Saltar para o conteúdo
PodcastsTecnologiaThe ITSM Practice: Elevating ITSM and IT Security Knowledge

The ITSM Practice: Elevating ITSM and IT Security Knowledge

Luigi Ferri
The ITSM Practice: Elevating ITSM and IT Security Knowledge
Último episódio

158 episódios

  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    DARE25: Why Defense Isn't Enough

    04/08/2026 | 9min
    Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and adaptive leadership. Learn how Enterprise Service Management, IT Service Management, and cybersecurity leaders can build resilient organizations by prioritizing behavior, faster adaptation, and continuous learning.

    In this episode, we answer to:
    Why is traditional cybersecurity defense no longer enough in the age of AI?
    How does the DARE25 framework improve risk management, governance, and organizational resilience?
    Why are accountability, adaptive leadership, and Purple Teaming essential for modern cybersecurity?

    Resources Mentioned in this Episode:
    Marco Amadei, creator of the DARE25 Digital Risk Management Framework, link https://www.linkedin.com/in/marco-amadei-0087844/

    APMG website, article "Digital Risk Management Certification (DARE25)", link https://apmg-international.com/product/digital-risk-management-certification-dare25

    APMG website, article "Introduction to AI in Risk Management", link https://apmg-international.com/article/introduction-ai-risk-management

    Strategic Digital Risk Management – an unofficial LinkedIn page sharing insights, research, and updates on the DARE25 Framework, link https://www.linkedin.com/company/strategicdigitalriskmanagement/

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    ISO 28000: Your Resilience, Their Budget

    28/07/2026 | 13min
    In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using practical examples from healthcare and public services, he explains how ISO 28000 shifts the conversation from protecting internal systems to managing the security and resilience of the organizations you depend on. Discover why supplier failures, inherited risk, and third-party dependencies are becoming the greatest threats to service continuity, cybersecurity, and operational resilience in government and regulated industries.

    In this episode, we answer:
    Why is ISO 28000 becoming essential for Government Managed Service Providers and supply chain resilience?
    How can third-party suppliers and subcontractors become the weakest link in your cybersecurity and operational resilience strategy?
    Why should CISOs focus on inherited risk and supplier dependencies rather than only internal security controls?

    Resources Mentioned in this Episode:
    The Standards Institution of Israel website, article "SI ISO 28000 :2022 Specification for security management systems for the supply chain", link https://www.sii.org.il/en/iso-28000

    ANSI website, article "What Is ISO 28000?", link https://blog.ansi.org/anab/what-is-iso-28000/

    Wikipedia website, article "ISO 28000", link https://en.wikipedia.org/wiki/ISO/PAS_28000

    NIST website, publication "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", link https://csrc.nist.rip/Pubs/sp/800/161/r1/2PD

    SITS website, article "NIS2, DORA & Co: Aren’t we all part of someone’s relevant supply chain?", link https://sits.com/en/blog/nis2-dora-supply-chain/

    UK Government website, notice "Research on cyber security in supplier management and procurement", link https://www.gov.uk/government/publications/research-on-cyber-security-in-supplier-management-and-procurement

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    No SBOM, No Trust

    21/07/2026 | 19min
    Discover why the Software Bill of Materials (SBOM) is rapidly becoming a strategic necessity for Managed Service Providers (MSPs) and enterprise IT leaders. In this episode, Luigi Ferri explains how software supply chain attacks such as Log4Shell and SolarWinds transformed SBOMs from technical documentation into essential tools for IT governance, cyber resilience, software supply chain security, and operational trust. Learn the four stages of SBOM maturity and how MSPs can strengthen transparency, improve vulnerability management, and build competitive advantage through continuous software dependency visibility.

    In this episode, we answer to:
    Why are Software Bill of Materials (SBOMs) becoming essential for Managed Service Providers (MSPs)?
    How can MSPs improve software supply chain security and gain complete visibility over software dependencies?
    What are the four stages of SBOM maturity that help organizations strengthen governance, resilience, and operational trust?

    Resources Mentioned in this Episode:
    US NTIA - National Telecommunications and Information Administration website, article "Software Bill of Materials", link https://www.ntia.gov/page/software-bill-materials

    US NTIA - National Telecommunications and Information Administration website, white paper "Software Consumers Playbook: SBOM Acquisition, Management, and Use", link https://www.ntia.gov/sites/default/files/publications/software_consumers_sbom_acquisition_management_and_use_-_final_0.pdf

    US NIST website, Executive Order 14028 "Improving the Nation's Cybersecurity: NIST’s Responsibilities Under the May 2021 Executive Order", link https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity

    US NTIA - National Telecommunications and Information Administration website, link

    Carnegy Mellon University - Software Engineering Institute, article "The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain", link https://www.sei.cmu.edu/blog/the-sei-sbom-framework-informing-third-party-software-management-in-your-supply-chain/

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    PSD3: Who Owns Trust?

