Only 1 in 10 IT teams has full software visibility. Here’s what it’s costing them.

Ask yourself how many applications are currently running across your organization. Now ask how many of them are actively being used, how many licenses you’re paying for that nobody needs, and when the next renewal is due.
If you can’t answer those questions with confidence, you’re not alone. Our research found that only 9.9% of organizations have full visibility into their software ecosystem. The other 90% are managing environments they can’t fully see.
That isn’t a reporting problem. It’s a control problem. Software inventory is CIS Control 2, sitting directly behind hardware inventory at the very front of the list. ISO 27001:2022 places it in Annex A, Section 5.9. NIST CSF 2.0 puts it under Identify, before anything else happens. Every framework agrees, and they agree for the same reason: almost every other control you run depends on it. Vulnerability management assumes you know what’s installed. Access recertification assumes you know what to review. Incident response assumes you know what was in scope. Break the inventory, and everything downstream inherits the gap.
Why poor software visibility is an operational risk
The consequences of limited software visibility show up in four concrete ways.
1. Security risk: you can’t patch software you can’t see
47% of respondents flagged poor visibility as a direct security risk. That number should be higher, because the exposure doesn’t depend on whether you’ve noticed it. You can’t patch what isn’t in your inventory. You can’t revoke access to a system you don’t know exists. And when a critical CVE lands on a Friday afternoon, the only question that matters is whether you’re running it. If assembling that answer takes two days, you’ve spent your entire response window on discovery.
The clocks are unforgiving. GDPR gives you 72 hours to notify a supervisory authority. The SEC gives US public companies four business days to file once an incident is judged material. Both clocks start running before you finish your inventory.
2. Shadow IT has become shadow AI
Shadow IT used to mean an unsanctioned file-sharing tool. In 2026, it usually means an AI tool. Someone pastes customer data into a chatbot your team never reviewed. A browser extension holds permission to read every page. An AI assistant is granted an OAuth token in your Microsoft 365 or Google tenant, with scopes nobody has looked at.
That last one matters most and gets the least attention. A shadow app with a delegated OAuth grant isn’t sitting outside your perimeter. It’s within your identity provider, maintaining persistent access to mail, files, and calendars, and it outlives the employee who installed it. Offboarding doesn’t touch it. Your firewall never sees it. It appears in no inventory, because nobody bought it.
IBM’s 2025 Cost of a Data Breach report priced the gap. High levels of shadow AI added USD 670,000 to the average breach cost. 63% of organizations had no AI governance policy at all. And 97% of organizations that suffered an AI-related security incident lacked proper AI access controls.
3. Financial waste: paying for unused software licenses
39% of organizations pay for redundant or unused licenses. Without a consolidated view of usage, renewals become reactive rather than strategic. A vendor emails to say a contract expires in 30 days. You have no usage data. You renew out of habit rather than making a decision. And every one of those renewals is a live data-processing relationship you re-sign without a review.
4. Operational drag: software sprawl blocks decisions
50% of respondents report poor visibility into usage because of software sprawl. If you don’t know what’s being used or how, you can’t decide what to keep, consolidate, or retire.
Why software sprawl compounds as environments grow
Sprawl doesn’t happen because your team is careless. It happens because tools accumulate. A point solution for a specific problem. Department software IT was never fully integrated. A legacy application is still running because no one has made a formal decision to retire it.
The more tools you hold, the harder it becomes to maintain a unified view. The harder the view becomes, the harder it is to make the decisions that would simplify the estate. Left alone, the problem feeds itself.
And every tool is more than a budget line. It’s another vendor to assess, another integration to maintain, another set of admin credentials, another processor in your processing records, another item in your audit scope. Third-party risk scales with tool count. It scales faster than your team does.
For directors, CTOs, and CISOs planning ahead, this compounds into something worse than untidiness. You can’t make a credible case for investment without data. You can’t optimize cost if you don’t know what you’re paying for. And you can’t sign off on risk for an environment you can’t describe.
Why IT tool consolidation is a top priority for 2026
Nearly 40% of IT organizations say consolidating their tools and platforms is a top priority for 2026. This shift reflects a broader change in how IT leadership thinks about its software portfolio.
The best-of-breed approach that dominated the last decade, picking the strongest individual tool for each function, is giving way to unified platforms with cleaner oversight and less integration complexity. Cost savings usually follow. They aren’t the main argument. Capability is.
Fewer platforms means a smaller third-party attack surface, fewer integration points to secure, and one audit trail instead of nine. It also means concentration risk. When you consolidate, a compromise at one vendor affects more of your estate. That trade is usually worth making. Make it deliberately. Ask for the vendor’s SOC 2 Type II report and current ISO 27001 certificate. Ask how tenants are segregated. Ask what happens to your data when you leave. Consolidation is only a security win if the platform you consolidate onto is one you would trust with the whole estate.
There’s a capability argument beneath it that lands even harder. You cannot deploy effective AI automation across a fragmented, disconnected landscape. Automation needs clean, connected data. It also needs governance: every action logged, every rule visible, every decision traceable to whoever authorized it. When your auditor asks what the AI did last quarter, “we’re not certain which system ran in” is not an answer. Consolidation is what makes a real answer possible.
How to start building software visibility: three moves that cost nothing
The organizations making the most progress in 2026 on efficiency, automation, and cost management share one thing in common: they started building visibility infrastructure before they needed it.
One caution, from experience: full visibility isn’t the real goal, and chasing 100% will stall the program. Aim instead for a known, bounded unknown. Measure your coverage. Track the gap. Treat what’s left as accepted risk with a named owner and a review date. A team that knows it can see 85% of its estate is in far better shape than a team that assumes it sees everything.
You can’t automate what you haven’t mapped. You can’t patch what you haven’t found. And you can’t defend an estate you can’t see.
Three moves that cost nothing and start this week:
- Pull the application list from your identity provider. Every app behind SSO is one you already know about.
- Pull the OAuth grants from your Microsoft 365 or Google tenant, sorted by scope. This is where the surprises live.
- Pull twelve months of card and expense data and filter for SaaS. Finance often holds the inventory, while security doesn’t.
Compare the three lists. The difference between them is your shadow estate. It’s usually larger than anyone expects, and it’s the most honest security metric you’ll produce this quarter.
Getting to real visibility is a project in itself. It’s also the foundation on which everything else sits.
Download the State of Service Management 2026 report for the full data on software visibility, the cost of sprawl, and how leading IT organizations are simplifying their environments.
Did you find this interesting?Share it with others:
Did you find this interesting? Share it with others: