The IT asset management landscape has changed shape. Data-centric working, automation and a tightening regulatory environment have pushed ITAM well past its original job of counting things. For CIOs managing increasingly complicated technology portfolios, the question is no longer whether to run an ITAM programme but what to demand of it.
ITAM is no longer about lifeless inventory and compliance checklists.
The change is driven by teams using live data on asset usage, software consumption and lifecycle status. That data is what surfaces the inefficiencies nobody had a way to see: over-provisioned software licences, hardware that was refreshed on schedule rather than on need, and subscriptions that renew because no one is watching the date.
The scale of the opportunity is not theoretical. The average organisation uses 54% of the SaaS licences it pays for — 46% go unused. Against an average annual SaaS spend of $55.7M per organisation, that is roughly $19.8M a year lost to licences nobody opens. In cloud, 29% of spend is wasted, and that figure rose for the first time in five years.
Modern ITAM platforms use live data and analytical dashboards so teams can decide in advance rather than react afterwards. That is what lets organisations plan budgets, reduce audit exposure and commit to IT investment with confidence rather than hope.
Depth of recognition is what makes the data trustworthy. CerteroX resolves what is installed against a Software Recognition Database of more than 3.5 million titles, normalised by publisher, product and version. Without that normalisation layer, an inventory is a list of strings, not a set of facts.
Cloud, hybrid and remote: managing complexity at scale
Hybrid environments — on-premises infrastructure alongside public and private cloud, with a permanently distributed workforce — place demands on ITAM that inventory tools were never built for.
Effective asset management now means tracking devices and software licences consistently across physical servers, virtual machines, cloud services and endpoints wherever they are. CerteroX ITAM covers six operating system families with one agent — Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris — plus VMware, Hyper-V, XenServer, IBM HMC, Oracle VM, Nutanix, AWS and Azure. The platforms most often treated as an integration problem are the ones most likely to hold your licensing exposure.
Deployment model matters too. Some organisations cannot place asset data in a vendor-hosted platform for security or governance reasons, and a shortlist that assumes cloud-only delivery will not survive contact with those constraints. Establish early whether the platform you are assessing can be run the way your policies require.
The newer challenge is everything that never passes through procurement. SaaS subscriptions bought on a card, usage-based cloud cost that varies daily, and applications adopted by teams without telling anyone. This is not a future problem for ITAM to grow into — it is solved work today. CerteroX SaaS Management converges three discovery signals: identity provider sync from Entra ID and Okta, 47 vendor API connectors pulling authoritative user and licence lists, and a browser extension that attributes real usage per user. Against a catalogue of more than 35,000 applications, that produces one inventory of what is actually in use, sanctioned or not.
The same applies to AI. The average enterprise portfolio now runs 305 SaaS applications, and spend on AI-native applications at large enterprises grew 393% year on year. CerteroX classifies AI tools from application feature tags rather than a hardcoded list, so the Shadow AI dashboard keeps finding tools that did not exist when the policy was written.
Automation and insight drive efficiency
Good ITAM data lets CIOs reduce hardware failures, set refresh cycles against evidence, and align spending with business priority instead of with last year’s budget.
The value is in catching risk while it is still cheap. Licence overuse, an agreement approaching renewal, a version approaching end of support — each of these is expensive if you meet it late and trivial if you meet it early. CerteroX tracks release date, end of support and extended support dates through the Software Recognition Service, meters actual application usage with first-used and last-used tracking, and reports a percentage-used figure over a rolling 90-day window. That last number is the one that ends most arguments about whether a licence is needed.
Security, compliance and mitigating risk
Regulatory compliance and cyber security both rest on the asset record. Data privacy law, software licensing terms and contractual obligations all demand transparent, well-documented asset records and a usable audit trail.
Mature organisations integrate ITAM with security and finance systems — SIEM, ITSM and ERP — so governance is expressed once and enforced everywhere, rather than argued about in three tools. Automated licence tracking and usage metering are what keep a compliance position current between audits instead of being reconstructed when the letter arrives.
As threats grow more capable, an accurate, current inventory of hardware and software remains the first line of defence. You cannot patch, isolate or decommission something you do not know you have. This is also where unauthorised software gets caught: CerteroX supports application blacklisting and prohibition rules, blocked-file logging per user and per device, and Governance Policies that check conditions such as BitLocker enabled or Defender running continuously rather than at audit time.
Embracing sustainability and lifecycle optimisation
Sustainability commitments are increasingly shaping ITAM strategy. Organisations are working to cut electronic waste, extend device life through reuse, and meet environmental regulation on responsible end-of-life disposal.
Lifecycle management is what makes that measurable. Tracking asset retirement, recycling and refurbishment turns an ESG commitment into a number you can report. Warranty retrieval and expiry tracking, stale device archiving and end-of-life tracking are ordinary ITAM functions that happen to be exactly the evidence a sustainability report needs.
Key takeaways for CIOs
- Invest in analysis, not just collection. Deploy ITAM with dashboards and real depth of insight so you can control cost and improve utilisation, rather than simply describe it.
- Prioritise hybrid coverage. Choose platforms that track assets consistently across cloud, on-premises and endpoint environments — and confirm the deployment model fits your governance constraints before you shortlist.
- Automate discovery and reconciliation. Manual workflows do not scale and do not stay accurate between runs.
- Integrate compliance. Work with vendors offering genuine licence management depth on the publishers that audit you, and reporting you can hand to a regulator.
- Embed sustainability. Track asset lifecycles so corporate responsibility reporting draws on the same data as everything else.
Taking the next step
The direction is clear enough: data-driven, deployment-flexible and automated ITAM, covering hardware, software, SaaS, cloud and AI as one asset portfolio rather than five disconnected ones.
If you want to benchmark your ITAM maturity or talk through any of the above, get in touch.