IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

IT Risk Assessment Ep. 4: The Risk Register, from Excel to Governance

We have reached the final act of our Playbook. We have discovered assets, analyzed threats, and chosen the calculation framework. Now, all this data must converge into a single, vital document: the Risk Register. This is not a mere bureaucratic compliance task; it is the executive dashboard of the entire IT department.


1. The Anatomy of a Risk Register

Whether managed on an advanced Excel spreadsheet or through a dedicated GRC (Governance, Risk, and Compliance) platform, a mature Risk Register must contain specific information:

  • Risk Description: What can happen and to which asset.
  • Risk Owner: The business owner responsible for this risk (Often this is NOT IT, but the business director the asset belongs to!).
  • Inherent Risk: The level of risk without any active defenses.
  • Mitigations / Countermeasures: The controls currently in place (e.g., Firewalls, EDR, Immutable Backups).
  • Residual Risk: The risk that remains after countermeasures are applied. This is the number that truly matters.

2. The Heat Map Trap

To communicate risk to the Board, "Heat Maps" (Risk matrices with Green, Yellow, and Red squares) are often used. Beware: a Heat Map based solely on gut feelings ("I think the impact is high") is misleading. The matrix colors must reflect the financial calculations (ALE) and the SLAs agreed upon in the Business Impact Assessment (BIA).


3. From Assessment to Governance

The Risk Register is not a document you fill out once a year before the ISO 27001 audit and then forget about. It is a living tool. When the IT Manager sits down with the Board to discuss the annual budget, the Risk Register is the only necessary documentation: "We have 3 risks in the Red zone (Unacceptable risk). To move them into the Yellow or Green zone (Accepted/Mitigated risk), the required investment for technology X is Y".

This is the moment when cybersecurity stops being perceived as an incomprehensible technical cost and becomes strategic business value. The Risk Assessment circle is finally complete.

Index: IT Risk Assessment Playbook

IT Risk Assessment Ep. 4: Il Risk Register, dal foglio Excel alla Governance

Siamo giunti all'ultimo atto del nostro Playbook. Abbiamo scoperto gli asset, analizzato le minacce e scelto il framework di calcolo. Ora, tutti questi dati devono convergere in un unico documento vitale: il Risk Register (Registro dei Rischi). Questo non è un semplice adempimento burocratico, è il cruscotto direzionale dell'intero dipartimento IT.


1. L'anatomia del Risk Register

Che sia gestito su un foglio Excel avanzato o tramite una piattaforma GRC (Governance, Risk, and Compliance) dedicata, un Risk Register maturo deve contenere informazioni specifiche:

  • Descrizione del Rischio: Cosa può succedere e a quale asset.
  • Risk Owner: Chi è il responsabile aziendale di questo rischio (Spesso NON è l'IT, ma il direttore di business a cui appartiene l'asset!).
  • Inherent Risk (Rischio Inerente): Il livello di rischio senza alcuna difesa attiva.
  • Mitigazioni / Contromisure: I controlli attualmente in essere (es. Firewall, EDR, Backup immutabili).
  • Residual Risk (Rischio Residuo): Il rischio che rimane dopo aver applicato le contromisure. È il numero che conta davvero.

2. La trappola della Heat Map

Per comunicare il rischio alla Direzione, si usano spesso le "Heat Map" (Matrici di rischio con i quadratini Verdi, Gialli e Rossi). Attenzione: una Heat Map basata solo su sensazioni ("Secondo me l'impatto è alto") è fuorviante. I colori della matrice devono riflettere i calcoli finanziari (ALE) e gli SLA concordati nel Business Impact Assessment (BIA).


3. Dalla valutazione alla Governance

Il Risk Register non è un documento che si compila una volta all'anno prima dell'audit ISO 27001 per poi dimenticarsene. È uno strumento vivo. Quando l'IT Manager si siede al tavolo con il Board per discutere il budget annuale, il Risk Register è l'unica documentazione necessaria: "Abbiamo 3 rischi in zona Rossa (Rischio inaccettabile). Per portarli in zona Gialla o Verde (Rischio accettato/mitigato), l'investimento richiesto per la tecnologia X è pari a Y".

Questo è il momento in cui la sicurezza informatica smette di essere percepita come un costo tecnico incomprensibile, e diventa valore strategico aziendale. Il cerchio del Risk Assessment è finalmente chiuso.

