The cost of poor visibility is rarely obvious. Until it is.
An organisation believed its environment was fully covered. The discovery tool
was running. The reports looked clean. Then a software audit turned up a handful
of devices and applications nobody could account for. No record, no
classification, no alerts. They were not threats. They were gaps. That was enough
to shake confidence across the whole team.
This is more common than most CIOs would expect. When you have spent since 2007
helping organisations defend against software vendor audits, you become acutely
aware of how expensive a small gap becomes. As infrastructure changes, the risk
of falling behind grows with it.
Good data beats a good interface
It is easy to be drawn in by a polished UI, or by the apparent simplicity of an
ITAM tool with out-of-the-box workflows that guide you through managing your
environment.
A strong interface that helps people make safe decisions is essential. But it is
worth asking whether the data underneath it is actually any good. Poor data
inside an automated or over-simplified system does not reduce risk. It
accelerates it, because now the wrong answer arrives faster and with more
confidence attached.
MDM is not asset management
The way end-user devices are administered has changed. Mobile device management
tools such as Microsoft Intune have become a straightforward way to support
enrolled Windows machines, not just phones.
That is genuinely valuable for supporting individual devices through the active
parts of their lifecycle. But administering devices you already know about, and
which have already been enrolled, is not the same as discovering systems. It is
not the same as managing the risk and cost of hardware and software across the
entire asset lifecycle, at volume.
The distinction matters most at the edges: the machines nobody enrolled, the
servers finance bought directly, the Unix frames that were never in scope for the
MDM project in the first place.
Static discovery does not fit dynamic environments
Legacy tools give you point-in-time visibility. The pace of change is not
point-in-time.
Teams end up dealing with assets that appear and disappear unnoticed, alerts that
arrive late, manual work that eats days, and several tools presenting different
versions of the truth. The result is a layer of noise and — more worryingly — a
false sense of security.
Discovery is a strategic capability, not a housekeeping task
Are mergers and acquisitions part of your business strategy? If so, being able to
discover and assess risk across a newly acquired environment quickly should be
near the top of your requirements list.
The faster you understand the hardware and software you have just inherited, the
faster it can be brought under policy, secured, governed and made useful.
What to actually look for
To close the gaps, prioritise tools that:
- Discover changes automatically. Your ITAM tool should tell you what to
manage, not wait for you to tell it.
- Identify and classify rogue assets, so you can assess risk and prioritise
rather than triage by hand.
- Track change continuously, instead of relying on delayed scans.
- Deploy with minimal effort, which is what shortens time to value.
- Deliver audit-ready visibility with verified data that stands up to
scrutiny.
None of that is aspirational. It is the baseline.
1. Check what is being missed
Run a gap analysis between real-time asset appearances and your existing
discovery logs. Look specifically for devices that appeared and vanished without
detection. That is where your current tool falls short, and it is the cheapest
diagnostic you can run.
2. Review how classification works
Examine how your system categorises new or unknown devices. If your team spends
time manually identifying and tagging assets, automation is missing. Automating
classification saves time, but the bigger win is that it removes human error from
a process that gets repeated thousands of times.
3. Move to continuous discovery
Evaluate tools that support event-driven or continuous scanning. These detect
assets as they connect, disconnect or change, which eliminates the blind spots
left by scheduled scans. Continuous visibility means you are not reacting to
changes days or weeks after they happened.
4. Strengthen audit support
Audit requirements demand clarity as much as accuracy. Make sure your discovery
tooling produces exportable, timestamped records with rich context for every
asset. Where the publisher offers one, use a vendor-verified tool — it changes
the nature of the conversation.
What this looks like when it ships
CerteroX ITAM was built against exactly this list.
Ten discovery methods land in one schema. Native agent, command-line
inventory, agentless, standalone, Active Directory import, network scan,
third-party ITAM import, cloud and SaaS connectors, browser monitoring and file
metering. There is no reconciliation project afterwards, because there is nothing
to reconcile.
Network Discovery sweeps a class-C subnet in under five seconds using
NetBIOS, SNMP and ICMP, then probes to establish where an agent can actually be
deployed. You find the machines before you own them — which is the M&A case
above, in practice.
Six operating system families share one native agent: Windows, macOS, Linux,
IBM AIX, HP-UX and Oracle Solaris. Agentless and command-line inventory cover
locked-down machines; standalone inventory covers air-gapped and offline systems;
non-persistent VDI is supported directly. The platforms most tools treat as an
integration problem are treated here as operating systems.
Classification is automatic, not manual. The Software Recognition Database
carries over 3.5 million titles with centrally maintained categorisation,
publisher normalisation and version recognition. Software identification (SWID)
tags carry UNSPSC classification. Duplicate system detection and stale device
archiving keep the record honest over time, rather than letting it silt up.
Audit support is a first-class feature. Governance Policies work as
compliance-as-code with a reusable filter builder — BitLocker enabled, Defender
running, Azure VM tag hygiene — and the audit trail spans agreements,
transactions and exclusions. On the vendor-verified point in step four: Certero
is verified by Oracle License Management Services, which means Oracle’s audit
team can accept data from Certero during an official audit, as an alternative to
installing Oracle’s own measurement tools.
Visibility is not a checkbox. It is a capability.
When asset discovery keeps pace with your environment, everything downstream gets
easier — security, compliance, daily operations, and possibly your sleep.
If your current tool does not give you this level of insight, it is worth looking
at what else is available.
Book a demo, or read more about CerteroX ITAM.