<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/operational-itam-podcast" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Operational ITAM Podcast</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/operational-itam-podcast</itunes:new-feed-url>
    <description>Thirty years of enterprise IT, distilled into something you can use on Monday morning.

Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.

No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.

New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.</description>
    <copyright>© 2026 EpicB Media LLC</copyright>
    <podcast:guid>d5ea2fb1-a58c-504c-b094-c3ef83c95ec5</podcast:guid>
    <podcast:podroll>
      <podcast:remoteItem feedGuid="801333c8-9953-542c-abc7-15722fe3d33d" feedUrl="https://www.spreaker.com/show/5721911/episodes/feed"/>
      <podcast:remoteItem feedGuid="470c4cc2-dab8-5299-8ae4-18231b39d258" feedUrl="https://ciotalknetwork.libsyn.com/rss"/>
      <podcast:remoteItem feedGuid="ba9bdce3-bec7-51ab-9767-034d9f8d0496" feedUrl="https://feeds.soundcloud.com/users/soundcloud:users:11138381/sounds.rss"/>
      <podcast:remoteItem feedGuid="605626de-4e7c-5a1c-9c5d-1f7773300f42" feedUrl="https://feeds.publicradio.org/public_feeds/marketplace-tech"/>
      <podcast:remoteItem feedGuid="09ecd9f4-8dd3-5eef-99fb-3818f9654251" feedUrl="https://cybersecuritytoday.libsyn.com/rss"/>
      <podcast:remoteItem feedGuid="8ef2a9d7-a244-55ae-8180-7b96ef6e0e0a" feedUrl="https://techblogwriter.libsyn.com/rss"/>
      <podcast:remoteItem feedGuid="73356740-db6e-53b8-b50d-0cc4b0568136" feedUrl="https://anchor.fm/s/57cf8f94/podcast/rss"/>
      <podcast:remoteItem feedGuid="500947e8-2172-5225-95aa-c749eed700eb" feedUrl="https://feeds.buzzsprout.com/1925438.rss"/>
      <podcast:remoteItem feedGuid="32b606ab-7ce4-5102-b07a-5c59c68f8265" feedUrl="https://feeds.simplecast.com/ui_HbBma"/>
      <podcast:remoteItem feedGuid="5fe387cf-ded3-5817-bcc0-7aeb08d5d18f" feedUrl="https://feeds.soundcloud.com/users/soundcloud:users:159335760/sounds.rss"/>
    </podcast:podroll>
    <podcast:locked>yes</podcast:locked>
    <itunes:applepodcastsverify>fdb74760-88f9-11f1-8f05-eba84b7b8a42</itunes:applepodcastsverify>
    <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
    <language>en</language>
    <pubDate>Sat, 15 Aug 2026 17:20:04 -0400</pubDate>
    <lastBuildDate>Tue, 18 Aug 2026 01:05:59 -0400</lastBuildDate>
    <link>https://www.operationalitam.com</link>
    <image>
      <url>https://img.transistorcdn.com/Debovra6CG-Fyz5E-OmSpiKrmImrda3yxVOmBb7_P64/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NjA4/YzdhOWJhZjcyZjYw/ZTY3Y2E1OTM1NTc2/N2M2Yi5wbmc.jpg</url>
      <title>Operational ITAM Podcast</title>
      <link>https://www.operationalitam.com</link>
    </image>
    <itunes:category text="Technology"/>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Bill Van Nort</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/Debovra6CG-Fyz5E-OmSpiKrmImrda3yxVOmBb7_P64/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NjA4/YzdhOWJhZjcyZjYw/ZTY3Y2E1OTM1NTc2/N2M2Yi5wbmc.jpg"/>
    <itunes:summary>Thirty years of enterprise IT, distilled into something you can use on Monday morning.

Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.

No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.

New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.</itunes:summary>
    <itunes:subtitle>Thirty years of enterprise IT, distilled into something you can use on Monday morning.</itunes:subtitle>
    <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
    <itunes:owner>
      <itunes:name>Bill Van Nort</itunes:name>
      <itunes:email>bill@operationalitam.com</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Do You Actually Need a Tool? The Readiness Test</title>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>Do You Actually Need a Tool? The Readiness Test</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">51b5afcc-e9c1-4420-aaf3-3358d9a91aaa</guid>
      <link>https://share.transistor.fm/s/1b9edce9</link>
      <description>
        <![CDATA[<p>Flexera's 2026 State of ITAM Report says complete visibility into the IT estate has dropped to 36 percent, down eleven points across three years, over the same stretch that organizations bought more asset management tooling than at any point in the discipline's history. We bought more and saw less. This episode explains why, and answers the question Mike from Columbus asked back in Episode 001: should we buy a tool, and how would we know?</p><p>Bill lays out the Readiness Test, five questions to answer honestly before any purchase order: Who owns the data? When two systems disagree, which one wins? Can you produce entitlements as documents? Does a lifecycle event change a record today, without a tool? Can someone write down what the tool is for, in one sentence, with a number in it? Fail any one and a platform makes your problems more expensive instead of more visible.</p><p>Then the case for tools, made fairly: what platforms genuinely do well according to Gartner's January 2026 Market Guide, the estate where the tool is a license term rather than a maturity choice (IBM sub-capacity and ILMT), the honest cost picture, and the four signals that it is actually time to buy. Plus, a listener question from Dana in Dayton on what to do when the platform is live and nobody trusts it, the catalog room in the library, and a one-hour homework assignment that will save some organizations two years.</p><p>Sources cited: Flexera 2026 State of ITAM Report; Gartner Market Guide for Software Asset Management Tools (January 2026); IBM Passport Advantage sub-capacity licensing terms; Forrester (2013); EU AI Act Article 50.</p><p>Case files wanted. One situation, one page, anonymized: what the constraint was, what you did, what happened. Details at https://www.operationalitam.com</p><p>Next episode: the AI estate, the first asset class to arrive with a regulator attached.</p><p>Chapters:<br></p><ul><li>(00:03) - Tool Question Answered</li>
<li>(04:31) - Readiness Test</li>
<li>(07:42) - Market Tells On Itself</li>
<li>(09:24) - What To Do Instead</li>
<li>(11:22) - When Tools Make Sense</li>
<li>(13:55) - When To Buy</li>
<li>(16:45) - The Library Catalog Lesson</li>
<li>(18:10) - Tooling Is Judgment</li>
<li>(19:23) - Homework And Next Episode</li>
</ul><br><a href="https://share.transistor.fm/s/1b9edce9/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>Operational ITAM Podcast · https://www.operationalitam.com · Bill Van Nort on LinkedIn: https://www.linkedin.com/in/billvannort/]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Flexera's 2026 State of ITAM Report says complete visibility into the IT estate has dropped to 36 percent, down eleven points across three years, over the same stretch that organizations bought more asset management tooling than at any point in the discipline's history. We bought more and saw less. This episode explains why, and answers the question Mike from Columbus asked back in Episode 001: should we buy a tool, and how would we know?</p><p>Bill lays out the Readiness Test, five questions to answer honestly before any purchase order: Who owns the data? When two systems disagree, which one wins? Can you produce entitlements as documents? Does a lifecycle event change a record today, without a tool? Can someone write down what the tool is for, in one sentence, with a number in it? Fail any one and a platform makes your problems more expensive instead of more visible.</p><p>Then the case for tools, made fairly: what platforms genuinely do well according to Gartner's January 2026 Market Guide, the estate where the tool is a license term rather than a maturity choice (IBM sub-capacity and ILMT), the honest cost picture, and the four signals that it is actually time to buy. Plus, a listener question from Dana in Dayton on what to do when the platform is live and nobody trusts it, the catalog room in the library, and a one-hour homework assignment that will save some organizations two years.</p><p>Sources cited: Flexera 2026 State of ITAM Report; Gartner Market Guide for Software Asset Management Tools (January 2026); IBM Passport Advantage sub-capacity licensing terms; Forrester (2013); EU AI Act Article 50.</p><p>Case files wanted. One situation, one page, anonymized: what the constraint was, what you did, what happened. Details at https://www.operationalitam.com</p><p>Next episode: the AI estate, the first asset class to arrive with a regulator attached.</p><p>Chapters:<br></p><ul><li>(00:03) - Tool Question Answered</li>
<li>(04:31) - Readiness Test</li>
<li>(07:42) - Market Tells On Itself</li>
<li>(09:24) - What To Do Instead</li>
<li>(11:22) - When Tools Make Sense</li>
<li>(13:55) - When To Buy</li>
<li>(16:45) - The Library Catalog Lesson</li>
<li>(18:10) - Tooling Is Judgment</li>
<li>(19:23) - Homework And Next Episode</li>
</ul><br><a href="https://share.transistor.fm/s/1b9edce9/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>Operational ITAM Podcast · https://www.operationalitam.com · Bill Van Nort on LinkedIn: https://www.linkedin.com/in/billvannort/]]>
      </content:encoded>
      <pubDate>Sat, 15 Aug 2026 17:20:04 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/1b9edce9/7e7a2217.mp3" length="18592351" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/i9nWEZhd5WEo6SBmjYPT6g3etnYlvEqSi4a-a6U6XUU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iZWZj/YWQ0YjUyOTU0MTUz/MjZiOWQ2OWE2NWU2/MjI5NC5wbmc.jpg"/>
      <itunes:duration>1304</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Flexera's 2026 State of ITAM Report says complete visibility into the IT estate has dropped to 36 percent, down eleven points across three years, over the same stretch that organizations bought more asset management tooling than at any point in the discipline's history. We bought more and saw less. This episode explains why, and answers the question Mike from Columbus asked back in Episode 001: should we buy a tool, and how would we know?</p><p>Bill lays out the Readiness Test, five questions to answer honestly before any purchase order: Who owns the data? When two systems disagree, which one wins? Can you produce entitlements as documents? Does a lifecycle event change a record today, without a tool? Can someone write down what the tool is for, in one sentence, with a number in it? Fail any one and a platform makes your problems more expensive instead of more visible.</p><p>Then the case for tools, made fairly: what platforms genuinely do well according to Gartner's January 2026 Market Guide, the estate where the tool is a license term rather than a maturity choice (IBM sub-capacity and ILMT), the honest cost picture, and the four signals that it is actually time to buy. Plus, a listener question from Dana in Dayton on what to do when the platform is live and nobody trusts it, the catalog room in the library, and a one-hour homework assignment that will save some organizations two years.</p><p>Sources cited: Flexera 2026 State of ITAM Report; Gartner Market Guide for Software Asset Management Tools (January 2026); IBM Passport Advantage sub-capacity licensing terms; Forrester (2013); EU AI Act Article 50.</p><p>Case files wanted. One situation, one page, anonymized: what the constraint was, what you did, what happened. Details at https://www.operationalitam.com</p><p>Next episode: the AI estate, the first asset class to arrive with a regulator attached.</p><p>Chapters:<br></p><ul><li>(00:03) - Tool Question Answered</li>
<li>(04:31) - Readiness Test</li>
<li>(07:42) - Market Tells On Itself</li>
<li>(09:24) - What To Do Instead</li>
<li>(11:22) - When Tools Make Sense</li>
<li>(13:55) - When To Buy</li>
<li>(16:45) - The Library Catalog Lesson</li>
<li>(18:10) - Tooling Is Judgment</li>
<li>(19:23) - Homework And Next Episode</li>
</ul><br><a href="https://share.transistor.fm/s/1b9edce9/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>Operational ITAM Podcast · https://www.operationalitam.com · Bill Van Nort on LinkedIn: https://www.linkedin.com/in/billvannort/]]>
      </itunes:summary>
      <itunes:keywords>ITAM tools, SAM tools, software asset management, tool selection, ITAM readiness, CMDB, license position, entitlement management, ILMT, IBM sub-capacity, Flexera, ServiceNow SAM, Gartner Market Guide, State of ITAM 2026, ITAM maturity, IT asset management, Operational ITAM</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/1b9edce9/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/1b9edce9/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Renewals: The Negotiation You Can Actually Win</title>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>Renewals: The Negotiation You Can Actually Win</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2974b982-2a04-4bb4-943a-2259eb16f080</guid>
      <link>https://share.transistor.fm/s/9c3a4091</link>
      <description>
