Ask any mid-sized company how many systems it uses and you will get a number. Ask for the list and it will not exist. Between the ERP everyone knows about and the tool one department bought with a card, there is a layer of applications, cloud services, integrations and access rights that nobody sees whole. It is not negligence: nobody has the job of seeing it.
Without that list, everything else limps. You cannot protect what you do not know exists, you cannot ask questions about a vendor that is not written down, and when an incident arrives, or a large customer with a questionnaire, or a new regulation, the first week is lost reconstructing what should have been on paper.
The minimum list fits in a spreadsheet and has five columns:
- The system, with a name and what it is used for.
- Who administers it, inside or outside the company.
- What data it touches, even broadly: customers, employees, finance.
- What it depends on: where it is hosted and what it integrates with.
- Who can get in from outside, including vendors and former employees nobody ever off-boarded.
The first version takes one afternoon and three sources: the invoices and subscriptions of the last twelve months, a walk through the departments asking what they actually use, and the access lists of email and VPN. It will come out incomplete. That is fine: an incomplete list that someone maintains is worth infinitely more than a perfect one that does not exist.
The hard part is not building it but keeping it alive, because a company's technology changes every month even if nobody writes it down. That maintenance is exactly the kind of work almost no SMB has covered, and the reason the inventory opens any serious audit: it is the map on which everything else is drawn.
What the teams that do have that map in front of them are looking at this year: The technology risk universe in 2026.