The ITSM Practice: Elevating ITSM and IT Security Knowledge

Luigi Ferri

Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals! Stay Connected: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Youtube: https://www.youtube.com/@theitsmpractice Website: http://www.theitsmpractice.com

  1. 1d ago

    Your SOC Stops at the Firewall. Should It? - Part 1

    Does your SOC really protect the entire business, or does its visibility stop at the firewall? In this episode of The ITSM Practice Podcast, Luigi Ferri explores drone threats against data centers and what they reveal about gaps between Cybersecurity, Physical Security, Facilities, IT Operations and Business Continuity. Discover why CISOs need to rethink the traditional cyber attack surface and focus on protecting the complete service. In this episode, we answer to: Where should the SOC security perimeter really end? How can CISOs identify the true attack surface of a critical business service? Who owns the incident when Cybersecurity, Physical Security and Facilities each detect different parts of the same threat? Resources Mentioned in this Episode: Bird & Bird website, article "European Commission Counter-UAS Action Plan", link https://www.twobirds.com/en/insights/2026/uk/european-commission-counter-uas-action-plan Commercial UAV News, article "How Counter-UAS Infrastructure Is Building the Foundation for Commercial Drone Operations", link https://www.commercialuavnews.com/counter-uas-europe-commercial-drone-infrastructure Digitalisation World website, article "Drones and Datacenters: An Unexpected Aerial Adversary Amidst the AI Boom", link https://digitalisationworld.com/blogs/58771/drones-and-datacenters-an-unexpected-aerial-adversary-amidst-the-ai-boom BBC News, article "Amazon Says Drones Damaged Three Facilities in UAE and Bahrain", link https://www.bbc.com/news/articles/cgk28nj0lrjo DW website, article "Germany Investigates Drone Flights Over Industrial Park", link https://www.dw.com/en/germany-investigates-drone-flights-over-industrial-park/a-70021895 Maris-Tech website, article "CUAS (Counter Unmanned Aerial Systems): A Complete Guide for Defense & HLS Teams", link https://www.maris-tech.com/blog/cuas-counter-unmanned-aerial-systems-a-complete-guide-for-defense-hls-teams/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  2. Sep 29

    ITIL 5: The 6C Model for AI

    AI that summarizes an incident is one thing. AI that disables accounts, isolates endpoints and blocks connections is another. In this episode of The ITSM Practice Podcast, Luigi Ferri explains the ITIL 5 6C Model for AI and why CIOs, CISOs and MSPs need to stop asking, “Are we using AI?” and start asking, “What are we allowing AI to do?” In this episode, we answer to: What is the ITIL 5 6C Model for AI? How much authority should MSPs give AI to decide and act? Who is accountable when autonomous AI gets a decision wrong? Resources Mentioned in this Episode: ITIL website, article "AI Governance in Organizations", link https://www.itil.com/Itil-News-and-Announcements/itil-ai-governance-organizations ITIL website, white paper "ITIL AI Governance White Paper", link https://www.itil.com/-/media/itilsite/site-assets/documents/itil-ai-governance/itil-ai-governance-white-paper-2025.pdf PeopleCert Community website, article "AI Governance in Service Management", link https://community.peoplecert.org/home/clubs/itil/blogs/ai-governance-in-service-management PeopleCert Community website, article "What ITIL AI Governance Teaches Us About Maturity in an AI-Enabled World", link https://community.peoplecert.org/public/clubs/itil/blogs/what-itil-ai-governance-teaches-us-about-maturity-in-an-ai-enabled-world ITIL website, article "Governing AI in organizations – new ITIL guidance is making a difference", link https://itil.com/Itil-News-and-Announcements/itil-version-5-ai-governance-guidance ITIL website, article "ITIL AI Governance (Version 5): categorizing and assessing AI, and deploying appropriate controls", link https://www.itil.com/Itil-News-and-Announcements/itil-version-5-ai-governance-controls PeopleCert Community website, article "ITIL (Version 5): A Value Stream Perspective", link https://community.peoplecert.org/public/clubs/itil/blogs/itil-version-5-a-value-stream-perspective Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  3. Sep 22

    Should Your CMDB Know Your Business Risk?

