161 épisodes
- Are cyber exercises actually improving your cybersecurity resilience, or just satisfying compliance requirements? In this episode, Luigi Ferri explores ENISA's cyber exercise methodology, the gap between testing and real capability improvement, the role of MSPs in incident response, and why organizations must focus on measurable cyber resilience instead of annual audit-driven exercises.
In this episode, we answer to:
Why are cyber exercises important for improving cybersecurity resilience rather than just meeting compliance?
What is the difference between testing cybersecurity and improving organizational cyber resilience?
How can organizations ensure cyber exercise findings lead to measurable capability improvement?
Resources Mentioned in this Episode:
ENISA website, guideline "ENISA Technical Advisory for Secure Use of Package Managers", link https://r.search.yahoo.com/_ylt=AwrkMQ3LAHFqUAIA0Av04olQ;_ylu=Y29sbwNpcjIEcG9zAzIEdnRpZAMEc2VjA3Ny/RV=2/RE=1787000268/RO=10/RU=https%3a%2f%2fwww.enisa.europa.eu%2fsites%2fdefault%2ffiles%2f2026-03%2fENISA%2520Technical%2520Advisory%2520-%2520Package_Managers_Final.pdf/RK=2/RS=gKGJNKMoHHsXF59MpNiBxFeSfpU-
Connect with me on:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Website: http://www.theitsmpractice.com
And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.
Credits:
Sound engineering by Alan Southgate - http://alsouthgate.co.uk/
Graphics by Yulia Kolodyazhnaya - Projects Deliver Outputs, Services Deliver Outcomes: The Ownership Crisis Nobody Discusses. Discover why the biggest risk in any IT project begins after go-live. In this episode, Luigi Ferri explores the critical difference between project outputs and service outcomes, why Service Ownership is essential for long-term business value, and how IT Service Management (ITSM), Product Management, and Business Capability Management must work together to drive sustainable success. Learn why organizations have an ownership problem.
In this episode, we answer to:
Why is the day after go-live often the most dangerous stage of a project?
What is the difference between a Product Owner and a Service Owner, and why does it matter?
How can organizations improve long-term business outcomes through Service Management and clear ownership?
Resources Mentioned in this Episode:
PMI Institute, article "Pulse of the Profession 2024", link https://www.scribd.com/document/709988299/PMI-Pulse-of-the-Profession-2024-Report
Balanced Scorecard Institute, article "Is Your Strategy Execution Crumbling as a Result of Too Many Projects?", link https://balancedscorecard.org/blog/is-your-strategy-execution-crumbling-as-a-result-of-too-many-projects/
PwC website, article "PwC Middle East Transformation and project management survey part 1", link https://www.pwc.com/m1/en/publications/transformation-and-project-management-survey.html
Business Chief website, article "MIT Sloan: Why so many business digital transformations fail", link https://businesschief.asia/digital-strategy/mit-sloan-why-so-many-business-digital-transformations-fail
MIT website, article "5 reasons companies struggle with digital transformation", link https://mitsloan.mit.edu/ideas-made-to-matter/5-reasons-companies-struggle-digital-transformation
Connect with me on:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Website: http://www.theitsmpractice.com
And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.
Credits:
Sound engineering by Alan Southgate - http://alsouthgate.co.uk/
Graphics by Yulia Kolodyazhnaya - AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are no longer sufficient for AI-enabled services. Learn how AI impacts ITIL service management, AI governance, MSP liability, ISO 42001, NIST AI RMF, the EU AI Act, and why AI ownership, accountability, and updated contracts are now business-critical.
In this episode, we answer:
How does AI change the nature of IT services and MSP service design?
Why are traditional MSP contracts, governance models, and risk frameworks becoming outdated with AI?
Who is accountable and liable when AI-enabled services make decisions or cause incidents?
