Skip to content
Artwork for The ITSM Practice: Elevating ITSM and IT Security Knowledge

The ITSM Practice: Elevating ITSM and IT Security Knowledge

Luigi Ferri

Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals!

Stay Connected:
LinkedIn: https://www.linkedin.com/in/theitsmpractice/
Youtube: https://www.youtube.com/@theitsmpractice
Website: http://www.theitsmpractice.com

Play
  • 22 episodes
  • weekly
  • Avg 10 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S3 · E25
    Tuesday · 8 min

    ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

    Are cyber exercises actually improving your cybersecurity resilience, or just satisfying compliance requirements? In this episode, Luigi Ferri explores ENISA's cyber exercise methodology, the gap between testing and real capability improvement, the role of MSPs in incident response, and why organizations must focus on measurable cyber resilience instead of annual audit-driven exercises. In this episode, we answer to: Why are cyber exercises important for improving cybersecurity resilience rather than just meeting compliance? What is the difference between testing cybersecurity and improving organizational cyber resilience? How can organizations ensure cyber exercise findings lead to measurable capability improvement? Resources Mentioned in this Episode: ENISA website, guideline "ENISA Technical Advisory for Secure Use of Package Managers", link https://r.search.yahoo.com/_ylt=AwrkMQ3LAHFqUAIA0Av04olQ;_ylu=Y29sbwNpcjIEcG9zAzIEdnRpZAMEc2VjA3Ny/RV=2/RE=1787000268/RO=10/RU=https%3a%2f%2fwww.enisa.europa.eu%2fsites%2fdefault%2ffiles%2f2026-03%2fENISA%2520Technical%2520Advisory%2520-%2520Package_Managers_Final.pdf/RK=2/RS=gKGJNKMoHHsXF59MpNiBxFeSfpU- Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E24
    August 18 · 11 min

    Projects Deliver Outputs. Services Deliver Outcomes.

    Projects Deliver Outputs, Services Deliver Outcomes: The Ownership Crisis Nobody Discusses. Discover why the biggest risk in any IT project begins after go-live. In this episode, Luigi Ferri explores the critical difference between project outputs and service outcomes, why Service Ownership is essential for long-term business value, and how IT Service Management (ITSM), Product Management, and Business Capability Management must work together to drive sustainable success. Learn why organizations have an ownership problem. In this episode, we answer to: Why is the day after go-live often the most dangerous stage of a project? What is the difference between a Product Owner and a Service Owner, and why does it matter? How can organizations improve long-term business outcomes through Service Management and clear ownership? Resources Mentioned in this Episode: PMI Institute, article "Pulse of the Profession 2024", link https://www.scribd.com/document/709988299/PMI-Pulse-of-the-Profession-2024-Report Balanced Scorecard Institute, article "Is Your Strategy Execution Crumbling as a Result of Too Many Projects?", link https://balancedscorecard.org/blog/is-your-strategy-execution-crumbling-as-a-result-of-too-many-projects/ PwC website, article "PwC Middle East Transformation and project management survey part 1", link https://www.pwc.com/m1/en/publications/transformation-and-project-management-survey.html Business Chief website, article "MIT Sloan: Why so many business digital transformations fail", link https://businesschief.asia/digital-strategy/mit-sloan-why-so-many-business-digital-transformations-fail MIT website, article "5 reasons companies struggle with digital transformation", link https://mitsloan.mit.edu/ideas-made-to-matter/5-reasons-companies-struggle-digital-transformation Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E23
    August 11 · 16 min

    MSPs: Your AI Contracts Are Obsolete

    AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are no longer sufficient for AI-enabled services. Learn how AI impacts ITIL service management, AI governance, MSP liability, ISO 42001, NIST AI RMF, the EU AI Act, and why AI ownership, accountability, and updated contracts are now business-critical. In this episode, we answer: How does AI change the nature of IT services and MSP service design? Why are traditional MSP contracts, governance models, and risk frameworks becoming outdated with AI? Who is accountable and liable when AI-enabled services make decisions or cause incidents? Resources Mentioned in this Episode: Simmons + Simmons website, article "The EU AI Act: A Quick Guide", link https://www.simmons-simmons.com/en/publications/clyimpowh000ouxgkw1oidakk/the-eu-ai-act-a-quick-guide ISO website, standard "ISO/IEC 42001:2023", link https://www.iso.org/standard/42001 European Parliament website, regulation "EU AI Act: first regulation on artificial intelligence", link https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence NIST website, AI Risk Management Framework, link https://airc.nist.gov/airmf-resources/airmf/ NIST website, The NIST AI Risk Management Framework, link https://www.nist.gov/itl/ai-risk-management-framework ISO website, article "AI management systems: What businesses need to know", link https://www.iso.org/artificial-intelligence/ai-management-systems European Commission website, regulation "AI Act", link https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E22
    August 4 · 9 min

