Insights

Could You Identify Every Device and Application Your Business Uses?

Why a simple asset inventory helps small businesses secure devices, manage software, control costs and prepare for Cyber Essentials.

A Plainsight Security consultant helping a customer with an asset inventory while unidentified devices sit around the scene.

Could your business quickly produce an accurate list of:

  • Every laptop, desktop computer and server
  • Every mobile device accessing company information
  • Every application and cloud service
  • Who uses and administers each system
  • Whether each product is supported and updated
  • What business information it contains

For many small businesses, the honest answer is no.

Devices and applications accumulate gradually. Employees purchase equipment, departments start software trials, people use personal devices for work and cloud subscriptions renew long after their original owners have left.

This creates a simple but important security problem: a business cannot reliably secure, update or recover systems it does not know it has.

What is an asset inventory?

An asset inventory is a maintained record of the technology used by a business.

It does not need to involve an expensive asset-management platform. For many smaller organisations, a carefully maintained spreadsheet is enough.

The inventory should cover more than computers. It needs to include the devices, applications and online services that store company information or provide access to business systems.

Which devices should be recorded?

A device inventory could include:

  • Laptops and desktop computers
  • Physical and virtual servers
  • Mobile phones and tablets
  • Firewalls and internet routers
  • Printers and other network equipment
  • Virtual machines
  • Backup devices
  • Employee-owned devices used for work

Personally owned devices are easily overlooked. If an employee uses a personal phone to access company email or a home computer to download business documents, that device forms part of the organisation’s technology environment.

Recording it does not necessarily mean the business owns or manages it, but the organisation should understand what access the device has and what controls apply.

Which applications and services should be recorded?

The inventory should also cover software and cloud services, including:

  • Operating systems
  • Installed business applications
  • Microsoft 365 and other cloud platforms
  • Accounting and payroll software
  • Customer relationship management systems
  • File-sharing services
  • Website hosting accounts
  • Domain name and DNS services
  • Backup platforms
  • Remote-access tools
  • Security products
  • Online payment platforms

Cloud services are particularly easy to overlook because there may be no software installed on a company computer. An employee may create an account using a company email address and begin storing business information without involving the IT provider.

Why does an asset inventory matter?

Patching and unsupported software

Before you can confirm that systems receive security updates, you need to know which operating systems and applications are present.

An accurate inventory can identify products that:

  • No longer receive security patches
  • Are approaching the end of support
  • Have been installed without approval
  • Are no longer used
  • Cannot be updated automatically
  • Need to be replaced

Without this information, an unsupported computer or forgotten application can remain exposed long after the rest of the business has been updated.

Cyber Essentials

Cyber Essentials requires an organisation to understand which devices, software and cloud services are within the scope of its assessment.

An incomplete inventory can result in systems being overlooked during preparation. This may cause problems when answering the assessment questions or leave weaknesses unaddressed because nobody realised that a particular device or service was in use.

Building the inventory early makes it easier to define the scope and identify anything that needs updating, reconfiguring or replacing before certification.

Vulnerability management

A vulnerability scan is only useful if the organisation knows what should have been scanned.

An inventory allows the business to compare its expected assets with its scan results. If a laptop is listed but has not reported to the vulnerability-management platform, the business can investigate. If a scan discovers an unknown device, the organisation can determine what it is and who is responsible for it.

Without this comparison, missing systems may create a false impression of complete coverage.

Incident response

During a cyber incident, responders may urgently need to know:

  • Who owns or uses the affected system
  • What information it contains
  • Which services it can access
  • Whether it has administrative privileges
  • Whether similar systems may also be vulnerable
  • How important it is to business operations
  • What security and backup arrangements apply

Searching for this information during an attack wastes valuable time. A current inventory helps the business understand the potential impact and make quicker containment and recovery decisions.

Employee offboarding

An asset inventory should connect employees to the equipment, applications and accounts they use.

When someone leaves, it can help the business:

  • Recover laptops, phones and other equipment
  • Disable user accounts
  • Revoke active sessions
  • Remove remote access
  • Transfer ownership of files and services
  • Recover or reassign software licences
  • Close accounts that are no longer required

This reduces the risk of former employees retaining access simply because an account or device was forgotten.

Licence and subscription management

Better asset management can also reduce unnecessary expenditure.

A software and service inventory may expose:

  • Licences assigned to former employees
  • Duplicate subscriptions
  • Services that nobody uses
  • Unapproved applications
  • Several products performing the same function
  • Unexpected renewal dates and costs

Improving security visibility can therefore produce direct financial savings.

A simple asset-inventory template

The following fields provide a practical starting point for a small business.

Device inventory

FieldExample
Asset nameLAPTOP-MT-01
Asset typeBusiness laptop
User or ownerMark Tomlinson
Make and modelDell Latitude 5550
Serial numberABC12345
Operating systemWindows 11 Pro
OS version25H2
LocationOffice or remote
OwnershipBusiness owned
Security softwareMicrosoft Defender for Business
Encryption enabledYes
Last checked6 September 2026
Support statusSupported
NotesReplacement planned for 2028

Application and cloud-service inventory

FieldExample
Service or applicationMicrosoft 365
Business purposeEmail and document storage
Business ownerOperations Director
Technical administratorIT provider
UsersAll employees
Authentication methodPassword and MFA
Data heldEmail, documents and contacts
Licence or renewal date1 September 2027
SupplierMicrosoft
Support statusSupported
Backup arrangementsThird-party cloud backup
Offboarding actionDisable account and revoke sessions

The template can be expanded to include information such as data classification, recovery priority, warranty expiry, network address or disposal date where these details would be useful.

How to keep the inventory manageable

The value of an asset inventory depends on its accuracy. A detailed spreadsheet that has not been updated for two years may be less useful than a smaller record that is reviewed regularly.

Small businesses should:

  • Give one person responsibility for maintaining the inventory
  • Update it whenever equipment or services are purchased
  • Include asset checks in employee joining and leaving procedures
  • Review the inventory at least quarterly
  • Compare it with Microsoft 365, security and network-management records
  • Record who approved new applications
  • Remove assets only after disposal or account closure is confirmed

The process should be proportionate. The objective is not to record every technical detail. It is to know what the business uses, who is responsible for it and whether it remains secure and supported.

A useful quarterly check

Every three months, ask:

  • Are all listed assets still in use?
  • Have any new devices or applications appeared?
  • Are any products unsupported or approaching the end of support?
  • Do former employees still have accounts or assigned licences?
  • Are security tools reporting from every expected device?
  • Are there unidentified devices connected to the network?
  • Are unused subscriptions still being paid for?
  • Have any services changed owner or administrator?

Anything that cannot be explained should be investigated and the inventory updated.

If you cannot identify it, you cannot protect it

An asset inventory is not the most glamorous security control, but it supports almost everything else.

It helps a small business update its systems, prepare for Cyber Essentials, manage vulnerabilities, control licences, remove leavers and respond more effectively when something goes wrong.

Most SMEs do not need a complicated asset-management system. They need a clear record, an identified owner and a routine for keeping it current.

If you cannot identify what your business has, you cannot be confident that it is protected.

Preparing for Cyber Essentials often reveals devices, software and cloud services that have been overlooked. Plainsight Security can help you understand your scope, identify gaps and prepare for certification.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights