No organisation wants to deal with a security incident, and the number of ways one can start keeps growing.
What is surprising is how many organisations have not yet connected security to software asset management. SAM is nearly always justified on licence cost and audit exposure. The security case is at least as strong, and it works both proactively and after the fact.
Increasing SAM maturity is not only about reducing licence spend and compliance risk. As IT has become more mixed — on-premises, cloud, mobile, subscribed — ITAM and SAM provide something security teams need and rarely have: an accurate account of what is out there, why it is there, and what each discovered piece of software actually is.
Combine that with the governance processes that keep it accurate, and you have a framework that catches problems early rather than reconstructing them afterwards.
Here are eight ways to use ITAM and SAM to reduce security risk.
1. Centralise visibility and intelligence
You cannot manage what you cannot see, and plenty of organisations still lack discovery that actively finds changes to the network and tells the central IT team about both the devices they already inventory and the ones they have never seen before.
This is the foundation, and its security value gets lost when SAM vendors limit themselves to licence management, while ITSM tools lack the sophistication to identify software accurately. You want both jobs done by the same system.
CerteroX ITAM uses ten discovery methods — agent, command-line, agentless, standalone, Active Directory, network scan, third-party import, cloud connector, browser monitoring and file metering — and they all land in one schema. Network Discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes port 22 to work out where an agent could be deployed. That is how you find machines before you own them.
The native agent covers Windows, macOS, Linux, AIX, HP-UX and Solaris. Unix platforms are not an integration afterthought, which matters because they are frequently the ones missing from the security team’s picture.
2. Identify vulnerable software fast
Maintaining a defensible security position requires a continuously maintained, detailed inventory of every piece of software deployed. That is what lets you answer “where is this version running?” in seconds rather than days — down to the minor version, the KB and the hotfix.
The Software Recognition Database behind CerteroX SAM holds over 3.5 million titles, with publisher normalisation and version recognition, so a query returns the real answer rather than four spellings of the same product. The Software Recognition Service adds release date, end-of-support date and extended-support date, which is how you find the software that still works, still runs, and stopped receiving security updates two years ago.
From the same console you can scope the exposure, push the update through software distribution or WSUS-integrated patch management, and track remediation to completion. See the risk, see the status, confirm it is closed.
3. Block access to unwanted applications
With visibility of what is deployed, preventing the use of suspect, malicious or simply unwanted applications becomes practical. Even with strict usage policies, portable storage and mobile devices mean software gets installed behind the firewall.
Using discovery and inventory data, you can build approved and denied lists and then actually enforce them. CerteroX SAM has application blacklisting and prohibition rules, Access Control rules covering RDS, Citrix and VDI streamed applications, and a Blocked Files log that records block counts per user and per device — so enforcement is evidenced rather than assumed. Governance Policies handle unauthorised software prevention as compliance-as-code, with a reusable filter builder.
Restriction works per user or per device. Policy is enforced, not published.
4. Examine usage data after a breach
SAM adds a layer most security tooling does not: a record of which people opened which applications, and when.
If an incident does occur, that record is what lets you establish when suspect software was last used and who launched it. AppsMonitor performs file-based usage metering with first-used and last-used tracking, plus a rolling 90-day utilisation metric and per-device remote-usage tracking for Terminal Server and RDS. It is the same data that drives licence harvesting, pointed at a different question.
5. Rationalise and standardise applications
SAM identifies redundant and outdated software so only what is needed stays available. Rationalising and standardising the number of titles in use means IT supports and patches fewer applications, which shrinks the surface directly.
On the subscription side, CerteroX SaaS Management does the same job with App Rationalization — overlap detection ranked by recoverable saving. Four tools doing one job is a licence problem and four sets of credentials, four OAuth grants and four places your data sits.
6. Use patch management properly
Using SAM to drive patch management — or choosing a platform that includes it — improves efficiency and, more importantly, makes the target list complete and current. Patching what you know about is not the same as patching what you have.
CerteroX ITAM includes WSUS-integrated patch management with downstream server support, software distribution for MSI, EXE and Click-to-Run packages, and Windows 11 upgrade orchestration. Because the target list is drawn from the same inventory that found the machines, the scope of a patch campaign matches reality.
7. Check security software is actually running
With a recognition database behind it, SAM can check for the absence of things as well as the presence of them — flagging machines with no anti-virus installed so they can be brought back into line.
This is now handled as policy rather than as a report. Governance Policies in CerteroX ITAM are compliance-as-code with a reusable filter builder, and the shipped examples are exactly this kind of check: Defender running, BitLocker enabled, Azure VM tag hygiene. Definitions export and import as JSON, so a policy written once can be applied across environments and version-controlled like anything else.
This sort of housekeeping sits at the far end of the SAM maturity curve. It is also the sort of thing a managed service can carry — internal teams focus on the big-ticket costs and Tier 1 publisher compliance while a partner handles Tier 2 and 3 vendors and maturity work.
8. Support data protection compliance
GDPR strengthened individuals’ privacy and security rights, and it applies to any organisation that collects, retains or processes the personal data of EU citizens, wherever that organisation is based. Penalties for a breach can reach tens of millions.
So consider a breach in which customer information is taken. The organisation is expected to answer questions it very often cannot: How many devices do we have — PCs, laptops, servers, mobiles? Who has access to them and where are they? What software is installed, which applications are actually used, and by whom? Do all the devices have encryption?
Establishing a clear, complete and accurate account of everything you own is precisely what ITAM and SAM technology does, which is what makes it a data protection capability and not only a cost one.
The part the original list missed: SaaS and AI
This list was written when the software that mattered was the software installed on machines. Most of it now is not.
Someone leaves. Their Microsoft 365 licence is removed on day one. Their Figma, Notion and ChatGPT seats are still active, and the OAuth grant they gave a third-party application still has read access to the company drive. That is a security incident waiting to be discovered by someone else, and it does not appear in any inventory of installed software.
CerteroX SaaS Management closes it. OAuth grant discovery finds consented third-party applications and scores each one from 0 to 100 on data sensitivity, scope, consent and dormancy, with one-click revocation available directly or as a workflow action. Offboarding produces a per-user checklist showing every licence held and the revocation status behind each one — pending, in progress or complete — with the monthly cost of whatever is still open. Every provisioning and deprovisioning step is written to an audit log.
Shadow AI gets the same treatment. AI tools are classified from application feature tags in the catalogue rather than a fixed list, so the detection set grows on its own, and the dashboard ranks adoption risk by the share of the organisation using each tool. Each one can be marked managed, blocked or ignored, and risk is assessed against data sensitivity, GDPR, HIPAA and SOC 2 exposure. Workflows can alert, block or revoke on detection.
The 2017 version of this article would have called that future work. It ships.
Using SAM to prevent security risk
As the scope of IT has widened, ITAM and SAM tools have turned into full-scope intelligence platforms. The benefit worth taking is not the licence saving, welcome as that is — it is that the same data answers the security question.
SAM strengthens the security tools and processes you already run, and materially improves your ability to protect data, software and systems. It will also, reliably, find the systems missing the controls you assumed were everywhere.