Resources Mentioned in this Episode:
Simmons + Simmons website, article "The EU AI Act: A Quick Guide", link https://www.simmons-simmons.com/en/publications/clyimpowh000ouxgkw1oidakk/the-eu-ai-act-a-quick-guide
ISO website, standard "ISO/IEC 42001:2023", link https://www.iso.org/standard/42001
European Parliament website, regulation "EU AI Act: first regulation on artificial intelligence", link https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence
NIST website, AI Risk Management Framework, link https://airc.nist.gov/airmf-resources/airmf/
NIST website, The NIST AI Risk Management Framework, link https://www.nist.gov/itl/ai-risk-management-framework
ISO website, article "AI management systems: What businesses need to know", link https://www.iso.org/artificial-intelligence/ai-management-systems
European Commission website, regulation "AI Act", link https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
Connect with me on:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Website: http://www.theitsmpractice.com
And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.
Credits:
Sound engineering by Alan Southgate - http://alsouthgate.co.uk/
Graphics by Yulia Kolodyazhnaya - Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and adaptive leadership. Learn how Enterprise Service Management, IT Service Management, and cybersecurity leaders can build resilient organizations by prioritizing behavior, faster adaptation, and continuous learning.
In this episode, we answer to:
Why is traditional cybersecurity defense no longer enough in the age of AI?
How does the DARE25 framework improve risk management, governance, and organizational resilience?
Why are accountability, adaptive leadership, and Purple Teaming essential for modern cybersecurity?
Resources Mentioned in this Episode:
Marco Amadei, creator of the DARE25 Digital Risk Management Framework, link https://www.linkedin.com/in/marco-amadei-0087844/
APMG website, article "Digital Risk Management Certification (DARE25)", link https://apmg-international.com/product/digital-risk-management-certification-dare25
APMG website, article "Introduction to AI in Risk Management", link https://apmg-international.com/article/introduction-ai-risk-management
Strategic Digital Risk Management – an unofficial LinkedIn page sharing insights, research, and updates on the DARE25 Framework, link https://www.linkedin.com/company/strategicdigitalriskmanagement/
Connect with me on:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Website: http://www.theitsmpractice.com
And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.
Credits:
Sound engineering by Alan Southgate - http://alsouthgate.co.uk/
Graphics by Yulia Kolodyazhnaya - In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using practical examples from healthcare and public services, he explains how ISO 28000 shifts the conversation from protecting internal systems to managing the security and resilience of the organizations you depend on. Discover why supplier failures, inherited risk, and third-party dependencies are becoming the greatest threats to service continuity, cybersecurity, and operational resilience in government and regulated industries.
In this episode, we answer:
Why is ISO 28000 becoming essential for Government Managed Service Providers and supply chain resilience?
How can third-party suppliers and subcontractors become the weakest link in your cybersecurity and operational resilience strategy?
Why should CISOs focus on inherited risk and supplier dependencies rather than only internal security controls?
Resources Mentioned in this Episode:
The Standards Institution of Israel website, article "SI ISO 28000 :2022 Specification for security management systems for the supply chain", link https://www.sii.org.il/en/iso-28000
ANSI website, article "What Is ISO 28000?", link https://blog.ansi.org/anab/what-is-iso-28000/
Wikipedia website, article "ISO 28000", link https://en.wikipedia.org/wiki/ISO/PAS_28000
NIST website, publication "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", link https://csrc.nist.rip/Pubs/sp/800/161/r1/2PD
SITS website, article "NIS2, DORA & Co: Aren’t we all part of someone’s relevant supply chain?", link https://sits.com/en/blog/nis2-dora-supply-chain/
UK Government website, notice "Research on cyber security in supplier management and procurement", link https://www.gov.uk/government/publications/research-on-cyber-security-in-supplier-management-and-procurement
Connect with me on:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Website: http://www.theitsmpractice.com
And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.
Credits:
Sound engineering by Alan Southgate - http://alsouthgate.co.uk/
Graphics by Yulia Kolodyazhnaya
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de The ITSM Practice: Elevating ITSM and IT Security Knowledge
Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals!
Stay Connected:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Youtube: https://www.youtube.com/@theitsmpractice
Website: http://www.theitsmpractice.com
Site web du podcastÉcoutez The ITSM Practice: Elevating ITSM and IT Security Knowledge, Tech&Co, la quotidienne ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


The ITSM Practice: Elevating ITSM and IT Security Knowledge
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.
The ITSM Practice: Elevating ITSM and IT Security Knowledge: Podcasts du groupe





































