CIOs and senior IT leaders are under permanent pressure to take cost out of IT
while keeping modernisation moving. That pressure sharpens when the change is
forced rather than planned — as it was through 2020, and as it has been
repeatedly since.
The balancing act is between short-term cost reduction and medium- to long-term
investment. It is especially awkward for IT asset management and software asset
management, because both are investments in risk mitigation and cost avoidance
rather than a line you can strike out of next month’s budget and feel the
benefit immediately.
So a decision point arrives. Do you invest further in SAM, HAM and ITAM to
extract more value from what you already own, or do you fall back on the
rudimentary asset tooling bundled with something you are already buying? The
answer turns on one question: can your current tooling show evidence of value?
Free is nearly always the most expensive option
ITSM platforms and complimentary inventory tools such as Microsoft’s SCCM are
not enterprise-scale SAM, and were never built to be. A service desk follows
ITIL. System Center is a desktop administration tool. Both do their own job
well. Neither produces audit-ready data you would want to defend in front of a
publisher, and — the part that gets overlooked — neither carries licensing logic
at all. No entitlement records, no downgrade rights, no second-use handling, no
processor core factors, no effective licence position.
Established SAM vendors can fall short too. Ageing architecture, thin support
and accumulating security obligations all eat into a programme that is supposed
to be returning value.
Both situations end in the same place: uncontrolled software spending and an
exposure nobody has quantified. Audits happen. The settlement usually exceeds
whatever was saved by dropping the capability that would have prevented it. SaaS
and cloud make this worse rather than better, because subscription sprawl
compounds every month and nothing stops it on its own.
There is a second reason not to let this capability lapse, and it has nothing to
do with licensing. SAM is a primary source of truth for what software is
actually deployed across everything you own, down to version and edition. That
is the first question asked in a security incident. CerteroX SAM resolves titles
against the Software Recognition Database — over 3.5 million normalised
publisher, product and version entries — and the Software Recognition Service
carries release date, end-of-support and extended-support dates alongside them,
so end-of-life exposure is a standing report rather than a fire drill.
Ask a plain question of whatever you run today. When the next critical
vulnerability is announced, can you say where that version is installed, and how
many instances, before the end of the day? If the honest answer is no, the tool
is not saving you money. It is deferring a cost.
Assess and understand the gaps
Before cutting or replacing anything, measure what you have. An independent SAM
maturity assessment, benchmarked against industry best practice and the
ISO/IEC 19770-1:2017 process standard, is the cheapest diagnostic available.
A proper assessment looks at technology, process, skills and expertise
separately, because they fail separately. Plenty of organisations have a capable
platform and no one with the standing to act on its output. Plenty of others
have deep licensing expertise and no reliable data to apply it to. The
assessment tells you which of those you are, and therefore what closing the gap
actually requires.
A SAM tool designed a decade ago cannot manage a hybrid environment properly. It
was built when the questions were about desktops and servers, and it obstructs IT
leaders who now need one view across devices, infrastructure, on-premises
software, SaaS subscriptions, cloud resources and — newly — AI.
Agility is the requirement. Information has to be available immediately and it
has to be trustworthy. Contracting is moving the same way: publishers
increasingly offer single agreements spanning several licensing models and
several environments at once, and a procurement team negotiating against that
needs an equally holistic picture or it will negotiate blind.
That coverage is no longer aspirational, which is the main thing that has changed
since this article was first published. It is worth being specific about what a
platform has to do now to be taken seriously.
For SaaS, discovery cannot rely on the finance system. CerteroX SaaS Management
converges three signals — identity provider sync from Entra ID and Okta, vendor
API connectors, and a browser extension — across 47 shipping connectors and a
catalogue of more than 35,000 applications. That combination is what surfaces the
tools nobody expensed, including AI tools, which are classified from application
feature tags rather than a hardcoded list so the detection set keeps up on its
own.
For cloud, “spend went up” is not a finding. CerteroX Cloud Management runs
twenty-six named, individually tunable recommendation checks across twelve cloud
and data platforms — abandoned instances and load balancers, obsolete snapshot
chains, instances stopped but never deallocated, rightsizing, reserved instance
and savings plan opportunities — and ingests the FinOps Open Cost and Usage
Specification natively, so the cost model stays portable. Certero’s average cloud
cost saving across environments under management is 38%.
For the traditional ground, the depth still matters most where the audits bite:
dedicated licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce,
with Oracle options and packs, IBM sub-capacity PVU calculation and SAP named-user
analysis handled properly rather than approximated.
Savings come from three places here — better-informed purchasing, eliminating
waste you can now see, and the negotiating position that comes from knowing your
own numbers before the publisher tells you theirs.
Join the renaissance
The fragmentation is the expensive part. Legacy arrangements scatter the data
across several tools, which means there is no single source of truth, which means
every significant question becomes a reconciliation project before it becomes an
answer.
CerteroX is one platform on one data model, covering ITAM, SAM, SaaS, cloud and
AI. It was built rather than assembled from acquisitions, which is why the data
model is shared rather than bridged. Scope runs from mobile devices through
Windows, macOS and Linux to AIX, HP-UX and Solaris, and out to SaaS and cloud —
in one environment, deployed as SaaS or on-premises. A modern foundation also
costs less to run and support than a tool designed in 2010, which is a saving
that shows up in staff time rather than a licence line.
If the budget conversation is coming, do not open it by asking what ITAM and SAM
cost. Open it by asking what they are currently returning, and what the last
audit, the last renewal and the last security incident cost by comparison.