For public sector IT, it is that annual point in the cycle when budgets are allocated and investment plans are finalised for the year ahead. Squeezing every bit of value out of a fixed allocation is not an accounting exercise — it decides which systems get replaced, which risks get closed and which do not. Driving costs down while improving security, governance and day-to-day operations is the whole job.
So how do you meet investment objectives and reduce cost at the same time? Shrewd planning, plus additional funds pulled from three places you already control.
1. Reallocating IT costs
Private sector organisations routinely reallocate IT costs across business units, operational functions and departments, so that each area carries the financial share of the IT resources it consumes. The effect is to release budget back to IT, where it can fund the priorities that are otherwise unaffordable. The same approach works in the public sector, and it works particularly well where an IT function serves multiple trusts, boroughs, forces or arm’s-length bodies.
Full visibility of the hardware, software, SaaS and cloud resources you run is what makes it possible. You cannot manage what you cannot see, and you cannot recharge what you cannot attribute. If you do not know what you own, where it is used and by whom, reallocation stays a proposal rather than a line in someone else’s budget.
This is no longer the hard part. CerteroX ITAM discovers and inventories every device across Windows, macOS, Linux, AIX, HP-UX and Solaris alongside virtual, mobile and cloud, using ten discovery methods that all land in one schema. Costing rules and cost tabs sit on the asset record itself, and dynamic, static and custom groups let you carve the population by organisational unit, location or any query you can express.
On the cloud side, CerteroX Cloud Management does the same job in FinOps terms. Cost pools are typed as budget, business unit, team, project, CI/CD or asset. Assignment rules with nine condition types keep ownership current without anyone maintaining a spreadsheet. Virtual tagging works independently of cloud-native tags, so a missing tag does not become an unallocatable cost. Showback and chargeback then run off pools, with forecast-aware overspend states so a department finds out it is heading over budget before the invoice arrives, not after.
That is the difference between a recharge model you argue about and one you can publish.
2. Prioritising investments and getting more from the assets you have
Once you are funding investment rather than absorbing cost, the decisions get harder: which initiatives come first, and which assets do you ask to last another year?
The most common pain point is the age and condition of the hardware. Assets that are five years old or more need replacing, and some of them are already an active security exposure. There is no squeezing another five years out of a device that no longer receives firmware updates, and protecting networks and mission-critical operations is not optional.
Making those calls well needs a comprehensive picture of what you actually have. Hardware warranty retrieval and expiry tracking tells you what is out of cover. Software end-of-life and end-of-support dates come from the Software Recognition Service, so “unsupported” is a date on a record rather than an opinion. Governance Policies express the security baseline as compliance-as-code — BitLocker enabled, Defender running, Azure VM tag hygiene — and report continuously against it.
That evidence does two things. It tells you which assets can safely be asked to last another year, and it makes the case for the ones that cannot. Demonstrating that level of control over what you own and what it costs is, in practice, the strongest argument for additional funding you can make.
3. Software and subscription licence costs
Assume you have reallocated costs, identified where you can stretch the asset base, prioritised for the year ahead and secured some additional budget. Where else is there capital?
Licensing, for most organisations. But it can go either way.
If you are over-licensed
Optimising software, SaaS and cloud raises funds for other investments. These are rarely available immediately — much of it can only be realised at an annual renewal — but reducing licence expenditure frees money at points across the financial year, which is often exactly when a plan needs topping up.
The SaaS side tends to be the fastest. CerteroX SaaS Management flags unused licences at thirty days of zero usage, ranks application overlap by recoverable saving, and shows upcoming renewals with days-to-renewal beside utilisation rate — so you renegotiate a seat count you can defend. The scale of the opportunity is 46% of SaaS licences going unused, across an average enterprise portfolio that now runs to 305 applications.
Cloud is the other reliable source. Twenty-six named, individually tunable checks in CerteroX Cloud Management look for abandoned instances, obsolete snapshot chains, volumes long unattached, instances stopped but never deallocated, and reserved instance and savings plan opportunities. Certero’s average saving across cloud environments under management is 38%. Wasted cloud spend runs at 29%, up for the first time in five years — which is to say the money is there whether or not anyone is looking for it.
If you are under-licensed
You are almost certainly non-compliant with your contractual terms, and that means back-charges and back-maintenance rather than a saving. Instead of raising funds for your priorities, you spend them settling a bill you did not plan for. That does not merely delay an investment programme; it can end it for the year.
The position you actually want
To know which of the two you are in, you need one platform covering every environment, server and device across your key publishers, with automation doing the reconciliation rather than people. CerteroX SAM computes an Effective Licence Position continuously — purchased, used, available, required, variance and exposure — with dedicated engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce, and the overspend and additional-licence-required calculations side by side. Over-licensing and under-licensing are the same report, not two projects.
Plenty of organisations attempt this with spreadsheets or a fragmented set of tools that do not talk to each other. Those organisations tend to be surprised by their own numbers, and the surprises are expensive.
Where expert support helps
Public sector organisations already run this way with Certero.
NHS South West London ICB used Certero’s SAM managed service to mitigate around £100k of Microsoft compliance risk. Their ITAM Asset/PSL Manager, Reece Emson, put it this way:
Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.
East of England Ambulance Service brought 130 sites into view. Andy Marrs, IM&T Security & Resilience Manager:
The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.
And an NHS Commissioning Support Unit runs the platform on behalf of more than 100 NHS organisations.
If you want the same before the new financial year starts, the practical route is a mix of platform and professional services to:
- automate ITAM and SAM processes rather than staff them
- produce the attribution data that makes cost reallocation defensible
- support prioritisation decisions with warranty, support-lifecycle and security-policy evidence
- establish an Effective Licence Position across every major publisher
- optimise licence, SaaS and cloud cost
- reduce exposure before a publisher finds it for you
The same data improves governance, cyber security posture and transformation planning, and gives your wider stakeholders something better than an educated guess.
If you want to talk it through, get in touch or book a demo.