
Most security gaps are not spectacular zero-days. They are things nobody in the company remembered existed.
A server a project team spun up two years ago for a test and never switched off. A SaaS tool the marketing team subscribed to on the company card. An account belonging to someone who left last summer and whose access was never disabled.
Each of these is an open window. And you cannot close a window you do not know is there.
Why the inventory comes first
Security has an uncomfortable order of operations. Before you can protect something, you have to know it exists.
That sounds trivial. In practice it is where many security programmes quietly fail. The vulnerability scans run, but only across the systems someone entered. Patch management is clean, but only for the devices the team knows about. The firewall rules are maintained, but the forgotten test server sits in a segment nobody has thought about for months.
The major security frameworks put the inventory at the very start. In the CIS Critical Security Controls, "Inventory and Control of Enterprise Assets" is Control number one, followed by the inventory of software. The reasoning from CIS fits in one sentence: an enterprise cannot defend what it does not know it has.
The numbers behind it are uncomfortably concrete. Roughly a third of the devices on corporate networks run outside the control of IT. And 74 percent of organisations have already had a security incident that traced back to exactly such an unknown or unmanaged asset.
This is not a question of company size. At a firm with 80 employees the blind spot looks different than at a corporation, but it is there. The marketing team with its five SaaS subscriptions, production with its old control machines, the home office with private devices.
The mistake almost everyone starts with
When a company decides to finally build an inventory, it usually goes like this: you treat it as a pure IT task, buy a scanning tool, run it across the network and get a list of 400 IP addresses.
It feels like progress. It is only half of it.
A network scan finds what is attached to the network. It does not find the SaaS subscription that never touches the company router because an employee uses it straight from the browser. It does not find the critical process that depends on an external service provider nobody counts as part of their own IT. It does not find the short-lived cloud instance that is gone again tomorrow. And above all, it does not tell you which of the 400 devices you need to protect first.
In the end you have a long, flat list with no ranking. That beats nothing, but it does not answer the only question that matters in an emergency: which of these must never fail or fall into the wrong hands? You cannot answer that with a scanner. You can only answer it by starting with the business.
The better way: start with your business processes
An inventory only becomes useful once you know what matters. And importance does not come from a device list, it comes from your business processes.
This order is not an ODCUS invention. It is what the recognised frameworks say. The NIST Cybersecurity Framework requires prioritising assets by their importance to the organisation's objectives. MITRE's Crown Jewels Analysis first decomposes the company's mission and derives the critical assets from it, not the other way round. And the Business Impact Analysis in NIST SP 800-34 starts with the business processes and works its way to the systems that carry them.
Translated into a sequence a SME can start from scratch with, that is five steps.
1. List your critical processes
What does your company actually do, day in and day out? Which five to ten processes would hurt the most if they stopped tomorrow? Order intake, production, payroll, invoicing, customer support. For every business this list looks different, and it is shorter than most people think. That is your priority list, and it stands before you have looked at a single device.
If this step feels familiar: it is the foundation of the Crown Jewel Analysis we wrote about separately. The principle is the same. Focus on what really matters instead of treating everything equally.
2. Attach to each process what it depends on
Take each critical process and write down what it relies on: which applications, which data, which systems, which people, which external providers.
This is exactly where the things a scan never sees show up. Invoicing depends on a cloud tool only one person operates. Production depends on a machine controller running a version of Windows nobody wants to touch. Support depends on a mailbox three former employees still had access to. This is the real work, and it happens in conversation with the departments, not in the tool.
3. Give every asset an owner
Every asset on your list needs a person who is responsible for it. Not "IT", but a name.
This is the step that decides whether an inventory lives or dies. Without an owner, every list goes stale because nobody feels responsible for keeping it current. ISO 27001 explicitly requires named ownership in Annex A 5.9. And the best part: this step costs nothing and needs no tool. It only needs a decision.
4. Now you scan
Only at this point does the technology come in. Now you run the technical discovery, or you pull the data from systems you often already have: Microsoft 365 shows you who logged in and when, Intune knows your managed devices, your directory service knows your accounts.
The scan now has a clear job. It fills the gaps in your business-driven list and finds what the departments forgot. It does not replace the list, it completes it. The difference is decisive: you arrive at the scan with a ranking, not with an empty table.
5. Make it continuous, not a one-off
Last year's inventory is fiction. The day you save it, it starts to age, because new devices arrive, old ones disappear, and subscriptions get cancelled or signed.
For Control 1, CIS therefore explicitly requires active, ongoing maintenance, not the one-time snapshot. For a SME that does not mean around the clock, it means a fixed cadence and someone responsible for the list itself. A fixed date each quarter where someone reconciles the discrepancies is often enough.
The most common pitfalls
In projects we keep seeing the same patterns where inventories fail. The most common is the one-time snapshot nobody updates afterwards. Then there is the spreadsheet that drifts across five versions in different departments until none of them is correct. A classic is the missing ownership, where everyone assumes someone else is responsible. Often a discovery tool gets bought first, before it is even clear what counts as an asset and what it is for. And whoever tries to capture everything at once watches accuracy collapse until nobody trusts the list.
The common denominator is always the same: too early on the technology, too late on the business. Whoever starts with the critical processes and a clear owner avoids most of these traps on their own.
The double payoff
An asset inventory is one of the few security measures that pays off twice.
On the security side, everything else suddenly becomes possible. You can patch deliberately because you know which systems exist. You can monitor sensibly because you know what normal looks like. And in an emergency you react fast because you do not first have to find out what is affected. The inventory is the quiet factor behind almost every good incident response.
On the cost side, something happens that surprises many. As soon as you list what you have, you also see what you pay for without using it. Companies use on average only about half of the software licences they pay for. Dead entries, duplicate tools for the same job, premium tiers for occasional users.
So the same process that improves your security lowers your bill. That is not a nice side effect, it is often the argument that gets the project approved internally in the first place. Anyone thinking about the right way to allocate the security budget sensibly starts here.
Why this counts double for Swiss firms
For companies in Switzerland there is a regulatory side on top. The revised Data Protection Act requires, in many cases, a record of processing activities. At its core, that is a data inventory. You cannot fill it in without knowing which personal data you hold, where, and who accesses it.
Smaller firms with low-risk processing are partly exempt from the formal obligation. You do the work behind it anyway, the moment you want to seriously protect anything. And anyone heading towards ISO 27001 or a pragmatic ISMS will not get three steps far without an inventory. It is the foundation everything else builds on.
Start small, but start right
You need no budget, no tool and no consultant to start your asset inventory. You need a blank sheet and the question of which five processes keep your company running.
Write those down. Attach the systems, data and people to them. Give each one an owner. Only then is it worth looking at tools that automate the rest.
An inventory that starts with the technology gives you a long list. An inventory that starts with the business gives you a ranking, and with it a foundation you can build on.
If you are unsure where your crown jewels sit and which dependencies you might be missing, we will look at it together in an initial conversation. The first step is always the same: make visible what is there.
Sources
- CIS Critical Security Controls, Control 1 (Inventory and Control of Enterprise Assets): cisecurity.org
- Trend Micro / Sapio Research, 2025 (74 percent of incidents involving unknown or unmanaged assets): newsroom.trendmicro.com
- Palo Alto Networks, 2025 Device Security Threat Report (roughly a third of devices outside IT control): paloaltonetworks.com
- Zylo 2024 SaaS Management Index (about half of licences unused): zylo.com



