ITCHRONICLE
ICT JOB DIARIES
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
List topics: List topics:

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Network Segmentation: Mitigating Threats with VLANs

The Problem: The "Flat" Network and Lateral Movement

Network Segmentation
Image generated with Gemini AI


In many legacy corporate infrastructures, all devices (office computers, production servers, IP cameras, and guest Wi-Fi) reside on the exact same subnet (e.g., 192.168.1.0/24). If an employee opens a malicious attachment and triggers a ransomware payload, the malware exploits this "flat" architecture to perform lateral movement, instantly scanning and infecting critical servers and backup repositories without encountering a single network obstacle.

The Solution: Segmentation via VLANs and Firewalls

The principle of least privilege applies to networking as well. We must physically or logically isolate different corporate areas using VLANs (Virtual Local Area Networks) and route traffic through an internal firewall to inspect and block unauthorized communications.

1. Creating VLANs (Logical Isolation)

On your managed switches (Layer 2 or Layer 3), carve out distinct network segments. A standard minimal architecture includes:

  • VLAN 10 (Management): 10.0.10.0/24 - Exclusive sysadmin access to hypervisors, switches, and iLOs.
  • VLAN 20 (Servers): 10.0.20.0/24 - Application servers, databases, and Active Directory.
  • VLAN 30 (Clients): 10.0.30.0/24 - Employee workstations.
  • VLAN 40 (IoT/Printers): 10.0.40.0/24 - Vulnerable embedded devices.

2. Inter-VLAN Routing and Firewall Rules

Without a router or firewall (like pfSense or FortiGate) acting as the gateway, VLANs cannot communicate. Enforce strict firewall rules to allow only strictly necessary traffic. For example, clients (VLAN 30) must not be able to initiate RDP sessions to servers (VLAN 20); only the Management VLAN should have that capability.

# Logical Firewall Rule Example on pfSense
Action: PASS
Interface: VLAN_CLIENT
Source: VLAN_CLIENT Subnet
Destination: VLAN_SERVER Subnet
Ports: 443 (HTTPS), 3306 (MySQL)

Action: DROP
Interface: VLAN_CLIENT
Source: ANY
Destination: VLAN_SERVER Subnet
Ports: 3389 (RDP), 22 (SSH)

Conclusion

Network segmentation transforms your infrastructure from an open prairie into a series of watertight compartments. If an endpoint is compromised, the blast radius is confined strictly within its VLAN, saving critical services and backups from total destruction.

Segmentazione di Rete: Mitigare le Minacce con le VLAN

Il Problema: La Rete "Piatta" e il Movimento Laterale

Segmentazione di Rete
Immagine realizzata con Gemini AI


In molte infrastrutture aziendali legacy, tutti i dispositivi (computer degli uffici, server di produzione, telecamere IP e Wi-Fi ospiti) risiedono sulla stessa subnet (es. 192.168.1.0/24). Se un dipendente apre un allegato malevolo e innesca un ransomware, il malware sfrutta questa architettura "piatta" per eseguire un movimento laterale, scansionando e infettando istantaneamente i server critici e i repository di backup senza alcun ostacolo di rete.

La Soluzione: Segmentazione tramite VLAN e Firewall

Il principio del privilegio minimo si applica anche al networking. Dobbiamo isolare fisicamente o logicamente le diverse aree aziendali utilizzando le VLAN (Virtual Local Area Network) e instradare il traffico attraverso un firewall interno per bloccare le comunicazioni non autorizzate.

1. Creazione delle VLAN (Isolamento Logico)

Sui tuoi switch gestiti (Layer 2 o Layer 3), crea segmenti di rete distinti. Un'architettura standard minima prevede:

  • VLAN 10 (Management): 10.0.10.0/24 - Accesso esclusivo per i Sysadmin a hypervisor, switch e iLO.
  • VLAN 20 (Server): 10.0.20.0/24 - Server applicativi, database e Active Directory.
  • VLAN 30 (Client): 10.0.30.0/24 - Workstation dei dipendenti.
  • VLAN 40 (IoT/Stampanti): 10.0.40.0/24 - Dispositivi embedded vulnerabili.

2. Regole di Routing e Firewall Inter-VLAN

Senza un router o un firewall (come pfSense o FortiGate) a fare da gateway, le VLAN non possono comunicare tra loro. Applica regole rigide sul firewall per consentire solo il traffico strettamente necessario. Ad esempio, i client (VLAN 30) non devono poter avviare sessioni RDP verso i server (VLAN 20); solo la VLAN di Management può farlo.

# Esempio logico di regola Firewall su pfSense (UFW non gestisce VLAN routing)
Azione: PASS
Interfaccia: VLAN_CLIENT
Sorgente: VLAN_CLIENT Subnet
Destinazione: VLAN_SERVER Subnet
Porte: 443 (HTTPS), 3306 (MySQL)

Azione: DROP
Interfaccia: VLAN_CLIENT
Sorgente: ANY
Destinazione: VLAN_SERVER Subnet
Porte: 3389 (RDP), 22 (SSH)

Conclusione

Segmentare la rete trasforma l'infrastruttura da una prateria aperta a una serie di compartimenti stagni. Se un endpoint viene compromesso, il raggio dell'attacco (blast radius) rimane confinato all'interno della sua VLAN, salvando i servizi critici e i backup.