    DARE25: Why Defense Isn't Enough

    Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and adaptive leadership. Learn how Enterprise Service Management, IT Service Management, and cybersecurity leaders can build resilient organizations by prioritizing behavior, faster adaptation, and continuous learning. In this episode, we answer to: Why is traditional cybersecurity defense no longer enough in the age of AI? How does the DARE25 framework improve risk management, governance, and organizational resilience? Why are accountability, adaptive leadership, and Purple Teaming essential for modern cybersecurity? Resources Mentioned in this Episode: Marco Amadei, creator of the DARE25 Digital Risk Management Framework, link https://www.linkedin.com/in/marco-amadei-0087844/ APMG website, article "Digital Risk Management Certification (DARE25)", link https://apmg-international.com/product/digital-risk-management-certification-dare25 APMG website, article "Introduction to AI in Risk Management", link https://apmg-international.com/article/introduction-ai-risk-management Strategic Digital Risk Management – an unofficial LinkedIn page sharing insights, research, and updates on the DARE25 Framework, link https://www.linkedin.com/company/strategicdigitalriskmanagement/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E21
    July 28 · 13 min

    ISO 28000: Your Resilience, Their Budget

    In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using practical examples from healthcare and public services, he explains how ISO 28000 shifts the conversation from protecting internal systems to managing the security and resilience of the organizations you depend on. Discover why supplier failures, inherited risk, and third-party dependencies are becoming the greatest threats to service continuity, cybersecurity, and operational resilience in government and regulated industries. In this episode, we answer: Why is ISO 28000 becoming essential for Government Managed Service Providers and supply chain resilience? How can third-party suppliers and subcontractors become the weakest link in your cybersecurity and operational resilience strategy? Why should CISOs focus on inherited risk and supplier dependencies rather than only internal security controls? Resources Mentioned in this Episode: The Standards Institution of Israel website, article "SI ISO 28000 :2022 Specification for security management systems for the supply chain", link https://www.sii.org.il/en/iso-28000 ANSI website, article "What Is ISO 28000?", link https://blog.ansi.org/anab/what-is-iso-28000/ Wikipedia website, article "ISO 28000", link https://en.wikipedia.org/wiki/ISO/PAS_28000 NIST website, publication "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", link https://csrc.nist.rip/Pubs/sp/800/161/r1/2PD SITS website, article "NIS2, DORA & Co: Aren’t we all part of someone’s relevant supply chain?", link https://sits.com/en/blog/nis2-dora-supply-chain/ UK Government website, notice "Research on cyber security in supplier management and procurement", link https://www.gov.uk/government/publications/research-on-cyber-security-in-supplier-management-and-procurement Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E20
    July 21 · 19 min

    No SBOM, No Trust

    Discover why the Software Bill of Materials (SBOM) is rapidly becoming a strategic necessity for Managed Service Providers (MSPs) and enterprise IT leaders. In this episode, Luigi Ferri explains how software supply chain attacks such as Log4Shell and SolarWinds transformed SBOMs from technical documentation into essential tools for IT governance, cyber resilience, software supply chain security, and operational trust. Learn the four stages of SBOM maturity and how MSPs can strengthen transparency, improve vulnerability management, and build competitive advantage through continuous software dependency visibility. In this episode, we answer to: Why are Software Bill of Materials (SBOMs) becoming essential for Managed Service Providers (MSPs)? How can MSPs improve software supply chain security and gain complete visibility over software dependencies? What are the four stages of SBOM maturity that help organizations strengthen governance, resilience, and operational trust? Resources Mentioned in this Episode: US NTIA - National Telecommunications and Information Administration website, article "Software Bill of Materials", link https://www.ntia.gov/page/software-bill-materials US NTIA - National Telecommunications and Information Administration website, white paper "Software Consumers Playbook: SBOM Acquisition, Management, and Use", link https://www.ntia.gov/sites/default/files/publications/software_consumers_sbom_acquisition_management_and_use_-_final_0.pdf US NIST website, Executive Order 14028 "Improving the Nation's Cybersecurity: NIST’s Responsibilities Under the May 2021 Executive Order", link https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity US NTIA - National Telecommunications and Information Administration website, link Carnegy Mellon University - Software Engineering Institute, article "The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain", link https://www.sei.cmu.edu/blog/the-sei-sbom-framework-informing-third-party-software-management-in-your-supply-chain/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E19
    July 14 · 6 min

    PSD3: Who Owns Trust?