        <![CDATA[<p>Microsoft gave everyone seven months of warning. Almost nobody had a plan. The gap between the memo and the plan is the whole episode.</p><p>An audit arrives on somebody else's schedule. A settlement is negotiated from behind. Shadow IT happens whether you sanction it or not. Disposal's best possible outcome is that nothing happens to you. The renewal is different. It is the only recurring event in asset management where the date is known years in advance, where the other side needs something from you, and where you decide when the work begins. And we blow it consistently as a profession.</p><p>This one is the 18-month clock — four positions, each with exactly one job — and the five traps written into paper you have already signed. The thesis is not subtle: in a renewal, timing beats tactics. The clever negotiator who starts 60 days out loses to the mediocre one who started 18 months out. Every lever in this episode takes months to build and four seconds to deploy.</p><p>A listener in Indianapolis writes in six weeks from a renewal whose quote just doubled, and gets an honest answer rather than an encouraging one.</p><p>IN THIS EPISODE</p><p>- Why 61% of IT leaders cut a project or initiative to pay for unplanned software cost increases — renewals are now cancelling roadmap items, not headcount<br>- Flat application counts and 8% more money: the growth is not sprawl anymore, it is price<br>- The 18-month clock — count, decide, build, ask — and the 60-day cliff most programs are actually standing on<br>- The version of shelfware that survives every audit and fails every business case: deployed, assigned, compliant, and completely idle<br>- Why leverage is a documented, costed, credible answer to "and what if we don't" — and why it never has to be executed<br>- Broadcom/VMware and Oracle Java as live worked examples, including opening quotes that overstated the actual footprint by 20 to 40%<br>- Five traps: the notice window, the uplift clause, the co-term, the discount shell game, and the multi-year commitment<br>- Why you should never negotiate against list price, and the one discipline that catches more money than every other tactic combined<br>- The University of California walking away from Elsevier, and the single reason they could</p><p>CHAPTERS<br></p><ul><li>(00:03) - Renewal Power Plays</li>
<li>(03:15) - The 18-Month Clock</li>
<li>(05:56) - VMware and Java Leverage</li>
<li>(09:22) - Renewal Traps</li>
<li>(13:58) - Six Weeks Left</li>
<li>(15:46) - The Serials Department</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/9c3a4091/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft 365 pricing and packaging updates — the official notice. Announced 4 December, effective 1 July 2026, covering Enterprise, Business, Frontline, and Government commercial equivalents. Office 365 E3 moves from $23 to $26 per user per month, Microsoft 365 E5 from $57 to $60, with Frontline plans rising as much as 43%.<br>https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates</p><p>Zylo 2026 SaaS Management Index — 305 applications and roughly $55.7M average annual SaaS spend, up about 8% year over year on a flat application count. Also the source for 54% average license utilization, 79% of IT leaders seeing a renewal price increase, 78% hit with unexpected consumption or AI charges, and 61% cutting a project to absorb unplanned software cost.<br>https://zylo.com/2026-saas-management-index</p><p>VMware distributor Arrow says minimum software subs set to jump from 16 to 72 cores — The Register, 28 March 2025. The primary reporting on the minimum core-count change and the 20% penalty for subscriptions not renewed by the anniversary date.<br>https://www.theregister.com/2025/03/28/arrow_vmware_licensing_change/</p><p>VMware Cloud Foundation — current product and licensing information<br>https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation</p><p>Oracle Java SE Universal Subscription — the per-employee licensing metric introduced in January 2023<br>https://www.oracle.com/java/java-se-subscription/</p><p>Organizations are parting ways with Oracle Java for open-source alternatives — IT Brew, 29 July 2025, reporting on the joint ITAM Forum and Azul survey of 500 IT and software asset management professionals, which found 79% of organizations have migrated away from Oracle Java or plan to.<br>https://www.itbrew.com/stories/2025/07/29/organizations-are-parting-ways-with-oracle-java-for-open-source-alternatives</p><p>OpenJDK distributions referenced in this episode: Eclipse Adoptium, Amazon Corretto, Azul Zulu, Red Hat build of OpenJDK, and the Microsoft Build of OpenJDK</p><p>UC terminates subscriptions with the world's largest scientific publisher in push for open access — University of California, 2019. The Elsevier walk-away referenced in the library segment.<br>https://www.universityofcalifornia.edu/press-room/uc-terminates-subscriptions-worlds-largest-scientific-publisher-push-open-access</p><p>A note on evidence: settlement terms and negotiated pricing are almost universally covered by non-disclosure, so no public dataset of renewal outcomes exists. The advisory-firm figures on VMware settlement ranges and quote overstatement are reported observations rather than published research, and the negotiation guidance in this episode reflects thirty years on the customer side of the table. It is offered as practitioner knowledge, not as study findings.</p><p>THE COMPANION TOOL</p><p>The 90-Day Pre-Renewal Readiness Checklist executes what this episode describes — 57 checks across intake, waste signal analysis, business owner validation, and negotiation preparation, with an owner and an evidence artefact named for every item. Free, no email required.<br>https://www.operationalitam.com/pages/resources.html</p><p>RELATED EPISODES</p><p>Episode 003 — Software Asset Management: Proving What You Own<br>Episode 004 — Surviving a Software Audit, Part One: The Letter Lands<br>Episode 005 — Surviving a Software Audit, Part Two: The Settlement</p><p>LISTENER CASE FILES</p><p>Got a renewal you cannot justify, or a notice window closing faster than your data is coming together? Send it over — anonymized, sanitized, no company names. Just the situation, what you did, and what happened.<br>https://www.operationalitam.com/pages/podcast-ask.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft gave everyone seven months of warning. Almost nobody had a plan. The gap between the memo and the plan is the whole episode.</p><p>An audit arrives on somebody else's schedule. A settlement is negotiated from behind. Shadow IT happens whether you sanction it or not. Disposal's best possible outcome is that nothing happens to you. The renewal is different. It is the only recurring event in asset management where the date is known years in advance, where the other side needs something from you, and where you decide when the work begins. And we blow it consistently as a profession.</p><p>This one is the 18-month clock — four positions, each with exactly one job — and the five traps written into paper you have already signed. The thesis is not subtle: in a renewal, timing beats tactics. The clever negotiator who starts 60 days out loses to the mediocre one who started 18 months out. Every lever in this episode takes months to build and four seconds to deploy.</p><p>A listener in Indianapolis writes in six weeks from a renewal whose quote just doubled, and gets an honest answer rather than an encouraging one.</p><p>IN THIS EPISODE</p><p>- Why 61% of IT leaders cut a project or initiative to pay for unplanned software cost increases — renewals are now cancelling roadmap items, not headcount<br>- Flat application counts and 8% more money: the growth is not sprawl anymore, it is price<br>- The 18-month clock — count, decide, build, ask — and the 60-day cliff most programs are actually standing on<br>- The version of shelfware that survives every audit and fails every business case: deployed, assigned, compliant, and completely idle<br>- Why leverage is a documented, costed, credible answer to "and what if we don't" — and why it never has to be executed<br>- Broadcom/VMware and Oracle Java as live worked examples, including opening quotes that overstated the actual footprint by 20 to 40%<br>- Five traps: the notice window, the uplift clause, the co-term, the discount shell game, and the multi-year commitment<br>- Why you should never negotiate against list price, and the one discipline that catches more money than every other tactic combined<br>- The University of California walking away from Elsevier, and the single reason they could</p><p>CHAPTERS<br></p><ul><li>(00:03) - Renewal Power Plays</li>
<li>(03:15) - The 18-Month Clock</li>
<li>(05:56) - VMware and Java Leverage</li>
<li>(09:22) - Renewal Traps</li>
<li>(13:58) - Six Weeks Left</li>
<li>(15:46) - The Serials Department</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/9c3a4091/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft 365 pricing and packaging updates — the official notice. Announced 4 December, effective 1 July 2026, covering Enterprise, Business, Frontline, and Government commercial equivalents. Office 365 E3 moves from $23 to $26 per user per month, Microsoft 365 E5 from $57 to $60, with Frontline plans rising as much as 43%.<br>https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates</p><p>Zylo 2026 SaaS Management Index — 305 applications and roughly $55.7M average annual SaaS spend, up about 8% year over year on a flat application count. Also the source for 54% average license utilization, 79% of IT leaders seeing a renewal price increase, 78% hit with unexpected consumption or AI charges, and 61% cutting a project to absorb unplanned software cost.<br>https://zylo.com/2026-saas-management-index</p><p>VMware distributor Arrow says minimum software subs set to jump from 16 to 72 cores — The Register, 28 March 2025. The primary reporting on the minimum core-count change and the 20% penalty for subscriptions not renewed by the anniversary date.<br>https://www.theregister.com/2025/03/28/arrow_vmware_licensing_change/</p><p>VMware Cloud Foundation — current product and licensing information<br>https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation</p><p>Oracle Java SE Universal Subscription — the per-employee licensing metric introduced in January 2023<br>https://www.oracle.com/java/java-se-subscription/</p><p>Organizations are parting ways with Oracle Java for open-source alternatives — IT Brew, 29 July 2025, reporting on the joint ITAM Forum and Azul survey of 500 IT and software asset management professionals, which found 79% of organizations have migrated away from Oracle Java or plan to.<br>https://www.itbrew.com/stories/2025/07/29/organizations-are-parting-ways-with-oracle-java-for-open-source-alternatives</p><p>OpenJDK distributions referenced in this episode: Eclipse Adoptium, Amazon Corretto, Azul Zulu, Red Hat build of OpenJDK, and the Microsoft Build of OpenJDK</p><p>UC terminates subscriptions with the world's largest scientific publisher in push for open access — University of California, 2019. The Elsevier walk-away referenced in the library segment.<br>https://www.universityofcalifornia.edu/press-room/uc-terminates-subscriptions-worlds-largest-scientific-publisher-push-open-access</p><p>A note on evidence: settlement terms and negotiated pricing are almost universally covered by non-disclosure, so no public dataset of renewal outcomes exists. The advisory-firm figures on VMware settlement ranges and quote overstatement are reported observations rather than published research, and the negotiation guidance in this episode reflects thirty years on the customer side of the table. It is offered as practitioner knowledge, not as study findings.</p><p>THE COMPANION TOOL</p><p>The 90-Day Pre-Renewal Readiness Checklist executes what this episode describes — 57 checks across intake, waste signal analysis, business owner validation, and negotiation preparation, with an owner and an evidence artefact named for every item. Free, no email required.<br>https://www.operationalitam.com/pages/resources.html</p><p>RELATED EPISODES</p><p>Episode 003 — Software Asset Management: Proving What You Own<br>Episode 004 — Surviving a Software Audit, Part One: The Letter Lands<br>Episode 005 — Surviving a Software Audit, Part Two: The Settlement</p><p>LISTENER CASE FILES</p><p>Got a renewal you cannot justify, or a notice window closing faster than your data is coming together? Send it over — anonymized, sanitized, no company names. Just the situation, what you did, and what happened.<br>https://www.operationalitam.com/pages/podcast-ask.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Mon, 03 Aug 2026 21:41:33 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/9c3a4091/afb6f234.mp3" length="17122850" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GY42WXzfZvmPYiil54Zs34tRRSdS7IiPLWorm4yTOi8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zMmFh/MDRlMDNmOTI0ZjEw/OGI5NzA4MmQ3N2Q1/Mjk5MC5wbmc.jpg"/>
