You can't protect what you never counted

Every security conversation eventually lands on the same question: “what do we even have?” The breach post-mortem, the insurance questionnaire, the offboarding of the employee who left eight months ago — all of them need a list of devices, accounts, and services that actually exists, not the list someone wrote in a spreadsheet in 2023 and never opened again. An asset inventory is not an enterprise compliance artifact; it is the smallest possible map of what matters, and the annual security review is only as good as it is.

1. Keep the register small enough to survive contact with reality

2. The discovery pass: find what nobody wrote down

3. Assign a lifecycle state to every row — and make onboarding write the first one

4. Tag the data, not just the device

5. Keep it alive with one calendar and one honest audit

6. The 10-minute version for teams with no time

Related: new admin first week runbook