Cloud and SaaS dominate the budget conversation. But everything still runs on physical machines. Every workload sits on a server. Every employee depends on a laptop or a phone. Every device costs money and carries risk.
With hybrid and remote working now normal, and compliance rules carrying real penalties, the unglamorous basics of hardware visibility matter more than they have in years.
Are you really confident in your hardware visibility?
Ask an IT team how many devices the organisation owns and you will usually get a number. Ask how confident they are in it and the number starts to move.
When you are running thousands of devices across departments, offices, home setups and borders, visibility is genuinely hard. Laptops are left in drawers when people leave. Monitors disappear. Some assets never make it onto the books at all, and you end up with a shadow layer of kit nobody is accountable for.
Every one of those unaccounted devices may still hold company data, carry a live software licence, or be quietly generating support costs.
It also creates a trust problem. If an IT team doubts its own asset data, it cannot plan or report with any confidence — and it will stop maintaining the data, because what would be the point.
Hardware visibility is not admin. It is the base layer of good IT management.
You can’t secure what you can’t see
Wasted spending is bad enough. The larger risk is the part you cannot see.
Security and IT working from different views of the same hardware is how vulnerabilities survive. A patching programme is only as complete as the device list it runs against. If a machine is not on the list, it is not in scope, and nobody notices until something goes wrong.
The 2017 WannaCry ransomware attack on the NHS is the reference case. Unsupported operating systems went unpatched in part because there was no reliable record of where those machines were. The gap was not in the patch. It was in knowing which devices needed it.
Hardware visibility still does real security work. It shows where the risk sits, so teams can act before the incident rather than during it.
Is hardware lifecycle management overlooked?
Visibility also saves time and money.
Teams still tracking hardware in spreadsheets spend more time chasing data than managing anything. Meanwhile people leave with company laptops. New starters wait weeks for equipment that is already sitting in a store cupboard.
With live tracking, you can see which devices are active, which need repair or will soon, and which can be reissued. That means longer working lives, fewer unnecessary purchases and less waste.
Control follows visibility, and cost control follows both.
Ending the spreadsheet era
Manual hardware tracking is slow and error-prone, and it degrades fastest in exactly the large, complex environments that most need it to work.
CerteroX ITAM discovers devices through ten methods that all land in one schema: a native agent, a command-line inventory for locked-down machines, agentless collection, standalone inventory for air-gapped systems, network discovery, Active Directory import, third-party ITAM import, cloud and SaaS connectors, browser monitoring and file metering. Network Discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work out where an agent can actually be deployed — so you find machines before you own the problem they represent.
The same native agent covers Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. Non-persistent VDI is supported, duplicate systems are detected and stale devices are archived rather than left to rot in the reporting.
Because it is one schema rather than several tools stitched together, IT, security and finance read the same record. Anyone can check who holds a device, what is installed on it, how it is being used and whether it is current.
There is also a conversational assistant that sits over your own asset and cost data, so a question about which devices are missing a control can be asked in plain language and answered from the database rather than assembled by hand.
That is what stops the drift between what you have recorded and what is actually out there.
Hardware visibility is the foundation of ITAM maturity
Many organisations go at Software Asset Management first, on the assumption that the bigger prize is there.
In practice, without accurate hardware data, software data is unreliable. Every licence, patch and configuration attaches to a physical device. A licence position computed over an incomplete device list is an incomplete licence position, however good the licensing engine behind it.
Get the hardware layer right and software accuracy, service desk speed, budgeting and security all improve together. Get it wrong and every process downstream inherits the error.
The price of ignoring it
Untrusted data stops being maintained. Unmaintained data makes reports into guesswork. Decisions then get made on stale numbers.
The symptoms are familiar: unpatched machines, subscriptions still running for people who left, budgets that never quite reconcile, assets with no owner. All of them trace back to the same root cause.
The longer it runs, the more expensive it is to unpick.
Closing the gap
Adding another monitoring tool rarely closes a visibility gap. It usually adds a fourth version of the truth. The work is in connecting and consolidating what you already run.
One asset view gives everyone the same picture. When it improves:
- Security teams patch faster, because scope is real.
- Finance plans against what exists rather than what was ordered.
- IT recovers and reuses equipment instead of rebuying it.
That is the difference between hardware visibility as a box-ticking exercise and hardware visibility as something that pays for itself.
An NHS Commissioning Support Unit we work with serves more than one hundred NHS organisations, including clinical commissioning groups, hospital trusts and GP practices. It needed to know which devices its users held, locate missing ones, wipe and lock remotely, and push configuration for Wi-Fi, VPN, email and security policy — across a fleet its central team could not physically reach.
Mobile device management for iOS and Android, including Apple DEP enrolment, is part of the same platform as the rest of the asset record. That matters more than the feature list suggests: the mobile fleet stops being a separate system with its own separate truth.
Where to start
Digital services still run on hardware. Ignoring it weakens security, wastes money and degrades decisions.
The first step is not a tool. It is an honest count. Work out how much of your hardware you can actually account for. List what is missing, unused or out of support. Then decide what has to change to get a complete and current view — and fix the visibility layer before you build anything on top of it.