Remote working moved from an exception to a default faster than anyone planned
for. Most organisations were nowhere near ready for the mass migration of staff
from the office to their living rooms, and then did it anyway, in weeks.
What has proved harder to finish is the part underneath: keeping full visibility
of the hardware and software those people are using, wherever it now sits.
This article looks at the challenges that come with a distributed workforce, and
at what ITAM, SAM, SaaS and cloud management have to do to close them.
The challenges of remote working
Plenty of organisations made the transition to remote and hybrid models without
much drama. The difficulty lands on those that had not prepared their technology
assets for it — where the tooling assumed devices would be on the corporate
network, in an office, most of the time.
Maintaining visibility
The immediate pressure is the volume of new software requests. Remote working
creates real needs, and meeting them puts strain on IT: managing requests,
approving software, installing it on machines nobody can walk over to. The
harder part is understanding what each team actually requires, making sure each
application is properly sanctioned, and keeping it visible and under control.
Put simply: you cannot manage what you own — track and approve licences, oversee
cloud resources, identify and block security risks — if you do not know what you
have or where it is.
During the first lockdowns, organisations bought IT assets quickly to keep
people working. That was the right call. The consequence was that a large share
of those new assets were not visible on the network at all, so nobody could see
how they were being handled. That gap is a security problem before it is an
administrative one: if you cannot tell whether a machine is patched or running
anti-malware, you are missing a link in the chain, and the whole business is
exposed through it.
Closing it is a discovery problem, and discovery is the thing most affected by
people not being in the building. CerteroX ITAM uses ten methods that all land
in one schema: a native inventory agent for Windows, macOS, Linux, IBM AIX,
HP-UX and Oracle Solaris; agentless and command-line collection (csinvcli) for
locked-down machines; standalone inventory for air-gapped and offline systems;
Active Directory import; network scanning; third-party ITAM import; cloud and
SaaS connectors; browser monitoring; and file metering. An agent-based record
follows the device rather than the subnet, which is the difference between an
inventory that survives a year of home working and one that quietly decays.
For the machines you do not know about yet, Network Discovery sweeps a class-C
subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes port 22
to establish where an agent can actually be deployed. You find the devices
before you own the problem.
Because the data is collected and reconciled automatically into one record, IT
teams do not fall back on spreadsheets and manual tracking — which is what
happens, reliably, the moment the tool stops reaching half the fleet.
Dealing with security
Security risk is a function of visibility: if you cannot see it, you do not know
what it is doing.
Remote working has only sharpened this. Every device that joins the network is a
potential vulnerability, and this goes well beyond laptops. As remote setups
become permanent, smartphones, tablets and a long list of internet-enabled
devices attach themselves to corporate systems, and IT needs to see all of them
to understand what has been introduced. Mobile is part of the same record here:
CerteroX ITAM manages iOS and Android devices directly, including Apple DEP
enrolment, rather than treating them as a separate inventory to reconcile later.
Large-scale incidents — the 2017 ransomware attack that took NHS systems offline
across the UK is the obvious example — make the same point each time: partial
visibility behaves like no visibility. If you cannot see every device on the
network, an attacker only needs the ones you cannot.
The useful capability here is not a longer device list. It is a policy that
fires when a device drifts. CerteroX ITAM’s Governance Policies express
compliance as code, using a reusable filter builder, with examples that map
directly to this problem: BitLocker enabled, Defender running, tag hygiene on
cloud VMs. Policy definitions export and import as JSON, so the rules are
reviewable and portable rather than locked in one administrator’s head. File
metering and usage monitoring fill in the detail underneath — what is actually
installed and actually being run on a machine, not what the build image said
should be there.
Licensing and auditing
A fluctuating workforce makes over-licensing routine. Starter and leaver
processes go lax under pressure, and organisations end up paying for licences
nobody is using. The waste is easiest to size on the SaaS side: 46% of SaaS
licences go unused, and the average organisation uses 54% of what it buys.
The subtler issue is entitlement during the move from office to home. Do all
your licences carry the same user rights? Are entitlements transferable? In some
cases, licences bought for use in an office cannot lawfully be used remotely,
which leaves the organisation open to scrutiny and to cost. It is worth checking
entitlements before making changes rather than after — and that is only possible
if you can see what you have.
One scenario deserves particular attention: applications installed at server
level, where access rather than use creates the liability. Everyone who can
reach the server could theoretically reach the application. Under device-based
licensing this produces a genuinely expensive trap. If one person needs
Microsoft Project on a Citrix farm that a thousand users can reach, all thousand
need licensing to stay compliant — whether they ever open it or not. Publishers
find this pattern reliably at audit.
