IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

The Risk Matrix Series - Beyond Mitigation: DFIR, Business Continuity, and the Art of Surviving

There is a fundamental paradigm that every security professional must accept to transition from technician to manager: zero risk does not exist. We can optimize, patch, and mitigate endlessly, but sooner or later, defenses will be breached. This is the Assume Breach philosophy. And this is where our Risk Management series concludes, talking about resilience.


1. From Mitigation to Survival

When the risk turns into a real incident (a ransomware, a natural disaster, a destructive attack), the financial metrics of the BIA become our survival manual. The clock starts ticking against our RTO (Recovery Time Objective). It's no longer the time to prevent; it's the time to react by executing the Business Continuity Plan (BCP) and the Disaster Recovery Plan (DRP).


2. The Role of DFIR (Digital Forensics and Incident Response)

In the event of an incident, the IT's instinctive reaction is to shut everything down or format to restart quickly. This is a fatal mistake. Doing so destroys evidence (RAM, volatile logs, system artifacts).

The correct approach requires a structured Incident Response procedure (e.g., NIST or SANS frameworks). First, you contain the threat by isolating networks, then perform a quick Digital Forensics analysis to understand "Patient Zero", the extent of the damage, and most importantly, how the attacker got in. If we restore backups without closing the original flaw (Eradication), we will be re-encrypted the very next day.


3. Closing the Loop

True IT risk management is circular. The incident (even if only simulated in a Tabletop Exercise) provides the "Lessons Learned" to update our probability (ARO) and impact (EV) estimates, improving the following year's Business Impact Assessment.

Leading IT does not mean building insurmountable walls, but building ships capable of floating and continuing the course even after taking on water. That is true Resilience.

In the next few posts, we'll explore the other side of IT Risk Management, diving into the details of IT risk assessment and attack surface reduction through mitigation techniques.

The Risk Matrix Series - Oltre la Mitigazione: DFIR, Business Continuity e l'arte di sopravvivere

C'è un paradigma fondamentale che ogni professionista della sicurezza deve accettare per passare da tecnico a manager: il rischio zero non esiste. Possiamo ottimizzare, patchare e mitigare all'infinito, ma prima o poi le difese verranno bucate. Questa è la filosofia dell'Assume Breach (assumere la compromissione). Ed è qui che la nostra serie sul Risk Management si chiude, parlando di resilienza.


1. Dalla Mitigazione alla Sopravvivenza

Quando il rischio si trasforma in un incidente reale (un ransomware, un disastro naturale, un attacco distruttivo), le metriche finanziarie del BIA diventano il nostro manuale di sopravvivenza. Le ore iniziano a scorrere contro il nostro RTO (Recovery Time Objective). Non è più il momento di prevenire, è il momento di reagire eseguendo il piano di Business Continuity (BCP) e di Disaster Recovery Plan(DRP).


2. Il ruolo della DFIR (Digital Forensics and Incident Response)

In caso di incidente, la reazione istintiva dell'IT è spegnere tutto o formattare per ripartire in fretta. Questo è un errore fatale. Così facendo si distruggono le prove (RAM, log volatili, artefatti di sistema).

L'approccio corretto richiede una procedura di Incident Response strutturata (es. framework NIST o SANS). Prima si contiene la minaccia isolando le reti, poi si esegue una rapida analisi di Digital Forensics per capire il "Paziente Zero", l'estensione del danno e, soprattutto, come l'attaccante è entrato. Se ripristiniamo i backup senza aver chiuso la falla originale (Eradication), verremo ri-crittografati il giorno seguente.


3. La chiusura del cerchio

La vera gestione del rischio IT è circolare. L'incidente (anche solo simulato in un Tabletop Exercise) fornisce la "Lessons Learned" per aggiornare le nostre stime di probabilità (ARO) e di impatto (EV), migliorando il Business Impact Assessment del prossimo anno.

Guidare l'IT non significa costruire muri invalicabili, ma costruire navi capaci di galleggiare e proseguire la rotta anche dopo aver imbarcato acqua. Questa è la vera Resilienza.

Nei prossimi post passeremo dall'altra parte dell'IT Risk Management, mettendo le mani in pasta per effettuare una valutazione del rischio IT e la riduzione della superficie d'attacco tramite tecniche di mitigazione.