The Uncomfortable Truth
Most incidents that spiral out of control share a root cause that has nothing to do with attacker sophistication, the team didn't have a reliable picture of what was on the network. An unknown switch, a forgotten server still running an end-of-life OS, an IP address no one can account for: each is a blind spot, and blind spots are where risk accumulates quietly.
Why Leadership Should Care
A current inventory is the foundation every other control depends on. Vulnerability management, patching, incident response, segmentation, even budgeting for refresh cycles, all of them assume you know what you have. When the asset list is a stale spreadsheet or living in one engineer's head, those controls degrade without anyone noticing until an audit or an outage exposes the gap.
What Good Looks Like
A good inventory is not a one-time stocktake; it is a maintained record with a clear owner, consistent naming, and enough context to act on. For each device you want to answer three questions instantly: what is it and where, who owns it, and is it still supported. A few practical habits make the difference:
Adopt one naming convention (site-role-number) and enforce it, since inconsistent names are the first sign an inventory is decaying.
Record lifecycle data (OS/firmware version and end-of-life or warranty date) so you can plan refreshes before they become emergencies.
Assign an owner to every asset, since unowned devices are the ones that get missed at patch time.
Review quarterly against a discovery scan to catch drift between the record and reality.
The attached template, 01: Network Device & IP Address Inventory, gives you a tab per site or a single filterable register with drop-downs for device type and status, plus lifecycle columns and a worked example row. Start from the example, replace it with your estate, and keep it current: it will repay the effort every time something breaks.
