PodcastsTechnologiesThe ITSM Practice: Elevating ITSM and IT Security Knowledge

The ITSM Practice: Elevating ITSM and IT Security Knowledge

Luigi Ferri
The ITSM Practice: Elevating ITSM and IT Security Knowledge
Dernier épisode

149 épisodes

  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    Identity Is the New Perimeter

    02/06/2026 | 10 min
    AI is changing cybersecurity faster than most organizations can govern it.

    In this episode of The ITSM Practice Podcast, Luigi Ferri explores why identity has become the true enterprise perimeter. As organizations race to deploy Agentic AI, autonomous agents, cloud platforms, and APIs, many are building on identity governance models that were never designed for machine-scale decision-making.

    From Zero Trust Architecture and Identity & Access Management (IAM) to the lessons behind major breaches at MGM, Snowflake, and Uber, this episode examines a critical question:

    If enterprises struggled to govern human identities, how will they govern autonomous AI identities?

    Discover why AI governance without identity governance is impossible, why identity is evolving into the operational control plane of digital business, and what CIOs and CISOs must do before AI adoption outpaces organizational control.

    In this episode, we answer:
    Why is identity becoming the new perimeter in the age of AI?
    What risks emerge when autonomous agents operate without strong identity governance?
    How can organizations redesign trust before AI scales faster than governance?

    Resources Mentioned in this Episode:
    NIST website, Zero Trust Architecture (SP 800-207), link https://csrc.nist.gov/pubs/sp/800/207/final?

    NIST website, AI Risk Management Framework, link https://www.nist.gov/itl/ai-risk-management-framework

    European Commission website, EU AI Act, link https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

    Dark Reading website, article "Okta Agent Involved in MGM Resorts Breach, Attackers Claim", link https://www.darkreading.com/application-security/okta-flaw-involved-mgm-resorts-breach-attackers-claim

    Cyberark website, article "The MGM Resorts Attack: Initial Analysis", link https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-analysis

    Blackfog website, article "Showflake Data Breach Explained", link https://www.blackfog.com/snowflake-data-breach-explained-key-lessons/

    Cloud Security Alliance website, article "Unpacking the 2024 Snowflake Data Breach", link https://cloudsecurityalliance.org/blog/2025/05/07/unpacking-the-2024-snowflake-data-breach

    USA CISA website, article "Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester", link https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a?

    USA CISA website, advisory on MFA fatigue and modern identity attacks, link https://www.cisa.gov/news-events/alerts/2022/10/31/cisa-releases-guidance-phishing-resistant-and-numbers-matching-multifactor-authentication

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    FINMA and ITIL 4: Building Resilient Swiss Banks

    26/05/2026 | 9 min
    FINMA Circular 2023/1 is transforming operational resilience from a compliance exercise into a strategic leadership priority for Swiss banks. In this episode, Luigi Ferri explains why ITIL 4 is far more than ITSM, it is a powerful enterprise operating model that connects governance, cybersecurity, risk management, supplier coordination, and business continuity to build truly resilient financial institutions.

    In this episode, we answer to:
    Why is operational resilience becoming the new license to operate for banks?
    How does ITIL 4 support FINMA resilience and cybersecurity requirements?
    What organizational silos are preventing true enterprise resilience?

    Resources Mentioned in this Episode:
    Finma website, Circular 2023/1 Operational risks and resilience for banks, link https://www.finma.ch/en/~/media/finma/dokumente/dokumentencenter/myfinma/rundschreiben/finma-rs-2023-01-20221207.pdf

    Finma website, article "FINMA publishes Circular “Operational risks and resilience – banks”, link https://www.finma.ch/en/news/2022/12/20221213-mm-anh-rs-op-risks/

    KPMG website, article "FINMA Circular 2023/1", link https://assets.kpmg.com/content/dam/kpmgsites/ch/pdf/finma-circular-2023.pdf.coredownload.inline.pdf

    InfoGuard website, article "FINMA Circular 2023/1 Checklist - Ready for a regulatory audit?", link https://www.infoguard.ch/hubfs/images/blog/24/InfoGuard-FINMA-Checkliste_EN.pdf

    Manage Engine website, article "The ITIL 4 Service Value System", link https://www.manageengine.com/products/service-desk/itsm/itil-4-service-value-system.html

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    Broken Transmission: Why Fintech Strategy Fails

    19/05/2026 | 6 min
    Broken Transmission: Why Agile Fintechs Miss Strategy | In this episode of The ITSM Practice Podcast, Luigi Ferri explains why fintech strategy execution fails despite Agile delivery, strong squads, and constant releases. Learn how fragmented ownership, poor prioritization, and disconnected KPIs create operational misalignment, reducing business outcomes and authorization rate performance.