    PSD3 is more than a compliance requirement, it's a test of organisational maturity, security leadership, accountability, and decision-making. Discover how Enterprise Service Management, IT Service Management, and cybersecurity principles help organisations balance security, customer trust, and clear ownership to build resilience beyond regulatory compliance. In this episode, we answer: How does PSD3 reveal an organisation's maturity and decision-making under pressure? When should security lead, and when should it step back to enable business ownership? Who is truly accountable for trust, fraud prevention, and customer protection under PSD3? Resources Mentioned in this Episode: Stripe website, article "What platforms and marketplaces can expect from PSD3", link https://stripe.com/guides/what-platforms-and-marketplaces-can-expect-from-psd3 Deloitte Luxembourg website, article "Shedding light on PSD3/PSR", link https://www.deloitte.com/lu/en/Industries/banking-capital-markets/perspectives/shedding-light-on-psd3-psr.html European Payments Council website, article "What do the PSD3 and PSR mean for the payments sector?", link https://www.europeanpaymentscouncil.eu/news-insights/insight/what-do-psd3-and-psr-mean-payments-sector Advapay website, article "PSD2 vs PSD3/PSR: what’s new in the upcoming EU’s Payment Services Directive and Regulations", link https://advapay.eu/psd2-vs-psd3-whats-new-in-the-upcoming-eus-3rd-payment-services-directive/ PWC Ireland website, article "PSD3: Shaping the future of secure, innovative payments", link https://www.pwc.ie/industries/banking/insights/payment-services-directive-3.html Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E18
    July 7 · 11 min

    The Hidden Cost of Untrusted Data

    Why do organizations struggle to trust their operational data despite having plenty of it? In this episode of The ITSM Practice Podcast, Luigi Ferri explains the critical difference between data quality and data integrity, and why CIOs must build operational trust before launching digital transformation initiatives. Learn practical ITSM strategies to improve data governance, CMDB accuracy, operational accountability, and Enterprise Service Management. In this episode, we answer to: What is the difference between data quality and data integrity, and why does it matter for CIOs? Why do multiple departments report different numbers for the same operational metric? How can organizations build trusted operational data before starting digital transformation? Resources Mentioned in this Episode: Precisely website, article "Data Integrity vs. Data Quality: How Are They Different?", link https://www.precisely.com/blog/data-integrity/data-integrity-vs-data-quality-different Atlan website, article "Data Quality vs Data Governance: How Are They Different in 2026?", link https://atlan.com/data-quality-vs-data-governance/ Salesforce website, article "Salesforce Signs Definitive Agreement to Acquire Informatica", link https://www.salesforce.com/news/press-releases/2025/05/27/salesforce-signs-definitive-agreement-to-acquire-informatica/ Qlik Support Portal, article "Validating data", link https://help.qlik.com/talend/en-US/studio-user-guide/8.0-R2024-12/validating-data Informatica website, white paper "Informatice Data Quality and Observability", link https://www.informatica.com/content/dam/informatica-com/en/collateral/data-sheet/cloud-data-quality_data-sheet_3688en.pdf Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E16
    June 30 · 10 min

