Too many organisations implement software asset management defensively — as
insurance against a nasty surprise when a publisher audit lands. That is sound
business sense as far as it goes, but it should not be the only reason to do it.
The cost savings on their own make a compelling case.
Reducing overspend on software and hardware
The most obvious saving is straightforward overspend, on software and on
hardware both. The hardware part surprises people. It should not: the discipline
of a strong SAM programme surfaces where hardware has been over-deployed and
where consolidation — servers most obviously — will take cost out.
The inventory that supports this has to reach further than the word “software”
implies. In CerteroX ITAM that means:
- network structure, including switch port and routing tables via SNMP
- printers, with consumables and page counts
- devices — desktop, laptop, mobile, virtual and non-persistent VDI
- servers, across Windows, macOS, Linux, AIX, HP-UX and Solaris
Ten discovery methods feed one schema — native agent, command-line inventory for
locked-down machines, agentless, standalone for air-gapped systems, Active
Directory, network scan, third-party import, cloud connectors, browser monitoring
and file metering — so there is no reconciliation exercise between tools that
each know part of the answer.
On the software side, monitoring usage tells you where software is installed and
not being used, so the licence can be re-harvested and reissued elsewhere. This
is what stops the organisation buying what employees think they need rather than
what they demonstrably use. Usage metering in CerteroX SAM is file-based with
first-used and last-used tracking and a percentage-used figure over a rolling
ninety-day window, which is long enough to catch monthly and quarterly patterns
without treating a fortnight’s holiday as abandonment.
Capturing usage is only half of it. The licence position also depends on where
and how the software runs:
- virtualisation, with the host-to-guest relationship intact
- thin client, Terminal Server, RDS and Citrix streamed applications
- processors and cores, with the correct core factor applied
- clusters, where the licensable footprint is rarely one machine
Get any of those wrong and the compliance position is wrong regardless of how
good the usage data is.
Rationalising infrastructure and support
The next saving is in support.
Knowing exactly what hardware and software you have — typically down to version
and patch level for software, and processor and memory detail for hardware —
makes support easier day to day. More importantly, it makes longer-term
rationalisation decisions possible at all. You cannot standardise on three
builds if you do not know you are running eleven.
Better information also produces better purchasing. A more consistent
architecture reduces support cost, and it improves security across everything you
run, because a smaller and better-understood set of versions is a smaller set of
things to patch.
That security benefit deserves to be stated plainly rather than left as a
by-product. The Software Recognition Service in CerteroX SAM carries release
date, end-of-support and extended-support dates alongside each recognised title,
so end-of-life exposure is a standing report. When the next critical
vulnerability is announced, the question is where that version is installed and
how many instances — and the honest test of any tool is whether you can answer
that before the end of the day.
Building the expertise
There is a hidden cost in managing software licences, and it is people.
You need internal expertise to do it properly. That is true whether or not you
have a formal SAM programme, because you have to manage software licences as you
would any other asset regardless. So it makes sense to build that expertise
inside a programme, where processes are defined and the knowledge is developed
deliberately from the start, rather than accumulating it ad hoc through a
succession of audits.
Negotiating with publishers
The final saving is in the conversation with the vendor.
A complete and accurate view of what you have installed puts you in a materially
stronger position in any negotiation, including one that follows an audit
finding. It prevents significant overspend, particularly where a publisher uses
a licence shortfall as pressure to move you onto a new agreement that makes the
problem go away on terms that suit them rather than you.
Walking in with your own numbers changes what is being discussed. Without them,
you are negotiating about their figure.
A centralised view also lets you consolidate purchasing. Once all software and
hardware is visible in one place, volume and support options can be negotiated
across the whole organisation instead of department by department, which is
usually where the duplicated agreements were hiding.
The two cost centres that did not exist in 2016
The article above was written when the software bill meant licences and the
hardware bill meant machines. Both are still there. Two more have been added,
and in most organisations they now grow faster than either.
SaaS. Subscriptions are bought outside procurement, renew automatically, and
are invisible to a discovery agent because there is nothing installed. CerteroX
SaaS Management converges three signals to find them — identity provider sync
from Entra ID and Okta, vendor API connectors across 47 shipping integrations,
and a browser extension — against a catalogue of more than 35,000 applications.
Unused licences are flagged at thirty days of zero usage, overlapping
applications are ranked by recoverable saving, and offboarding is tracked per
licence so a leaver’s seats are actually released rather than assumed released.
Cloud. “The bill went up” is not a finding. CerteroX Cloud Management runs
twenty-six named, individually tunable recommendation checks across twelve cloud
and data platforms — abandoned instances and load balancers, obsolete snapshot
chains, instances stopped but never deallocated, rightsizing, reserved instance
and savings plan opportunities — with per-check thresholds and pool exclusions so
the engine fits your environment rather than nagging about it. Certero’s average
cloud cost saving across environments under management is 38%.
The same argument applies to both as applied to licences in 2016: you cannot
re-harvest what you cannot see.
The return
Added together, these contributions typically outweigh the cost of running the
programme, which is what makes the return on investment argument straightforward
to put to a finance director. Reduced overspend, cheaper support, better
purchasing, a stronger negotiating position, and — increasingly — subscription
and cloud waste that would otherwise compound quietly every month.
If you want to talk through what that would look like against your own numbers,
get in touch.