INSIDE FINANCE · Zero IN - Sharing Knowledge

Cyber, AI e codice fragile: perchè il vero rischio non è il budget ma la cultura. Intervista a Massimiliano Pierro MD del Gruppo Intent

·37 min·3 clips
Massimiliano Pierro explains why 80% of cyber attacks target vulnerable internal code, not external security shields.
1. Inside Finance Podcast hosts Vincenzo Marzetti in an interview with Massimiliano Pierro, General Manager of Intent S.P.A., on the state of cybersecurity and AI in Italy. 2. Massimiliano Pierro brings 20 years of experience at large multinationals and leads Intent, a top-150 Italian IT consultancy specializing in AI, cybersecurity, and ERP with 200 employees and €15 million in 2024 revenue. 3. The episode's core thesis is that Italy's digital security crisis stems from fragmented systems, lack of governance, and a culture that reacts to incidents rather than prevents them. 4. In the first half of 2025, Italy saw approximately 1,500 successful cyberattacks, many of which made national headlines, according to Pierro's firm-level observations. 5. Pierro describes Italy's public and private sector as working in 'silos,' lacking a unified roadmap or governance framework that would allow coherent security investment. 6. Only 37-40% of Italian organizations have adopted NIS 2 requirements; Pierro states that if the public administration had to achieve 100% NIS 2 compliance immediately, 'the country would grind to a halt.' 7. Pierro's firm is focused on Small Language Models (SLMs), which train narrow adaptive models for specific business processes, requiring far less compute power than large LLMs and enabling immediate ROI rather than proof-of-concept cycles. 8. He gives a concrete SLM example: building an adaptive model for an IT service management ticketing system uses a fraction of the compute of a general-purpose LLM while delivering a real production result rather than a pilot. 9. SLMs also carry an environmental benefit — less compute means lower energy consumption, which Pierro links to ESG ratings improvements for adopting companies. 10. Pierro states that 80% of cyberattacks exploit code vulnerabilities, not external perimeter failures, because software accumulates unmaintained legacy code that becomes an easily exploitable entry point. 11. He describes vulnerability assessment tooling that shows developers in real time the security implications of each line of code, which he calls a 'huge advantage that didn't exist a few years ago.' 12. A surgical approach is possible: security firms can deploy sentries on the client's own network to scan code without the client sharing proprietary source code externally. 13. The health sector is highlighted as especially high-risk: a centralized national health system that shares patient data interoperably is valuable but becomes catastrophic if not governed with security discipline. 14. Host Vincenzo Marzetti references a prior episode guest, Roberto Cingolani of Leonardo, who stated that basic personal health data — name, surname, blood type — is worth approximately €0.80 per record on the open market. 15. Pierro cites the three-day crisis triggered by threats to defund the American MITRE vulnerability database as evidence that Europe lacks an equivalent infrastructure and awareness. 16. He notes that Agid issued an August circular introducing personal financial penalties for public managers (RUP) who fail to pursue digital evolution within their administration — framing this as a first step toward accountability. 17. The interview is conducted in Italian with an efficient, direct style; Marzetti asks specific follow-up questions and Pierro responds with concrete examples and statistics rather than abstractions. 18. The energy is collaborative and calm, with both participants agreeing on core diagnoses and occasionally finishing each other's points. 19. Business owners, IT managers, and public sector decision-makers in Italy concerned about NIS 2 compliance and digital transformation will find this episode most relevant. 20. Non-Italian speakers and listeners seeking technical deep-dives into specific cybersecurity tooling will find the episode too general and language-inaccessible.
Listen to the show on