Why Every Risk Conversation We Have Starts With the Asset Inventory

You can't quantify what you can't name. The state of asset inventories we find at new clients, and how tying assets to risks, controls, and loss scenarios changes everything downstream. The first meeting with a new client almost always goes the same way. They want to talk about risk quantification, or a board report, or the framework they are being audited against. I ask one question first: can you show me your asset inventory? The room gets quiet. A 40 person accounting firm we onboarded last spring produced three spreadsheets, a network diagram from 2019, and a shrug. That is not a criticism of them — it is the normal starting condition. But it tells us exactly where the real work is. You cannot quantify a risk to something you have not named. Every downstream artifact — the scope of an assessment, the dollar figure on a loss scenario, the control mapping in a compliance report — rests on knowing what you actually have. Skip the inventory and you are estimating risk to an imaginary environment. The mess we usually find At that accounting firm, the "inventory" listed 60 laptops and a file server. What it did not list: the tax prep SaaS holding client Social Security numbers, the document portal a partner had spun up on a personal card, the on prem box in the closet still running the old practice management app, and the two dozen mailboxes with sensitive attachmen