Indice: IT Risk Assessment Playbook

IT Risk Assessment Ep. 3: Choosing the Framework (NIST SP 800-30 vs FAIR)

We have our assets and we know the threats. Now it's time to connect the dots and calculate the Risk. As an IT Manager, the temptation is to invent a custom spreadsheet, but in the corporate world (and to pass compliance audits), you must rely on recognized standards. Let's explore the two most authoritative frameworks.


1. The Qualitative Approach: NIST SP 800-30

NIST's Special Publication 800-30 is the de facto standard of the US government. It offers a rigorous and tested approach. It relies predominantly on qualitative or semi-quantitative assessments: probability and impact are classified on scales such as Very High, High, Medium, Low.

The Pro: It is relatively simple to implement and provides a solid, unassailable baseline for compliance (e.g., ISO 27001).
The Con: It is subjective. One sysadmin's "High Risk" might be another's "Medium Risk", and most importantly, it doesn't tell the CFO how much money the company is risking.


2. The Quantitative Approach: FAIR

FAIR (Factor Analysis of Information Risk) flips the paradigm. Instead of using colors and adjectives, it uses statistics and financial modeling (like Monte Carlo simulations). It breaks risk down into its fundamental mathematical factors: Event Frequency and Financial Loss Magnitude (very reminiscent of the ARO and ALE concepts we discussed previously).

The Pro: It speaks the Board's language. Instead of saying "There is a critical risk of ransomware", FAIR allows you to say: "There is a 15% probability of experiencing ransomware this year, with an expected loss between €50,000 and €250,000".
The Con: It requires historical data, precise measurements, and a very high level of corporate maturity to be implemented correctly.


3. Which to choose?

The strategic advice is a hybrid approach: use NIST SP 800-30 for the initial screening and to quickly discard minor risks, and apply FAIR's quantitative analysis only to risks considered "High" or "Critical" to justify security investments (ROI) to management.

Index: IT Risk Assessment Playbook

IT Risk Assessment Ep. 3: Scegliere il Framework (NIST SP 800-30 vs FAIR)

Abbiamo gli asset e conosciamo le minacce. Ora è il momento di unire i puntini e calcolare il Rischio. Da IT Manager, la tentazione è quella di inventarsi un foglio di calcolo personalizzato, ma nel mondo aziendale (e per superare gli audit di compliance) devi affidarti a standard riconosciuti. Esploriamo i due framework più autorevoli.


1. L'approccio Qualitativo: NIST SP 800-30

La Special Publication 800-30 del NIST è lo standard de facto del governo USA. Offre un approccio rigoroso e testato. Si basa prevalentemente su valutazioni qualitative o semi-quantitative: la probabilità e l'impatto vengono classificati su scale come Molto Alto, Alto, Medio, Basso.

Il pro: È relativamente semplice da implementare e fornisce una base solida e inattaccabile per la compliance (es. ISO 27001).
Il contro: È soggettivo. Il "Rischio Alto" di un sistemista potrebbe essere un "Rischio Medio" per un altro, e soprattutto non dice al CFO quanti soldi rischia l'azienda.


2. L'approccio Quantitativo: FAIR

FAIR (Factor Analysis of Information Risk) capovolge il paradigma. Invece di usare colori e aggettivi, usa la statistica e i modelli finanziari (come le simulazioni Monte Carlo). Scompone il rischio nei suoi fattori matematici fondamentali: Frequenza dell'evento e Magnitudo della perdita finanziaria (ricorda molto i concetti di ARO e ALE che abbiamo visto in passato).

Il pro: Parla la lingua del Board. Invece di dire "C'è un rischio critico di ransomware", FAIR ti permette di dire: "C'è il 15% di probabilità di subire un ransomware quest'anno, con una perdita attesa tra i 50.000€ e i 250.000€".
Il contro: Richiede dati storici, misurazioni precise e un livello di maturità aziendale molto alto per essere implementato correttamente.


3. Quale scegliere?

Il consiglio strategico è un approccio ibrido: usa il NIST SP 800-30 per lo screening iniziale e per scartare rapidamente i rischi minori, e applica l'analisi quantitativa di FAIR solo ai rischi considerati "Alti" o "Critici" per giustificare gli investimenti di sicurezza (ROI) al management.

Indice: IT Risk Assessment Playbook

IT Risk Assessment Ep. 2: Threat Modeling and Knowing the Adversary

In the first episode, we mapped our territory, identifying assets and defusing Shadow IT. Now that we know what we must defend, the next question is: who will attack us, and how will they do it? This logical step is called Threat Modeling.


