If one person buys every device and hands it out, a shared table that person updates the day equipment changes hands is enough. If equipment moves between people, locations or roles, an automated inventory tool that reports what it finds will hold up better. If nobody on staff owns IT, have your managed provider keep the IT asset inventory as part of the service. The method matters less than this: the record has to change the moment the equipment does.

A stale list costs you at the worst moment. A laptop goes missing and nobody can say what it could open. Somebody leaves and their phone doesn’t come back. A warranty claim stalls because the serial number is buried in an old email. Equipment nobody has written down is equipment nobody is checking, and the replacement gets bought in a hurry.

Three ways to keep the record current

The first is a shared spreadsheet or table that one named person keeps. Every purchase, handover and return gets typed in by that person.

The second is an automated inventory tool that collects details from the devices it’s installed on or can reach on your network. It refreshes its own list, so the machines that report in stay accurate without anyone typing.

The third is an inventory kept by a managed IT provider as part of its service. That’s how our IT asset management service works: we establish a clear record of every IT asset, from hardware to software.

None of this is exotic advice. NIST’s small business quick-start guide for its Cybersecurity Framework puts it plainly: “Understand what assets your business relies upon by creating and maintaining an inventory of hardware, software, systems, and services.” The same page describes the same progression, starting with a table you keep yourself and moving to an automated asset inventory solution or a managed security service provider as the business matures.

What you’re comparingShared spreadsheetAutomated toolManaged provider
Who updates it, and when?A named person types in each change.The tool reports what it can reach on its own schedule.The provider maintains it for the equipment it manages.
What can it miss?Anything nobody writes down.Spare gear that’s switched off, personal phones and equipment it can’t reach.Devices bought outside what the provider covers.
What if the keeper leaves or gets busy?The file ages quietly until someone needs it.Connected devices keep reporting, but the notes go stale.The record continues under the service.
What does it ask of your team?An empty file to start, then steady discipline.Setup, plus someone who reads what it reports.Report what you buy and check the record.

Who updates the record decides how stale it gets

The automated tool wins this one, but only for the devices it can reach. It doesn’t rely on anyone remembering, so a laptop that’s switched on and connected stays accurate whether or not the office is busy.

A spreadsheet is accurate on the day someone types in the change, and it drifts every day nobody does. A provider’s record stays current for the equipment under its care, and you still have to say when something new arrives. None of the three updates itself for a device that never gets plugged in.

Every method has a blind spot

The spreadsheet wins here, which isn’t the obvious answer. It’s the only one of the three that can hold something with no technical footprint at all, because a person decides what belongs on the list.

Think about what an automated tool can’t see. The spare laptop in a drawer, switched off since the last person left. The phone somebody uses for work email that the business never bought. The switch in the closet and the access point above the ceiling tiles. A cloud account that isn’t a device anywhere.

A tool reports on what it’s installed on or can reach. A provider’s record covers what the provider manages. Both gaps close the same way: somebody notices the thing and writes it down. Paid software seats have their own version of this problem, and we covered software licenses nobody uses separately.

The record has to outlast the person who keeps it

The tool and the provider both win this criterion, because neither depends on one person’s habit. A spreadsheet is only as reliable as the attention of whoever owns it, and attention is the first thing to go in a busy month.

If you keep the spreadsheet, two things protect it. Name a second person who can update it. Keep the file in a shared business account rather than someone’s personal drive, so that when the person who kept it leaves, the record stays behind with the laptop.

What each option asks of your team

The managed provider asks the least ongoing work of your team, and the spreadsheet asks the least to get started. Those are different questions, and the second one is why a spreadsheet is a reasonable place to begin.

A spreadsheet starts with an empty file and a small amount of discipline forever. A tool needs setting up, and it needs somebody who reads what it reports, because a report nobody opens changes nothing. A provider’s inventory asks you to report what you buy and to compare the record against reality now and then.

What every entry should record

A record that only lists device names won’t answer the questions you’ll be asked. NIST’s sample table is a good starting shape. For each asset, record:

  • What it is: the piece of hardware, the software, the system or the service.
  • What the business officially uses it for.
  • Who administers or owns it.
  • The sensitive data it can reach.
  • Whether getting into it requires a second step beyond a password.
  • The risk to the business if you lose access to it.

Then add the practical identifiers. That part isn’t in the NIST table, but it’s our recommendation, because it turns a record into something you can act on: who the device is assigned to, where it sits, the serial number, the purchase date and the warranty end date. Without the serial number and the dates, a warranty claim turns into an archaeology project.

The sensitive-data line earns its keep when something disappears. It tells you straight away whether the missing laptop held customer files or nothing much at all, and our guide to what to do before a company laptop goes missing covers the protection side.

Update it when equipment changes hands

A calendar reminder alone won’t keep a record current. Events will. Update the entry when something is bought, when it’s assigned or reassigned to a person, when it’s repaired or replaced, when it’s retired, and when an employee leaves and hands equipment back.

Because O&O’s IT asset management service follows each asset from acquisition to disposal, our recommendation is to update the record whenever equipment changes hands: when it’s bought, assigned, repaired or retired.

CISA’s Cybersecurity Performance Goals ask organizations to maintain a regularly updated inventory of all organizational assets, and to update the ones critical to business or operational functions more frequently. CISA’s own rating for that goal is low cost and high impact. Unaccounted equipment is the part you can’t protect, because nobody knows to look at it.

Retirement is the last line in an asset’s record, and retiring old computers without leaking data covers what should happen to the drive before the machine goes.

Match the method to who handles your equipment

The right answer depends less on the shape of your business than on who touches the devices.

Choose the spreadsheet if one person buys and hands out every device

When purchasing and handover already run through one desk, that person is the inventory. Give them a shared file and a standing rule: nothing lands on a desk without a line in the table. Name a second person who can update it, and compare the file against the real equipment now and then.

Choose an automated tool if equipment moves between people or locations

When laptops change hands and move between sites without a single gatekeeper, a person typing entries will fall behind. A tool that collects details from the devices it can reach carries the routine part of that work. Keep a short manual list beside it for what the tool can’t see, starting with spare equipment that’s switched off.

Choose a managed provider if nobody on staff owns IT

When no one in the business has IT in their job description, and an outside provider already manages the devices, the record belongs with the people who touch the equipment. Ask what the record contains, how you get a copy, and what happens to equipment bought outside their scope. Then hold them to the answers.

Where the managed option loses

Handing the record to a provider moves the work, and it moves the dependency too. You’re relying on somebody else’s system for an answer you may need under pressure. Before you commit, confirm two things. You can see the full inventory whenever you ask and export a copy the business keeps. And you know exactly what’s in scope, because a provider’s record covers the equipment that provider manages, so the tablet somebody bought on a company card still has to be reported before it appears anywhere.

Frequently Asked Questions About an IT Asset Inventory

What counts as an IT asset?

Anything the business relies on to work. That means the laptops and phones, the network equipment in the closet, the systems people log into and the cloud services where your work lives. Software counts. So do the accounts that give people access, even though there’s no device to point at.

Where should the inventory live?

Somewhere the business owns and more than one person can open. A file in a personal drive disappears with the person. Whichever method you choose, make sure you can export a copy and read it without a specialist, because you’ll be reaching for it under pressure.

Start with the list you already have

Start with what you can already name. Open a file and write down every device you can name, who has it and where it is. The gaps show up fast: the spare equipment nobody claims, the account nobody manages. That list is the honest starting point, whichever method you pick to keep it going.

Then decide who answers for the record when it turns out to be wrong. If you’d rather not carry that yourself, talk with O&O Systems about your IT asset inventory.