    14/07/2026 | 6min
    PSD3 is more than a compliance requirement, it's a test of organisational maturity, security leadership, accountability, and decision-making. Discover how Enterprise Service Management, IT Service Management, and cybersecurity principles help organisations balance security, customer trust, and clear ownership to build resilience beyond regulatory compliance.

    In this episode, we answer:
    How does PSD3 reveal an organisation's maturity and decision-making under pressure?
    When should security lead, and when should it step back to enable business ownership?
    Who is truly accountable for trust, fraud prevention, and customer protection under PSD3?

    Resources Mentioned in this Episode:
    Stripe website, article "What platforms and marketplaces can expect from PSD3", link https://stripe.com/guides/what-platforms-and-marketplaces-can-expect-from-psd3

    Deloitte Luxembourg website, article "Shedding light on PSD3/PSR", link https://www.deloitte.com/lu/en/Industries/banking-capital-markets/perspectives/shedding-light-on-psd3-psr.html

    European Payments Council website, article "What do the PSD3 and PSR mean for the payments sector?", link https://www.europeanpaymentscouncil.eu/news-insights/insight/what-do-psd3-and-psr-mean-payments-sector

    Advapay website, article "PSD2 vs PSD3/PSR: what’s new in the upcoming EU’s Payment Services Directive and Regulations", link https://advapay.eu/psd2-vs-psd3-whats-new-in-the-upcoming-eus-3rd-payment-services-directive/

    PWC Ireland website, article "PSD3: Shaping the future of secure, innovative payments", link https://www.pwc.ie/industries/banking/insights/payment-services-directive-3.html

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
  • The ITSM Practice: Elevating ITSM and IT Security Knowledge

    The Hidden Cost of Untrusted Data

    07/07/2026 | 11min
    Why do organizations struggle to trust their operational data despite having plenty of it? In this episode of The ITSM Practice Podcast, Luigi Ferri explains the critical difference between data quality and data integrity, and why CIOs must build operational trust before launching digital transformation initiatives. Learn practical ITSM strategies to improve data governance, CMDB accuracy, operational accountability, and Enterprise Service Management.

    In this episode, we answer to:
    What is the difference between data quality and data integrity, and why does it matter for CIOs?
    Why do multiple departments report different numbers for the same operational metric?
    How can organizations build trusted operational data before starting digital transformation?

    Resources Mentioned in this Episode:
    Precisely website, article "Data Integrity vs. Data Quality: How Are They Different?", link https://www.precisely.com/blog/data-integrity/data-integrity-vs-data-quality-different

    Atlan website, article "Data Quality vs Data Governance: How Are They Different in 2026?", link https://atlan.com/data-quality-vs-data-governance/

    Salesforce website, article "Salesforce Signs Definitive Agreement to Acquire Informatica", link https://www.salesforce.com/news/press-releases/2025/05/27/salesforce-signs-definitive-agreement-to-acquire-informatica/

    Qlik Support Portal, article "Validating data", link https://help.qlik.com/talend/en-US/studio-user-guide/8.0-R2024-12/validating-data

    Informatica website, white paper "Informatice Data Quality and Observability", link https://www.informatica.com/content/dam/informatica-com/en/collateral/data-sheet/cloud-data-quality_data-sheet_3688en.pdf

    Connect with me on:
    LinkedIn: https://www.linkedin.com/in/theitsmpractice/
    Website: http://www.theitsmpractice.com
    And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.

    Credits:
    Sound engineering by Alan Southgate - http://alsouthgate.co.uk/

    Graphics by Yulia Kolodyazhnaya
Mais podcasts de Tecnologia
Sobre The ITSM Practice: Elevating ITSM and IT Security Knowledge
Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals! Stay Connected: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Youtube: https://www.youtube.com/@theitsmpractice Website: http://www.theitsmpractice.com
Sítio Web de podcast

Ouve The ITSM Practice: Elevating ITSM and IT Security Knowledge, A Hora da Maçã e muitos outros podcasts de todo o mundo com a aplicação radio.pt

Obtenha a aplicação gratuita radio.pt

  • Guardar rádios e podcasts favoritos
  • Transmissão via Wi-Fi ou Bluetooth
  • Carplay & Android Audo compatìvel
  • E ainda mais funções
The ITSM Practice: Elevating ITSM and IT Security Knowledge: Podcast do grupo
Aplicações
Social
v8.12.4 | © 2007-2026 radio.de GmbH
Generated: 8/8/2026 - 11:39:17 PM