Skip to content

ITAM & SAM: The foundations of modern cyber security

Security tools only protect what they can see. ITAM and SAM close the visibility gaps that leave legacy machines, unsupported software and mixed-platform hardware outside your defences.

“What exactly are we trying to protect? And have we covered everything?”

Every IT security programme starts with those two questions. Many organisations cannot answer either one confidently, and asset coverage is usually where the confidence runs out.

The reason is that most teams depend on security tools to detect threats, patch vulnerabilities and block attacks, then assume that means the environment is covered. It rarely is, because security tools only protect what they can see.

That is why 74% of cybersecurity leaders report having experienced a security incident caused by unknown or unmanaged assets, in a global study of more than 2,000 of them (Source: Trend Micro, April 2025).

IT Asset Management and Software Asset Management fill those visibility gaps. They are quickly becoming the base layer of modern cyber security.

You can’t secure what you can’t see

Security tools are excellent at spotting malicious activity, and the better ones now predict and prevent attacks before they land.

But they are limited to what is live in an environment. They do not run full lifecycle management, so devices approaching the end of their useful life fall through the gaps.

If you do not have accurate data on the hardware you own, where it sits, which operating systems are still running and what software is installed, you have a vulnerability regardless of what your security stack costs.

Unknown assets become accidental entry points. Unknown software becomes an unpatched vulnerability. Unknown devices become unmanaged risk.

This is not a fringe concern. Deloitte’s ITAM Global Survey found that the lack of cyber security alignment is now considered the greatest concern for ITAM.

Effective ITAM and SAM remove those unknowns and give security teams the starting point they actually need — a clear picture of everything they are protecting.

The visibility gaps security tools cannot see

A shortfall in asset visibility creates predictable blind spots, and attackers know exactly which ones to look for.

Legacy machines

Old or forgotten systems usually sit outside security coverage because nobody knew they needed protecting. A long-abandoned machine in a drawer will never appear in a security console. Network discovery will find it: CerteroX ITAM sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work out where an agent could be deployed. You find the machines before you own the incident.

Mixed operating systems and hardware

Older Linux servers, unsupported devices and machines running outdated agents slip through. Security tooling gives a partial view. This is where most asset tools also give up — which is why CerteroX ITAM runs the same native agent, the same inventory cycle and the same recognition engine across Windows, macOS, Linux, AIX, HP-UX and Solaris. Six operating system families, one schema, no reconciliation project.

These are the assets attackers hunt for. Unmonitored, unpatched and easy to compromise.

For the consequence, look at the WannaCry attack on the NHS in 2017, where unknown, unpatched versions of Microsoft Windows gave attackers the door they needed.

Unsupported, unlicensed software: the hidden security risk

Effective security relies on simple principles:

  • Use supported software
  • Keep it patched
  • Licence it correctly

Unsupported or unlicensed applications break all three immediately. Unsupported software does not get security fixes. Unlicensed software bypasses governance entirely.

S&P Global has stated that effective IT asset management is foundational to cyber-risk management, and that gaps in ITAM can be indicative of flawed cyber-risk processes.

SAM exposes those weaknesses by showing versions, end-of-support dates and whether an application belongs in your environment at all. In CerteroX SAM, the Software Recognition Service carries release date, end-of-support and extended-support dates for recognised titles, so lifecycle risk surfaces as data rather than as a research task. Application blacklisting and prohibition rules handle the software that should not be there in the first place.

Without that clarity you are guessing about your security position instead of working on actual threats.

Why zero-day response depends on ITAM and SAM

Zero-day threats appear suddenly, before security tools can detect or block them. When one lands, the first question a security team asks is:

Where is the vulnerable software installed?

Security tooling often cannot answer that quickly. ITAM and SAM already hold the data. They show exactly which devices run the affected version, so teams can isolate or patch immediately.

Fast visibility is what turns a zero-day vulnerability from a crisis into a contained incident.

Why modern security strategies need ITAM and SAM

The best security team in the world cannot protect what it cannot find. No governance rule works against software nobody knows about. No zero-day response works if part of your environment is invisible.

ITAM and SAM close those gaps. They surface forgotten devices, outdated software and unmanaged assets before any of them becomes an incident. And the control does not stop at reporting: Governance Policies in CerteroX let you express compliance as code — BitLocker enabled, Defender running, Azure VM tag hygiene — with a reusable filter builder and policy definitions you can export, review and import as JSON.

While security teams work to detect threats, ITAM and SAM define exactly what needs protecting.

Effective cyber security does not start with alerts and patching. It starts with knowing what you own, where it is, what it runs and whether it is still supported.

Book a demo and put the hardest claim on this page to a technical person with the product open.

Related reading

Other posts covering the same ground.

  • Is your ITAM function ready for Coronavirus?

    A business continuity checklist for ITAM and SAM leaders — licensing when staff work from personal devices, temporary rights changes that are never reversed, unsanctioned software, and keeping sight of machines that no longer touch the corporate network.

    • ITAM
    • SAM
    • Governance
    • Security
    7 min
  • 4 Steps to Understand (and Trust) Your ITAM / SAM Solution

    How to tell whether an ITAM or SAM vendor can actually do what they say — security credentials, the one publisher verification that genuinely exists, independent customer evidence, and testing the outputs yourself.

    • ITAM
    • SAM
    • Governance
    • Security
    9 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.