    ITIL 5 Foundation: Exam Success

    Preparing for the ITIL 5 Foundation exam? Discover why successful candidates focus on understanding the ITIL Value System, Value Chain, Governance, AI Capability, Four Dimensions, and Service Lifecycles as one connected system instead of isolated chapters. Learn smarter study strategies to improve your exam performance and master ITIL 5 concepts. In this episode, we answer to: Why is the ITIL Value System the foundation for understanding the entire ITIL 5 framework? How does AI Capability depend on governance, knowledge management, and operating models? How can you study the ITIL 5 Foundation exam more effectively by focusing on system thinking instead of memorizing chapters? Resources Mentioned in this Episode: Mind Mesh Academy website, article "ITIL® Foundation (Version 5) Study Guide", link https://www.mindmeshacademy.com/certifications/itil/itil-5-foundation/study-guide PeopleCert website, article "ITIL Foundation (Version 5)", link https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-5-foundation-version-50-4154 InProgress website, document name "Training Program - ITIL Foundation (Version 5)", link https://inprogressplus.com/wp-content/uploads/2026/05/Training-programme_ITIL5F_ENG_v2.0.pdf PeopleCert website, ITIL 5 Mock exams, link https://www.peoplecert.org/browse-mock-exams/it-governance-and-service-management/ITIL-1 1 World Training Official Channel YouTube Channel, video "Sample Paper | ITIL® Foundation Bridge (version 5)", link https://www.youtube.com/watch?v=-21MZIbPUDI Value Insights website, article "Are you ready to pass the ITIL® (Version 5) Foundation exam?", link https://www.valueinsights.ch/itil5-foundation-exam-quiz/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E17
    June 23 · 7 min

    PSD3: Governance Before Technology

    In this episode, Luigi Ferri explores why organisations often take the wrong first step when preparing for PSD3 compliance. Rather than rushing into new tools, fraud platforms, or transformation programmes, PSD3 readiness begins with observation. Learn how incident response, governance, decision authority, and organisational behaviour under uncertainty reveal the real gaps that PSD3 exposes. Discover why governance maturity and clear accountability are critical for building a resilient PSD3 strategy. In this episode, we answer to: Why is the first step towards PSD3 compliance so often the wrong one? How can incident response reveal governance gaps and decision-making weaknesses? What should organisations stabilise before launching PSD3 programmes, fraud initiatives, or policy transformations? Resources Mentioned in this Episode: Deloitte website, article "Shedding light on PSD3/PSR", link https://www.deloitte.com/lu/en/Industries/banking-capital-markets/perspectives/shedding-light-on-psd3-psr.html Schoenherr website, article "The EU's new Payments Services Package", link https://www.schoenherr.eu/content/the-eu-s-new-payments-services-package European Payments Council website, article "What do the PSD3 and PSR mean for the payments sector?", link https://www.europeanpaymentscouncil.eu/news-insights/insight/what-do-psd3-and-psr-mean-payments-sector MK Fintech Partners website, article "PSD3 is Here! How is it Different From Previous Directives?", link https://mkfintechpartners.com/2023/07/11/difference-psd1-psd2-and-psd3/ Finexer website, article "PSD3: All you need to know in 2025", link https://blog.finexer.com/psd3-all-you-need-to-know-in-2025/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E14
    June 16 · 13 min

    AI Security Strategy: Why Midmarket Organizations Get It Wrong

    Why do most AI security strategies fail in the midmarket? In this episode of The ITSM Practice Podcast, we explore why successful AI security is not about buying more AI tools but about building the right foundation first. Learn how identity management, telemetry quality, governance, and operational maturity determine AI security success. We discuss AI readiness, MSSP evolution, cybersecurity automation, SOC transformation, and practical AI security roadmaps for midmarket organizations. Discover why AI augments security teams rather than replacing them and how organizations can achieve sustainable cyber resilience through proper sequencing. In this Episode, we answer: Why do most AI security initiatives fail in midmarket organizations despite significant investments in AI-powered cybersecurity tools? How do identity management, telemetry quality, and governance impact AI security readiness and operational resilience? What should MSPs and MSSPs prioritize over the next 2–3 years to build effective AI security strategies and support midmarket clients? Resources Mentioned in this Episode: SailPoint website, ebook "Identity as the foundation: The modern zero trust blueprint for 2026", link https://www.sailpoint.com/identity-library/identity-security-essential-to-zero-trust-strategy Xage Security website, article "Zero Trust: A Proven Solution for the New AI Security Challenge", link https://xage.com/blog/zero-trust-proven-solution-for-the-new-ai-security-challenge/ Checkpoint website, article "How AI Phishing Attacks Became A Threat in 2025", link https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-phishing/ai-phishing-attacks/ EC-Council website, article "The Rising Threat of AI-Powered Phishing: What it is, How to Detect it, and How to Prevent it", link https://www.eccu.edu/blog/ai-powered-phishing-detection-prevention/ Your Alaska Link TV YouTube Channel, video "Hackers use AI to boost cyber scams and attacks", link https://www.youtube.com/watch?v=hRJqRFj0kRQ Microsoft Mechanics YouTube Channel, video "AI with Zero Trust Security", link https://www.youtube.com/watch?v=OnlN-2Q5QsE Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E14
    June 9 · 11 min

