In a global Trend Micro survey of more than 2,000 cybersecurity leaders, 74% said they had already experienced a security incident caused by an unknown or unmanaged asset. Not a projected risk. That’s what unmanaged device risk looks like once it stops being theoretical.
Most advice on this problem starts at remediation. That skips a step, because you can’t scope a fix against an unknown quantity. If you ran a complete agentless discovery this afternoon, how many devices would appear that aren’t in your asset register? Most security leaders can’t answer that with a number, and everything downstream, from segmentation scope to insurance disclosure, rests on a count nobody verified.
Every device missing from your asset register sits permanently outside your security controls. You can’t patch it, you can’t monitor it, and you can’t respond to an incident on a device you don’t know exists. It is not a weak point in your defenses. It is a place your defenses were never applied.
For most, the honest answer is that nobody knows. Ask three people in the same company how many devices are on the network and you’ll get three numbers, pulled from three systems, none of which was built to answer that question. That disagreement is the finding. It isn’t the preamble to one.
Historical research puts a rough shape on the gap. A 2019 Forrester survey found that 26% of organizations reported three times as many unmanaged devices as managed ones. That research predates the remote work expansion, the industrial IoT buildout, and the arrival of AI tooling on corporate networks, so treat it as a floor rather than a current estimate.
No reliable industry average exists to fall back on either. Unknown assets expand your attack surface in ways that vary too much by sector, headcount, and OT footprint for a benchmark to tell you much about your own. One pattern does generalize: the direction of the error. When organizations measure properly for the first time, the count comes in above the estimate. Nobody discovers they have fewer devices than they thought.
IoT and OT device inventory gaps top the list, but the devices that go uncounted are consistent enough to name in full:
Read that list against your own environment and the honest output is a range, not a certainty. That’s enough to work with. A number you can defend beats an assumption you can’t.
Microsoft’s 2024 Digital Defense Report provides the clearest available figure on how attackers use these devices. Of ransomware attacks that progressed to the encryption stage, more than 90% used unmanaged devices as the initial access point or for remote encryption.
We’re being careful with that wording on purpose. The looser version circulates widely, and a good board will pick it apart. The finding isn’t that unmanaged devices cause most ransomware. It is that when ransomware succeeds, the device that let it in was usually not under management. Attackers are not defeating your controls. They are entering where your controls were never installed.
The regulatory exposure is easier to explain and harder to argue with. HIPAA, GDPR, PCI DSS, NIS2, and DORA all rest on the same assumption: that you know what falls in scope. An asset register that omits devices is not a documentation gap. It is an attestation you cannot support. When a regulator asks which systems process regulated data, the ones we know about are not an answer that survives scrutiny. Auditors have heard that sentence before, and they know exactly what it means. This is also where an inventory problem stops being an IT concern and becomes a general counsel concern.
For the board, the framing that lands is not a security metric. It is three business exposures:
Accurate IT asset management is the control that reduces all three at once, which is unusual and worth saying out loud in a budget conversation.
The reason these devices stay hidden is structural. It isn’t a configuration anyone forgot. Here are four common approaches, and what each one is structurally unable to see:
| Discovery Method | Why It Misses Devices | What Stays Invisible |
|---|---|---|
| Agent-based tools | Someone has to install the agent, and that someone already knew the device existed. | Devices that were never enrolled. The coverage dashboard still reads green, because it measures the devices it already knows about. |
| Credential-based scanning | IoT firmware, OT controllers, and network gear reject standard authentication or were never built to accept it. | Industrial, medical, and infrastructure equipment. |
| Scheduled scans | A scan describes a single moment in time. | Devices that connect and disconnect inside the gap between scan windows. |
| Registers and approval workflows | Shadow IT, BYOD, and contractor equipment never enter the process. | Devices fully known to the people using them and invisible to everyone securing them. |
None of this is a failure of diligence, and it’s worth saying that to your team plainly. This is what makes unmanaged device risk structural rather than a hygiene problem. Each is a design limit of tooling built for an environment that no longer exists. Shadow IT security risks aren’t an edge case in that environment. They’re the ordinary result of it. The device landscape changed. Most discovery approaches didn’t.
Cyber Asset Attack Surface Management (CAASM) is a security discipline focused on building a complete, continuously validated inventory of every asset in an environment, including the devices that agents and scheduled scans miss. It maps those assets to risk context such as vulnerability exposure, end-of-life status, and absent security controls. The result is a single source of truth for the attack surface rather than a record of what the organization believes it owns.
The distinction from traditional asset management is worth holding onto. Asset management answers what we own. CAASM answers what exists, what condition is it in, and what does that mean for risk. One is a register. The other is an operating picture.
For a security leader, that translates into three things: defensible device visibility, a number that can be reported upward without technical translation, and a foundation the downstream programs depend on. Vulnerability management, Zero Trust segmentation, and compliance reporting all inherit the accuracy of the inventory beneath them. Build them on a partial inventory and every one of them is partial.
Lansweeper approaches this as a Cyber Asset Intelligence Platform. Agentless asset discovery across 50+ protocols reaches IT, OT, IoT, cloud, and BYOD assets without requiring an agent or credentials on every device. Our traffic sensor passively monitors network traffic between scans, so short-lived devices still register. HVMND Collective Intelligence adds peer context drawn from 175M+ devices across 30,000+ environments, so total asset visibility means a validated picture rather than a longer list. Because IT and Security both work from that same validated record, a finding stops stalling while two teams argue about whether the asset exists.
The first count this produces is usually a correction. Across our MSP partners, 89% find more assets than expected on first deployment, which is the practical case for measuring before planning rather than after.
Here’s the reversal: the most serious risk in your environment is not the threat you’re tracking. It’s a device you don’t know is there. One of those has your attention. The other has none of your controls.
Which means the first move is not mitigation. It is an enumeration. Before any remediation plan, segmentation project, or Zero Trust initiative can be scoped honestly, someone has to establish how many assets exist and how many of them were unaccounted for. Everything downstream inherits that number.
So start there. Run a complete agentless discovery against your environment and find out what your real device count is, before anyone asks you for it. If your teams want the technical follow-through once the gap is visible, our guide to detecting and managing rogue devices covers what comes next.
FURTHER READING
A closer look at how much the unmanaged device gap has grown and why it’s harder to estimate than it used to be.
No reliable industry average exists, which is itself the finding. A 2019 Forrester survey found 26% of organizations reported three times as many unmanaged devices as managed ones, though that predates recent IoT and remote work growth. The more useful signal is directional: 89% of Lansweeper MSP partners discover more assets than expected on first deployment, so the real count is almost always higher than the asset register shows.
Unmanaged devices sit permanently outside security controls. They receive no patch management, carry no endpoint protection, and generate no monitoring telemetry. If a device is absent from your inventory, you cannot respond to an incident involving it. Microsoft’s Digital Defense Report found that of ransomware attacks reaching the encryption stage, more than 90% used unmanaged devices for initial access or remote encryption.
CAASM is a security discipline focused on achieving complete, continuously validated visibility into every asset in an environment, including devices that agents and periodic scans miss. It maps discovered assets to risk context such as vulnerabilities, end-of-life status, and missing controls. Lansweeper approaches CAASM through agentless discovery across 50+ protocols, giving security teams a shared foundation for attack surface management rather than a static inventory of known assets.
Generally no, and the reason is structural rather than a matter of configuration. Agent-based tools only reach endpoints where an agent was installed, so they cannot discover devices nobody enrolled. Credential-based scanners fail on IoT, OT, and infrastructure equipment that rejects standard authentication. Scheduled scans miss transient devices. Agentless, protocol-diverse discovery is designed specifically to close this gap.
Explore the full platform, free for 14 days.
No credit card required.