vendor Audits – 8 Things you need to know

    What an audit actually is, how it differs from a SAM review, what triggers one, and what you can do about it once the letter has arrived — including whether a completed audit can still be challenged.

    • SAM
    • Governance
    • Security
    9 min

2022 4 posts

  1. 8 Ways Software Asset Management Benefits Your Business

    SAM is usually justified as audit insurance. It is also cost reduction, a security control, acquisition due diligence, a stronger negotiating position, and the only reliable basis for rationalising applications.

    • ITAM
    • SAM
    • SaaS
    • Cloud
    • Security
    10 min
  2. SaaS or on-prem – which option is best for ITAM / SAM solutions?

    Not every ITAM or SAM platform survives the move to the cloud intact. The questions worth asking a vendor before you accept a hosted option — on functionality, tenancy, upgrade control, integration and security.

    • ITAM
    • SAM
    • SaaS
    • Security
    9 min
  3. 4 Steps to Understand (and Trust) Your ITAM / SAM Solution

    How to tell whether an ITAM or SAM vendor can actually do what they say — security credentials, the one publisher verification that genuinely exists, independent customer evidence, and testing the outputs yourself.

    • ITAM
    • SAM
    • Governance
    • Security
    9 min
  4. The Rise in Oracle Java Audits: How to gain clarity

    Oracle asks to see your Java deployments before it will sell you more subscriptions. Why Java is the hardest thing in your environment to count, what the employee-based subscription changed, and how to build a deployment record you can actually defend.

    • SAM
    • Governance
    • Security
    6 min

2021 1 post

  1. Risk & Reward: Digital Transformation's Impact on Cyber Security

    Moving to cloud changes the shape of the attack surface, not just its location. Why third-party sprawl and rushed adoption create the exposure — and what complete visibility across devices, software, SaaS and cloud actually has to include.

    • ITAM
    • Cloud
    • Security
    4 min

2020 0 posts

2019 6 posts

  1. Windows 7, Office 2010 & Server 2008 End of Support: Are you ready?

    End of support is not really a patching problem, it is an inventory problem. Written ahead of the January 2020 cut-off, the argument holds for every deadline since: you cannot remediate the machines your asset register has never seen.

    • ITAM
    • SAM
    • Security
    5 min
  2. MDM: agent or agent-less management for your mobile devices?

    Agent-based mobile device management sees more and annoys users. Agent-less sees less and stays out of the way. The trade-off is real — but the more useful question in 2026 is why mobile is being managed in a separate tool at all.

    • ITAM
    • Security
    4 min
  3. Cloud Based Asset Management Software, Without Limitations

    Most cloud-delivered asset management tools cover software and quietly drop the hardware and cloud data underneath it. Four places that gap costs you money.

    • ITAM
    • SAM
    • SaaS
    • Cloud
    • Security
    7 min
  4. Manage Android Devices and iOS Across Your IT Ecosystem

    Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.

    • ITAM
    • Governance
    • Security
    6 min
  5. IT Asset Management – An Overview of Managing the Hardware Life Cycle

    A working introduction to the hardware life cycle — plan, acquire, commission, maintain, retire — and what an ITAM platform has to do at each stage to be worth having.

    • ITAM
    • SAM
    • Security
    7 min
  6. IT Hardware Asset Management and Microsoft's "New WannaCry" Security Threat

    When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.

    • ITAM
    • Governance
    • Security
    5 min

2018 0 posts

2017 4 posts

  1. Eight ways mature software asset management minimises security risk

    SAM is usually justified on licence cost and audit exposure. The security case is stronger and less often made: you cannot secure software you cannot see, name or date.

    • ITAM
    • SAM
    • Governance
    • Security
    8 min
  2. Managing your Apple devices

    Macs and iPhones arrived in the workplace one department at a time, and most management tooling still treats them as an exception. They should be inventoried, metered and licensed on exactly the same terms as everything else you own.