    A critical vulnerability is not automatically a critical business risk. If your CMDB only tells you which server is affected but not the customer, service, contract, SLA, or revenue behind it, you are missing the information that matters. This episode explains why CISOs need a business-aware CMDB to connect technical risk with real business impact. In this episode, we answer to: Can your CMDB tell the CISO what a security incident actually means for the business? How do you prioritize vulnerabilities based on customers, SLAs, contracts, and revenue at risk? Why is connecting CMDB, ITSM, CRM, and ERP data critical for risk-based security decisions? Resources Mentioned in this Episode: PeopleCert website, course "ITIL 4 Practitioner: Service Configuration Management", link https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-configuration-management-3800 PeopleCert website, case study "SITA", link https://www.peoplecert.org/-/media/folders-reorganized/pdfs/itil-maturity-model/cs-sita.pdf ServiceNow website, guide "CMDB Design Guidance", link https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/white-paper/wp-cmdb-design-guidance.pdf BMC website, article "Best Practices for the Common Data Model", link https://docs.bmc.com/xwiki/bin/view/Service-Management/IT-Service-Management/BMC-Helix-CMDB/ac254/Managing-the-common-data-model/Best-Practices-for-the-Common-Data-Model/ Device42 website, article "CMDB Architecture Best Practices: Aligning Design with IT Objectives", link https://www.device42.com/cmdb-best-practices/cmdb-architecture/ Device42 website, guide "The Technical Guide to CMDB Best Practices", link https://www.device42.com/cmdb-best-practices/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  4. Sep 15

    Is Your Security Stack Too Big?

    Is your security stack actually protecting you, or are you just paying for too many tools? This episode looks at security tool sprawl, unused capabilities, overlapping products, skills gaps and vendor dependency. Before buying another security product, understand what you already have, what your team can actually operate and what would really happen if you switched a tool off. In this episode, we answer to: Are you paying for security tools you do not actually need? Is your team using the security capabilities you already pay for? Should you consolidate security tools or invest in specialist products? Resources Mentioned in this Episode: Meriplex website, blog article “Cybersecurity Services for Mid-Market Businesses: What You Really Need in 2025”, link: https://meriplex.com/cybersecurity-services-for-mid-market-businesses/ HashiCorp website, blog article “The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority”, link: https://www.hashicorp.com/en/blog/the-risks-of-cybersecurity-tool-sprawl-and-why-we-need-consolidation MES Computing website, article “What Midmarket CIOs Must Prove By EOY 2026: Fewer Platforms, Faster Security, Measurable Outcomes”, link: https://www.mescomputing.com/news/2026/business/what-midmarket-cios-must-prove-by-eoy-2026 CyberNeurix website, blog article “Security Tool Consolidation in 2026: Why CISOs Are Deleting Tools Instead of Buying Them”, link: https://blogs.cyberneurix.com/blog/security-tool-consolidation-2026/ Red Canary website, blog article “Why CISOs under consolidation pressure are embracing Microsoft Security solutions”, link: https://redcanary.com/blog/microsoft/tool-consolidation-microsoft/ Bitdefender Business Insights website, article “The Security Platform Is Dead. Long Live the Security Platform.”, link: https://businessinsights.bitdefender.com/security-platform-is-dead-long-live-security-platform Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  5. Sep 8

    24/7 IT Support: Why Coverage Is Not Capability

    24/7 support does not automatically mean 24/7 capability. In this episode of The ITSM Practice Podcast, Luigi Ferri explores how MSPs can design profitable 24/7 IT support using follow-the-sun models, AI, automation, Level Zero support, intelligent routing, and service tiers, while protecting engineering capacity, customer experience, SLAs, and margins. In this episode, we answer to: How can MSPs deliver effective 24/7 IT support without replicating expensive engineering capability across every time zone? How can AI, automation, and Level Zero improve incident management, troubleshooting, routing, and follow-the-sun handovers? How can MSPs balance SLA performance, customer experience, engineering capacity, and profitability in a 24/7 support model? Resources Mentioned in this Episode: TechMonarch website, article “How to Scale Managed IT Services for Growing Businesses Without Compromising Quality”, link: https://techmonarch.com/blog/how-to-scale-managed-it-services-for-growing-businesses-without-compromising-quality/ Splashtop website, article “5 Strategies for Scaling IT Operations”, link https://www.splashtop.com/blog/5-strategies-for-scaling-it-operations Convergence Networks website, article “How to Overcome the 10 Biggest Managed Services Challenges”, link: https://convergencenetworks.com/blog/managed-it-services-challenges/ Advance IT website, article “From Startups to Scale-Ups: Key Trends in Scaling Operations for Long-Term Growth”, link: https://www.advanceit.sg/blog/from-startups-to-scale-ups-key-trends-in-scaling-operations-for-long-term-growth ScottMadden, website, article “IT Organizational Structures Explained: Finding the Best Fit”, link: https://www.scottmadden.com/insight/it-organizational-structures-explained-finding-the-best-fit/ BPM website, article “Scaling IT Security Operations”, link: https://www.bpm.com/insights/scaling-it-security-operations/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  6. Sep 1