The control for it is access control, and it needs to produce evidence, not just
intent. CerteroX SAM applies Access Control rules to RDS, Citrix and VDI
streamed-application licensing, restricting usage per user and per device, with
a Blocked Files log recording per-user and per-device block counts. That log is
the point: it demonstrates the restriction was in force, which is what an
auditor is actually asking for. Alongside it, the Exclude From Licensing
workflow handles MSDN, development, training and second-use devices properly
instead of leaving them in the count.
Audits did not stop. Whether or not their number rises, the letter still
arrives, and the difference is whether you are computing your position
continuously or reconstructing it under a deadline. CerteroX SAM maintains a
continuous effective licence position — purchased, used, available, required,
variance and exposure — with downgrade rights, second-use entitlement and
per-core, per-processor and per-device assignment handled in the engine rather
than in a spreadsheet appended to it.
Containing the cloud
Cloud IaaS, PaaS and SaaS made the shift to remote working possible: the
applications stay put even when the people and the devices do not. But a cloud
environment that cannot be non-compliant can still be badly wrong. One of the
larger problems created by the rush to remote working was hasty cloud adoption,
and the waste that came with it. Across the market, 29% of cloud spend is
wasted, and that share rose for the first time in five years.
Four failure modes account for most of it.
Shadow IT. Cloud systems bought without the IT department’s approval, or
deployed by other departments on their own initiative. The cost is unregulated
because nobody is looking at it. CerteroX SaaS Management addresses this
directly — identity provider sync, 47 vendor connectors and a browser extension
converging on one list of what is genuinely in use, resolved against a catalogue
of more than 35,000 applications.
Bill shock. Costs change unexpectedly, usually because people signed up for
capacity without planning for it. The counter is not a monthly report but a
policy that fires first: CerteroX Cloud Management runs expense anomaly
detection against a rolling daily average, expiring and recurring budget
policies, and total and daily expense limits per resource or pool.
Toxic consumption. Resources bought and then left unmanaged. Someone spins
up a workload in AWS to test a database version and never powers it down. This
is the largest single category of avoidable cloud cost, and it is why the
optimisation engine names its checks instead of reporting a total: abandoned
instances, images, load balancers, S3 buckets and Kinesis streams; obsolete
images, IPs, snapshots and snapshot chains; instances stopped but not
deallocated; volumes long unattached. Twenty-six named checks in all, each with
its own thresholds, pool exclusions and account skips. Resource TTL then
enforces a lifecycle automatically, so the same resource does not come back next
month.
Cloud sprawl. The uncontrolled spread of instances, services and providers —
a developer launching a workload in one account when the capacity already exists
in another, or when an existing agreement would have priced it better. Cost
pools typed as budget, business unit, team, project, CI/CD or asset, with
assignment rules that allocate ownership automatically across nine condition
types, are what stop the sprawl becoming anonymous. Virtual tagging computes
allocation independently of cloud-native tags, so an untagged resource is not an
unowned one.
CerteroX Cloud Management covers twelve cloud and data platforms and ingests the
FinOps Open Cost and Usage Specification natively, so the cost model stays
portable rather than locked in a vendor schema. Across cloud environments under
management, the average saving is 38%.
We have set out the core problems of remote working through an ITAM, SAM, SaaS
and cloud lens. The resolution has less to do with any single feature than with
where the data lives.
First, the tooling has to work when the people running it are not in the office
either. Deploying, configuring and reporting all have to be possible remotely,
and delegation has to be safe: CerteroX uses role-based access control with
granular permissions, Reporting Levels that restrict visibility by
organisational unit or location, and a read-only API with a documented Power BI
data source, so routine reporting can continue without anyone logging in.
Second, and more consequentially, all five disciplines read from one asset
model. Discovery, licence reconciliation, SaaS management, cloud cost and AI
governance are not five products stitched together by integrations; they are one
data source with five interfaces onto it. That is what makes a question like
“which of the devices we shipped to home workers are unpatched, over-licensed
and duplicated by a SaaS subscription somebody expensed” answerable at all.
The practical effect is that reporting stops being an assembly job. The data is
already reconciled, so the report takes minutes rather than a fortnight of
exports.
What does this mean for the future?
Remote and flexible working is now simply how a large share of the workforce
operates. That makes ITAM, SAM, SaaS and cloud management more important, not
less, as organisations try to hold service levels while operating more
efficiently.
It also means complete visibility is the baseline rather than the goal. IT
leaders need enough insight to be confident that staff have the tools to do
their jobs, and that those tools are not creating unnecessary cost or
unnecessary risk on the way.