      <itunes:duration>1221</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Microsoft gave everyone seven months of warning. Almost nobody had a plan. The gap between the memo and the plan is the whole episode.</p><p>An audit arrives on somebody else's schedule. A settlement is negotiated from behind. Shadow IT happens whether you sanction it or not. Disposal's best possible outcome is that nothing happens to you. The renewal is different. It is the only recurring event in asset management where the date is known years in advance, where the other side needs something from you, and where you decide when the work begins. And we blow it consistently as a profession.</p><p>This one is the 18-month clock — four positions, each with exactly one job — and the five traps written into paper you have already signed. The thesis is not subtle: in a renewal, timing beats tactics. The clever negotiator who starts 60 days out loses to the mediocre one who started 18 months out. Every lever in this episode takes months to build and four seconds to deploy.</p><p>A listener in Indianapolis writes in six weeks from a renewal whose quote just doubled, and gets an honest answer rather than an encouraging one.</p><p>IN THIS EPISODE</p><p>- Why 61% of IT leaders cut a project or initiative to pay for unplanned software cost increases — renewals are now cancelling roadmap items, not headcount<br>- Flat application counts and 8% more money: the growth is not sprawl anymore, it is price<br>- The 18-month clock — count, decide, build, ask — and the 60-day cliff most programs are actually standing on<br>- The version of shelfware that survives every audit and fails every business case: deployed, assigned, compliant, and completely idle<br>- Why leverage is a documented, costed, credible answer to "and what if we don't" — and why it never has to be executed<br>- Broadcom/VMware and Oracle Java as live worked examples, including opening quotes that overstated the actual footprint by 20 to 40%<br>- Five traps: the notice window, the uplift clause, the co-term, the discount shell game, and the multi-year commitment<br>- Why you should never negotiate against list price, and the one discipline that catches more money than every other tactic combined<br>- The University of California walking away from Elsevier, and the single reason they could</p><p>CHAPTERS<br></p><ul><li>(00:03) - Renewal Power Plays</li>
<li>(03:15) - The 18-Month Clock</li>
<li>(05:56) - VMware and Java Leverage</li>
<li>(09:22) - Renewal Traps</li>
<li>(13:58) - Six Weeks Left</li>
<li>(15:46) - The Serials Department</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/9c3a4091/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft 365 pricing and packaging updates — the official notice. Announced 4 December, effective 1 July 2026, covering Enterprise, Business, Frontline, and Government commercial equivalents. Office 365 E3 moves from $23 to $26 per user per month, Microsoft 365 E5 from $57 to $60, with Frontline plans rising as much as 43%.<br>https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates</p><p>Zylo 2026 SaaS Management Index — 305 applications and roughly $55.7M average annual SaaS spend, up about 8% year over year on a flat application count. Also the source for 54% average license utilization, 79% of IT leaders seeing a renewal price increase, 78% hit with unexpected consumption or AI charges, and 61% cutting a project to absorb unplanned software cost.<br>https://zylo.com/2026-saas-management-index</p><p>VMware distributor Arrow says minimum software subs set to jump from 16 to 72 cores — The Register, 28 March 2025. The primary reporting on the minimum core-count change and the 20% penalty for subscriptions not renewed by the anniversary date.<br>https://www.theregister.com/2025/03/28/arrow_vmware_licensing_change/</p><p>VMware Cloud Foundation — current product and licensing information<br>https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation</p><p>Oracle Java SE Universal Subscription — the per-employee licensing metric introduced in January 2023<br>https://www.oracle.com/java/java-se-subscription/</p><p>Organizations are parting ways with Oracle Java for open-source alternatives — IT Brew, 29 July 2025, reporting on the joint ITAM Forum and Azul survey of 500 IT and software asset management professionals, which found 79% of organizations have migrated away from Oracle Java or plan to.<br>https://www.itbrew.com/stories/2025/07/29/organizations-are-parting-ways-with-oracle-java-for-open-source-alternatives</p><p>OpenJDK distributions referenced in this episode: Eclipse Adoptium, Amazon Corretto, Azul Zulu, Red Hat build of OpenJDK, and the Microsoft Build of OpenJDK</p><p>UC terminates subscriptions with the world's largest scientific publisher in push for open access — University of California, 2019. The Elsevier walk-away referenced in the library segment.<br>https://www.universityofcalifornia.edu/press-room/uc-terminates-subscriptions-worlds-largest-scientific-publisher-push-open-access</p><p>A note on evidence: settlement terms and negotiated pricing are almost universally covered by non-disclosure, so no public dataset of renewal outcomes exists. The advisory-firm figures on VMware settlement ranges and quote overstatement are reported observations rather than published research, and the negotiation guidance in this episode reflects thirty years on the customer side of the table. It is offered as practitioner knowledge, not as study findings.</p><p>THE COMPANION TOOL</p><p>The 90-Day Pre-Renewal Readiness Checklist executes what this episode describes — 57 checks across intake, waste signal analysis, business owner validation, and negotiation preparation, with an owner and an evidence artefact named for every item. Free, no email required.<br>https://www.operationalitam.com/pages/resources.html</p><p>RELATED EPISODES</p><p>Episode 003 — Software Asset Management: Proving What You Own<br>Episode 004 — Surviving a Software Audit, Part One: The Letter Lands<br>Episode 005 — Surviving a Software Audit, Part Two: The Settlement</p><p>LISTENER CASE FILES</p><p>Got a renewal you cannot justify, or a notice window closing faster than your data is coming together? Send it over — anonymized, sanitized, no company names. Just the situation, what you did, and what happened.<br>https://www.operationalitam.com/pages/podcast-ask.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/9c3a4091/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/9c3a4091/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Surviving a Software Audit, Part One: The Letter Lands</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Surviving a Software Audit, Part One: The Letter Lands</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">65f0de50-4dd4-4998-8fea-0a1c41ce1fea</guid>
      <link>https://share.transistor.fm/s/c727725b</link>
      <description>
        <![CDATA[<p>The first seventy-two hours decide the outcome. Five opening moves for the moment the audit notice arrives.</p><p>Part one of two. The letter arrives — or, increasingly, the friendly invitation to a "SAM engagement" that is an audit wearing a nicer coat. What you do in the first seventy-two hours shapes everything that follows.</p><p>Bill lays out five opening moves: contain it, read the contract, control the terms, build your own position before you share anything, and control the data. Along the way: which publishers audit most aggressively, why third-party audit firms are paid by the vendor and what that means for you, why unverified script output drives more inflated claims than actual non-compliance does, and the single most expensive instinct in this situation — panic-buying licenses after the notice arrives, which frequently doesn't count toward the findings anyway.</p><p>Plus a listener question from Sandra in Grand Rapids on the soft-audit trap.</p><p>Part two picks up when the findings document lands.</p><p>IN THIS EPISODE</p><p>- The five opening moves for the first seventy-two hours<br>- Soft audits and "SAM engagement" invitations — the audit wearing a nicer coat<br>- What your contract's audit clause actually permits, and what it doesn't<br>- Why third-party audit firms are paid by the publisher, and what that changes<br>- Building your own license position before you share a single data point<br>- Controlling the data: what you provide, in what format, and what you never send<br>- Why unverified script output drives more inflated claims than real non-compliance<br>- The most expensive instinct in the room: panic-buying licenses after the notice<br>- Which publishers audit most aggressively, and what the current data shows</p><p>CHAPTERS<br></p><ul><li>(00:03) - Audit Defense Begins</li>
<li>(02:11) - Audit Reality Check</li>
<li>(05:10) - Five Opening Moves</li>
<li>(08:00) - Negotiating Audit Terms</li>
<li>(09:35) - Build Your Position</li>
<li>(11:08) - Control the Data</li>
<li>(13:29) - Settlement and Takeaways</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/c727725b/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report — audit activity by publisher<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>Audit incidence and publisher behavior in this episode is drawn from licensing advisory practice and from thirty years of firsthand audit response. Where a figure rests on industry survey data rather than primary research, it is stated as such on air.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>The first seventy-two hours decide the outcome. Five opening moves for the moment the audit notice arrives.</p><p>Part one of two. The letter arrives — or, increasingly, the friendly invitation to a "SAM engagement" that is an audit wearing a nicer coat. What you do in the first seventy-two hours shapes everything that follows.</p><p>Bill lays out five opening moves: contain it, read the contract, control the terms, build your own position before you share anything, and control the data. Along the way: which publishers audit most aggressively, why third-party audit firms are paid by the vendor and what that means for you, why unverified script output drives more inflated claims than actual non-compliance does, and the single most expensive instinct in this situation — panic-buying licenses after the notice arrives, which frequently doesn't count toward the findings anyway.</p><p>Plus a listener question from Sandra in Grand Rapids on the soft-audit trap.</p><p>Part two picks up when the findings document lands.</p><p>IN THIS EPISODE</p><p>- The five opening moves for the first seventy-two hours<br>- Soft audits and "SAM engagement" invitations — the audit wearing a nicer coat<br>- What your contract's audit clause actually permits, and what it doesn't<br>- Why third-party audit firms are paid by the publisher, and what that changes<br>- Building your own license position before you share a single data point<br>- Controlling the data: what you provide, in what format, and what you never send<br>- Why unverified script output drives more inflated claims than real non-compliance<br>- The most expensive instinct in the room: panic-buying licenses after the notice<br>- Which publishers audit most aggressively, and what the current data shows</p><p>CHAPTERS<br></p><ul><li>(00:03) - Audit Defense Begins</li>
<li>(02:11) - Audit Reality Check</li>
<li>(05:10) - Five Opening Moves</li>
<li>(08:00) - Negotiating Audit Terms</li>
<li>(09:35) - Build Your Position</li>
<li>(11:08) - Control the Data</li>
<li>(13:29) - Settlement and Takeaways</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/c727725b/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report — audit activity by publisher<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>Audit incidence and publisher behavior in this episode is drawn from licensing advisory practice and from thirty years of firsthand audit response. Where a figure rests on industry survey data rather than primary research, it is stated as such on air.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Sun, 02 Aug 2026 13:41:33 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/c727725b/49e0ea47.mp3" length="11679351" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Ytgv_hOE_4cJtP5GoGhhTDEJ3A6b6cTRd0wMPW5_HKM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iZGFi/ZDU1YWQ0OGEyYTEy/YTZhYzBiY2Y4NmVj/MWFmNC5wbmc.jpg"/>