    The Last Human-Only Leadership Generation: How AI Is Transforming the Workforce

    AI is no longer just a technology tool, it is becoming part of the workforce. In this episode, Luigi Ferri explores why AI represents a workforce transformation rather than a technology project, and how CIOs, CISOs, and business leaders must rethink governance, digital workers, AI leadership, cybersecurity, and Enterprise Service Management to successfully manage hybrid human-AI teams. In this episode, we answer to: Why is AI a workforce transformation rather than just another technology implementation? How should CIOs and CISOs govern and manage digital workers alongside human employees? What leadership, governance, and cybersecurity challenges emerge when AI agents become part of the workforce? Resources Mentioned in this Episode: ServiceNow website, article "Autonomous Workforce", link https://www.servicenow.com/platform/autonomous-workforce.html Atomicwork website, article "The AI Workforce: What it actually is and how to make it work for your service teams", link https://www.atomicwork.com/itsm/ai-workforce-guide Digital Workforce, article "Business Automation. Orchestrated.", link https://digitalworkforce.com NICE Cognigy website, article "AI Agent Examples and Use Cases for Enterprise Contact Centers", link https://www.cognigy.com/ai-agents/examples-ai-agents DOMO website, article "Customer Support AI Agents: What They Are and How to Build Them for Best Results", link https://www.domo.com/blog/customer-support-ai-agents-what-they-are-and-how-to-build-them-for-best-results IBM website, article "Better customer service with AI agents", link https://www.ibm.com/think/topics/ai-agents-in-customer-service Torq website, article "The Economics of an Agentic SOC: How AI Reduces Security Operations Costs", link https://torq.io/blog/economics-agentic-soc/ KuppingerCole website, article "The Emerging AI Security Operations Center (SOC)", link https://www.kuppingercole.com/research/lc81057/the-emerging-ai-security-operations-center-soc Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  7. Aug 25

    ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

    Are cyber exercises actually improving your cybersecurity resilience, or just satisfying compliance requirements? In this episode, Luigi Ferri explores ENISA's cyber exercise methodology, the gap between testing and real capability improvement, the role of MSPs in incident response, and why organizations must focus on measurable cyber resilience instead of annual audit-driven exercises. In this episode, we answer to: Why are cyber exercises important for improving cybersecurity resilience rather than just meeting compliance? What is the difference between testing cybersecurity and improving organizational cyber resilience? How can organizations ensure cyber exercise findings lead to measurable capability improvement? Resources Mentioned in this Episode: ENISA website, guideline "ENISA Technical Advisory for Secure Use of Package Managers", link https://r.search.yahoo.com/_ylt=AwrkMQ3LAHFqUAIA0Av04olQ;_ylu=Y29sbwNpcjIEcG9zAzIEdnRpZAMEc2VjA3Ny/RV=2/RE=1787000268/RO=10/RU=https%3a%2f%2fwww.enisa.europa.eu%2fsites%2fdefault%2ffiles%2f2026-03%2fENISA%2520Technical%2520Advisory%2520-%2520Package_Managers_Final.pdf/RK=2/RS=gKGJNKMoHHsXF59MpNiBxFeSfpU- Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

  8. Aug 18

    Projects Deliver Outputs. Services Deliver Outcomes.

    Projects Deliver Outputs, Services Deliver Outcomes: The Ownership Crisis Nobody Discusses. Discover why the biggest risk in any IT project begins after go-live. In this episode, Luigi Ferri explores the critical difference between project outputs and service outcomes, why Service Ownership is essential for long-term business value, and how IT Service Management (ITSM), Product Management, and Business Capability Management must work together to drive sustainable success. Learn why organizations have an ownership problem. In this episode, we answer to: Why is the day after go-live often the most dangerous stage of a project? What is the difference between a Product Owner and a Service Owner, and why does it matter? How can organizations improve long-term business outcomes through Service Management and clear ownership? Resources Mentioned in this Episode: PMI Institute, article "Pulse of the Profession 2024", link https://www.scribd.com/document/709988299/PMI-Pulse-of-the-Profession-2024-Report Balanced Scorecard Institute, article "Is Your Strategy Execution Crumbling as a Result of Too Many Projects?", link https://balancedscorecard.org/blog/is-your-strategy-execution-crumbling-as-a-result-of-too-many-projects/ PwC website, article "PwC Middle East Transformation and project management survey part 1", link https://www.pwc.com/m1/en/publications/transformation-and-project-management-survey.html Business Chief website, article "MIT Sloan: Why so many business digital transformations fail", link https://businesschief.asia/digital-strategy/mit-sloan-why-so-many-business-digital-transformations-fail MIT website, article "5 reasons companies struggle with digital transformation", link https://mitsloan.mit.edu/ideas-made-to-matter/5-reasons-companies-struggle-digital-transformation Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

About

Join Luigi Ferri, an experienced ITSM & IT Security Professional, in 'The ITSM Practice.' Explore IT Service Management and IT Security, uncovering innovations and best practices with insights from leading organizations like Volkswagen Financial Services, Vodafone, and more. Each episode offers practical guides and expert discussions for learning and growth. Ideal for all ITSM and IT Security Professionals! Stay Connected: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Youtube: https://www.youtube.com/@theitsmpractice Website: http://www.theitsmpractice.com

You Might Also Like