Ask a business owner how many servers, laptops and network devices the company runs, and the answer is usually a guess. “Twenty or so?” Ask which of those still receive updates, and the room goes quiet. That’s not a criticism. People who run a business don’t count switches. For your security, though, that blind spot is a real problem, because a device nobody knows about is a device nobody protects.
Which is why practically every security standard starts in the same place. CyFun puts asset management at the front of its Identify function. NIS2 supplier questionnaires from large clients open with it almost without exception. And every incident analysis I’ve seen in fifteen years of enterprise environments sooner or later contained the sentence: “that system wasn’t documented anywhere.”
Why the spreadsheet always loses
The classic approach is an Excel file. Someone walks around for an afternoon, writes everything down, and the result gets saved as “inventory_final_v3.xlsx”. Six months later a NAS has been added, two laptops were replaced, and a supplier has spun up a virtual machine “just temporarily”. The spreadsheet knows nothing about any of it.
The problem isn’t the effort of filling it in. The problem is that a static list starts aging the day you save it, and nobody notices. You think you have an inventory. What you have is a photo of the past.
What a living inventory does differently
A monitoring platform like CheckMK approaches it from the other side: it discovers what’s present on the network and keeps tracking it continuously. A new system appears in the overview. A disappearing one shows up too, and that second signal is often the more interesting one: a server that’s “gone” is sometimes simply switched off, and sometimes the start of an incident.
For each system you also immediately know what it is and what it does: which operating system, which services it runs, which certificates it holds and when those expire. The inventory stops being a separate document someone has to maintain. It becomes a by-product of the monitoring you wanted anyway.
What that’s worth during an audit or questionnaire
Anyone working through the CyFun Basic checklist hits the inventory question first. With a living inventory, the answer is an export from today rather than a spreadsheet from last year. The same goes for the supplier questionnaires that NIS2 clients send with increasing frequency: “provide an overview of your systems” turns into a ten-minute job.
There’s a second win that rarely appears on the questionnaire: patching only becomes manageable once you know what needs patching. An outdated machine that’s off the radar stays outdated forever.
Getting started, concretely
You don’t need a big project for this. Setting up a monitoring environment that scans your network and builds the inventory is a matter of days for an SME, not months. The real value comes in the tuning afterwards: deciding what’s critical, what deserves monitoring, and who gets alerted when something deviates.
That tuning is exactly what I do for SMEs through Althona, including the reports you can forward straight to an auditor or client. Curious what your environment looks like once it’s properly mapped? Book a no-obligation call. You’ll have that first inventory sooner than you think.