IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Linux Server Hardening: The 5 Mandatory Post-Install Steps

Linux Hardening


The Problem: Default Exposure

A freshly installed Linux server exposed to the public cloud is a blank canvas, but also an easy target. Default SSH daemon configurations and open ports immediately attract automated scanners, botnets, and brute-force attacks.



The Solution: 5 Steps to Hardening

Before installing any enterprise application, the infrastructure must be locked down by enforcing the principle of least privilege.

  • 1. Public Key Authentication: Ditch passwords entirely. Generate a certificate using ssh-keygen, copy it to the server, and edit /etc/ssh/sshd_config by setting PasswordAuthentication no.
  • 2. Disable Root Login: In the same SSH configuration file, ensure you set PermitRootLogin no to force access only via standard users and subsequent privilege elevation via sudo.
  • 3. Firewall Segmentation (UFW): Drop all incoming traffic except what is strictly necessary.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Brute-Force Mitigation (Fail2Ban): Automatically ban malicious IPs at the network level that repeatedly fail login attempts.
    sudo apt install fail2ban -y
  • 5. Silent Updates: Keep the system protected from zero-day vulnerabilities by installing unattended-upgrades for the automatic application of critical security patches without service interruptions.

Hardening Server Linux: I 5 Passi Obbligatori Post-Installazione

Immagine generata con Gemini AI


Il Problema: L'Esposizione Predefinita

Un server Linux appena installato ed esposto su cloud pubblico è una tela bianca, ma anche un bersaglio facile. Le configurazioni predefinite del demone SSH e le porte aperte attirano immediatamente scansioni automatizzate, botnet e attacchi brute-force.

La Soluzione: 5 Passaggi di Hardening

Prima di installare qualsiasi applicativo aziendale, l'infrastruttura deve essere blindata applicando il principio del minimo privilegio.

  • 1. Autenticazione a Chiave Pubblica: Abbandona le password. Genera un certificato con ssh-keygen, copialo sul server e modifica /etc/ssh/sshd_config impostando PasswordAuthentication no.
  • 2. Disabilitare l'accesso Root: Nello stesso file di configurazione SSH, assicurati di inserire PermitRootLogin no per forzare l'accesso solo tramite utenza standard e successiva elevazione tramite sudo.
  • 3. Segmentazione con Firewall (UFW): Chiudi tutto il traffico in ingresso tranne lo stretto necessario.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Mitigazione Brute-Force (Fail2Ban): Banna automaticamente a livello di rete gli IP malevoli che falliscono ripetutamente i login.
    sudo apt install fail2ban -y
  • 5. Aggiornamenti Silenti: Mantieni il sistema protetto dalle vulnerabilità zero-day installando unattended-upgrades per l'applicazione automatica delle sole patch di sicurezza critiche, senza interruzioni di servizio.

IT First Aid - Ep. 30: "This app has been blocked for your protection"


You are trying to install an old (perhaps management) software that is perfectly legitimate, but a large red Windows screen yells at you: "This app has been blocked for your protection". There is no "Run anyway" button.

1. The Certificate Block

The UAC (User Account Control) intercepts software whose digital signature certificate has expired or been revoked. Right-click the downloaded .exe file, go to Properties. If you see a security warning at the bottom, check the "Unblock" box and hit Apply.

2. Forced Launch via Terminal

App Lock


If Windows continues to block it, use Admin authority. Open the Command Prompt by running it as Administrator. Navigate using the cd command to the folder where the file is located (e.g., cd C:\Downloads) and type the name of the executable (e.g., setup.exe). Being launched from an already verified environment with maximum privileges, the installation will bypass the graphical block.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 29: Forgot Windows Local Password


Warning: this maneuver is exactly why we sysadmins always insist on encrypting drives with BitLocker. If the account is local (not linked to a Microsoft email) and unencrypted, here is the classic "skeleton key" trick.

Forgot Password


1. The Utilman Trick

Boot the PC with a Windows installation USB drive. Use Shift+F10 to open the command prompt. The game involves navigating to the System32 folder and renaming the Accessibility executable (utilman.exe), replacing it with the command prompt (cmd.exe).

2. The Brutal Reset

Rebooting the PC normally, when you reach the lock screen, clicking on the Accessibility icon in the bottom right will open a command prompt with maximum privileges (SYSTEM). Just type net user username newpassword to force the change and get back into the system. No formatting required.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 26: High CPU from Antimalware Service Executable


Your computer is struggling; you open Task Manager and see a process at the top of the list called Antimalware Service Executable devouring RAM and CPU. It's the Windows Defender background engine.

1. The Scanning Paradox

The reason it gets stuck is often surreal: the antivirus is incessantly checking its own folder and files in an infinite loop.

High CPU from Antimalware Service


2. The Exclusions Trick

Open Windows Security > Virus & threat protection. Under settings, click on "Manage settings" and scroll down to Exclusions. Click "Add or remove exclusions". Choose "Process" and type exactly MsMpEng.exe. Also add a Folder exclusion pointing to C:\ProgramData\Microsoft\Windows Defender. Now the antivirus will breathe.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 22: Folder Access Denied


You transferred a hard drive from an old PC or tried to modify a specific folder, but Windows denies you access even if you are an Administrator. The blame lies with the ACLs (Access Control Lists).

Folder Access Denied


1. Taking Ownership

Right-click the inaccessible folder > Properties > Security tab > click on Advanced. At the top, you will see "Owner: TrustedInstaller" or an unknown alphanumeric code. Click on Change.

2. Apply Permissions

Type your username or simply "Administrators", press "Check Names", and hit OK. Pay close attention: check the box "Replace owner on subcontainers and objects" before hitting Apply. Now that you are the legal owner of the files, you can delete or modify them at will.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services