Hardening · 10 July 2026 · 4 min read
Asset and data inventory: build it in a day, keep it alive
You can't protect what you don't know you have. How to build your company's inventory of devices, applications and data in one day, with a simple spreadsheet — and keep it current.
ClearSecurity Vision
Almost every serious security conversation hits the same question within the first ten minutes: “how many laptops do you have, and what runs on them?”. If the answer is “roughly”, every other measure stands on sand: you can’t patch what you don’t know exists, you can’t back up data you haven’t located, and you can’t close a former employee’s accounts if you don’t know which applications they had access to.
The good news: for a small company, a useful inventory needs no special software. A spreadsheet built with discipline in one day beats any expensive tool that never gets used.
What you need
- A spreadsheet (Excel, Google Sheets — whatever you already use), kept somewhere accessible to the people responsible for it
- Half a day for devices and applications, another half for data
- Honesty: the inventory is a picture of reality, not of the org chart
Step 1: the devices
Create a “Devices” tab with one row per device that touches company data:
- List the laptops, desktops, servers, work phones, network printers and NAS boxes. Don’t forget the router and the firewall.
- For each one, note: what it is, who uses it, where it lives, what operating system it runs and whether it is encrypted.
- Include personal devices used for work (the home laptop that reads company email) — they are part of reality, even if they’re not on the books.
Step 2: applications and cloud services
A second tab, “Applications” — this is where most surprises hide:
- Start from the payment records: the monthly subscriptions on the card statements surface services nobody remembered.
- For each application: what it’s for, who has an account, who is the administrator, what data it holds and how people sign in (plain password? two-factor?).
- Ask every department “what else do you use besides these?” — accounting, sales and marketing almost always have their own tools IT doesn’t know about.
Step 3: the important data
A third tab, “Data”. Don’t catalogue every file — work in categories:
- List the categories that would hurt if they disappeared or went public: customer data, contracts, employee data (salaries, IDs), offers, production know-how.
- For each category: where it lives (server, cloud, laptops), who has access and who is responsible for it.
- Mark the categories containing personal data — they carry GDPR obligations, and in an incident you must know quickly what was exposed.
Step 4: keep it alive
An inventory from six months ago is an archive, not a tool:
- Name one person responsible for updates — “everyone” means no one.
- Tie updates to events, not goodwill: new hire, departure, equipment purchase, new subscription — each one passes through the inventory.
- Once a quarter, 15 minutes: is what’s written here still true?
Verify the result
- Pick three employees at random and check that their devices and accounts appear correctly in the sheet.
- Ask the test question: “if X’s laptop vanished tomorrow, would the inventory tell me what data and accounts were on it?” If yes, the inventory works.
Common mistakes
- Perfectionism. An 80%-complete inventory today beats the plan for a perfect one that never starts. Gaps fill in along the way.
- Devices only, no data. A list of laptops without “what’s on them” helps accounting, not security.
- The secret inventory. If only one person knows where it is and how to read it, you’ve created a new single point of failure.
- Undocumented admin accounts. For every application, note who the administrator is — in an incident or a departure, that’s the first thing you need.
Under NIS2? The inventory is the silent foundation of every measure in the law — and the first thing any serious assessment asks for.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.