Ask most small businesses for a list of their IT assets and you will get a spreadsheet last updated eighteen months ago, missing the laptops bought since, still listing three that were disposed of, and silent on what software is installed on any of them.
An asset register is unglamorous and it underpins a surprising amount — security, budgeting, insurance, compliance and the ability to answer basic questions during an incident.
What it is for
Four things, and the security one is the least obvious.
You cannot secure what you do not know exists. Every unmanaged device is an unpatched device, and vulnerability management begins with an inventory. When an advisory lands about a specific product version, the first question is whether you run it — without a register, answering that means walking around asking people.
Budgeting improves when you know the age profile of your fleet. Replacement becomes a planned annual cost rather than a series of emergencies.
Insurance and claims require evidence of what you owned. After a fire or a burglary, reconstructing an equipment list from memory produces an under-claim.
And licensing compliance depends on knowing what is installed where. Software audits are unpleasant without records and straightforward with them.
What to record
Keep it lean enough to maintain. For hardware: what it is, make and model, serial number, who has it, where it is, purchase date and cost, warranty expiry, and expected replacement date. For software: product, version, licence count, renewal date, and who owns the relationship.
Two fields matter more than people expect. Warranty expiry, because knowing whether a failed machine is covered saves both money and an argument. And expected replacement date, because it converts your register into a forecast.
Resist adding fields you will not maintain. A register with twelve fields that are accurate beats one with thirty that are not.
Include the things that are not on a desk
Registers routinely miss the assets that cause the most trouble when forgotten. Domain names and their expiry dates. TLS certificates. Cloud subscriptions and who they are billed to. Network equipment in a cupboard. The multifunction printer, which is a networked computer with a hard drive whether or not anyone thinks of it that way. Mobile devices with company access. And any equipment held by staff working from home.
Domains and certificates deserve particular attention because their expiry causes total outages on a known date, and they are the assets least likely to be on anyone’s list.
Automate the collection
Manual registers decay because maintaining them depends on someone remembering during a busy week. Anything that can be discovered automatically should be.
Device management platforms, network discovery and endpoint management tools can populate most hardware and software fields without human effort, and — more importantly — flag things that appear on the network but are not in the register. That exception report is where the value is, because it catches the machine someone connected without telling anyone.
The same infrastructure that performs discovery generally also performs ongoing monitoring of those assets, which is a reasonable argument for treating inventory and monitoring as one capability rather than two separate purchases.
Tie it to your processes
A register stays current only if updating it is part of something that already happens. Purchasing adds the asset. Onboarding assigns it. Offboarding returns it and records the return. Disposal records the date and the certificate reference.
Offboarding is where most registers break. Equipment goes home with a departing employee and nothing records it. A register that is checked during offboarding catches this while there is still a relationship to recover it through.
Audit occasionally
Once a year, physically verify a sample. Not everything — a sample large enough to tell you whether the register is broadly right. If a spot check of twenty items finds three discrepancies, the register needs work. If it finds none, the process is working and you can trust it during an incident, which is precisely when you need to.