Security needs visibility: The defence value of ITAM
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
- ITAM
- Governance
- Security
When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.
In May 2019 Microsoft published a fix for a Remote Desktop Services vulnerability serious enough that it also shipped emergency updates for operating systems it had stopped supporting years earlier. Windows XP and Windows Server 2003 both got a patch. That does not happen often, and when it does it is worth paying attention.
The flaw was CVE-2019-0708, later given the name BlueKeep. It allowed remote code execution over RDP with no authentication and no user interaction — the attacker did not need anyone to click anything. Microsoft rated it critical and warned it was wormable, meaning a working exploit could spread from machine to machine on its own. That is precisely the property that let WannaCry cross the planet in 2017, which is why the comparison was made at the time.
The affected versions were Windows XP through Windows 7, and Windows Server 2003 through Server 2008 R2.
Microsoft did the difficult engineering. The update existed, it was free, and it was available to everyone including organisations running unsupported operating systems.
What organisations could not do at speed was answer a much more basic question: which machines do we own that are exposed?
That question is not a security question. It is an IT hardware asset management question, and it is the one that determines how long you spend at risk. You cannot patch a device you do not know about. You cannot report on your remaining exposure if your inventory is a spreadsheet that was accurate last quarter. And you cannot tell a board that the risk is closed if the number you are quoting is an estimate.
Every incident of this shape follows the same sequence:
Steps one and two are where organisations lose days. Steps three to five are mechanical once you have them.
CerteroX ITAM answers step one with ten discovery methods that all land in a single schema, so there is no reconciliation exercise between them:
csinvcli) for locked-down
environments where an agent is not permitted, and standalone inventory for
air-gapped and offline systems.The last one matters more than it sounds during an incident. A device list inflated by duplicates and decommissioned hardware produces a remediation figure that never reaches zero, and nobody can tell whether the residue is a reporting artefact or a genuine gap.
Once the machines are known, CerteroX ITAM reports operating system, build and patch level down to the KB identifier, so “which devices are missing this specific update” is a query rather than a project.
Remediation runs from the same console:
And because CerteroX is delivered as SaaS, there is no server procurement cycle between deciding you need visibility and having it. Certero’s founder and CEO, John Lunt, made this point at the time: an organisation worried about a live vulnerability does not have weeks to stand up infrastructure before it can start looking. An on-premises or hybrid deployment remains available where that is the requirement.
The part of this that has changed most since 2019 is what happens next.
Patching a specific CVE is a one-off. Not being caught out by the next one is a standing control, and CerteroX ITAM expresses those as Governance Policies — compliance as code, built on a reusable filter builder. A policy is a condition evaluated continuously across everything discovered: BitLocker enabled, Defender running, Azure VM tag hygiene, and whatever else your security team considers non-negotiable. Policy definitions export and import as JSON, so a control that works in one environment can be moved to another rather than rebuilt.
That turns “are we exposed?” from a fire drill into a dashboard, with threshold alerts when the answer changes.
The specific flaw described here is long patched. The pattern is not.
Windows 10 reached end of support on 14 October 2025. Every device still running it is in the same position the Windows 7 and Server 2008 R2 machines were in when BlueKeep landed: functional, in daily use, and no longer receiving security updates by default. The organisations that handled that deadline well were the ones who could produce an accurate, current count of affected devices — by location, by owner, by hardware model, and split by which of them could actually take the upgrade.
CerteroX ITAM does that specific job with Windows 11 upgrade orchestration against the hardware inventory it already holds, so eligibility and remediation run off one record rather than two.
The lesson from 2019 holds. When the next wormable vulnerability is published, the organisations that close it fastest will not be the ones with the best patching tool. They will be the ones who already knew what they owned.
Other posts covering the same ground.
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.
Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.