← Back to blog

30–90 Day IT Asset Inventory for SMEs: live 'last seen' visibility

October 5, 2026
30–90 Day IT Asset Inventory for SMEs: live 'last seen' visibility

An IT asset inventory is a continuously updated record of every piece of hardware, software and cloud service an organisation runs, tied to who owns it and where it lives. Its main value is visibility: you cannot secure, patch or budget for what you cannot see. The strongest inventories track a "last seen" timestamp for every entry, turning a static list into a live picture of your environment.


TL;DR:

  • Regular reconciliation with procurement and cloud billing data is crucial to uncover untracked assets and manage shadow IT effectively.
  • Continuous discovery methods, including agent-based and passive network logs, are necessary to maintain an accurate, real-time inventory.
  • Assigning clear ownership and lifecycle policies ensures the inventory remains accurate and up-to-date across all asset stages.
  • "Last seen" timestamps and confidence scores are key to verifying asset activity and preventing stale or inaccurate records.
  • Starting small with pilot projects and expanding scope gradually helps establish reliable, ongoing discovery processes while minimizing rework.

Ctasystems
Keep Your IT Assets Visible
CTA Systems provides proactive IT support, monitoring and maintenance to help SMEs manage systems before technical issues disrupt operations.
Visit CTA Systems

Table of Contents

Why an accurate IT asset inventory matters for security and compliance

An inventory is not paperwork. The NCSC treats asset management as a core security function, recommending continuous discovery and change detection as foundational controls rather than a once-a-year exercise. When an incident happens, the first question is always "what do we actually have running?" and a stale spreadsheet rarely answers it.

A well-maintained inventory supports several jobs at once:

  • Incident response teams can isolate affected systems faster when ownership and location are already recorded.
  • Vulnerability management relies on a complete asset list to know what needs patching and what has quietly been missed.
  • Licence optimisation prevents paying for software nobody uses, or worse, running software nobody licensed.
  • Audit evidence becomes straightforward when asset records are current rather than reconstructed under pressure.

Gaps in the inventory create shadow IT: unapproved cloud accounts, forgotten test servers and personal devices that nobody is patching or monitoring, all invisible until something goes wrong.

Scope of an inventory: which asset types and boundaries you must cover

A useful inventory covers more than desks and laptops. Scope should extend wherever data moves or decisions depend on uptime, including:

  • Physical hardware, virtual machines, cloud instances and containers across every environment you run.
  • Installed software, SaaS subscriptions, service accounts, digital certificates and DNS or IP allocations.
  • Operational technology and IoT devices, where they support functions the business depends on.

The boundary question often trips teams up. A test environment spun up for a week still counts if it touches production data. A free SaaS tool one team adopted without approval counts too, and is often the first thing an attacker finds. The Cyber Assessment Framework's principle on asset management asks organisations to keep inventories current for essential functions and to record how assets depend on one another, which is a useful test for deciding what belongs in scope.

Core data fields every asset record must include

An inventory entry only earns its place if it answers a question someone will eventually ask. At minimum, each record needs:

  1. Unique identifiers: hostname, serial number, MAC address, IP address and an internal asset tag.
  2. Ownership and location: the responsible owner, department, physical site or cloud tenancy, plus procurement date and warranty status.
  3. Software detail: installed applications, version numbers, licence terms, current patch level and end-of-life date.
  4. Operational metadata: when the asset was last seen, which discovery tool reported it, and a confidence score reflecting how trustworthy that record is.

That last category is often skipped, yet it is what separates a working inventory from a list that quietly goes stale. A record with no "last seen" date gives you no way to tell whether an asset was decommissioned last month or simply stopped reporting in.

Discovery and data sources: scans, logs, procurement and reconciliation

No single discovery method sees everything, so the practical approach combines a few.

  • Active discovery, through host agents and authenticated scans, gives deep per-device detail but depends on the agent being installed and reachable.
  • Passive discovery, using DHCP and DNS logs, network telemetry and access logs, catches devices that scanning tools miss entirely, including guest laptops and short-lived virtual machines.
  • Reconciliation against procurement records, cloud billing statements and directory services surfaces assets that were bought but never logged, or cloud services quietly expensed on a card.
  • Vulnerability management and monitoring platforms double as validation feeds, flagging devices that appear in scan results but not in the inventory itself.

The NCSC's guidance on asset management describes agented and agentless methods as complementary rather than competing, and notes that reconciling with procurement and billing data is one of the highest-leverage activities available, since it catches both unrecorded purchases and unmanaged SaaS usage.

Pro Tip: Run your first reconciliation against last month's cloud bill rather than your inventory tool, since billing rarely lies about what is actually running.

Keeping the inventory continuous and trustworthy

A list that is accurate on the day it is built and wrong a month later is not much use. Continuous discovery, through agent heartbeats and frequent agentless checks, keeps the picture current rather than relying on periodic audits that are already outdated by the time they finish; for detailed guidance, see how to create your own inventory system using AI.

Three habits keep an inventory trustworthy day to day:

  • Label every record with its source and a confidence score, so a device reported by three systems is trusted more than one seen once.
  • Set alerts for anything new or unmanaged that appears on the network, rather than discovering it during the next scheduled scan.
  • Integrate the inventory with your CMDB, service desk, vulnerability scanner and incident response tooling, so one update propagates everywhere it is needed.