    • ITAM
    • SAM
    • Security
    4 min
  3. Benefits of a self-service app store: from reducing shadow IT to enhancing IT security

    A corporate app store gives users the frictionless experience they already expect and gives IT the control it keeps losing. It reduces shadow IT, improves licence compliance, tightens security and cuts service desk load — but only if it also covers the SaaS people reach through a browser.

    • ITAM
    • SaaS
    • Governance
    • Security
    8 min
  4. Which Is Better for SAM — Agent or Agentless Discovery?

    Agent-based discovery and agentless discovery each fail in places the other covers. The useful question is not which one to buy, but whether your tool can run both against one data model.

    • ITAM
    • SAM
    • Security
    6 min

2016 11 posts

  1. The Internet of Things and IT Asset Management

    The 2016 Mirai botnet took websites offline using unsecured CCTV cameras. The lesson for IT asset management has not changed: you cannot secure a device you have never discovered.

    • ITAM
    • Governance
    • Security
    4 min
  2. Microsoft Licensing Update — The Secure Productive Enterprise Offer

    Microsoft bundled Office 365, Windows 10 Enterprise and Enterprise Mobility + Security into a single SKU in late 2016. The bundle has been renamed twice since, and the licensing problem it created has not changed at all.

    • SAM
    • Governance
    • Security
    6 min
  3. BSA Continues its Push Against Unlicensed Software in Australia

    Asia Pacific has the highest rate of unlicensed software use in the world, and the BSA has been settling cases in Australia and paying rewards to the employees who report them. What that means for anyone without a defensible licence position.

    • SAM
    • Governance
    • Security
    5 min
  4. Protecting your mobile devices with geo-fencing

    A geo-fence turns a location into a control. Here is what geo-fencing actually does to a mobile device that leaves its assigned site, what it does not do, and how to set the boundaries so the alerts mean something.

    • ITAM
    • Governance
    • Security
    6 min
  5. How software licence management benefits IT security

    The inventory you build to survive an audit is the same inventory your security team has been asking for. Unsupported versions, unpatched installs, unauthorised software and forgotten access are licensing problems and security problems at the same time.

    • SAM
    • SaaS
    • Governance
    • Security
    7 min
  6. Avoiding Microsoft Software Piracy

    The five ways unlicensed Microsoft software gets into an organisation — hard disk loading, unauthorised downloads, standalone certificates, leaked volume keys and auction-site resale — updated for a world where almost none of it arrives on a disc.

    • SAM
    • Governance
    • Security
    7 min
  7. The benefits of a bring your own device (BYOD) policy

    BYOD is usually argued for on cost, productivity and morale. All three hold up — but only if you can still see what the devices are doing, which is the part the policy rarely covers.

    • ITAM
    • SaaS
    • Governance
    • Security
    8 min
  8. The challenges of enterprise mobile management

    Enrolment, platform diversity and device security were the three things that made mobile management hard. Two of them have changed shape completely, and the third answer is no longer a separate product.

    • ITAM
    • Governance
    • Security
    5 min
  9. Mobile Device Management Is a Real Blind Spot

    Most organisations that buy mobile device management software never make it mandatory. The gap is almost never the tooling — it is the absence of a policy that applies to every department without exception.

    • ITAM
    • Governance
    • Security
    5 min
  10. Is Apple Set to Dominate the Enterprise?

    Written in 2016, when IBM had just started replacing Windows PCs with Macs at scale and Android fragmentation was making broad mobile support expensive. The argument holds up better than the prediction.

    • ITAM
    • Security
    5 min
  11. What jailbreak detection is, and why it matters to your organisation

    Jailbreaking and rooting are privilege escalation — they dismantle the security model the device was sold with. Here is what that actually exposes, and what detecting it depends on.

    • ITAM
    • Security
    5 min
Beyond the reading

Every argument here
is checkable against the product.

Posts about visibility, licensing and cost only matter if the platform behind them holds up. Bring the hardest claim on this page and put it to a technical person with the product open.

Nothing is gated, and reading a post does not put you on a scoring model or a call list.