      <itunes:duration>971</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>The first seventy-two hours decide the outcome. Five opening moves for the moment the audit notice arrives.</p><p>Part one of two. The letter arrives — or, increasingly, the friendly invitation to a "SAM engagement" that is an audit wearing a nicer coat. What you do in the first seventy-two hours shapes everything that follows.</p><p>Bill lays out five opening moves: contain it, read the contract, control the terms, build your own position before you share anything, and control the data. Along the way: which publishers audit most aggressively, why third-party audit firms are paid by the vendor and what that means for you, why unverified script output drives more inflated claims than actual non-compliance does, and the single most expensive instinct in this situation — panic-buying licenses after the notice arrives, which frequently doesn't count toward the findings anyway.</p><p>Plus a listener question from Sandra in Grand Rapids on the soft-audit trap.</p><p>Part two picks up when the findings document lands.</p><p>IN THIS EPISODE</p><p>- The five opening moves for the first seventy-two hours<br>- Soft audits and "SAM engagement" invitations — the audit wearing a nicer coat<br>- What your contract's audit clause actually permits, and what it doesn't<br>- Why third-party audit firms are paid by the publisher, and what that changes<br>- Building your own license position before you share a single data point<br>- Controlling the data: what you provide, in what format, and what you never send<br>- Why unverified script output drives more inflated claims than real non-compliance<br>- The most expensive instinct in the room: panic-buying licenses after the notice<br>- Which publishers audit most aggressively, and what the current data shows</p><p>CHAPTERS<br></p><ul><li>(00:03) - Audit Defense Begins</li>
<li>(02:11) - Audit Reality Check</li>
<li>(05:10) - Five Opening Moves</li>
<li>(08:00) - Negotiating Audit Terms</li>
<li>(09:35) - Build Your Position</li>
<li>(11:08) - Control the Data</li>
<li>(13:29) - Settlement and Takeaways</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/c727725b/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report — audit activity by publisher<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>Audit incidence and publisher behavior in this episode is drawn from licensing advisory practice and from thirty years of firsthand audit response. Where a figure rests on industry survey data rather than primary research, it is stated as such on air.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/c727725b/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/c727725b/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Welcome to Operational ITAM: Know What You Own</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Welcome to Operational ITAM: Know What You Own</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5037e782-af31-497d-9709-8c904f7e0de6</guid>
      <link>https://share.transistor.fm/s/92a4149a</link>
      <description>
        <![CDATA[<p>Thirty years in enterprise IT, distilled into four questions every asset program has to answer.</p><p>The pilot episode. Host Bill Van Nort opens the series with three decades of enterprise IT leadership behind him — banking, mortgage, automotive — and a straightforward thesis: buried inside a boring-sounding phrase are millions of dollars, real career leverage, and some of the best war stories in enterprise technology.</p><p>This episode establishes the four fundamentals every program must answer: know what you have, know where it is, know what it costs, know when it leaves. Bill explains why asset management is ultimately a trust discipline rather than an inventory discipline, states his biases up front — evidence over enthusiasm, customer over publisher, simple over clever — and previews the season ahead.</p><p>Plus: a listener question from Mike in Columbus on what to do when leadership says an ITAM tool isn't in the budget.</p><p>IN THIS EPISODE</p><p>- Why nobody notices asset management until it's broken<br>- The four fundamentals: know what you have, where it is, what it costs, when it leaves<br>- Why IT asset management is really about trust, not assets<br>- How the same fifteen questions wear two hundred different outfits<br>- Starting an ITAM program with no tool and no budget<br>- What license compliance actually costs when nobody is keeping score<br>- The show's format, biases, and what's coming this season</p><p>CHAPTERS<br></p><ul><li>(00:23) - Podcast Opening</li>
<li>(01:15) - Why Asset Counts Matter</li>
<li>(02:05) - The Four Fundamentals</li>
<li>(02:46) - Invisible Until Broken</li>
<li>(03:16) - The Cost of Chaos</li>
<li>(04:16) - Human Side of ITAM</li>
<li>(05:01) - Show Format Explained</li>
<li>(05:29) - Bill’s Background</li>
<li>(06:17) - ITAM Is About Trust</li>
<li>(06:59) - What’s Coming Next</li>
<li>(07:16) - Start Without a Tool</li>
<li>(08:04) - Why This Podcast Exists</li>
<li>(08:45) - Show Biases and Principles</li>
<li>(09:24) - Season Preview</li>
<li>(10:09) - Listener Case Files</li>
<li>(10:35) - Who This Show Isn’t For</li>
<li>(11:01) - New Names, Same Discipline</li>
<li>(11:46) - Closing Thanks</li>
<li>(12:21) - Final Takeaway</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/92a4149a/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>FURTHER READING<p>ISO/IEC 19770-1 — IT Asset Management Systems standard<br>https://www.iso.org/standard/68531.html</p><p>IAITAM — International Association of IT Asset Managers<br>https://www.iaitam.org</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Thirty years in enterprise IT, distilled into four questions every asset program has to answer.</p><p>The pilot episode. Host Bill Van Nort opens the series with three decades of enterprise IT leadership behind him — banking, mortgage, automotive — and a straightforward thesis: buried inside a boring-sounding phrase are millions of dollars, real career leverage, and some of the best war stories in enterprise technology.</p><p>This episode establishes the four fundamentals every program must answer: know what you have, know where it is, know what it costs, know when it leaves. Bill explains why asset management is ultimately a trust discipline rather than an inventory discipline, states his biases up front — evidence over enthusiasm, customer over publisher, simple over clever — and previews the season ahead.</p><p>Plus: a listener question from Mike in Columbus on what to do when leadership says an ITAM tool isn't in the budget.</p><p>IN THIS EPISODE</p><p>- Why nobody notices asset management until it's broken<br>- The four fundamentals: know what you have, where it is, what it costs, when it leaves<br>- Why IT asset management is really about trust, not assets<br>- How the same fifteen questions wear two hundred different outfits<br>- Starting an ITAM program with no tool and no budget<br>- What license compliance actually costs when nobody is keeping score<br>- The show's format, biases, and what's coming this season</p><p>CHAPTERS<br></p><ul><li>(00:23) - Podcast Opening</li>
<li>(01:15) - Why Asset Counts Matter</li>
<li>(02:05) - The Four Fundamentals</li>
<li>(02:46) - Invisible Until Broken</li>
<li>(03:16) - The Cost of Chaos</li>
<li>(04:16) - Human Side of ITAM</li>
<li>(05:01) - Show Format Explained</li>
<li>(05:29) - Bill’s Background</li>
<li>(06:17) - ITAM Is About Trust</li>
<li>(06:59) - What’s Coming Next</li>
<li>(07:16) - Start Without a Tool</li>
<li>(08:04) - Why This Podcast Exists</li>
<li>(08:45) - Show Biases and Principles</li>
<li>(09:24) - Season Preview</li>
<li>(10:09) - Listener Case Files</li>
<li>(10:35) - Who This Show Isn’t For</li>
<li>(11:01) - New Names, Same Discipline</li>
<li>(11:46) - Closing Thanks</li>
<li>(12:21) - Final Takeaway</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/92a4149a/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>FURTHER READING<p>ISO/IEC 19770-1 — IT Asset Management Systems standard<br>https://www.iso.org/standard/68531.html</p><p>IAITAM — International Association of IT Asset Managers<br>https://www.iaitam.org</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Sun, 02 Aug 2026 13:39:17 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/92a4149a/a75d2f88.mp3" length="9376127" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/OxgCp14s_5LxktHGnTSkygEbb5kLh6rVCiYGTWSTD2U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZDI2/NjM4NDczMDU4OTc5/Y2ZhYzVmOGQ0OWFm/ZDM3MS5wbmc.jpg"/>
      <itunes:duration>779</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Thirty years in enterprise IT, distilled into four questions every asset program has to answer.</p><p>The pilot episode. Host Bill Van Nort opens the series with three decades of enterprise IT leadership behind him — banking, mortgage, automotive — and a straightforward thesis: buried inside a boring-sounding phrase are millions of dollars, real career leverage, and some of the best war stories in enterprise technology.</p><p>This episode establishes the four fundamentals every program must answer: know what you have, know where it is, know what it costs, know when it leaves. Bill explains why asset management is ultimately a trust discipline rather than an inventory discipline, states his biases up front — evidence over enthusiasm, customer over publisher, simple over clever — and previews the season ahead.</p><p>Plus: a listener question from Mike in Columbus on what to do when leadership says an ITAM tool isn't in the budget.</p><p>IN THIS EPISODE</p><p>- Why nobody notices asset management until it's broken<br>- The four fundamentals: know what you have, where it is, what it costs, when it leaves<br>- Why IT asset management is really about trust, not assets<br>- How the same fifteen questions wear two hundred different outfits<br>- Starting an ITAM program with no tool and no budget<br>- What license compliance actually costs when nobody is keeping score<br>- The show's format, biases, and what's coming this season</p><p>CHAPTERS<br></p><ul><li>(00:23) - Podcast Opening</li>
<li>(01:15) - Why Asset Counts Matter</li>
<li>(02:05) - The Four Fundamentals</li>
<li>(02:46) - Invisible Until Broken</li>
<li>(03:16) - The Cost of Chaos</li>
<li>(04:16) - Human Side of ITAM</li>
<li>(05:01) - Show Format Explained</li>
<li>(05:29) - Bill’s Background</li>
<li>(06:17) - ITAM Is About Trust</li>
<li>(06:59) - What’s Coming Next</li>
<li>(07:16) - Start Without a Tool</li>
<li>(08:04) - Why This Podcast Exists</li>
<li>(08:45) - Show Biases and Principles</li>
<li>(09:24) - Season Preview</li>
<li>(10:09) - Listener Case Files</li>
<li>(10:35) - Who This Show Isn’t For</li>
<li>(11:01) - New Names, Same Discipline</li>
<li>(11:46) - Closing Thanks</li>
<li>(12:21) - Final Takeaway</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/92a4149a/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>FURTHER READING<p>ISO/IEC 19770-1 — IT Asset Management Systems standard<br>https://www.iso.org/standard/68531.html</p><p>IAITAM — International Association of IT Asset Managers<br>https://www.iaitam.org</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/92a4149a/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/92a4149a/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>The Last Mile: Disposal, Data Destruction, and Chain of Custody</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>The Last Mile: Disposal, Data Destruction, and Chain of Custody</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c0e34062-b9da-493e-a698-daa48a213a8e</guid>
      <link>https://share.transistor.fm/s/732a157c</link>
      <description>
        <![CDATA[<p>Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed nine months ago.</p><p>At the end of life, a device stops being an asset and becomes a liability with a serial number. Disposal is the only gate in the lifecycle where getting it wrong doesn't cost you efficiency or budget — it costs you a regulator.</p><p>This episode covers what actually changed when NIST published SP 800-88 Revision 2 in September 2025 and withdrew Revision 1 the same day: the shift from a device-by-device technical manual to a program-level governance framework, the deferral of technique detail to IEEE 2883, the retirement of degaussing and multi-pass overwriting, and new language on establishing trust in a vendor's implementation. Then the regulatory stack — GLBA, FACTA, HIPAA, PCI DSS, Sarbanes-Oxley, Regulation S-P — and why one device can sit under five frameworks at once.</p><p>The centerpiece is a public enforcement case. Morgan Stanley paid $95 million across two regulators after handing roughly 4,900 devices to a moving and storage company with no data destruction experience. Devices reached an internet auction site with unencrypted customer information intact. Every control that failed was an asset management control.</p><p>Plus a listener question from Marcus in Fort Wayne on whether wiping drives in-house before they reach the ITAD vendor is duplicated effort.</p><p>IN THIS EPISODE</p><p>- NIST SP 800-88 Revision 2 — published September 2025, Revision 1 withdrawn the same day<br>- Why the media-specific tables were removed and what replaced them<br>- Clear, Purge, Destroy — what survived and what didn't<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern media<br>- Cryptographic erase, and why it's the one technique NIST kept<br>- Should you wipe in-house before the ITAD vendor? A listener question<br>- The Morgan Stanley case: $95 million, 15 million customers, 42 unaccounted servers<br>- The regulatory stack, and why one device sits under five frameworks<br>- R2v3, e-Stewards, and NAID AAA — what each actually verifies<br>- The downstream gap auditors find over and over<br>- What makes a certificate of destruction defensible, and what makes it worthless<br>- Deaccession, the ledger, and why the shredder isn't the point</p><p>CHAPTERS<br></p><ul><li>(00:03) - Disposal’s Hidden Liability</li>
