Securing the Future of Enterprise IT
CIOREVIEW >> Artificial Intelligence >> NEWS

SITE Resource Group

Riccardo Francese, General Manager Information Technology

Securing the Future of Enterprise IT

Riccardo Francese, General Manager Information Technology
Riccardo Francese, General Manager Information Technology, SITE Resource Group

Riccardo Francese

IT Security Steward

Establishing a Secure Foundation for AI Adoption

The first consideration isn’t technical; it’s honesty about your starting point. Most organizations bolt AI onto environments that already carry unresolved debt: flat networks, over-privileged accounts and inconsistent patching. AI doesn’t create those weaknesses; it accelerates the consequences of them. Before any AI initiative, I want to know three things: where our data actually lives, who can touch it and what happens when a credential is compromised. Identity is the new perimeter, and AI tools—which consume credentials, tokens and data at machine speed—make identity hygiene nonnegotiable. The second consideration is data governance. Every AI tool is, functionally, a data exfiltration channel you’ve invited in. Sanctioned or not, employees will feed it information. Your job is to make the sanctioned path easier than the shadow one.

Driving Efficiency and Operational Resilience

The unglamorous wins are the biggest ones. AI’s real value in IT operations isn’t strategy decks—it’s compressing the time between “something looks wrong” and “we understand why.” Log triage, anomaly detection, first-draft documentation and correlating alerts across systems that were never designed to talk to each other: these are tasks that used to consume skilled hours and now consume minutes. That shift matters most in lean IT teams supporting distributed, operationally demanding businesses, where the same people who manage infrastructure also answer the phone when a site goes down. AI doesn’t replace judgment in that environment; it clears the noise so judgment can be applied where it counts. The resilience gain is subtle but real—when your team spends less time on repetitive triage, they have the capacity to think about the failure that hasn’t happened yet.

Balancing Innovation with Governance and Trust

I’d challenge the framing: speed and governance aren’t opposing forces— ungoverned speed is just deferred slowness. Every shortcut taken during adoption resurfaces later as an incident, an audit finding, or a trust problem with a client. The practical balance comes from three habits. First, write the usage policy before the tool arrives, not after—people need to know what data can and cannot leave the building. Second, keep humans accountable for outputs. AI can draft; it cannot sign. Anything client-facing, financial, or compliance-related gets human verification, full stop. Third, treat trust as a budget you spend carefully. One mishandled dataset costs more credibility than a year of fast delivery earns. Organizations that internalize this move quickly and sleep at night.

Making Technology Work for People and Workflows

The hardest-won lesson: adoption fails at the workflow level, not the technology level. I’ve seen technically sound deployments die because they added one extra step to someone’s day, and modest tools succeed because they removed one. So I start with the friction, not the feature list. The second lesson is that the people closest to the work will find the gaps faster than any pilot plan—involve them early and take their objections seriously because they’re usually describing a real constraint, not resisting change. The third is to resist the urge to solve everything at once. A narrow deployment that demonstrably works buys you the political capital for the broader one. Technology decisions are ultimately trust decisions, and trust is built incrementally.

Preparing for the Future of AI and Cybersecurity

The line between “IT system” and “AI system” is dissolving, and with it, the assumption that a human sits between every action and its consequence. Agentic tools that act—not just advise—will force us to rethink access control, logging and accountability from the ground up. Attackers are adopting the same capabilities, which means the tempo of both attack and defense is increasing; the organizations that struggle will be those still operating on humanspeed detection against machine-speed threats. What should leaders prepare now? Fundamentals, unglamorously: identity governance, network segmentation, tested backups and an incident response plan people have actually rehearsed. AI will change what’s possible, but it rewards the disciplined and punishes the improvised. The future belongs to teams who treated the basics as non-negotiable before the pace picked up.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.