    In this episode, we answer to:
    Why do Agile fintech teams fail to execute business strategy effectively?
    How does fragmented ownership impact authorization rate improvement initiatives?
    Why do operational priorities override strategic portfolio management in fintech organizations?

    Resources Mentioned in this Episode:
    Project Management Institute, whitepaper "The High Cost of Low Performance 2014", link https://www.pmi.org/-/media/pmi/documents/public/pdf/learning/thought-leadership/pulse/pulse-of-the-profession-2014.pdf

    University of Salford - Manchester, Abdallah M. Salameh, document "A Heterogeneous Approach to Agile Tailoring", link https://salford-repository.worktribe.com/OutputFile/1487893

    Institute of Project Management website, article "The Emerging Importance of Benefits Realisation", link https://projectmanagement.ie/blog/the-emerging-importance-of-benefits-realisation/

    McKinsey & Company website, article "Don’t cancel or coddle at-risk capital projects—challenge them", link https://www.mckinsey.com/capabilities/operations/our-insights/dont-cancel-or-coddle-at-risk-capital-projects-challenge-them

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    FINOS vs ISO 42001: What to Choose

    12/05/2026 | 8 min
    Fintech leaders: stop defaulting to ISO 42001. Discover how FINOS empowers you to design scalable, audit-ready AI governance before regulation forces your hand. Learn to align controls, reduce risk, and build governance by design—not by pressure.

    In this episode, we answer to:
    What makes FINOS a powerful alternative to ISO 42001?
    How can fintechs design governance before audits hit?
    Why does governance fail without alignment?

    Resources Mentioned in this Episode:
    FINOS website, article "AI Strategic initiative series: Building an AI Governance Framework - Key Takeaways from the NYC Workshop", link https://www.finos.org/blog/building-an-ai-governance-framework-key-takeaways-from-the-nyc-workshop

    FINOS website, article "FINOS AI Governance Framework v1.0 — Turning Drafts into Deployable Guardrails", link https://www.finos.org/blog/finos-ai-governance-framework-v1.0-turning-drafts-into-deployable-guardrails

    Air Governance website, article "A heuristic approach to identifying GenAI risks", link https://air-governance-framework.finos.org/heuristic-assessment.html

    Air Governance website, article "FINOS AI Governance Framework", link https://air-governance-framework.finos.org

    GitHub website, repo "finos/ai-governance-framework - Public", link https://github.com/finos/ai-governance-framework

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    Who Owns Cloud Security?

    05/05/2026 | 9 min
    A single question can expose a major cloud risk: who is responsible? This episode breaks down the cloud shared responsibility model, revealing how unclear ownership, misconfigurations, and weak governance lead to data breaches, and how ISO/IEC 27017 helps close the gaps.

    In this episode, we answer to:
    Who is really accountable for cloud security failures?
    Why do misconfigurations cause most cloud data breaches?
    How does ISO/IEC 27017 strengthen cloud security governance?

    Resources Mentioned in this Episode:
    ISO Standards website, standard ISO/IEC 27017:2015, link https://www.iso.org/standard/43757.html

    Vanta website, article "The ultimate guide to ISO 27017", link https://www.vanta.com/collection/iso-27001/guide-to-iso-27017

    Microsoft website, article "ISO/IEC 27017:2015", link https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-iso-27017

    Safeshield website, article "Why should SaaS companies comply with the ISO/IEC 27017 security standard for cloud service providers (CSP)", link https://www.safeshield.cloud/why-should-saas-companies-comply-with-the-iso-27017-security-standard-for-cloud-service-providers-csp

    NordLayer website, article "ISO 27017: cloud protection essentials", link https://nordlayer.com/learn/iso/iso-27017/

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
Plus de podcasts Technologies
À propos de The ITSM Practice: Elevating ITSM and IT Security Knowledge
Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals! Stay Connected: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Youtube: https://www.youtube.com/@theitsmpractice Website: http://www.theitsmpractice.com
Site web du podcast

Écoutez The ITSM Practice: Elevating ITSM and IT Security Knowledge, Tech Café ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr
 gratuite

  • Ajout de radios et podcasts en favoris
  • Diffusion via Wi-Fi ou Bluetooth
  • Carplay & Android Auto compatibles
  • Et encore plus de fonctionnalités
The ITSM Practice: Elevating ITSM and IT Security Knowledge: Podcasts du groupe