PodcastsTechnologiesThe ITSM Practice: Elevating ITSM and IT Security Knowledge

The ITSM Practice: Elevating ITSM and IT Security Knowledge

Luigi Ferri
The ITSM Practice: Elevating ITSM and IT Security Knowledge
Dernier épisode

151 épisodes

  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    AI Security Strategy: Why Midmarket Organizations Get It Wrong

    16/06/2026 | 13 min
    Why do most AI security strategies fail in the midmarket? In this episode of The ITSM Practice Podcast, we explore why successful AI security is not about buying more AI tools but about building the right foundation first. Learn how identity management, telemetry quality, governance, and operational maturity determine AI security success. We discuss AI readiness, MSSP evolution, cybersecurity automation, SOC transformation, and practical AI security roadmaps for midmarket organizations. Discover why AI augments security teams rather than replacing them and how organizations can achieve sustainable cyber resilience through proper sequencing.

    In this Episode, we answer:
    Why do most AI security initiatives fail in midmarket organizations despite significant investments in AI-powered cybersecurity tools?
    How do identity management, telemetry quality, and governance impact AI security readiness and operational resilience?
    What should MSPs and MSSPs prioritize over the next 2–3 years to build effective AI security strategies and support midmarket clients?

    Resources Mentioned in this Episode:
    SailPoint website, ebook "Identity as the foundation: The modern zero trust blueprint for 2026", link https://www.sailpoint.com/identity-library/identity-security-essential-to-zero-trust-strategy

    Xage Security website, article "Zero Trust: A Proven Solution for the New AI Security Challenge", link https://xage.com/blog/zero-trust-proven-solution-for-the-new-ai-security-challenge/

    Checkpoint website, article "How AI Phishing Attacks Became A Threat in 2025", link https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-phishing/ai-phishing-attacks/

    EC-Council website, article "The Rising Threat of AI-Powered Phishing: What it is, How to Detect it, and How to Prevent it", link https://www.eccu.edu/blog/ai-powered-phishing-detection-prevention/

    Your Alaska Link TV YouTube Channel, video "Hackers use AI to boost cyber scams and attacks", link https://www.youtube.com/watch?v=hRJqRFj0kRQ

    Microsoft Mechanics YouTube Channel, video "AI with Zero Trust Security", link https://www.youtube.com/watch?v=OnlN-2Q5QsE

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    What DoDAF Can Teach Leaders About Architecture and Complexity

    09/06/2026 | 11 min
    Are modern enterprises losing control of their architecture? In this episode, Luigi Ferri explores why cloud adoption, outsourcing, SaaS expansion, and fragmented governance are creating hidden dependencies and increasing operational risk. Discover how the Department of Defense Architecture Framework (DoDAF) offers valuable lessons for improving architectural visibility, governance, resilience, and enterprise-wide coordination in today's complex digital ecosystems.

    In this episode, we answer to:
    Why are modern enterprises losing architectural ownership and visibility across complex digital ecosystems?
    How can the Department of Defense Architecture Framework (DoDAF) help organizations manage complexity, interoperability, and governance?
    Why do modern outages and operational failures increasingly result from undocumented dependencies and architectural blind spots rather than individual system failures?

    Resources Mentioned in this Episode:
    US DoDAF Official Documentation, Department of Defense Architecture Framework (DoDAF) Version 2.02, link https://dodcio.defense.gov/Library/DoD-Architecture-Framework/

    TOGAF® Enterprise Architecture Framework, TOGAF® Standard, link https://www.opengroup.org/togaf

    NIST Cybersecurity Framework (CSF) 2.0, link https://www.nist.gov/cyberframework

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    Identity Is the New Perimeter

    02/06/2026 | 10 min
    AI is changing cybersecurity faster than most organizations can govern it.

    In this episode of The ITSM Practice Podcast, Luigi Ferri explores why identity has become the true enterprise perimeter. As organizations race to deploy Agentic AI, autonomous agents, cloud platforms, and APIs, many are building on identity governance models that were never designed for machine-scale decision-making.

    From Zero Trust Architecture and Identity & Access Management (IAM) to the lessons behind major breaches at MGM, Snowflake, and Uber, this episode examines a critical question:

    If enterprises struggled to govern human identities, how will they govern autonomous AI identities?

    Discover why AI governance without identity governance is impossible, why identity is evolving into the operational control plane of digital business, and what CIOs and CISOs must do before AI adoption outpaces organizational control.

    In this episode, we answer:
    Why is identity becoming the new perimeter in the age of AI?
    What risks emerge when autonomous agents operate without strong identity governance?
    How can organizations redesign trust before AI scales faster than governance?

    Resources Mentioned in this Episode:
    NIST website, Zero Trust Architecture (SP 800-207), link https://csrc.nist.gov/pubs/sp/800/207/final?