    What DoDAF Can Teach Leaders About Architecture and Complexity

    Are modern enterprises losing control of their architecture? In this episode, Luigi Ferri explores why cloud adoption, outsourcing, SaaS expansion, and fragmented governance are creating hidden dependencies and increasing operational risk. Discover how the Department of Defense Architecture Framework (DoDAF) offers valuable lessons for improving architectural visibility, governance, resilience, and enterprise-wide coordination in today's complex digital ecosystems. In this episode, we answer to: Why are modern enterprises losing architectural ownership and visibility across complex digital ecosystems? How can the Department of Defense Architecture Framework (DoDAF) help organizations manage complexity, interoperability, and governance? Why do modern outages and operational failures increasingly result from undocumented dependencies and architectural blind spots rather than individual system failures? Resources Mentioned in this Episode: US DoDAF Official Documentation, Department of Defense Architecture Framework (DoDAF) Version 2.02, link https://dodcio.defense.gov/Library/DoD-Architecture-Framework/ TOGAF® Enterprise Architecture Framework, TOGAF® Standard, link https://www.opengroup.org/togaf NIST Cybersecurity Framework (CSF) 2.0, link https://www.nist.gov/cyberframework Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E13
    June 2 · 10 min

    Identity Is the New Perimeter

    AI is changing cybersecurity faster than most organizations can govern it. In this episode of The ITSM Practice Podcast, Luigi Ferri explores why identity has become the true enterprise perimeter. As organizations race to deploy Agentic AI, autonomous agents, cloud platforms, and APIs, many are building on identity governance models that were never designed for machine-scale decision-making. From Zero Trust Architecture and Identity & Access Management (IAM) to the lessons behind major breaches at MGM, Snowflake, and Uber, this episode examines a critical question: If enterprises struggled to govern human identities, how will they govern autonomous AI identities? Discover why AI governance without identity governance is impossible, why identity is evolving into the operational control plane of digital business, and what CIOs and CISOs must do before AI adoption outpaces organizational control. In this episode, we answer: Why is identity becoming the new perimeter in the age of AI? What risks emerge when autonomous agents operate without strong identity governance? How can organizations redesign trust before AI scales faster than governance? Resources Mentioned in this Episode: NIST website, Zero Trust Architecture (SP 800-207), link https://csrc.nist.gov/pubs/sp/800/207/final? NIST website, AI Risk Management Framework, link https://www.nist.gov/itl/ai-risk-management-framework European Commission website, EU AI Act, link https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai Dark Reading website, article "Okta Agent Involved in MGM Resorts Breach, Attackers Claim", link https://www.darkreading.com/application-security/okta-flaw-involved-mgm-resorts-breach-attackers-claim Cyberark website, article "The MGM Resorts Attack: Initial Analysis", link https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-analysis Blackfog website, article "Showflake Data Breach Explained", link https://www.blackfog.com/snowflake-data-breach-explained-key-lessons/ Cloud Security Alliance website, article "Unpacking the 2024 Snowflake Data Breach", link https://cloudsecurityalliance.org/blog/2025/05/07/unpacking-the-2024-snowflake-data-breach USA CISA website, article "Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester", link https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a? USA CISA website, advisory on MFA fatigue and modern identity attacks, link https://www.cisa.gov/news-events/alerts/2022/10/31/cisa-releases-guidance-phishing-resistant-and-numbers-matching-multifactor-authentication Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E12
    May 26 · 9 min

    FINMA and ITIL 4: Building Resilient Swiss Banks

    FINMA Circular 2023/1 is transforming operational resilience from a compliance exercise into a strategic leadership priority for Swiss banks. In this episode, Luigi Ferri explains why ITIL 4 is far more than ITSM, it is a powerful enterprise operating model that connects governance, cybersecurity, risk management, supplier coordination, and business continuity to build truly resilient financial institutions. In this episode, we answer to: Why is operational resilience becoming the new license to operate for banks? How does ITIL 4 support FINMA resilience and cybersecurity requirements? What organizational silos are preventing true enterprise resilience? Resources Mentioned in this Episode: Finma website, Circular 2023/1 Operational risks and resilience for banks, link https://www.finma.ch/en/~/media/finma/dokumente/dokumentencenter/myfinma/rundschreiben/finma-rs-2023-01-20221207.pdf Finma website, article "FINMA publishes Circular “Operational risks and resilience – banks”, link https://www.finma.ch/en/news/2022/12/20221213-mm-anh-rs-op-risks/ KPMG website, article "FINMA Circular 2023/1", link https://assets.kpmg.com/content/dam/kpmgsites/ch/pdf/finma-circular-2023.pdf.coredownload.inline.pdf InfoGuard website, article "FINMA Circular 2023/1 Checklist - Ready for a regulatory audit?", link https://www.infoguard.ch/hubfs/images/blog/24/InfoGuard-FINMA-Checkliste_EN.pdf Manage Engine website, article "The ITIL 4 Service Value System", link https://www.manageengine.com/products/service-desk/itsm/itil-4-service-value-system.html Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E11
    May 19 · 6 min

    Broken Transmission: Why Fintech Strategy Fails

    Broken Transmission: Why Agile Fintechs Miss Strategy | In this episode of The ITSM Practice Podcast, Luigi Ferri explains why fintech strategy execution fails despite Agile delivery, strong squads, and constant releases. Learn how fragmented ownership, poor prioritization, and disconnected KPIs create operational misalignment, reducing business outcomes and authorization rate performance. In this episode, we answer to: Why do Agile fintech teams fail to execute business strategy effectively? How does fragmented ownership impact authorization rate improvement initiatives? Why do operational priorities override strategic portfolio management in fintech organizations? Resources Mentioned in this Episode: Project Management Institute, whitepaper "The High Cost of Low Performance 2014", link https://www.pmi.org/-/media/pmi/documents/public/pdf/learning/thought-leadership/pulse/pulse-of-the-profession-2014.pdf University of Salford - Manchester, Abdallah M. Salameh, document "A Heterogeneous Approach to Agile Tailoring", link https://salford-repository.worktribe.com/OutputFile/1487893 Institute of Project Management website, article "The Emerging Importance of Benefits Realisation", link https://projectmanagement.ie/blog/the-emerging-importance-of-benefits-realisation/ McKinsey & Company website, article "Don’t cancel or coddle at-risk capital projects—challenge them", link https://www.mckinsey.com/capabilities/operations/our-insights/dont-cancel-or-coddle-at-risk-capital-projects-challenge-them Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E10
    May 12 · 8 min

    FINOS vs ISO 42001: What to Choose

    Fintech leaders: stop defaulting to ISO 42001. Discover how FINOS empowers you to design scalable, audit-ready AI governance before regulation forces your hand. Learn to align controls, reduce risk, and build governance by design—not by pressure. In this episode, we answer to: What makes FINOS a powerful alternative to ISO 42001? How can fintechs design governance before audits hit? Why does governance fail without alignment? Resources Mentioned in this Episode: FINOS website, article "AI Strategic initiative series: Building an AI Governance Framework - Key Takeaways from the NYC Workshop", link https://www.finos.org/blog/building-an-ai-governance-framework-key-takeaways-from-the-nyc-workshop FINOS website, article "FINOS AI Governance Framework v1.0 — Turning Drafts into Deployable Guardrails", link https://www.finos.org/blog/finos-ai-governance-framework-v1.0-turning-drafts-into-deployable-guardrails Air Governance website, article "A heuristic approach to identifying GenAI risks", link https://air-governance-framework.finos.org/heuristic-assessment.html Air Governance website, article "FINOS AI Governance Framework", link https://air-governance-framework.finos.org GitHub website, repo "finos/ai-governance-framework - Public", link https://github.com/finos/ai-governance-framework Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E17
    May 5 · 9 min

    Who Owns Cloud Security?

