Blog

Unmanaged Device Risk: The First Step Is Knowing Your Count

8 min. read
28/08/2026
By Dan Smullen
Cybersecurity
unmanaged device risk

In a global Trend Micro survey of more than 2,000 cybersecurity leaders, 74% said they had already experienced a security incident caused by an unknown or unmanaged asset. Not a projected risk. That’s what unmanaged device risk looks like once it stops being theoretical.

Most advice on this problem starts at remediation. That skips a step, because you can’t scope a fix against an unknown quantity. If you ran a complete agentless discovery this afternoon, how many devices would appear that aren’t in your asset register? Most security leaders can’t answer that with a number, and everything downstream, from segmentation scope to insurance disclosure, rests on a count nobody verified.

Every device missing from your asset register sits permanently outside your security controls. You can’t patch it, you can’t monitor it, and you can’t respond to an incident on a device you don’t know exists. It is not a weak point in your defenses. It is a place your defenses were never applied.

How Many Unmanaged Devices Does Your Network Actually Have?

For most, the honest answer is that nobody knows. Ask three people in the same company how many devices are on the network and you’ll get three numbers, pulled from three systems, none of which was built to answer that question. That disagreement is the finding. It isn’t the preamble to one.

Historical research puts a rough shape on the gap. A 2019 Forrester survey found that 26% of organizations reported three times as many unmanaged devices as managed ones. That research predates the remote work expansion, the industrial IoT buildout, and the arrival of AI tooling on corporate networks, so treat it as a floor rather than a current estimate.

No reliable industry average exists to fall back on either. Unknown assets expand your attack surface in ways that vary too much by sector, headcount, and OT footprint for a benchmark to tell you much about your own. One pattern does generalize: the direction of the error. When organizations measure properly for the first time, the count comes in above the estimate. Nobody discovers they have fewer devices than they thought.

IoT and OT device inventory gaps top the list, but the devices that go uncounted are consistent enough to name in full:

  • IoT endpoints such as sensors, cameras, printers, and building management systems, which sit on the network without ever appearing in an endpoint console.
  • OT and ICS equipment in manufacturing, healthcare, and energy environments, where security teams often have no mandate to install anything.
  • BYOD and contractor laptops, which are entirely known to the people using them and entirely unknown to the security team.
  • Cloud workloads that spin up, do their work, and disappear without touching the corporate network.
  • Unauthorized hardware that teams bring onto the network when they need to move faster than procurement allows.

Read that list against your own environment and the honest output is a range, not a certainty. That’s enough to work with. A number you can defend beats an assumption you can’t.

What Unmanaged Devices Cost When They’re Exploited

Microsoft’s 2024 Digital Defense Report provides the clearest available figure on how attackers use these devices. Of ransomware attacks that progressed to the encryption stage, more than 90% used unmanaged devices as the initial access point or for remote encryption.

We’re being careful with that wording on purpose. The looser version circulates widely, and a good board will pick it apart. The finding isn’t that unmanaged devices cause most ransomware. It is that when ransomware succeeds, the device that let it in was usually not under management. Attackers are not defeating your controls. They are entering where your controls were never installed.

The regulatory exposure is easier to explain and harder to argue with. HIPAA, GDPR, PCI DSS, NIS2, and DORA all rest on the same assumption: that you know what falls in scope. An asset register that omits devices is not a documentation gap. It is an attestation you cannot support. When a regulator asks which systems process regulated data, the ones we know about are not an answer that survives scrutiny. Auditors have heard that sentence before, and they know exactly what it means. This is also where an inventory problem stops being an IT concern and becomes a general counsel concern.

For the board, the framing that lands is not a security metric. It is three business exposures:

  • Financial exposure concentrates in the assets nobody was watching, because incident cost scales with dwell time and dwell time scales with visibility.
  • Regulatory exposure follows from certifying compliance across an inventory rather than across an environment.
  • Operational exposure shows up during response, when the team spends its first hours establishing what a device is instead of containing it.

Accurate IT asset management is the control that reduces all three at once, which is unusual and worth saying out loud in a budget conversation.

Why Traditional Discovery Tools Miss More Than You Think

The reason these devices stay hidden is structural. It isn’t a configuration anyone forgot. Here are four common approaches, and what each one is structurally unable to see:

Discovery MethodWhy It Misses DevicesWhat Stays Invisible
Agent-based toolsSomeone has to install the agent, and that someone already knew the device existed.Devices that were never enrolled. The coverage dashboard still reads green, because it measures the devices it already knows about.
Credential-based scanningIoT firmware, OT controllers, and network gear reject standard authentication or were never built to accept it.Industrial, medical, and infrastructure equipment.
Scheduled scansA scan describes a single moment in time.Devices that connect and disconnect inside the gap between scan windows.
Registers and approval workflowsShadow IT, BYOD, and contractor equipment never enter the process.Devices fully known to the people using them and invisible to everyone securing them.