    NIST website, AI Risk Management Framework, link https://www.nist.gov/itl/ai-risk-management-framework

    European Commission website, EU AI Act, link https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

    Dark Reading website, article "Okta Agent Involved in MGM Resorts Breach, Attackers Claim", link https://www.darkreading.com/application-security/okta-flaw-involved-mgm-resorts-breach-attackers-claim

    Cyberark website, article "The MGM Resorts Attack: Initial Analysis", link https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-analysis

    Blackfog website, article "Showflake Data Breach Explained", link https://www.blackfog.com/snowflake-data-breach-explained-key-lessons/

    Cloud Security Alliance website, article "Unpacking the 2024 Snowflake Data Breach", link https://cloudsecurityalliance.org/blog/2025/05/07/unpacking-the-2024-snowflake-data-breach

    USA CISA website, article "Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester", link https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a?

    USA CISA website, advisory on MFA fatigue and modern identity attacks, link https://www.cisa.gov/news-events/alerts/2022/10/31/cisa-releases-guidance-phishing-resistant-and-numbers-matching-multifactor-authentication

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    FINMA and ITIL 4: Building Resilient Swiss Banks

    26/05/2026 | 9 min
    FINMA Circular 2023/1 is transforming operational resilience from a compliance exercise into a strategic leadership priority for Swiss banks. In this episode, Luigi Ferri explains why ITIL 4 is far more than ITSM, it is a powerful enterprise operating model that connects governance, cybersecurity, risk management, supplier coordination, and business continuity to build truly resilient financial institutions.

    In this episode, we answer to:
    Why is operational resilience becoming the new license to operate for banks?
    How does ITIL 4 support FINMA resilience and cybersecurity requirements?
    What organizational silos are preventing true enterprise resilience?

    Resources Mentioned in this Episode:
    Finma website, Circular 2023/1 Operational risks and resilience for banks, link https://www.finma.ch/en/~/media/finma/dokumente/dokumentencenter/myfinma/rundschreiben/finma-rs-2023-01-20221207.pdf

    Finma website, article "FINMA publishes Circular “Operational risks and resilience – banks”, link https://www.finma.ch/en/news/2022/12/20221213-mm-anh-rs-op-risks/

    KPMG website, article "FINMA Circular 2023/1", link https://assets.kpmg.com/content/dam/kpmgsites/ch/pdf/finma-circular-2023.pdf.coredownload.inline.pdf

    InfoGuard website, article "FINMA Circular 2023/1 Checklist - Ready for a regulatory audit?", link https://www.infoguard.ch/hubfs/images/blog/24/InfoGuard-FINMA-Checkliste_EN.pdf

    Manage Engine website, article "The ITIL 4 Service Value System", link https://www.manageengine.com/products/service-desk/itsm/itil-4-service-value-system.html

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    Broken Transmission: Why Fintech Strategy Fails

    19/05/2026 | 6 min
    Broken Transmission: Why Agile Fintechs Miss Strategy | In this episode of The ITSM Practice Podcast, Luigi Ferri explains why fintech strategy execution fails despite Agile delivery, strong squads, and constant releases. Learn how fragmented ownership, poor prioritization, and disconnected KPIs create operational misalignment, reducing business outcomes and authorization rate performance.

    In this episode, we answer to:
    Why do Agile fintech teams fail to execute business strategy effectively?
    How does fragmented ownership impact authorization rate improvement initiatives?
    Why do operational priorities override strategic portfolio management in fintech organizations?

    Resources Mentioned in this Episode:
    Project Management Institute, whitepaper "The High Cost of Low Performance 2014", link https://www.pmi.org/-/media/pmi/documents/public/pdf/learning/thought-leadership/pulse/pulse-of-the-profession-2014.pdf

    University of Salford - Manchester, Abdallah M. Salameh, document "A Heterogeneous Approach to Agile Tailoring", link https://salford-repository.worktribe.com/OutputFile/1487893

    Institute of Project Management website, article "The Emerging Importance of Benefits Realisation", link https://projectmanagement.ie/blog/the-emerging-importance-of-benefits-realisation/

    McKinsey & Company website, article "Don’t cancel or coddle at-risk capital projects—challenge them", link https://www.mckinsey.com/capabilities/operations/our-insights/dont-cancel-or-coddle-at-risk-capital-projects-challenge-them

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
Plus de podcasts Technologies
À propos de The ITSM Practice: Elevating ITSM and IT Security Knowledge
Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals! Stay Connected: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Youtube: https://www.youtube.com/@theitsmpractice Website: http://www.theitsmpractice.com
Site web du podcast

Écoutez The ITSM Practice: Elevating ITSM and IT Security Knowledge, De quoi jme mail ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr
 gratuite

  • Ajout de radios et podcasts en favoris
  • Diffusion via Wi-Fi ou Bluetooth
  • Carplay & Android Auto compatibles
  • Et encore plus de fonctionnalités
The ITSM Practice: Elevating ITSM and IT Security Knowledge: Podcasts du groupe