Skip to content

Assets

You can’t protect what you can’t see. The Asset Directory is your inventory of everything worth securing — laptops and servers, domains, cloud and SaaS services, and software — each with an owner, a criticality, and a risk picture.

786 Cyber groups assets into clear categories so your inventory stays tidy:

CategoryExamples
EndpointLaptops, desktops, mobiles
HardwareServers, network appliances
NetworkFirewalls, switches, routers
Software (on‑prem)Installed applications
Software (cloud)SaaS services
DomainYour internet domains
CloudCloud accounts and resources

Like people, assets can be added three ways and mixed freely:

Connect your directory and device data flows in automatically — the fastest way to seed endpoints and the accounts behind them.

Use the same 4‑step Import Wizard you use for people:

  1. Upload your CSV.
  2. Map columns to asset fields — including criticality, owner, department, serial number, manufacturer/model, and OS name (under Advanced details).
  3. Validate every row before saving.
  4. Import, with the same 24‑hour rollback safety net.

The same fuzzy‑matching that protects your people import protects this one: departments named in your asset file are matched against departments you already have (so a spreadsheet full of “IT”, “I.T.” and “Information Technology” doesn’t fragment into three departments), and validation surfaces bad rows — missing owners, malformed fields — before anything is committed. Combined with the 24‑hour rollback, that makes a large asset import from an old spreadsheet or a legacy tool export safe to try rather than something you have to get perfect first time.

Use Add asset and complete the form. Advanced fields (OS name, serial, manufacturer, model) live under Advanced details.

The Add Asset form with the Advanced details section expanded, showing the IP address, MAC address and operating system fields.

Migrating from an RMM, CMDB, or another asset tool? Native RMM/PSA connectors are on the roadmap — CSV import covers you today, and if there’s a specific tool you’d like connected natively, let us know.

  • Every asset is tied to a department (its accountability owner). Endpoints can also have an assigned user.
  • Set each asset’s criticality — this feeds directly into how vulnerabilities are prioritised (a critical server outranks a spare laptop). See Vulnerability management.

Import software → on the Asset Directory brings in the applications installed across your estate. This unlocks two things:

  • Installed Software on each asset’s detail page — what is actually running where.
  • Internal Asset vulnerability matching — 786 Cyber matches installed versions against the CVE database (CPE → NVD) and promotes the high‑confidence, genuinely exploitable results into your Internal Asset posture lane. See Vulnerability management.

Export SBOM ↓ downloads your software inventory as a CycloneDX 1.5 file (sbom-cyclonedx-YYYY-MM-DD.json) — the standard format customers, insurers and assessors increasingly ask for. It needs a software inventory to have been imported first.

The SBOM covers what software you have and where. It does not yet include a vulnerability (VEX) section, and importing someone else’s SBOM is not yet supported.

  • Bulk actions — select many assets to update or delete together.
  • CSV export — take your inventory out at any time.
  • Risk column — each asset carries a unified risk score combining criticality with its open vulnerabilities and exposure. Criticality acts as a floor, so a business‑critical asset never reads as low risk just because nothing has been found on it yet.
  • Recompute risk — recalculates those scores on demand. It also runs automatically overnight.
  • The map beside the table is filter‑synced — narrow the table and the map narrows with it, so you can see the shape of whatever you’ve just filtered to. See Network connections.
  • Deep links — dashboard and finding views can jump you straight to a highlighted asset.

Open any asset to see its full record: category, owner, criticality, installed software, scan results, and its connections to other assets, which you add and manage from the Connections panel.

Two asset types have an extra panel:

On a domain asset you can enable a web scan (within your plan’s quota) and then run it. Findings populate your Application & Web posture lane, and Download report ↓ gives you a branded PDF.

Domain assets can also be included in an active scan, which sends real attack payloads to confirm whether a vulnerability is exploitable. Active scanning now lives in Testing & Validation, is admin‑gated, and is worth telling your security team about first — see Testing & Validation.

On a cloud asset, the Cloud Security panel connects an AWS, Azure or GCP account for misconfiguration scanning. For AWS it’s one click: Launch Stack ↗ opens CloudFormation with a read‑only role template and your ExternalId pre‑filled — 786 Cyber never gets write access to your cloud, and never sees your credentials. Once connected, enable cloud scanning and run it; findings score in your Cloud Posture lane, with a PDF report available.

The full step‑by‑step is on its own page: Connect a cloud account (CSPM).

For everyday security: a complete, owned inventory is the foundation of everything else — patching, incident response, and knowing what’s exposed to the internet.

For compliance: an accurate asset inventory with owners and criticality is a named requirement in Cyber Essentials Plus, NCA ECC and SAMA CSF. Criticality and ownership also make risk assessments and audits far quicker to evidence.


Next: Network connections →