Computer Source Mag All articles
Cybersecurity

What's Actually Running on Your Network: The Software Compliance Crisis Hiding in Plain Sight

Computer Source Mag
What's Actually Running on Your Network: The Software Compliance Crisis Hiding in Plain Sight

There is a particular kind of organizational confidence that precedes a software audit. IT directors submit their license inventories, procurement teams produce their purchase orders, and finance signs off on the compliance attestation. Everyone assumes the numbers match. Then the audit begins — and they almost never do.

For mid-market businesses operating between 200 and 2,000 employees, the gap between perceived and actual software deployment has become one of the most quietly expensive problems in modern IT management. It is not typically the result of deliberate misconduct. It is the result of complexity — departmental autonomy, decentralized purchasing, automatic software updates, and the persistent expansion of shadow IT — converging into a compliance exposure that neither the IT team nor legal counsel anticipated.

The Anatomy of an Unauthorized Deployment

Unauthorized software deployments rarely begin with bad intent. They begin with convenience. A department head purchases a productivity suite on a corporate credit card to solve an immediate problem. A developer installs a licensed tool on three additional workstations to meet a deadline. An automatic update quietly upgrades a product from a licensed tier to a premium tier that the organization never paid for.

Each of these events is individually minor. Collectively, they create what software asset management professionals call a "compliance gap" — the measurable distance between what an organization is licensed to run and what is actually executing across its infrastructure at any given moment.

According to research from the BSA | The Software Alliance, a significant percentage of software running on corporate endpoints in the United States is either unlicensed, over-deployed beyond purchased seat counts, or operating under a license tier that no longer matches the installed version. The financial exposure from these gaps is not theoretical. It is quantified during vendor-initiated audits, and the penalties can be severe.

Case Study: The Mid-Market Manufacturer That Didn't Know It Had a Problem

Consider the experience of a mid-sized manufacturing company in the Midwest — approximately 600 employees, two production facilities, and a centralized IT team of eight. When a major enterprise software vendor initiated a license review as part of a routine contract renewal, the company's IT director was unconcerned. Licenses had been tracked in a spreadsheet for years, and the numbers seemed right.

The audit revealed a different reality. A software package originally purchased for the engineering department had been quietly installed by employees in operations, quality control, and supply chain management over a three-year period — none of whom had requested formal IT provisioning. A separate discovery tool found that an automatic product update had migrated approximately 90 workstations from a standard licensed version to an advanced edition that carried a significantly higher per-seat cost.

The total liability, inclusive of back-licensing fees and audit penalties, exceeded $340,000. The company had no formal software asset management program, no endpoint discovery tool, and no policy governing departmental software purchases outside of IT-approved channels.

Shadow IT Is Not a New Problem — But It Is Getting Worse

The proliferation of SaaS platforms has dramatically expanded the shadow IT surface area for most organizations. When employees can provision software subscriptions with a credit card and a business email address, the traditional IT gatekeeping function becomes difficult to enforce. A team adopts a project management tool. A sales department subscribes to a data enrichment platform. Marketing deploys a design application across twelve workstations without submitting a purchase request.

Each of these deployments may carry its own licensing terms, usage restrictions, and seat limitations. Without a centralized discovery and reconciliation process, IT has no reliable mechanism for knowing what is running, who authorized it, or whether the organization is operating within the bounds of its agreements.

The challenge is compounded by multi-device licensing arrangements. Many enterprise agreements permit installation on a defined number of devices per user. When employees change roles, leave the organization, or upgrade hardware without formal deprovisioning, those license seats frequently remain occupied by software running on devices that are no longer actively managed.

What a Proper Software Asset Management Program Actually Requires

Addressing software compliance exposure is not primarily a technology problem. It is an organizational governance problem that technology can help solve — but only once the governance structure is in place.

Effective software asset management begins with endpoint discovery: deploying tools that provide continuous, real-time visibility into what software is installed and executing across every managed device on the network. Solutions from vendors such as ServiceNow, Flexera, and Snow Software are commonly deployed in mid-market environments for this purpose. Discovery alone, however, is insufficient.

The data produced by discovery tools must be reconciled against entitlement records — the actual license agreements, purchase confirmations, and volume contract terms that define what the organization is permitted to run. This reconciliation process frequently reveals discrepancies that spreadsheet-based tracking cannot detect, particularly in environments where software has been purchased through multiple procurement channels over multiple fiscal years.

Organizations should also establish a formal software request and approval workflow that routes all software purchases — including SaaS subscriptions — through IT review before deployment. This does not eliminate departmental autonomy, but it does ensure that licensing implications are evaluated before installation rather than discovered during an audit.

The Audit Itself: Understanding Vendor Rights and Organizational Exposure

Most enterprise software agreements include audit rights provisions that permit the vendor — or a designated third-party auditor — to review the organization's deployment records on relatively short notice. The scope of these audits has expanded in recent years, with some vendors deploying telemetry tools that provide real-time deployment data independent of the customer's own records.

Organizations that have not conducted internal compliance reviews before a vendor-initiated audit are at a significant disadvantage. Without accurate entitlement and deployment data, negotiating audit findings becomes substantially more difficult. The vendor's numbers become the default, and the organization's ability to contest discrepancies is limited.

Proactive internal audits — conducted annually at minimum, and more frequently in environments with high software churn — allow IT and procurement teams to identify and remediate compliance gaps before they become audit liabilities. In many cases, remediating a compliance gap proactively by purchasing additional licenses costs significantly less than resolving the same gap under audit conditions, where penalties and back-fees are applied.

The Organizational Imperative

Software licensing compliance is not a back-office administrative function. It is a material financial risk that belongs on the agenda of every IT leadership team and, in larger organizations, every board-level risk committee. The companies that treat software asset management as a periodic housekeeping exercise rather than a continuous operational discipline are the ones that receive audit notices and spend the next six months negotiating settlement terms.

The technology to manage this problem effectively exists, is widely available, and is not prohibitively expensive relative to the exposure it prevents. What is frequently missing is the organizational will to treat software compliance as the serious business risk it has become. For mid-market IT leaders looking to protect their organizations from a liability they may not yet know they carry, the time to act is well before the auditor's letter arrives.

All Articles

Related Articles

Held in Place: How Aging System Dependencies Are Quietly Dictating Your Technology Strategy

Held in Place: How Aging System Dependencies Are Quietly Dictating Your Technology Strategy

Forgotten and Festering: The Organizational Cost of Consumer Devices That Never Get Formally Retired

Forgotten and Festering: The Organizational Cost of Consumer Devices That Never Get Formally Retired

Dead Ends and Live Threats: The Unmanaged USB Devices Quietly Compromising Enterprise Security

Dead Ends and Live Threats: The Unmanaged USB Devices Quietly Compromising Enterprise Security