None of this is a failure of diligence, and it’s worth saying that to your team plainly. This is what makes unmanaged device risk structural rather than a hygiene problem. Each is a design limit of tooling built for an environment that no longer exists. Shadow IT security risks aren’t an edge case in that environment. They’re the ordinary result of it. The device landscape changed. Most discovery approaches didn’t.

What CAASM Changes for Security Leaders

Cyber Asset Attack Surface Management (CAASM) is a security discipline focused on building a complete, continuously validated inventory of every asset in an environment, including the devices that agents and scheduled scans miss. It maps those assets to risk context such as vulnerability exposure, end-of-life status, and absent security controls. The result is a single source of truth for the attack surface rather than a record of what the organization believes it owns.

The distinction from traditional asset management is worth holding onto. Asset management answers what we own. CAASM answers what exists, what condition is it in, and what does that mean for risk. One is a register. The other is an operating picture.

For a security leader, that translates into three things: defensible device visibility, a number that can be reported upward without technical translation, and a foundation the downstream programs depend on. Vulnerability management, Zero Trust segmentation, and compliance reporting all inherit the accuracy of the inventory beneath them. Build them on a partial inventory and every one of them is partial.

Lansweeper approaches this as a Cyber Asset Intelligence Platform. Agentless asset discovery across 50+ protocols reaches IT, OT, IoT, cloud, and BYOD assets without requiring an agent or credentials on every device. Our traffic sensor passively monitors network traffic between scans, so short-lived devices still register. HVMND Collective Intelligence adds peer context drawn from 175M+ devices across 30,000+ environments, so total asset visibility means a validated picture rather than a longer list. Because IT and Security both work from that same validated record, a finding stops stalling while two teams argue about whether the asset exists.

The first count this produces is usually a correction. Across our MSP partners, 89% find more assets than expected on first deployment, which is the practical case for measuring before planning rather than after.

Start With the Count

Here’s the reversal: the most serious risk in your environment is not the threat you’re tracking. It’s a device you don’t know is there. One of those has your attention. The other has none of your controls.

Which means the first move is not mitigation. It is an enumeration. Before any remediation plan, segmentation project, or Zero Trust initiative can be scoped honestly, someone has to establish how many assets exist and how many of them were unaccounted for. Everything downstream inherits that number.

So start there. Run a complete agentless discovery against your environment and find out what your real device count is, before anyone asks you for it. If your teams want the technical follow-through once the gap is visible, our guide to detecting and managing rogue devices covers what comes next.

FURTHER READING

The Scale of the Unmanaged Asset Problem in 2026

A closer look at how much the unmanaged device gap has grown and why it’s harder to estimate than it used to be.

FAQ

  • How Many Unmanaged Devices Does the Average Enterprise Have?

    No reliable industry average exists, which is itself the finding. A 2019 Forrester survey found 26% of organizations reported three times as many unmanaged devices as managed ones, though that predates recent IoT and remote work growth. The more useful signal is directional: 89% of Lansweeper MSP partners discover more assets than expected on first deployment, so the real count is almost always higher than the asset register shows.

  • Why Are Unmanaged Devices a Security Risk?

    Unmanaged devices sit permanently outside security controls. They receive no patch management, carry no endpoint protection, and generate no monitoring telemetry. If a device is absent from your inventory, you cannot respond to an incident involving it. Microsoft’s Digital Defense Report found that of ransomware attacks reaching the encryption stage, more than 90% used unmanaged devices for initial access or remote encryption.

  • What Is Cyber Asset Attack Surface Management (CAASM)?

    CAASM is a security discipline focused on achieving complete, continuously validated visibility into every asset in an environment, including devices that agents and periodic scans miss. It maps discovered assets to risk context such as vulnerabilities, end-of-life status, and missing controls. Lansweeper approaches CAASM through agentless discovery across 50+ protocols, giving security teams a shared foundation for attack surface management rather than a static inventory of known assets.

  • Can Traditional Security Tools Find Unmanaged Devices?

    Generally no, and the reason is structural rather than a matter of configuration. Agent-based tools only reach endpoints where an agent was installed, so they cannot discover devices nobody enrolled. Credential-based scanners fail on IoT, OT, and infrastructure equipment that rejects standard authentication. Scheduled scans miss transient devices. Agentless, protocol-diverse discovery is designed specifically to close this gap.

Ready to get started?

Explore the full platform, free for 14 days.
No credit card required.

Need help evaluating?
Get guidance on pricing at scale and enterprise requirements.
Talk to sales
Clear pricing as you grow
Transparent plans that scale with your environment.
View plans & pricing