<li>(01:31) - NIST 800-88 Changes</li>
<li>(05:47) - The $95 Million Failure</li>
<li>(10:21) - Rules, Vendors, and Proof</li>
<li>(15:50) - The Ledger Matters Most</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/732a157c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2 — current standard, published 26 September 2025<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>NIST announcement and summary of changes from Revision 1<br>https://www.nist.gov/news-events/news/2025/09/guidelines-media-sanitization-nist-publishes-sp-800-88r2</p><p>NIST SP 800-88 Revision 1 — withdrawal notice<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed nine months ago.</p><p>At the end of life, a device stops being an asset and becomes a liability with a serial number. Disposal is the only gate in the lifecycle where getting it wrong doesn't cost you efficiency or budget — it costs you a regulator.</p><p>This episode covers what actually changed when NIST published SP 800-88 Revision 2 in September 2025 and withdrew Revision 1 the same day: the shift from a device-by-device technical manual to a program-level governance framework, the deferral of technique detail to IEEE 2883, the retirement of degaussing and multi-pass overwriting, and new language on establishing trust in a vendor's implementation. Then the regulatory stack — GLBA, FACTA, HIPAA, PCI DSS, Sarbanes-Oxley, Regulation S-P — and why one device can sit under five frameworks at once.</p><p>The centerpiece is a public enforcement case. Morgan Stanley paid $95 million across two regulators after handing roughly 4,900 devices to a moving and storage company with no data destruction experience. Devices reached an internet auction site with unencrypted customer information intact. Every control that failed was an asset management control.</p><p>Plus a listener question from Marcus in Fort Wayne on whether wiping drives in-house before they reach the ITAD vendor is duplicated effort.</p><p>IN THIS EPISODE</p><p>- NIST SP 800-88 Revision 2 — published September 2025, Revision 1 withdrawn the same day<br>- Why the media-specific tables were removed and what replaced them<br>- Clear, Purge, Destroy — what survived and what didn't<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern media<br>- Cryptographic erase, and why it's the one technique NIST kept<br>- Should you wipe in-house before the ITAD vendor? A listener question<br>- The Morgan Stanley case: $95 million, 15 million customers, 42 unaccounted servers<br>- The regulatory stack, and why one device sits under five frameworks<br>- R2v3, e-Stewards, and NAID AAA — what each actually verifies<br>- The downstream gap auditors find over and over<br>- What makes a certificate of destruction defensible, and what makes it worthless<br>- Deaccession, the ledger, and why the shredder isn't the point</p><p>CHAPTERS<br></p><ul><li>(00:03) - Disposal’s Hidden Liability</li>
<li>(01:31) - NIST 800-88 Changes</li>
<li>(05:47) - The $95 Million Failure</li>
<li>(10:21) - Rules, Vendors, and Proof</li>
<li>(15:50) - The Ledger Matters Most</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/732a157c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2 — current standard, published 26 September 2025<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>NIST announcement and summary of changes from Revision 1<br>https://www.nist.gov/news-events/news/2025/09/guidelines-media-sanitization-nist-publishes-sp-800-88r2</p><p>NIST SP 800-88 Revision 1 — withdrawal notice<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Jul 2026 11:59:26 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/732a157c/2be15bf5.mp3" length="14126430" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1bbt0D3cXnJ9iK8O6DABgMlermTXONzLzKEgpHQ0nKM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YzAz/YWVkNDUyNWIzYzdk/MTBjMDBhZTI2MDI2/MTBlYy5wbmc.jpg"/>
      <itunes:duration>1175</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed nine months ago.</p><p>At the end of life, a device stops being an asset and becomes a liability with a serial number. Disposal is the only gate in the lifecycle where getting it wrong doesn't cost you efficiency or budget — it costs you a regulator.</p><p>This episode covers what actually changed when NIST published SP 800-88 Revision 2 in September 2025 and withdrew Revision 1 the same day: the shift from a device-by-device technical manual to a program-level governance framework, the deferral of technique detail to IEEE 2883, the retirement of degaussing and multi-pass overwriting, and new language on establishing trust in a vendor's implementation. Then the regulatory stack — GLBA, FACTA, HIPAA, PCI DSS, Sarbanes-Oxley, Regulation S-P — and why one device can sit under five frameworks at once.</p><p>The centerpiece is a public enforcement case. Morgan Stanley paid $95 million across two regulators after handing roughly 4,900 devices to a moving and storage company with no data destruction experience. Devices reached an internet auction site with unencrypted customer information intact. Every control that failed was an asset management control.</p><p>Plus a listener question from Marcus in Fort Wayne on whether wiping drives in-house before they reach the ITAD vendor is duplicated effort.</p><p>IN THIS EPISODE</p><p>- NIST SP 800-88 Revision 2 — published September 2025, Revision 1 withdrawn the same day<br>- Why the media-specific tables were removed and what replaced them<br>- Clear, Purge, Destroy — what survived and what didn't<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern media<br>- Cryptographic erase, and why it's the one technique NIST kept<br>- Should you wipe in-house before the ITAD vendor? A listener question<br>- The Morgan Stanley case: $95 million, 15 million customers, 42 unaccounted servers<br>- The regulatory stack, and why one device sits under five frameworks<br>- R2v3, e-Stewards, and NAID AAA — what each actually verifies<br>- The downstream gap auditors find over and over<br>- What makes a certificate of destruction defensible, and what makes it worthless<br>- Deaccession, the ledger, and why the shredder isn't the point</p><p>CHAPTERS<br></p><ul><li>(00:03) - Disposal’s Hidden Liability</li>
<li>(01:31) - NIST 800-88 Changes</li>
<li>(05:47) - The $95 Million Failure</li>
<li>(10:21) - Rules, Vendors, and Proof</li>
<li>(15:50) - The Ledger Matters Most</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/732a157c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2 — current standard, published 26 September 2025<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>NIST announcement and summary of changes from Revision 1<br>https://www.nist.gov/news-events/news/2025/09/guidelines-media-sanitization-nist-publishes-sp-800-88r2</p><p>NIST SP 800-88 Revision 1 — withdrawal notice<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/732a157c/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/732a157c/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Hardware Refresh Cycles: The Great Debate</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Hardware Refresh Cycles: The Great Debate</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f5abf6ab-3dfb-4d2c-9400-b2be573ab489</guid>
      <link>https://share.transistor.fm/s/4495f6ff</link>
      <description>
        <![CDATA[<p>Three years, four, or five? Three curves you can measure in your own environment — and why the confident numbers are the least trustworthy.</p><p>Somebody in your organization decided how long a laptop lives. Ask where that number came from and you'll usually get "it's industry standard," "that's what the lease term was," or a long pause. Meanwhile it quietly determines a seven-figure line item every year.</p><p>This episode doesn't hand you a number. It hands you a method. The Three Curves — failure, cost, and value — each measurable in your own environment from data you already have, and where they intersect is your refresh cycle rather than a vendor's.</p><p>Along the way: why the widely quoted refresh statistics don't survive being traced to their sources, what actually fails in a modern laptop and why it's cheaper to fix than you think, the residual value you forfeit by stretching a cycle, and how the Windows 11 hardware requirements turned refresh from a hardware question into a platform runway question.</p><p>Plus a listener question from Tony in Toledo, whose CFO wants to move from four years to six — and the argument that actually works in that meeting.</p><p>IN THIS EPISODE</p><p>- Why most refresh cycles have no documented origin<br>- The provenance problem: tracing the widely quoted statistics back to dated or vendor-funded sources<br>- Curve one — failure: what actually breaks in a modern laptop, and why it's rarely the drive<br>- Curve two — cost: building your own support-cost-by-age curve in an afternoon<br>- Why the cost curve turns upward exactly when the warranty expires<br>- Curve three — value: the residual recovery you forfeit by stretching the cycle<br>- Paying twice, in two different budgets, across an accounting seam<br>- How Windows 11 hardware requirements changed refresh from hardware to platform runway<br>- Buying for supported life rather than unit price<br>- The AI PC question, and whether NPU capability justifies acceleration<br>- Weeding the collection: why librarians never withdraw a book for turning four<br>- Segmenting the fleet — why one cycle is wrong for most of your users</p><p>CHAPTERS<br></p><ul><li>(00:03) - Refresh Debate Begins</li>
<li>(02:22) - The Three Curves</li>
<li>(04:09) - Failure and Cost</li>
<li>(07:01) - Push Back with Data</li>
<li>(07:22) - The Value Curve</li>
<li>(08:46) - Security Changes the Game</li>
<li>(11:01) - The Library Analogy</li>
<li>(12:01) - Segment Your Fleet</li>
<li>(12:39) - Refresh Is Economics</li>
<li>(14:02) - Disposal Next Time</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/4495f6ff/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft — Windows 10 end of support<br>https://www.microsoft.com/en-us/windows/end-of-support</p><p>Microsoft — Windows 11 system requirements<br>https://www.microsoft.com/en-us/windows/windows-11-specifications</p><p>A note on evidence: the refresh statistics circulating in this field are unusually poorly sourced. Figures on failure rates and support costs for aging hardware typically trace back either to studies more than a decade old or to research funded by hardware manufacturers. This episode deliberately avoids quoting them. The Three Curves framework exists so you can measure your own environment instead of borrowing someone else's number.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Three years, four, or five? Three curves you can measure in your own environment — and why the confident numbers are the least trustworthy.</p><p>Somebody in your organization decided how long a laptop lives. Ask where that number came from and you'll usually get "it's industry standard," "that's what the lease term was," or a long pause. Meanwhile it quietly determines a seven-figure line item every year.</p><p>This episode doesn't hand you a number. It hands you a method. The Three Curves — failure, cost, and value — each measurable in your own environment from data you already have, and where they intersect is your refresh cycle rather than a vendor's.</p><p>Along the way: why the widely quoted refresh statistics don't survive being traced to their sources, what actually fails in a modern laptop and why it's cheaper to fix than you think, the residual value you forfeit by stretching a cycle, and how the Windows 11 hardware requirements turned refresh from a hardware question into a platform runway question.</p><p>Plus a listener question from Tony in Toledo, whose CFO wants to move from four years to six — and the argument that actually works in that meeting.</p><p>IN THIS EPISODE</p><p>- Why most refresh cycles have no documented origin<br>- The provenance problem: tracing the widely quoted statistics back to dated or vendor-funded sources<br>- Curve one — failure: what actually breaks in a modern laptop, and why it's rarely the drive<br>- Curve two — cost: building your own support-cost-by-age curve in an afternoon<br>- Why the cost curve turns upward exactly when the warranty expires<br>- Curve three — value: the residual recovery you forfeit by stretching the cycle<br>- Paying twice, in two different budgets, across an accounting seam<br>- How Windows 11 hardware requirements changed refresh from hardware to platform runway<br>- Buying for supported life rather than unit price<br>- The AI PC question, and whether NPU capability justifies acceleration<br>- Weeding the collection: why librarians never withdraw a book for turning four<br>- Segmenting the fleet — why one cycle is wrong for most of your users</p><p>CHAPTERS<br></p><ul><li>(00:03) - Refresh Debate Begins</li>