1. Thinking like an attacker

Threat Modeling is the structured exercise of putting yourself in the adversary's shoes. It is not about making an endless list of irrational fears, but systematically identifying architectural and operational vulnerabilities before they are exploited. It means stopping configuring firewalls based on "gut feelings" and starting to place defenses where the attacker is most likely to strike.


2. Two approaches compared: STRIDE and MITRE ATT&CK

To avoid getting lost in theory, the IT industry uses highly specific frameworks:

  • STRIDE (Microsoft): Born in software development but excellent for IT architecture. It divides threats into six categories: Spoofing (pretending to be someone else), Tampering (altering data), Repudiation (untraceability of actions), Information Disclosure (data leaks), Denial of Service (blocking systems), and Elevation of Privilege. It forces you to look at your network and ask: "How can someone spoof an identity here?".
  • MITRE ATT&CK: The operational bible for Blue Teams. It is a matrix based on real-world data that maps Tactics (the attacker's goal) and Techniques (how they achieve it). It is perfect for testing your EDR/XDR systems: "If a ransomware uses technique T1003 to steal credentials from RAM, will our SOC notice?".

3. Mapping threats to assets

The result of Threat Modeling must intersect with Asset Discovery. If we discovered an old industrial PLC server (Asset), and we know our sector is targeted by ransomware exploiting unencrypted OT protocols (Threat), we have just identified a critical Risk to include in our Assessment.

Index: IT Risk Assessment Playbook

IT Risk Assessment Ep. 2: Threat Modeling e la conoscenza dell'avversario

Nel primo episodio abbiamo mappato il nostro territorio, individuando gli asset e disinnescando lo Shadow IT. Ora che sappiamo cosa dobbiamo difendere, la domanda successiva è: chi ci attaccherà, e come lo farà? Questo passaggio logico prende il nome di Threat Modeling (Modellazione delle Minacce).


1. Pensare come un attaccante

Il Threat Modeling è l'esercizio strutturato di immedesimazione nell'avversario. Non si tratta di fare un elenco infinito di paure irrazionali, ma di identificare in modo sistematico le vulnerabilità architetturali e operative prima che vengano sfruttate. Significa smettere di configurare firewall "a sensazione" e iniziare a posizionare le difese dove l'attaccante ha più probabilità di colpire.


2. Due approcci a confronto: STRIDE e MITRE ATT&CK

Per non perdersi nella teoria, l'industria IT utilizza framework ben precisi:

  • STRIDE (Microsoft): Nato in ambito di sviluppo software ma eccellente per l'architettura IT. Suddivide le minacce in sei categorie: Spoofing (fingersi un altro), Tampering (manomettere i dati), Repudiation (non tracciabilità delle azioni), Information Disclosure (fuga di dati), Denial of Service (bloccare i sistemi) e Elevation of Privilege. Ti costringe a guardare la tua rete e chiederti: "Qui, come possono falsificare un'identità?".
  • MITRE ATT&CK: È la bibbia operativa dei Blue Team. È una matrice basata su dati reali che mappa le Tattiche (l'obiettivo dell'attaccante) e le Tecniche (come lo raggiunge). È perfetto per testare i propri sistemi EDR/XDR: "Se un ransomware usa la tecnica T1003 per rubare le credenziali dalla RAM, il nostro SOC se ne accorge?".

3. Mappare le minacce sugli asset

Il risultato del Threat Modeling deve intersecarsi con l'Asset Discovery. Se abbiamo scoperto un vecchio server PLC industriale (Asset), e sappiamo che il nostro settore è bersagliato da ransomware che sfruttano protocolli OT non cifrati (Threat), abbiamo appena identificato un Rischio critico da inserire nel nostro Assessment.

Indice: IT Risk Assessment Playbook

IT Risk Assessment Ep. 1: Asset Visibility and the Danger of Shadow IT

There is a fundamental axiom in cybersecurity that every IT Manager should have engraved on their desk: "You cannot protect what you don't know you have". Any Risk Assessment activity that skips the Discovery phase is doomed to fail, leaving blind spots where risks proliferate unchecked. Welcome to the first chapter of our operational Playbook.


1. The Invisible Enemy: Shadow IT

Shadow IT represents the collection of devices, software, and cloud services used within the company without explicit approval from the IT department. This could be a Wi-Fi access point installed by an employee for "better signal," or an entire database moved to a personal cloud account for convenience. From a risk perspective, Shadow IT is a landmine: it is unpatched, unmonitored, and often exposes critical data to the Internet.


