A quick inventory check in most Brazilian small and medium-sized companies reveals a familiar answer to the question "how many computers do you have?" — nobody knows. There's the owner's laptop, the desktop computer in finance that sometimes gets left on, the printer that occasionally doubles as a data server, the intern's notebook from three years ago that's still somehow connected to the network, the salesman's phone that was registered in the distribution system, which might be in São Paulo or a hotel room in Argentina. No list. No updates. No certainty.

This absence of inventory is one of the largest security risks a company can face — and it's also something no sophisticated attack needs to exploit. According to Verizon's 2025 data breach report, breaches that started with a system intrusion surged to 53% in Europe, the Middle East and Africa — nearly double the 27% of the year before. Some of them come in through a machine nobody knew existed, or one forgotten in a corner of the server room.

The effect cascades. Without knowing how many devices exist, the company cannot say how quickly they can be updated. Cannot say whether a new computer arrives with antivirus already installed. Cannot say whether a shared password across ten machines from one employee continues running two years after she left. Cannot say whether that server someone turned on in 2022 "just for testing" is still there, unprotected, with weak credentials, accessible to anyone on the network. Cannot prevent what it cannot see.

The risk of an invisible machine

The first consequence of not knowing what exists is being unable to protect it. According to CISA's Catalog of Known Exploited Vulnerabilities, over 1,700 vulnerabilities are actively being exploited today — that number grows every month. Each one is an open door, but the door only works if a machine exists to enter through. A machine not in the inventory, not being updated, not being monitored.

This is not negligence. Competent and well-intentioned people work in IT departments at companies with hundreds of employees without having, anywhere, a central list of machines. What happens instead is that the space where this list should be is filled with "how" — how to fix the printer, how to access the legacy system, how to reset the password because someone forgot it. The inventory is always pushed to later.

The damage from an invisible machine appears when it becomes the entry bridge. Sophos, in its 2026 report on data-hostage attacks — where a program scrambles the company files and the attackers demand a ransom to give them back —, measured that the average cost of recovering from a successful attack is USD 1.7 million. It's not just ransom money — it's the hours the team spends trying to figure out what happened, production that stops, the customer who calls suspicious because they received a strange email from the company's domain, the rework of everything that was being done when the system went down.

The vulnerability is worse in companies that grew quickly. That server the partner turned on in 2019 "just to store old files" is still sitting there, with a password shared with someone's cousin, no backup, no monitoring, nobody really responsible for it. That notebook from the IT director who left in 2023 was given to an intern, who then transferred it to someone else, who now works remotely and nobody is sure which machine her account is active on.

In this scenario, an attack doesn't need to be sophisticated. Doesn't need a zero-day. Just needs patience to find the machine nobody is paying attention to.

Why the usual approach doesn't work

The natural reaction is "let's do an inventory" — someone spends a weekend doing a manual count, lists 147 machines, sends it to management. Three months later, 40 of them have moved, five left the company and were replaced by 12 others, and the list still says 147. The inventory became a piece of paper.

The usual way often means counting only what's on invoices: "we have 32 computers because the invoice says 32." But between the invoice from 2018 and now, machines were given to other departments, loans that became permanent, replaced, turned on just for testing and forgotten. The invoice is a fixed point in time. The real fleet is dynamic.

Another common path is leaving this responsibility with one person. "John handles the inventory." John goes on vacation, John gets in a motorcycle accident, John finds a better job, and nobody else knows where the information is or whether it was trustworthy. And even if John were immortal, one person alone cannot keep a real-time, accurate inventory of 500 machines up to date, especially when new ones are constantly arriving, old ones leaving, passwords changing, access being revoked, all at different times.

The difference between an inventory that exists on paper and one that works in reality is one thing. A system that alerts when a new machine joins the network. A log that shows who is accessing what. A list that updates itself, because it's derived from who is actually using it, not from who should be using it according to a spreadsheet from 2021.

What has to be in place

A real asset inventory control requires a few verifiable mechanisms.

Automatic registration of everything that joins the network. When a new machine is turned on or a phone connects to WiFi for the first time, the system knows — not because someone filled out a form, but because the network sees it. Who it is, what its IP address is, what its name is, what operating system it runs, what its access history looks like. No machine stays invisible by accident.

Clear ownership of each asset. Who is responsible for that server over there? That notebook? The phone that was here and now nobody knows where it went? Without an owner there is no one responsible; without responsibility there is no updating or monitoring.

Continuous updates when machines arrive or leave. When someone leaves the company, what happens to their notebook? Is it wiped? Recycled? Sold? Who tells the system? If nobody does, the machine stays in the inventory and on the network for years, and when an attacker finds it, they find an official company machine with domain access and old files stored inside.

A map of each machine — operating system, installed software, what permissions it has, who is using it now. This makes it possible to know within minutes which machines have a specific Windows vulnerability, which one is running an outdated version of Adobe, which has an expired antivirus license, or which has access to sensitive data.

A record of who accesses what. Not to spy, but to understand: which machine accesses databases? Which accesses client contract folders? Which is communicating with a cloud service nobody knows about? When an alarm sounds, this map tells you where to look.

This is how Skills IT works: with automatic registration of every device that arrives, a defined owner, continuous updates as machines come and go, and a clear map of what each one accesses. It is not surveillance — it is visibility.

What changes when the company knows what it has

When a company gains real inventory visibility, the benefit is not abstract. The first thing that changes is response time. When a security alert arrives saying "there is a machine here with vulnerability X," the company doesn't spend hours trying to figure out which one. The map says in minutes: machine, location, who uses it, what it accesses.

The second gain is budgetary. Without inventory, the company renews licenses "by guesswork" — buys 20 because there are 19 known machines plus maybe some others. With inventory, you know exactly: 47 machines, 47 licenses, renewal in year X, monthly cost Z, no surplus, no shortage. Costs become predictable.

The third, perhaps most important: the team can actually work. Instead of spending hours hunting for which machine caused a problem, discovering it was one not in the inventory, and having to redo the entire investigation, the team finds answers quickly. Less time firefighting, more time on real work.

According to IBM's 2025 report on the cost of data breaches, the global average cost of a breach came to USD 4.44 million, down from USD 4.88 million the year before — a 9% drop, and still a bill no mid-sized company absorbs painlessly. Inventory alone does not bring that number down, but it does shorten the time between "something happened" and "we already know where" — and on that bill, time is money.

Three questions to bring to your next meeting

Before waiting for an attack, it's worth asking now:

  1. Is there an updated record of every computer, server, and phone the company has? If nobody can answer in five minutes "we have 47 machines, here they all are," then it doesn't exist.

  2. When a machine is purchased, turned on for the first time, or taken out of service, who is notified? If it's "we take a note" or "John knows," that's because there is no automated system. If there is a system, is it reliable — or does it need to be?

  3. If a security alarm comes in saying "machine X is running vulnerable software," how long does it take to find that machine? If the answer is more than an hour, the company is relying on luck — because the longer it takes, the longer the attacker has to do whatever they want.