← Back to Insights

Inventory

The container always has an owner.

Shipping made the unlabeled box impossible to move, and most enterprises still run production on assets nobody can name.

A formation of navy and gray shipping containers with one lifted mid-air by a crane spreader, lit electric blue

The manifest is the system

A container does not sail because someone loaded it onto a ship. It sails because a manifest says it can. Before the box ever touches a crane, it has a unique identifier, a declared contents type, a named responsible party, and a routing record that updates at every handoff, port to yard to vessel to truck.

This is not a courtesy. It is the mechanism. Customs will not clear an undeclared box. Insurers will not cover it. Terminal operators will not load it. The choreography of a modern port, hundreds of cranes and thousands of containers moving on a schedule measured in minutes, depends on every unit being knowable before it is movable. An unknown container is not an edge case the system tolerates. It is a state the system is built to make impossible.

Security has never built that state out. Most enterprises run production on an asset inventory assembled after the fact, stitched together from a CMDB that has not been reconciled in months, an EDR console that only sees what has an agent installed, a handful of cloud dashboards that disagree with each other, and a spreadsheet somebody maintains between other jobs. The honest answer to "what do we own" is usually "mostly, we think."

Cyber's ghost fleet

Shadow IT is the industry's name for cargo nobody declared. A marketing team spins up a SaaS trial on a company card. A developer stands up a test instance and forgets to tear it down. A storage bucket gets created for a one-off migration and outlives the project by three years. None of it passes through a process with real teeth, because no equivalent to the manifest exists to stop it.

The result is an asset base that grows by accretion and shrinks only by accident. Nobody deletes the forgotten VM. Nobody closes the abandoned tenant. It sits there, unpatched and unowned, until an incident response team finds it the way a beachcomber finds a container that washed off a ship. At that point the question is never abstract. It is how long this has been exposed, and what it holds.

Maersk's own history makes the irony hard to miss. In 2017 the company that runs its entire physical business on knowing precisely where every container sits was crippled by the NotPetya worm, which moved through its network faster than any manual process could contain. The recovery meant rebuilding a large share of the company's IT estate from scratch within days, at a cost its own leadership later put in the hundreds of millions of dollars. The business that solved the unknown-box problem at sea had not solved the unknown-asset problem on land. That gap is the whole argument in one sentence.

Where the analogy holds, and where it doesn't

It is worth being honest about the limits here. A container is a physical object. It changes hands a fixed, countable number of times between factory and destination, and every handoff is a natural checkpoint for a scan. A cloud workload can be created by an API call, cloned five times, and destroyed, all inside a single afternoon, with no physical custody chain forcing a checkpoint anywhere. Digital assets do not queue at a gate. They multiply the moment someone with valid credentials decides they should exist.

That difference is exactly why the discipline matters more in security, not less. Shipping gets its manifest enforced by physics and regulation working together: a box that isn't declared cannot move through a port. Security has neither constraint working for it by default. The only way to get manifest-grade discipline into an environment where anyone can provision anything is to build the enforcement in on purpose, because nothing external is going to do it for you.

What changes on Monday

The fix is not a bigger scanning tool. Most enterprises already own three or four discovery tools that each see a different slice of the estate and disagree with each other about the rest. The fix is treating "unknown" as a state the organization refuses to leave standing, the same way a port refuses to load an undeclared box.

Pick one authoritative registry.

Not another dashboard. Give it the job of reconciling what every other tool reports. Where they disagree, the registry wins, and the disagreement itself becomes a tracked exception until it is resolved.

Make ownership a mandatory field, not a nice-to-have.

Every asset, workload, identity, and data store gets a named business owner and a stated function before it goes live. No owner, no production access. This single rule kills more shadow IT than any scanning tool, because it moves the friction to the moment of creation instead of the moment of discovery.

Give every asset a defined lifecycle, not an indefinite one.

Provisioned, active, deprecated, destroyed, with a patching SLA attached to each state and an automatic escalation when something sits past its date. A test VM with no scheduled destruction date is a container with no destination port. It will sit somewhere, accumulating risk, until someone finds it the hard way.

None of this needs new technology. It needs the same decision the shipping industry made decades ago: refuse to let "we don't actually know" count as an answer, and build the process so that answer becomes structurally impossible to give.

The lookup, not the debate

When a container goes missing, nobody at a shipping line convenes a task force to guess where it might be. Someone runs a query. The manifest has the answer, because the system was built so the answer always exists.

That is the standard worth borrowing. Not the ships, not the cranes, not the container dimensions. The standard is this: an asset that cannot be found in seconds, with an owner attached, is not an inventory gap. It is a decision the organization made, whether it meant to or not, to run part of its business on cargo nobody declared. Shipping stopped accepting that decision generations ago. Security is still deciding whether to.

Key point

An unknown container is not an edge case the system tolerates. It is a state the system is built to make impossible.

On Monday

No owner, no production access. That single rule kills more shadow IT than any scanning tool.

The takeaway

An asset that cannot be found in seconds, with an owner attached, is not an inventory gap. It is a decision to run part of the business on cargo nobody declared.

Keep reading

More from the seat.