What We Keep Finding in Enterprise Software Estates

LICENSEWARE has now run NEO Insights across a large body of enterprise software estates, covering organisations of very different sizes, sectors and maturity levels.

Not one of the findings below required new tooling, a new agent, or a new discovery project. Every figure came out of data the organisation already had. The software was already installed. The inventory already existed.

Nobody had read it.

Most companies are paying twice

Figures describe software categories, drawn from the estates whose reports classified every product as paid or free. A category is a functional group such as PDF tools, browsers, or databases.

FindingFigure
Categories with a paid tool that also had a free tool doing the same job87%
Overlapping categories paying for two or more competing commercial tools70%
Overlapping categories paying for three or more competing commercial tools56%
Products in the median overlapping category6
Paid products in the median overlapping category3
Most paid tools competing inside a single category19

Every estate we were able to check had at least one category where a paid tool sat alongside a free equivalent.

The clearest illustration came from a single developer tooling category holding 43 distinct products, 17 of them paid. Four of those were separately licensed IDEs. The install counts tell the story on their own: roughly 1,800 on the first, around 1,000 on the second, under 300 on the third, and exactly one on the fourth. Three separate paid statistics platforms were running alongside them.

Nobody decided to buy four IDEs. It happened one procurement request at a time, over years, with no category-level view to make the accumulation visible. That is what software rationalization exists to surface.

Software the vendor has already abandoned

Figures describe the share of estates analysed.

This is the most defensible category in the entire analysis, because discontinuation is a matter of public record. No assumptions are involved. Either the vendor still ships patches or it does not.

FindingFigure
Still running software its own vendor has discontinued72%
End-of-life SQL Server (2008, 2012 or 2014)56%
End-of-life server, desktop OS or Office software47%
End-of-life Windows Server (2008 or 2012)31%
Windows 7 endpoints still present22%

The product list reads like a museum inventory. Microsoft Silverlight appeared again and again, across thousands of installs. Adobe Flash Player, Adobe AIR, Shockwave and Apple QuickTime all turned up. So did TrueCrypt, which its own authors abandoned mid-security-audit in 2014 and never came back to.

The time-decay findings are the ones worth sitting with:

  • A Citrix component on nearly 4,000 endpoints, almost twelve years past its final security patch
  • A SQL Server component more than thirteen years past support
  • An install-weighted average of 2.3 years past end of support across all dated findings
  • One organisation running seven concurrent versions of the Java JDK, and several running five concurrent versions of SQL Server

A patch that will never arrive is not a licensing problem. It is a permanent opening that cannot be remediated, sitting on the asset register as though it were an ordinary line item. Surfacing it is what software risk and hygiene analysis is for.

Remote access has quietly multiplied

Figures describe the share of estates analysed. Counted products include TeamViewer, AnyDesk, RealVNC, UltraVNC, TigerVNC, TightVNC, Radmin, Ammyy, DameWare, LogMeIn, GoToAssist, Splashtop and ScreenConnect.

FindingFigure
Two or more different remote access tools installed78%
Three or more50%
Four or more34%
Five or more12%
Median number of different remote access products per affected estate3
Most found in a single estate7

One organisation had a single remote access agent deployed on more than 30,000 endpoints. Another was running five different VNC variants alongside TeamViewer.

A note on interpretation, because it matters. The data shows what is installed. It does not show whether anyone signed it off, and we make no claim either way. Many of these tools are deployed deliberately by IT for good reasons.

The finding is not that they are illegitimate. The finding is that half the estates we analysed were maintaining three or more separate remote entry paths, each with its own patch cycle, its own credential model, and its own licence position.

Scanning and capture tools, in volume

Figures describe the share of estates analysed. Counted products include Nmap, Wireshark, tcpdump, Npcap, Advanced IP Scanner, Angry IP Scanner, SoftPerfect, Ettercap, Aircrack, Metasploit and Burp Suite.

FindingFigure
Packet sniffers installed69%
Port or vulnerability scanners installed62%
Two or more different scanning or capture tools56%
Three or more50%
Four or more25%

Wireshark installs ran into the thousands, with more than 300 Nmap installs in a single estate.

These are legitimate tools in the right hands, and the data carries no user or department attribution, so we make no claim about who installed them or why. The observation is about spread. When a quarter of the estates we analysed carry four or more distinct scanning and capture products, that is a footprint worth being able to describe accurately, before somebody else describes it for you.

What staff installed themselves

Figures describe the share of estates analysed.

FindingFigure
Music or video streaming apps installed72%
Personal cloud storage installed66%
Gaming apps installed62%
AI tools the company had not provided28%

Personal cloud storage deserves a second look. Google Drive, Dropbox, Cyberduck and iCloud all appeared in volume, Google Drive across thousands of installs. Every one of those is a route by which a file can leave a managed device without leaving a trace anyone is watching.

The AI findings are newer, and the interesting part is not the chatbots. It is the runtimes.