    A single question can expose a major cloud risk: who is responsible? This episode breaks down the cloud shared responsibility model, revealing how unclear ownership, misconfigurations, and weak governance lead to data breaches, and how ISO/IEC 27017 helps close the gaps. In this episode, we answer to: Who is really accountable for cloud security failures? Why do misconfigurations cause most cloud data breaches? How does ISO/IEC 27017 strengthen cloud security governance? Resources Mentioned in this Episode: ISO Standards website, standard ISO/IEC 27017:2015, link https://www.iso.org/standard/43757.html Vanta website, article "The ultimate guide to ISO 27017", link https://www.vanta.com/collection/iso-27001/guide-to-iso-27017 Microsoft website, article "ISO/IEC 27017:2015", link https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-iso-27017 Safeshield website, article "Why should SaaS companies comply with the ISO/IEC 27017 security standard for cloud service providers (CSP)", link https://www.safeshield.cloud/why-should-saas-companies-comply-with-the-iso-27017-security-standard-for-cloud-service-providers-csp NordLayer website, article "ISO 27017: cloud protection essentials", link https://nordlayer.com/learn/iso/iso-27017/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E16
    April 28 · 7 min

    CISO Strategy: Where Product Security Fails at Scale

    Most organisations manage only build and operate, ignoring growth, where security risk explodes. Luigi Ferri reveals how CISOs miss the most critical phase, where scaling, DevOps, and rapid decisions create hidden security debt. This episode challenges leaders to shift from reactive controls to full product lifecycle governance before risk turns into incidents. In this episode, we answer to: Why is product growth the most dangerous phase for cybersecurity risk? Are CISOs governing product lifecycle or just reacting to failures? How does DevOps accelerate delivery but weaken security accountability? Resources Mentioned in this Episode: Advisera website, article "ISO 27001 control 8.25 Secure development life cycle", link https://advisera.com/iso27001/control-8-25-secure-development-life-cycle/ Ikarus website, article "Security by Design", link https://www.ikarussecurity.com/en/security-news-en/security-by-design-cybersecurity-throughout-the-product-life-cycle/ Netguru website, article "SaaS Development Life Cycle: Key Stages & Best Practices", link https://www.netguru.com/blog/saas-development-life-cycle DevOps by Techstrong Group website, article "DevSecOps: Integrating Security Into the DevOps Lifecycle", link https://devops.com/devsecops-integrating-security-into-the-devops-lifecycle/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E13
    April 21 · 8 min

    ITIL 5 Exposed: Accountability Without Authority

    ITIL 5 exposes a critical ITSM flaw: Service Owners held accountable without authority. Discover how broken governance, security vs delivery conflicts, and unclear decision rights undermine outcomes. Learn why real accountability starts before operations, and how to redesign Enterprise Service Management for true leadership. In this episode, we answer to: Why are Service Owners accountable but not empowered in ITIL 5? How does the security vs delivery tension reveal weak ITSM governance? Resources Mentioned in this Episode: PeopleCert website, article "Understanding the evolution of ITIL", link https://www.peoplecert.org/news-and-announcements/itil-version-5-explained Learning Tree International website, article "ITIL® (Version 5) Has Arrived", link https://www.learningtree.com/blog/itil-5-launch-what-you-need-to-know/ Agile PM Hub website, article "ITIL® 5 Is Here: What’s New and Why It Matters", link https://agilepmhub.com/blog/itil-version-5-whats-new-and-why-it-matters Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  • S3 · E7
    April 14 · 8 min

    PSD3 Explained: Payments Security & Fraud

    PSD3 is reshaping payments security, moving beyond PSD2’s access model to address fraud, scams and trust abuse. This episode explains why strong authentication is no longer enough, how APIs become critical to trust, and what banks and fintechs must change to stay secure, compliant and resilient. In this episode, we answer to: What makes PSD3 fundamentally different from PSD2 in payments security? Is strong customer authentication enough to stop modern fraud? How do APIs influence trust, performance and security under PSD3? Resources Mentioned in this Episode: Stripe website, article "What platforms and marketplaces can expect from PSD3", link https://stripe.com/guides/what-platforms-and-marketplaces-can-expect-from-psd3 Trustbuilder website, article "From PSD2 to PSD3: What’s Changing in the Future of Payments in Europe", link https://www.trustbuilder.com/en/psd2-psd3-directive-future-payments-europe/ Deloitte website, article "Shedding light on PSD3/PSR", link https://www.deloitte.com/lu/en/Industries/banking-capital-markets/perspectives/shedding-light-on-psd3-psr.html Schoenherr website, article "The EU's new Payments Services Package", link https://www.schoenherr.eu/content/the-eu-s-new-payments-services-package European Payments Council, article "What do the PSD3 and PSR mean for the payments sector", link https://www.europeanpaymentscouncil.eu/news-insights/insight/what-do-psd3-and-psr-mean-payments-sector Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

Showing 1–20 of 22 episodes