ClearSecurity VISION
EN / RO
← All articles

Hardening · 10 July 2026 · 4 min read

Asset and data inventory: build it in a day, keep it alive

You can't protect what you don't know you have. How to build your company's inventory of devices, applications and data in one day, with a simple spreadsheet — and keep it current.

ClearSecurity Vision

Almost every serious security conversation hits the same question within the first ten minutes: “how many laptops do you have, and what runs on them?”. If the answer is “roughly”, every other measure stands on sand: you can’t patch what you don’t know exists, you can’t back up data you haven’t located, and you can’t close a former employee’s accounts if you don’t know which applications they had access to.

The good news: for a small company, a useful inventory needs no special software. A spreadsheet built with discipline in one day beats any expensive tool that never gets used.

What you need

  • A spreadsheet (Excel, Google Sheets — whatever you already use), kept somewhere accessible to the people responsible for it
  • Half a day for devices and applications, another half for data
  • Honesty: the inventory is a picture of reality, not of the org chart

Step 1: the devices

Create a “Devices” tab with one row per device that touches company data:

  1. List the laptops, desktops, servers, work phones, network printers and NAS boxes. Don’t forget the router and the firewall.
  2. For each one, note: what it is, who uses it, where it lives, what operating system it runs and whether it is encrypted.
  3. Include personal devices used for work (the home laptop that reads company email) — they are part of reality, even if they’re not on the books.

Step 2: applications and cloud services

A second tab, “Applications” — this is where most surprises hide:

  1. Start from the payment records: the monthly subscriptions on the card statements surface services nobody remembered.
  2. For each application: what it’s for, who has an account, who is the administrator, what data it holds and how people sign in (plain password? two-factor?).
  3. Ask every department “what else do you use besides these?” — accounting, sales and marketing almost always have their own tools IT doesn’t know about.

Step 3: the important data

A third tab, “Data”. Don’t catalogue every file — work in categories:

  1. List the categories that would hurt if they disappeared or went public: customer data, contracts, employee data (salaries, IDs), offers, production know-how.
  2. For each category: where it lives (server, cloud, laptops), who has access and who is responsible for it.
  3. Mark the categories containing personal data — they carry GDPR obligations, and in an incident you must know quickly what was exposed.

Step 4: keep it alive

An inventory from six months ago is an archive, not a tool:

  1. Name one person responsible for updates — “everyone” means no one.
  2. Tie updates to events, not goodwill: new hire, departure, equipment purchase, new subscription — each one passes through the inventory.
  3. Once a quarter, 15 minutes: is what’s written here still true?

Verify the result

  • Pick three employees at random and check that their devices and accounts appear correctly in the sheet.
  • Ask the test question: “if X’s laptop vanished tomorrow, would the inventory tell me what data and accounts were on it?” If yes, the inventory works.

Common mistakes

  • Perfectionism. An 80%-complete inventory today beats the plan for a perfect one that never starts. Gaps fill in along the way.
  • Devices only, no data. A list of laptops without “what’s on them” helps accounting, not security.
  • The secret inventory. If only one person knows where it is and how to read it, you’ve created a new single point of failure.
  • Undocumented admin accounts. For every application, note who the administrator is — in an incident or a departure, that’s the first thing you need.

Under NIS2? The inventory is the silent foundation of every measure in the law — and the first thing any serious assessment asks for.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.