<li>(02:22) - The Three Curves</li>
<li>(04:09) - Failure and Cost</li>
<li>(07:01) - Push Back with Data</li>
<li>(07:22) - The Value Curve</li>
<li>(08:46) - Security Changes the Game</li>
<li>(11:01) - The Library Analogy</li>
<li>(12:01) - Segment Your Fleet</li>
<li>(12:39) - Refresh Is Economics</li>
<li>(14:02) - Disposal Next Time</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/4495f6ff/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft — Windows 10 end of support<br>https://www.microsoft.com/en-us/windows/end-of-support</p><p>Microsoft — Windows 11 system requirements<br>https://www.microsoft.com/en-us/windows/windows-11-specifications</p><p>A note on evidence: the refresh statistics circulating in this field are unusually poorly sourced. Figures on failure rates and support costs for aging hardware typically trace back either to studies more than a decade old or to research funded by hardware manufacturers. This episode deliberately avoids quoting them. The Three Curves framework exists so you can measure your own environment instead of borrowing someone else's number.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Jul 2026 08:31:26 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/4495f6ff/9d50e174.mp3" length="10863536" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/gcaYEihxbtDSBavuZ7JZwxfJ_zQ1VfVwR-TiCDdy1tA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMDg2/ZDljN2U2NTEwNmIz/MDhhOTgzYTExNzdm/OTFkZS5wbmc.jpg"/>
      <itunes:duration>903</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Three years, four, or five? Three curves you can measure in your own environment — and why the confident numbers are the least trustworthy.</p><p>Somebody in your organization decided how long a laptop lives. Ask where that number came from and you'll usually get "it's industry standard," "that's what the lease term was," or a long pause. Meanwhile it quietly determines a seven-figure line item every year.</p><p>This episode doesn't hand you a number. It hands you a method. The Three Curves — failure, cost, and value — each measurable in your own environment from data you already have, and where they intersect is your refresh cycle rather than a vendor's.</p><p>Along the way: why the widely quoted refresh statistics don't survive being traced to their sources, what actually fails in a modern laptop and why it's cheaper to fix than you think, the residual value you forfeit by stretching a cycle, and how the Windows 11 hardware requirements turned refresh from a hardware question into a platform runway question.</p><p>Plus a listener question from Tony in Toledo, whose CFO wants to move from four years to six — and the argument that actually works in that meeting.</p><p>IN THIS EPISODE</p><p>- Why most refresh cycles have no documented origin<br>- The provenance problem: tracing the widely quoted statistics back to dated or vendor-funded sources<br>- Curve one — failure: what actually breaks in a modern laptop, and why it's rarely the drive<br>- Curve two — cost: building your own support-cost-by-age curve in an afternoon<br>- Why the cost curve turns upward exactly when the warranty expires<br>- Curve three — value: the residual recovery you forfeit by stretching the cycle<br>- Paying twice, in two different budgets, across an accounting seam<br>- How Windows 11 hardware requirements changed refresh from hardware to platform runway<br>- Buying for supported life rather than unit price<br>- The AI PC question, and whether NPU capability justifies acceleration<br>- Weeding the collection: why librarians never withdraw a book for turning four<br>- Segmenting the fleet — why one cycle is wrong for most of your users</p><p>CHAPTERS<br></p><ul><li>(00:03) - Refresh Debate Begins</li>
<li>(02:22) - The Three Curves</li>
<li>(04:09) - Failure and Cost</li>
<li>(07:01) - Push Back with Data</li>
<li>(07:22) - The Value Curve</li>
<li>(08:46) - Security Changes the Game</li>
<li>(11:01) - The Library Analogy</li>
<li>(12:01) - Segment Your Fleet</li>
<li>(12:39) - Refresh Is Economics</li>
<li>(14:02) - Disposal Next Time</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/4495f6ff/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Microsoft — Windows 10 end of support<br>https://www.microsoft.com/en-us/windows/end-of-support</p><p>Microsoft — Windows 11 system requirements<br>https://www.microsoft.com/en-us/windows/windows-11-specifications</p><p>A note on evidence: the refresh statistics circulating in this field are unusually poorly sourced. Figures on failure rates and support costs for aging hardware typically trace back either to studies more than a decade old or to research funded by hardware manufacturers. This episode deliberately avoids quoting them. The Three Curves framework exists so you can measure your own environment instead of borrowing someone else's number.</p><p>LISTENER CASE FILES</p><p>Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>hardware refresh, refresh cycle, device lifecycle, laptop refresh, IT budgeting, total cost of ownership, residual value, Windows 11, TPM 2.0, AI PC, endpoint management, IT asset management, IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/4495f6ff/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/4495f6ff/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Shadow IT: Reading the Demand Signal</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Shadow IT: Reading the Demand Signal</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2042bafc-bc0d-41c0-a0ba-9a1a0fdd45ba</guid>
      <link>https://share.transistor.fm/s/d0250e3c</link>
      <description>
        <![CDATA[<p>Unsanctioned software isn't a discipline problem. It's your users telling you what IT failed to deliver.</p><p>The instinct is to treat shadow IT as rebellion — something to be found, blocked, and punished. That instinct is why it keeps happening.</p><p>This episode reframes unsanctioned technology as a demand signal. Every credit card SaaS subscription is a documented case of someone needing a capability badly enough to solve it themselves. The security exposure and license liability are real, and this episode does not soften them. But the durable fix isn't enforcement; it's service.</p><p>Bill covers how to find what's actually running, how to triage it by risk rather than by annoyance, and how to build an intake path fast enough that going around IT stops being the rational choice. The measure of an ITAM program isn't how much it prevents. It's how little anyone needs to go around it.</p><p>IN THIS EPISODE</p><p>- Why shadow IT is a demand signal, not a discipline problem<br>- Business units now control the overwhelming majority of SaaS spend — and what that means<br>- Finding what's actually running: expense reports, SSO logs, network data, and their blind spots<br>- Triage by risk, not by annoyance — a practical severity model<br>- The real exposure: data residency, license liability, and orphaned admin accounts<br>- AI-native tools entering through expense reports faster than governance can respond<br>- Building an intake path fast enough that going around IT stops making sense<br>- Why enforcement-first programs generate more shadow IT, not less<br>- Service as the organizing principle — measuring how little anyone needs to route around you</p><p>CHAPTERS<br></p><ul><li>(00:02) - Hunting Shadow IT</li>
<li>(03:22) - Shadow IT Costs</li>
<li>(06:31) - Shadow AI Rises</li>
<li>(09:20) - Finding Hidden Tools</li>
<li>(11:30) - What To Do Next</li>
<li>(14:20) - Refresh Debate Next</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/d0250e3c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Findings summary and methodology<br>https://zylo.com/news/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>IBM Cost of a Data Breach Report<br>https://www.ibm.com/reports/data-breach</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Unsanctioned software isn't a discipline problem. It's your users telling you what IT failed to deliver.</p><p>The instinct is to treat shadow IT as rebellion — something to be found, blocked, and punished. That instinct is why it keeps happening.</p><p>This episode reframes unsanctioned technology as a demand signal. Every credit card SaaS subscription is a documented case of someone needing a capability badly enough to solve it themselves. The security exposure and license liability are real, and this episode does not soften them. But the durable fix isn't enforcement; it's service.</p><p>Bill covers how to find what's actually running, how to triage it by risk rather than by annoyance, and how to build an intake path fast enough that going around IT stops being the rational choice. The measure of an ITAM program isn't how much it prevents. It's how little anyone needs to go around it.</p><p>IN THIS EPISODE</p><p>- Why shadow IT is a demand signal, not a discipline problem<br>- Business units now control the overwhelming majority of SaaS spend — and what that means<br>- Finding what's actually running: expense reports, SSO logs, network data, and their blind spots<br>- Triage by risk, not by annoyance — a practical severity model<br>- The real exposure: data residency, license liability, and orphaned admin accounts<br>- AI-native tools entering through expense reports faster than governance can respond<br>- Building an intake path fast enough that going around IT stops making sense<br>- Why enforcement-first programs generate more shadow IT, not less<br>- Service as the organizing principle — measuring how little anyone needs to route around you</p><p>CHAPTERS<br></p><ul><li>(00:02) - Hunting Shadow IT</li>
<li>(03:22) - Shadow IT Costs</li>
<li>(06:31) - Shadow AI Rises</li>
<li>(09:20) - Finding Hidden Tools</li>
<li>(11:30) - What To Do Next</li>
<li>(14:20) - Refresh Debate Next</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/d0250e3c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Findings summary and methodology<br>https://zylo.com/news/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>IBM Cost of a Data Breach Report<br>https://www.ibm.com/reports/data-breach</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Jul 2026 07:45:28 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/d0250e3c/cc0f3909.mp3" length="11181323" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/kW2E37pecyBEZbEjA87uITIFysHD7bbuuQvsJ1wrOA4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zODFk/MjMwMWQ1NTI2OGU5/YTc2NDY4MDgwNGM1/NjQ4NS5wbmc.jpg"/>
      <itunes:duration>929</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Unsanctioned software isn't a discipline problem. It's your users telling you what IT failed to deliver.</p><p>The instinct is to treat shadow IT as rebellion — something to be found, blocked, and punished. That instinct is why it keeps happening.</p><p>This episode reframes unsanctioned technology as a demand signal. Every credit card SaaS subscription is a documented case of someone needing a capability badly enough to solve it themselves. The security exposure and license liability are real, and this episode does not soften them. But the durable fix isn't enforcement; it's service.</p><p>Bill covers how to find what's actually running, how to triage it by risk rather than by annoyance, and how to build an intake path fast enough that going around IT stops being the rational choice. The measure of an ITAM program isn't how much it prevents. It's how little anyone needs to go around it.</p><p>IN THIS EPISODE</p><p>- Why shadow IT is a demand signal, not a discipline problem<br>- Business units now control the overwhelming majority of SaaS spend — and what that means<br>- Finding what's actually running: expense reports, SSO logs, network data, and their blind spots<br>- Triage by risk, not by annoyance — a practical severity model<br>- The real exposure: data residency, license liability, and orphaned admin accounts<br>- AI-native tools entering through expense reports faster than governance can respond<br>- Building an intake path fast enough that going around IT stops making sense<br>- Why enforcement-first programs generate more shadow IT, not less<br>- Service as the organizing principle — measuring how little anyone needs to route around you</p><p>CHAPTERS<br></p><ul><li>(00:02) - Hunting Shadow IT</li>
<li>(03:22) - Shadow IT Costs</li>
<li>(06:31) - Shadow AI Rises</li>
<li>(09:20) - Finding Hidden Tools</li>
<li>(11:30) - What To Do Next</li>