Alongside the expected consumer AI tools, we found local LLM runtimes installed in production environments: Ollama, LM Studio and Gradio. These sit outside data loss prevention entirely, not because they defeat it, but because the data never leaves the machine for a DLP tool to inspect in the first place. A control that watches the network cannot see a model running on the laptop.

We also found text-based browsers such as Elinks, which render pages in a form that web filtering and DLP tooling are not built to inspect.

Working around controls, at small volume

Figures describe the share of estates analysed.

FindingFigure
Torrent clients, consumer VPNs, password crackers, mouse wigglers or licence keygens installed31%
Mouse wigglers, presence fakers or auto-clickers22%
Torrent or P2P clients12%
Password cracking or credential recovery tools9%
Consumer VPN software6%
Licence keygens or activators3%

One caveat, which we would rather state than have someone find. The install volumes behind these percentages are tiny. Across every estate we looked at, torrent and consumer VPN installs together numbered in the low dozens.

This is a “somebody is doing this” finding, not a “this is everywhere” finding. The percentage counts how many estates had at least one instance, which is genuinely worth knowing, but it is not a measure of scale. Read as evidence of widespread misuse, these numbers are being overread.

Licensing exposure hiding in ordinary software

Figures describe the share of estates analysed.

FindingFigure
Overlapping PDF tooling94%
Multiple or legacy browsers in production84%
Oracle Java SE installed81%
WinRAR or WinZip installed81%
Docker Desktop installed28%

Oracle Java is the one that catches people out, because the exposure has nothing to do with how much you use it. Oracle charges per employee, not per install and not per user. An organisation with 47 Java installs and 4,000 employees is exposed on 4,000.

One estate carried more than 1,800 Oracle Java installs. That figure is not what determines the bill, which is exactly the problem, and why Oracle Java estates have to be modelled against the licensing metric rather than the install count.

WinRAR and WinZip sit in a similar blind spot. Both require commercial licences for corporate use, both are trivially installed, and neither tends to appear on anyone’s renewal calendar.

Fleet, capital and carbon

Figures come from the subset of estates where we also ran a hardware audit, so these are medians and ranges rather than universal claims.

MetricMedianRange
Share of fleet classed legacy or obsolete29%2% to 52%
Windows 11 blockers24924 to over 8,000
Estimated replacement CapEx liability$236k$28k to $2.8M
Estimated annual fleet energy cost$85k$18k to $710k
Annual carbon footprint (tCO2e)342152 to over 6,000

At the top of those ranges sits an organisation with more than half its fleet unable to take Windows 11, and an average asset age approaching a decade. The refresh liability there is not a procurement decision. It is a multi-year capital programme that nobody has budgeted.

The CapEx and energy figures are estimates requiring validation against actual purchasing and utility data. Treat them as orders of magnitude, not budget lines.

The sprawl nobody planned

A handful of single-estate findings illustrate the shape of the problem better than any average:

  • 299 distinct developer tool products inside one category
  • 171 distinct CAD products inside one category
  • 70 distinct database applications, 20 PDF editors and 25 remote support tools in one estate
  • 18 distinct web browsers in production at one organisation
  • 85 fragmented categories and more than 1,200 non-standard applications at another
  • One organisation split almost evenly between Microsoft 365 and LibreOffice, with colleagues on the same team breaking each other’s formatting daily

Brave was flagged as a duplicate in every rationalization report we reviewed. Firefox in nearly all of them. GoToMeeting, Opera, Google Drive and PyCharm recurred across most.

The finding underneath all the findings

Read the sections above and one pattern runs through every one of them.

None of this was hidden. There was no breach, no clever forensics, no tooling these organisations did not already own. The remote access tools were in the inventory. The end-of-life software was in the inventory. The four IDEs were in the inventory.

Every one of them had already paid for discovery, already collected the data, and already had the answer sitting in a table nobody had opened.

The gap was never data. The gap was that nothing turned the data into something a person could act on. A discovery tool that reports thousands of product records has done its job. It has also handed a specialist several days of reading before anyone can make a decision, and in most organisations that reading never happens. There is always something more urgent than reading a report about software you already own.

That is the difference between a reporting layer and decision-ready software intelligence. One tells you what is there. The other tells you what matters, why it matters now, and what should happen next.

Find out what is in yours

Every figure in this post came from data an organisation already had. The only variable was whether anyone read it.

Run NEO Insights against your own software data and find out what is sitting in your estate. If you would rather start with a conversation, book a review.

Source: LICENSEWARE NEO Insights analysis. Figures are drawn from enterprise software estates analysed by LICENSEWARE and describe our own book of work rather than a representative market survey. What each figure is a percentage of is stated per section. Financial and carbon figures are estimates requiring validation against source systems.

Alex Cojocaru

Alex has been active in the software world since he started his career as an Analyst in 2011. He had various roles in software asset management, data analytics, and software development. He walked in the shoes of an analyst, auditor, advisor, and software engineer, being involved in building SAM tools, amongst other data-focused projects. In 2020, Alex co-founded Licenseware and is currently leading the company as CEO.