2. Discovery Techniques: Active vs Passive

To map the infrastructure and flush out Shadow IT, we must adopt scanning strategies that do not impact business continuity, especially in Industrial (OT) or Medical environments:

  • Active Discovery: Directly querying assets (ping, port scanning). Highly precise but can be "noisy" or crash sensitive legacy devices.
  • Passive Discovery: Listening to network traffic via SPAN/Mirror ports. Non-invasive, perfect for identifying assets that "talk" spontaneously, but less effective for silent ones.

3. The Toolset: Open and Commercial Solutions

The choice of tool depends on network scale and the need for automation. Here are the market benchmarks every professional should know:

  • Open Source Solutions:
    • Nmap: The "Swiss Army knife." Indispensable for specific discovery and OS fingerprinting, but requires high technical skills to scale.
    • Netdisco: Excellent for mapping network topology via SNMP, allowing you to see exactly which switch port each device is connected to.
  • Commercial Solutions:
    • runZero (formerly Rumble): Likely the most innovative tool today. It performs "unauthenticated" (credential-less) and agentless active discovery, identifying IT, OT, and IoT assets with surgical precision without crashing systems.
    • Lansweeper: A complete IT Asset Management solution that combines network and agent-based scanning to maintain an up-to-date CMDB.

4. Conclusion

Without a granular and dynamic asset inventory, the risk calculation (ALE/ARO) discussed in previous posts remains a theoretical exercise based on partial data. Visibility is the prerequisite for security.

Index: IT Risk Assessment Playbook

IT Risk Assessment Ep. 1: Visibilità degli Asset e il pericolo dello Shadow IT

Esiste un assioma fondamentale nella sicurezza informatica che ogni IT Manager dovrebbe scolpire sulla propria scrivania: "Non puoi proteggere ciò che non sai di avere". Qualsiasi attività di Risk Assessment che ignori la fase di Discovery è destinata a fallire, lasciando zone d'ombra dove i rischi proliferano indisturbati. Benvenuti al primo capitolo del nostro Playbook operativo.


1. Il nemico invisibile: Lo Shadow IT

Lo Shadow IT rappresenta l'insieme di dispositivi, software e servizi cloud utilizzati all'interno dell'azienda senza l'approvazione esplicita del dipartimento IT. Può trattarsi di un access point Wi-Fi installato da un dipendente per "prendere meglio", o di un intero database spostato su un account cloud personale per comodità. Dal punto di vista del rischio, lo Shadow IT è una mina antiuomo: non è patchato, non è monitorato e spesso espone dati critici su Internet.


2. Tecniche di Discovery: Attiva vs Passiva

Per mappare l'infrastruttura e stanare lo Shadow IT, dobbiamo adottare strategie di scansione che non impattino sulla business continuity, specialmente in ambienti industriali (OT) o medici:

  • Active Discovery: Interrogazione diretta degli asset (ping, scansione porte). Molto precisa ma può essere "rumorosa" o bloccare dispositivi legacy sensibili.
  • Passive Discovery: Ascolto del traffico di rete tramite porte SPAN/Mirror. Non invasiva, perfetta per individuare asset che "parlano" spontaneamente ma meno efficace per quelli silenti.

3. Il Toolset: Soluzioni Open e Commerciali

La scelta dello strumento dipende dalla scala della rete e dalla necessità di automazione. Ecco i riferimenti di mercato che ogni professionista dovrebbe conoscere:

  • Soluzioni Open Source:
    • Nmap: Il "coltellino svizzero". Indispensabile per discovery puntuali e fingerprinting degli OS, ma richiede competenze tecniche elevate per essere scalato.
    • Netdisco: Eccellente per mappare la topologia di rete tramite SNMP, permettendo di vedere esattamente a quale porta dello switch è collegato ogni dispositivo.
  • Soluzioni Commerciali:
    • runZero (ex Rumble): Probabilmente lo strumento più innovativo oggi. Esegue una discovery attiva "unauthenticated" (senza credenziali) e senza agenti, riuscendo a identificare asset IT, OT e IoT con una precisione chirurgica senza abbattere i sistemi.
    • Lansweeper: Una soluzione completa per l'IT Asset Management che combina scansioni di rete e agent-based per mantenere una CMDB sempre aggiornata.

4. Conclusione

Senza un inventario degli asset granulare e dinamico, il calcolo del rischio (ALE/ARO) visto nei post precedenti rimane un esercizio teorico basato su dati parziali. La visibilità è il prerequisito della sicurezza.

Indice: IT Risk Assessment Playbook