Pubblica Amministrazione

"Prevention is cheaper than a breach"

Success Story

 

For a Central Public Administration office, we are supporting a program to review access to software, systems, and physical and virtual infrastructure. The process began with an extensive assessment of approximately 4,500 servers, necessary to reconstruct assets, services, dependencies, privilege levels, and operational criticalities. Based on the evidence gathered, we helped redefine priorities, access criteria, and corrective actions, balancing security, service continuity, and organizational constraints. Today, we support the client in coordinating activities, facilitating discussions among numerous stakeholders with different responsibilities, skills, and objectives. Our role is to ensure method, consistency, and progressive progress, transforming a complex and layered environment into a manageable, measurable, and sustainable path, capable of reducing risk without compromising operations.

The challenges

1
Infrastructure extension
A perimeter of 4,500 servers made it complex to reconstruct assets, dependencies, and ICT risk levels.
2
Technological heterogeneity
Non-homogeneous operating systems and services required different, coordinated, coherent and timely ICT analyses.
3
Legacy applications
Legacy but critical applications required caution to avoid impacting essential public IT services.
4
Reconstruction of flows
Accurately reconstructing network flows was essential to understand accesses, dependencies, and anomalies.
5
Continuity of knowledge
Staff turnover over the years dispersed knowledge, responsibility, and technical memory of ICT systems.
6
Numerous stakeholders
Many stakeholders with different roles made it difficult to align IT decisions, priorities, and operational activities.

The solution

1
Automated assessment
We created scripts to automate data collection, verification, and analysis for all 4,500 servers.
2
Structured objectives
We have defined short- and medium-term objectives consistent with the state entity's strategic risks and services.
3
Side view
We maintain a continuous lateral view to capture indirect effects, dependencies and non-immediate IT risks.
4
Progressive changes
We proceed with limited changes and defined areas, reducing risks and verifying each final result.
5
Continuous coordination
We coordinate technical and organizational stakeholders, clarifying responsibilities, priorities, and targeted next steps.
6
Decision support
Trasformiamo evidenze tecniche in indicazioni comprensibili per decidere accessi, tempi e investimenti mirati.
Scroll to top