<li>(14:20) - Refresh Debate Next</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/d0250e3c/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Findings summary and methodology<br>https://zylo.com/news/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>IBM Cost of a Data Breach Report<br>https://www.ibm.com/reports/data-breach</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/d0250e3c/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/d0250e3c/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Surviving a Software Audit, Part Two: The Settlement</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Surviving a Software Audit, Part Two: The Settlement</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9857de90-37b8-4121-bf9d-3690f78f5e85</guid>
      <link>https://share.transistor.fm/s/0770dc12</link>
      <description>
        <![CDATA[<p>The findings document is an opening offer, not a verdict. How claims get inflated, and how settlements actually get made.</p><p>Part two of two, picking up exactly where the last episode left off: the findings document has landed and the number on it is worse than you expected.</p><p>That number is a negotiating position. This episode covers how publisher claims get inflated in the first place, why opening claims routinely land several times higher than eventual settlements, what the publisher actually wants out of this — which is rarely the cash figure in front of you — and how zero-cash resolutions get traded into renewal and subscription commitments instead.</p><p>Audit defense ends in commerce. The practitioners who understand that walk away with a business outcome. The ones who treat it as a compliance verdict write the check.</p><p>IN THIS EPISODE</p><p>- Why the findings document is an opening position, not an invoice<br>- How claims get inflated: measurement errors, wrong metrics, and unverified assumptions<br>- Auditing the audit — challenging methodology before you challenge the number<br>- What the publisher actually wants, and why it's rarely the cash figure<br>- Zero-cash resolutions: trading findings into renewal and subscription commitments<br>- Where the leverage sits, and the timing that determines who has it<br>- Back maintenance, penalties, and which line items are genuinely negotiable<br>- Getting it in writing: release language and what a settlement should close<br>- Building the evidence discipline that prevents the next one</p><p>CHAPTERS<br></p><ul><li>(00:02) - Audit Defense Payoff</li>
<li>(02:43) - Claim Anatomy Unpacked</li>
<li>(04:14) - Rebuild the Count</li>
<li>(06:17) - Trading for Settlement</li>
<li>(10:39) - Locking the Paper</li>
<li>(11:44) - Fix the Leaks</li>
<li>(12:27) - Library Fee Lesson</li>
<li>(13:12) - Four-Part Audit Game</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/0770dc12/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>A note on evidence: software audit settlements are almost universally subject to non-disclosure terms, which means no public dataset of settlement outcomes exists. The negotiation guidance in this episode reflects licensing advisory practice and thirty years of firsthand experience on the customer side of the table. It is presented as practitioner knowledge, not as research.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>The findings document is an opening offer, not a verdict. How claims get inflated, and how settlements actually get made.</p><p>Part two of two, picking up exactly where the last episode left off: the findings document has landed and the number on it is worse than you expected.</p><p>That number is a negotiating position. This episode covers how publisher claims get inflated in the first place, why opening claims routinely land several times higher than eventual settlements, what the publisher actually wants out of this — which is rarely the cash figure in front of you — and how zero-cash resolutions get traded into renewal and subscription commitments instead.</p><p>Audit defense ends in commerce. The practitioners who understand that walk away with a business outcome. The ones who treat it as a compliance verdict write the check.</p><p>IN THIS EPISODE</p><p>- Why the findings document is an opening position, not an invoice<br>- How claims get inflated: measurement errors, wrong metrics, and unverified assumptions<br>- Auditing the audit — challenging methodology before you challenge the number<br>- What the publisher actually wants, and why it's rarely the cash figure<br>- Zero-cash resolutions: trading findings into renewal and subscription commitments<br>- Where the leverage sits, and the timing that determines who has it<br>- Back maintenance, penalties, and which line items are genuinely negotiable<br>- Getting it in writing: release language and what a settlement should close<br>- Building the evidence discipline that prevents the next one</p><p>CHAPTERS<br></p><ul><li>(00:02) - Audit Defense Payoff</li>
<li>(02:43) - Claim Anatomy Unpacked</li>
<li>(04:14) - Rebuild the Count</li>
<li>(06:17) - Trading for Settlement</li>
<li>(10:39) - Locking the Paper</li>
<li>(11:44) - Fix the Leaks</li>
<li>(12:27) - Library Fee Lesson</li>
<li>(13:12) - Four-Part Audit Game</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/0770dc12/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>A note on evidence: software audit settlements are almost universally subject to non-disclosure terms, which means no public dataset of settlement outcomes exists. The negotiation guidance in this episode reflects licensing advisory practice and thirty years of firsthand experience on the customer side of the table. It is presented as practitioner knowledge, not as research.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Thu, 30 Jul 2026 07:26:52 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/0770dc12/41c8a0fe.mp3" length="11366702" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/jckTzm0pnNrjpA0islB4DJ27ogTIAlve0FRNd8C1ScA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNzZh/Njg2OTA5MWQ4OWY2/MDIyODkxZTliMDc5/ODBkMy5wbmc.jpg"/>
      <itunes:duration>945</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>The findings document is an opening offer, not a verdict. How claims get inflated, and how settlements actually get made.</p><p>Part two of two, picking up exactly where the last episode left off: the findings document has landed and the number on it is worse than you expected.</p><p>That number is a negotiating position. This episode covers how publisher claims get inflated in the first place, why opening claims routinely land several times higher than eventual settlements, what the publisher actually wants out of this — which is rarely the cash figure in front of you — and how zero-cash resolutions get traded into renewal and subscription commitments instead.</p><p>Audit defense ends in commerce. The practitioners who understand that walk away with a business outcome. The ones who treat it as a compliance verdict write the check.</p><p>IN THIS EPISODE</p><p>- Why the findings document is an opening position, not an invoice<br>- How claims get inflated: measurement errors, wrong metrics, and unverified assumptions<br>- Auditing the audit — challenging methodology before you challenge the number<br>- What the publisher actually wants, and why it's rarely the cash figure<br>- Zero-cash resolutions: trading findings into renewal and subscription commitments<br>- Where the leverage sits, and the timing that determines who has it<br>- Back maintenance, penalties, and which line items are genuinely negotiable<br>- Getting it in writing: release language and what a settlement should close<br>- Building the evidence discipline that prevents the next one</p><p>CHAPTERS<br></p><ul><li>(00:02) - Audit Defense Payoff</li>
<li>(02:43) - Claim Anatomy Unpacked</li>
<li>(04:14) - Rebuild the Count</li>
<li>(06:17) - Trading for Settlement</li>
<li>(10:39) - Locking the Paper</li>
<li>(11:44) - Fix the Leaks</li>
<li>(12:27) - Library Fee Lesson</li>
<li>(13:12) - Four-Part Audit Game</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/0770dc12/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>A note on evidence: software audit settlements are almost universally subject to non-disclosure terms, which means no public dataset of settlement outcomes exists. The negotiation guidance in this episode reflects licensing advisory practice and thirty years of firsthand experience on the customer side of the table. It is presented as practitioner knowledge, not as research.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/0770dc12/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/0770dc12/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Hardware Asset Management: The Seven Gates</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Hardware Asset Management: The Seven Gates</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">222617bd-87b2-4775-89d6-5790c173ff9d</guid>
      <link>https://share.transistor.fm/s/e369e4c0</link>
      <description>
        <![CDATA[<p>Request to disposal, gate by gate — what each stage captures, how each one fails, and why custody is the whole game.</p><p>Hardware asset management is a custody discipline. This episode walks the full lifecycle gate by gate — request, procure, receive, deploy, maintain, recover, dispose — and applies the same three questions at every stage: what is this gate, what data has to be captured here, and how does it typically fail?</p><p>Part two moves to the end of life, where the risk concentrates: data sanitization under NIST SP 800-88 Revision 2, what R2v3, e-Stewards, and NAID AAA certifications actually mean when you're selecting an ITAD vendor, the real economics behind refresh cycle decisions, and ghost assets — the machines your records insist you still own.</p><p>If your inventory can't survive a simple question about where a specific laptop is today, this is the episode that fixes it.</p><p>IN THIS EPISODE</p><p>- The seven gates of the hardware lifecycle: request, procure, receive, deploy, maintain, recover, dispose<br>- What data has to be captured at each gate, and how each one typically fails<br>- Ghost assets: why your records insist you own machines that left two years ago<br>- Refresh cycle economics, and what the failure-rate data actually supports<br>- Data sanitization under NIST SP 800-88 Revision 2, and why Revision 1 is withdrawn<br>- Choosing an ITAD vendor: what R2v3, e-Stewards, and NAID AAA actually certify<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern flash media<br>- Custody as the organizing principle behind every hardware asset decision</p><p>CHAPTERS<br></p><ul><li>(00:03) - HAM Lifecycle Overview</li>
<li>(01:40) - Request and Approval</li>
<li>(02:48) - Procurement Records</li>
<li>(04:00) - Receiving the Asset</li>
<li>(05:01) - Deployment and Assignment</li>
<li>(06:22) - Maintenance Insights</li>
<li>(07:32) - Asset Recovery</li>
<li>(09:03) - Secure Disposal</li>
<li>(12:59) - Refresh Strategy</li>
<li>(14:26) - Ghost and Zombie Assets</li>
<li>(15:36) - Library Analogy</li>
<li>(16:19) - Custody Discipline</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/e369e4c0/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (current standard, September 2025)<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>Full text (PDF)<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. Much of the ITAD guidance circulating online still cites the withdrawn version.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Request to disposal, gate by gate — what each stage captures, how each one fails, and why custody is the whole game.</p><p>Hardware asset management is a custody discipline. This episode walks the full lifecycle gate by gate — request, procure, receive, deploy, maintain, recover, dispose — and applies the same three questions at every stage: what is this gate, what data has to be captured here, and how does it typically fail?</p><p>Part two moves to the end of life, where the risk concentrates: data sanitization under NIST SP 800-88 Revision 2, what R2v3, e-Stewards, and NAID AAA certifications actually mean when you're selecting an ITAD vendor, the real economics behind refresh cycle decisions, and ghost assets — the machines your records insist you still own.</p><p>If your inventory can't survive a simple question about where a specific laptop is today, this is the episode that fixes it.</p><p>IN THIS EPISODE</p><p>- The seven gates of the hardware lifecycle: request, procure, receive, deploy, maintain, recover, dispose<br>- What data has to be captured at each gate, and how each one typically fails<br>- Ghost assets: why your records insist you own machines that left two years ago<br>- Refresh cycle economics, and what the failure-rate data actually supports<br>- Data sanitization under NIST SP 800-88 Revision 2, and why Revision 1 is withdrawn<br>- Choosing an ITAD vendor: what R2v3, e-Stewards, and NAID AAA actually certify<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern flash media<br>- Custody as the organizing principle behind every hardware asset decision</p><p>CHAPTERS<br></p><ul><li>(00:03) - HAM Lifecycle Overview</li>
<li>(01:40) - Request and Approval</li>
<li>(02:48) - Procurement Records</li>
<li>(04:00) - Receiving the Asset</li>
<li>(05:01) - Deployment and Assignment</li>
