Illustration of hardware, virtual machines and cloud resources under a magnifier, with items marked out of support, unaccounted for, and barely used

Current Infrastructure Audit

Back to Server Setup · Workload Requirements · Dependency Mapping · Service Offerings

An infrastructure audit establishes what hardware, virtual machines, cloud resources and software you actually have, and which of it is outdated or underused. It is the second stage of a server setup, and it runs alongside workload requirements: one says what the work needs, the other says what you are already paying for.

Almost every organisation already has an inventory. The audit exists because the inventory is wrong — not through negligence, but because infrastructure is added under deadline and removed never. The output that matters is not the list. It is the difference between the list and reality, which is where both the risks and the savings live.

1. What Gets Counted

2. How We Find It

The same discipline as dependency mapping: several sources, each with a different blind spot, reconciled against one another.

Where an agent is unwelcome — appliances, vendor-managed systems, anything under a support contract — agentless discovery gets the same information without touching the machine.

3. “Outdated” Has Three Different Dates

This distinction is worth being precise about, because organisations regularly believe they are covered when they are not:

The audit records all three dates per product, plus hardware warranty expiry, and flags anything already past a date or passing one inside the planning horizon. That list is a risk register, and it is what turns “we should upgrade sometime” into a sequence with deadlines — which then feeds patch management.

4. “Underused” Is Where the Money Is

The counterpart matters too: the audit also flags anything running hot. A host at 90% at peak is not efficient, it is about to become slow — for the reasons set out under workload requirements.

5. The Disposition

Every asset is placed against two axes — how heavily it is used, and where it sits in its supported life — which gives four boxes and one action each.

Two-by-two matrix of usage against support status, giving four actions: keep and watch, upgrade or replace first, right-size or consolidate, and retire

One caution on the retire box. “Nobody uses it” is a claim about the window you observed. A system idle all week may be the quarter-end reconciliation, and switching it off is discovered in three months. Confirm against the dependency map and a long enough log history first — and where there is doubt, power it down and leave it recoverable for a cycle rather than deleting it.

What You Get

An audit is bounded work with an unusually direct payback: the retirements and right-sizing frequently cover its cost, and the lifecycle findings are the ones you would rather not discover during an incident. It feeds directly into architecture design and into capacity planning.