asset-inventory
Safeguard articles tagged "asset-inventory" — guides, analysis, and best practices for software supply chain and application security.
12 articles
Every SaaS Tool Nobody Approved Still Has Access
Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.
The System Nobody Touches Is Unpatched by Default, Not by Decision
It works, it matters, the person who built it has left, and everyone has agreed without discussing it that touching it is riskier than leaving it. That agreement gets more expensive every month.
The Agents on Your Hosts Have More Access Than Your Application
Four agents on every production host, each running as root or with kernel privileges, each auto-updating from its vendor, each sending data outward. Your application dependencies are pinned and scanned. These are neither.
Diligence Tells You What You Bought. Integration Is Where the Risk Arrives.
Most acquisition security effort happens before close and produces a report. Your exposure actually changes in the ninety days afterwards, when the pressure is to connect everything quickly and the security questions are marked answered.
The Asset Nobody Owns Is the One That Sits for a Year
The DNS record pointing at a dead vendor, the service account nobody can justify, the repository failing every scan. Each has a fix that takes an afternoon, and each waits a year because finding an owner has no owner either.
A Half-Deleted Service Is More Dangerous Than a Running One
Services are launched with a checklist and switched off with a Slack message. The container goes, the credentials stay, and nobody patches or monitors something everyone believes is gone.
The Average Enterprise Runs 900 APIs. It Can List Maybe 600 of Them.
API attacks are climbing steeply and 87% of organisations reported an incident last year. The root cause is not weak authentication — it is that many production endpoints are on nobody's list.
You Cannot Defend an MCP Server You Do Not Know You Are Running
Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.
Know your cloud environment: a practical asset inventory methodology
Gartner projects that through 2025, 99% of cloud security failures will be the customer's fault — almost always because an asset nobody tracked got misconfigured.
Why asset inventory should come before AppSec tooling
Only 17% of organizations can inventory 95%+ of their assets, and 69% have been breached through one they didn't know existed — start with the map, not the scanner.
NYDFS Part 500: The November 2025 Deadlines, One Year On
The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.
Asset Management AI: How AI Is Reshaping Security Asset Inventory
Asset management AI turns a stale spreadsheet of assets into a living, correlated inventory. Here is what it actually does for security teams and where it falls short.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.