<li>(06:22) - Maintenance Insights</li>
<li>(07:32) - Asset Recovery</li>
<li>(09:03) - Secure Disposal</li>
<li>(12:59) - Refresh Strategy</li>
<li>(14:26) - Ghost and Zombie Assets</li>
<li>(15:36) - Library Analogy</li>
<li>(16:19) - Custody Discipline</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/e369e4c0/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (current standard, September 2025)<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>Full text (PDF)<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. Much of the ITAD guidance circulating online still cites the withdrawn version.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Jul 2026 20:00:44 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/e369e4c0/0755b959.mp3" length="13080857" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-zTn4YCBoVteqokaCc-ZEvVDsITj39UOOoEy3AudG_Y/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTJk/NmRiZDJlZmNiOTFh/OWViNGRhMjE3ZDc5/YTQ4MS5wbmc.jpg"/>
      <itunes:duration>1088</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Request to disposal, gate by gate — what each stage captures, how each one fails, and why custody is the whole game.</p><p>Hardware asset management is a custody discipline. This episode walks the full lifecycle gate by gate — request, procure, receive, deploy, maintain, recover, dispose — and applies the same three questions at every stage: what is this gate, what data has to be captured here, and how does it typically fail?</p><p>Part two moves to the end of life, where the risk concentrates: data sanitization under NIST SP 800-88 Revision 2, what R2v3, e-Stewards, and NAID AAA certifications actually mean when you're selecting an ITAD vendor, the real economics behind refresh cycle decisions, and ghost assets — the machines your records insist you still own.</p><p>If your inventory can't survive a simple question about where a specific laptop is today, this is the episode that fixes it.</p><p>IN THIS EPISODE</p><p>- The seven gates of the hardware lifecycle: request, procure, receive, deploy, maintain, recover, dispose<br>- What data has to be captured at each gate, and how each one typically fails<br>- Ghost assets: why your records insist you own machines that left two years ago<br>- Refresh cycle economics, and what the failure-rate data actually supports<br>- Data sanitization under NIST SP 800-88 Revision 2, and why Revision 1 is withdrawn<br>- Choosing an ITAD vendor: what R2v3, e-Stewards, and NAID AAA actually certify<br>- Why degaussing and multi-pass overwriting are the wrong answer for modern flash media<br>- Custody as the organizing principle behind every hardware asset decision</p><p>CHAPTERS<br></p><ul><li>(00:03) - HAM Lifecycle Overview</li>
<li>(01:40) - Request and Approval</li>
<li>(02:48) - Procurement Records</li>
<li>(04:00) - Receiving the Asset</li>
<li>(05:01) - Deployment and Assignment</li>
<li>(06:22) - Maintenance Insights</li>
<li>(07:32) - Asset Recovery</li>
<li>(09:03) - Secure Disposal</li>
<li>(12:59) - Refresh Strategy</li>
<li>(14:26) - Ghost and Zombie Assets</li>
<li>(15:36) - Library Analogy</li>
<li>(16:19) - Custody Discipline</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/e369e4c0/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (current standard, September 2025)<br>https://csrc.nist.gov/pubs/sp/800/88/r2/final</p><p>Full text (PDF)<br>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf</p><p>IEEE 2883 — Standard for Sanitizing Storage<br>https://standards.ieee.org/ieee/2883/10277/</p><p>SERI — R2v3 standard and certified facility directory<br>https://sustainableelectronics.org</p><p>e-Stewards certified recycler directory<br>https://e-stewards.org/find-a-recycler/</p><p>i-SIGMA — NAID AAA certification<br>https://isigma.org</p><p>Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. Much of the ITAD guidance circulating online still cites the withdrawn version.</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/e369e4c0/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/e369e4c0/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Software Asset Management: Proving What You Own</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>Software Asset Management: Proving What You Own</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7a653016-1c56-4300-813b-6634e209eb43</guid>
      <link>https://share.transistor.fm/s/f38c5c28</link>
      <description>
        <![CDATA[<p>Installs are not entitlements. Building an Effective License Position, and why the gap between the two is where the money hides.</p><p>Crossing over to the intangible side of the house. Where hardware asset management is about custody, software asset management is about evidence — and the evidence standard is considerably higher, because the party asking to see it has a financial interest in the answer.</p><p>This episode covers the discipline of reconciling what's deployed against what you're entitled to deploy: how publisher licensing metrics actually work, why an installation count is not a license position, and how to construct an Effective License Position that holds up when someone external is checking your arithmetic.</p><p>The homework matters more than usual on this one. The entitlement library you build here is the same document that determines how the next two episodes go for you.</p><p>IN THIS EPISODE</p><p>- Why software asset management is an evidence discipline, not an inventory discipline<br>- Entitlements versus installations, and why counting deployments proves nothing<br>- How publisher licensing metrics actually work — per-user, per-device, per-core, per-employee<br>- Building an Effective License Position that survives external scrutiny<br>- Oracle's per-employee Java licensing and what it changed<br>- VMware under Broadcom: subscription-only, per-core, and the sixteen-core minimum<br>- Where the money hides: unused licenses, wrong editions, and unclaimed downgrade rights<br>- The entitlement library — your homework, and the foundation for audit defense</p><p>CHAPTERS<br></p><ul><li>(00:02) - Software Asset Basics</li>
<li>(03:26) - Entitlements and Proof</li>
<li>(05:30) - Deployment Discovery</li>
<li>(08:08) - Audit Threats</li>
<li>(13:13) - SaaS Waste</li>
<li>(16:04) - Evidence Over Custody</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/f38c5c28/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Oracle Java SE Universal Subscription (per-employee licensing)<br>https://www.oracle.com/java/java-se-subscription/</p><p>Broadcom / VMware Cloud Foundation licensing<br>https://www.broadcom.com/products/software/vmware-cloud-foundation</p><p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Installs are not entitlements. Building an Effective License Position, and why the gap between the two is where the money hides.</p><p>Crossing over to the intangible side of the house. Where hardware asset management is about custody, software asset management is about evidence — and the evidence standard is considerably higher, because the party asking to see it has a financial interest in the answer.</p><p>This episode covers the discipline of reconciling what's deployed against what you're entitled to deploy: how publisher licensing metrics actually work, why an installation count is not a license position, and how to construct an Effective License Position that holds up when someone external is checking your arithmetic.</p><p>The homework matters more than usual on this one. The entitlement library you build here is the same document that determines how the next two episodes go for you.</p><p>IN THIS EPISODE</p><p>- Why software asset management is an evidence discipline, not an inventory discipline<br>- Entitlements versus installations, and why counting deployments proves nothing<br>- How publisher licensing metrics actually work — per-user, per-device, per-core, per-employee<br>- Building an Effective License Position that survives external scrutiny<br>- Oracle's per-employee Java licensing and what it changed<br>- VMware under Broadcom: subscription-only, per-core, and the sixteen-core minimum<br>- Where the money hides: unused licenses, wrong editions, and unclaimed downgrade rights<br>- The entitlement library — your homework, and the foundation for audit defense</p><p>CHAPTERS<br></p><ul><li>(00:02) - Software Asset Basics</li>
<li>(03:26) - Entitlements and Proof</li>
<li>(05:30) - Deployment Discovery</li>
<li>(08:08) - Audit Threats</li>
<li>(13:13) - SaaS Waste</li>
<li>(16:04) - Evidence Over Custody</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/f38c5c28/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Oracle Java SE Universal Subscription (per-employee licensing)<br>https://www.oracle.com/java/java-se-subscription/</p><p>Broadcom / VMware Cloud Foundation licensing<br>https://www.broadcom.com/products/software/vmware-cloud-foundation</p><p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Jul 2026 19:59:37 -0400</pubDate>
      <author>Bill Van Nort</author>
      <enclosure url="https://media.transistor.fm/f38c5c28/1078251d.mp3" length="13401663" type="audio/mpeg"/>
      <itunes:author>Bill Van Nort</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Hwvrxy25WSIw0zGWWjYgYuqaeYUnt7TT-uvn0v6bkrc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80Y2M2/MTYzZWU4ZGI0NDVm/OGYyYmQ4MzUzMDA2/YTk4ZC5wbmc.jpg"/>
      <itunes:duration>1114</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Installs are not entitlements. Building an Effective License Position, and why the gap between the two is where the money hides.</p><p>Crossing over to the intangible side of the house. Where hardware asset management is about custody, software asset management is about evidence — and the evidence standard is considerably higher, because the party asking to see it has a financial interest in the answer.</p><p>This episode covers the discipline of reconciling what's deployed against what you're entitled to deploy: how publisher licensing metrics actually work, why an installation count is not a license position, and how to construct an Effective License Position that holds up when someone external is checking your arithmetic.</p><p>The homework matters more than usual on this one. The entitlement library you build here is the same document that determines how the next two episodes go for you.</p><p>IN THIS EPISODE</p><p>- Why software asset management is an evidence discipline, not an inventory discipline<br>- Entitlements versus installations, and why counting deployments proves nothing<br>- How publisher licensing metrics actually work — per-user, per-device, per-core, per-employee<br>- Building an Effective License Position that survives external scrutiny<br>- Oracle's per-employee Java licensing and what it changed<br>- VMware under Broadcom: subscription-only, per-core, and the sixteen-core minimum<br>- Where the money hides: unused licenses, wrong editions, and unclaimed downgrade rights<br>- The entitlement library — your homework, and the foundation for audit defense</p><p>CHAPTERS<br></p><ul><li>(00:02) - Software Asset Basics</li>
<li>(03:26) - Entitlements and Proof</li>
<li>(05:30) - Deployment Discovery</li>
<li>(08:08) - Audit Threats</li>
<li>(13:13) - SaaS Waste</li>
<li>(16:04) - Evidence Over Custody</li>
</ul><br>TRANSCRIPT<br><a href="https://share.transistor.fm/s/f38c5c28/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
<br>SOURCES &amp; FURTHER READING<p>Oracle Java SE Universal Subscription (per-employee licensing)<br>https://www.oracle.com/java/java-se-subscription/</p><p>Broadcom / VMware Cloud Foundation licensing<br>https://www.broadcom.com/products/software/vmware-cloud-foundation</p><p>Zylo 2026 SaaS Management Index<br>https://zylo.com/2026-saas-management-index</p><p>Flexera 2026 State of ITAM Report<br>https://www.flexera.com/blog/it-asset-management/state-of-itam-2026/</p><p>ISO/IEC 19770-1 — IT Asset Management Systems<br>https://www.iso.org/standard/68531.html</p><p>ABOUT THE SHOW</p><p>Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.</p><p>Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.</p><p>Consulting enquiries and listener case files: operationalitam.com</p>]]>
      </itunes:summary>
      <itunes:keywords>IT asset management, ITAM, software asset management, SAM, software licensing, software audit, license compliance, hardware asset management, SaaS management, shadow IT, IT cost optimization, enterprise IT, Operational ITAM, Bill Van Nort</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://www.operationalitam.com" img="https://img.transistorcdn.com/oPagcXZMImM10kuQfJ7Gi-snADdSNY14Bx-Vf4VhRCk/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjNm/NjgyNzU0NzhkZDEx/ZDljZjU1OGYwZWQ4/YjI4MS5qcGc.jpg">Bill Van Nort</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/f38c5c28/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:chapters url="https://share.transistor.fm/s/f38c5c28/chapters.json" type="application/json+chapters"/>
    </item>
  </channel>
</rss>