Background tooling built for this purpose often tracks dozens of data points per asset and refreshes them in near real time, which is a meaningful step up from a spreadsheet updated whenever someone remembers. Treating configuration items the way ITIL recommends, as living records tied to services rather than static entries, makes that data genuinely useful for both security and service management. The payoff is record freshness: a device that was accurate six months ago but hasn't reported since is a liability during an incident, not an asset.

Governance and lifecycle: ownership, policies and validation

Technology solves discovery; people solve accuracy. Someone has to own the inventory, and someone has to own each asset within it.

  1. Assign a named asset owner for each device or service, and a configuration manager accountable for the inventory's overall health.
  2. Define what happens at each lifecycle stage: procurement, onboarding, reassignment, decommissioning and disposal, so nothing falls through the cracks between them.
  3. Write a short policy for exceptions, manual entries and privacy-sensitive assets that cannot be scanned the normal way.
  4. Validate regularly through spot checks, reconciliation against procurement data, and, where resources allow, penetration tests that often reveal devices the inventory missed entirely.

Without clear ownership, an inventory degrades the moment the person who built it moves to another project.

Your first 30 to 90 days to a working inventory

Building an inventory from nothing feels large, so break it into stages rather than trying to capture everything at once.

  1. Weeks 1 to 2: Define scope, agree what "complete" looks like, and pick your primary data sources.
  2. Weeks 3 to 6: Run discovery pilots combining agented and agentless methods, then reconcile the results against procurement records and cloud billing.
  3. Weeks 7 to 10: Integrate findings with your CMDB and vulnerability scanner, and set thresholds for how old a "last seen" entry can get before it is flagged.
  4. Weeks 11 to 13: Set up ongoing monitoring, alerts for new devices, an ownership register, and a recurring reconciliation schedule, monthly or quarterly depending on how fast your environment changes.

Pro Tip: Start the pilot in one department or site rather than the whole organisation, since lessons learned on a small scope save far more rework than they cost in time.

Who stands behind this guidance

This guide draws on established security practice, including NCSC asset management principles, rather than a single vendor's product manual. We bring that same thinking into daily managed IT work: proactive monitoring and maintenance designed to catch issues before they affect the business, built on more than 30 years of supporting SMEs with predictable, fixed-cost IT support. That combination of continuous oversight and tailored support structures is what lets organisations focus on their core work while their infrastructure stays accounted for.

Who stands behind this guidance — overview diagram

Why 'last seen' matters more than most checklists admit

Most advice on this topic still treats the inventory as a project with an end date: build the spreadsheet, tick the box, move on. That misses the point entirely. An inventory that isn't continuously refreshed is already lying to you within weeks, and the gap between what it says and what's actually running is exactly where incidents happen.

Timeline showing inventory records becoming stale

If we had to pick one priority for a team starting from scratch, it would not be coverage, it would be freshness. A smaller inventory with reliable "last seen" data and honest confidence scores beats a sprawling one nobody trusts enough to act on during a crisis. Shadow IT rarely gets caught by a bigger spreadsheet; it gets caught by reconciliation against procurement and cloud billing, done often enough that gaps surface in weeks rather than years.

Start narrow, make it continuous, and expand scope once the process is trusted. A perfect inventory built once is worth less than an imperfect one that updates itself every day.

— Will

Let us manage the inventory while you run the business

Building and maintaining an accurate IT asset inventory takes ongoing attention most internal teams cannot spare alongside their day jobs. Our Remote Monitoring & Management service handles continuous discovery and "last seen" tracking directly, while our Care Plans wrap that oversight into fixed monthly support covering cybersecurity, Microsoft 365 management and the lifecycle work an inventory depends on.

Ctasystems

Onboarding typically starts with a discovery pass across your estate, integration with your existing tools, and a handover to ongoing monitoring and reconciliation. If you want that handled for you rather than built from scratch, get in touch about managed IT support and we will scope what your environment needs.

FAQ

What is an IT asset inventory?

An IT asset inventory is a continuously maintained record of every hardware, software and cloud asset an organisation operates, including who owns each one and where it is located. Its purpose is visibility: security, compliance and operations teams all rely on it to know what exists and whether it is being managed.

What information should be included in an IT asset inventory?

Each record should capture unique identifiers such as hostname, serial number and IP address, along with ownership, location, software and licence details, and patch level. Equally important is operational metadata: a "last seen" timestamp and a confidence score showing how reliable that entry currently is.

How do you manage an IT asset inventory effectively?

Effective management combines active discovery, such as agents and authenticated scans, with passive methods like network and log monitoring, then reconciles the results against procurement records and cloud billing. The NCSC recommends treating asset management as a continuous process integrated with procurement, service desk and vulnerability management, not a static register reviewed once a year.

What are examples of IT assets?

IT assets include physical devices like laptops and servers, virtual machines and cloud instances, installed software and SaaS subscriptions, digital certificates, and network resources such as DNS and IP allocations. Operational technology and IoT devices also count where they support functions the business depends on.