Modernizing ITSM – Shifting from Reactive to Resilient Cyber Operations
David Moskowitz – Founder Member and Chief Content Architect, at the DVMS Institute
IT service management (ITSM) wasn’t designed to manage the full scope of digital business risk. Yet many organizations behave as if it does.
Frameworks that support service management, like ITIL, VeriSM, and FitSM, continue to evolve. Governance frameworks such as COBIT also contribute, but with a different emphasis. The guidance is clear, but implementation often stalls, leaving a gap between vision and execution. The Digital Value Management System® (DVMS) helps close that gap.
The DVMS is not a new framework. It’s an overlay. It works with what already exists, adding structure and alignment without disruption. Rather than replace existing practices, it connects them to broader organizational goals. It connects long-term goals to day-to-day execution, translating strategy into results.
From Reactive Utility to Resilient Capability
Most ITSM programs focus on uptime, ticket flow, and process compliance. While these are important, they rarely deliver the value business leaders recognize or prioritize. To many executives and board members, ITSM remains part of the technical infrastructure, a domain that ensures continuity but doesn’t drive strategy. That mindset is precisely what the DVMS challenges, by helping ITSM practices connect to organizational goals like resilience, trust, and business outcomes.
Business leaders care about growth, customer confidence, resilience under pressure, and measurable outcomes that support enterprise priorities. They want to know that digital services are stable and relevant risks are understood, visible, and appropriately managed.
Traditional ITSM tools weren’t built for that. They focus on process execution, not managing digital business risk or measuring trust. Frameworks encourage systems thinking and value co-creation, but they still describe themselves as ‘best practice’, a model rooted in past success. That orientation can lag behind emerging needs. The DVMS overlay becomes essential because it exposes gaps between what frameworks describe and what strategic and operational intent demand.
Why ITSM Frameworks Fall Short
Modern ITSM frameworks offer strong guidance. But translating guidance into daily action remains difficult.
The problem isn’t with the frameworks. It’s the way organizations apply them, or fail to.
Silos persist and priorities can conflict. Culture often gets overlooked or treated as incidental.
The DVMS addresses these challenges directly. It overlays practical structures on what’s already in use. These include methods for aligning teams, assuring outcomes, and integrating risk into daily decisions. It doesn’t rip and replace. It fills the gaps that frameworks leave behind.
What the DVMS Adds
The DVMS overlay includes five essential components that reshape how organizations think about ITSM, risk, and value.
- Governance, Resilience, and Assurance (GRA)
GRA treats resilience as an organizational capability. It embeds assurance into daily decisions, not just audits. It also reframes governance as delivering value and ensuring it is appropriately protected. Without the right level of protection, value becomes fragile, exposed, or unsustainable. - Strategy-Risk Integration
The DVMS combines strategy and risk into a single decision model: strategy-risk. Every strategic decision must account for risk, and every risk-related issue must be evaluated in light of strategic goals. This approach replaces the disconnected “strategy here, risk there” thinking with a cohesive framework that guides tradeoffs, priorities, and protection. The result is alignment, with decisions that reflect both ambition and accountability. - Seven Minimum Viable Capabilities (MVC)
The DVMS identifies seven capabilities that every organization demonstrates, regardless of size, location, or sector. These capabilities may be referred to by different names and applied with varying degrees of rigor. Everything an organization currently does corresponds to one or more of these capabilities.
- Govern – Ensure decision-making structures are clear and aligned to strategic outcomes.
- Assure – Build confidence that risk is managed and expectations are met.
- Plan – Set direction based on priorities and risk appetite.
- Design – Structure services and systems to create and protect value.
- Change – Adapt intentionally and minimize disruption.
- Execute – Deliver with consistency and transparency.
- Innovate – Balance small incremental improvements with disruptive strategic breakthroughs.
- 3D Knowledge Model
The DVMS 3D Knowledge Model addresses two inseparable perspectives that together enable organizations to break down silos, align strategy with execution, and foster a culture of collaboration and resilience.
Perspective 1: Teams, Alignment, and Execution focuses on how teams work, independently and together, to deliver value while staying aligned with strategic goals.
Perspective 2: System Behavior, Structure, and Leadership focuses on how leaders shape the organization as a system, including how structure and behavior influence, and are influenced by, culture. Culture is not a standalone component; it emerges from how leadership curates, reinforces, and models behavior.
- QO–QM (Question Outcome, Question Metric)
This method links questions to outcomes. Teams ask whether results are fit for purpose and use, then verify with shared evidence. The DVMS acknowledges that implementer and auditor perspectives must be present throughout the entire lifecycle to create, protect, and deliver value effectively. This dual perspective helps reduce system blind spots and strengthens assurance across digital value delivery.
Culture Emerges from Leadership
Leadership is the foundation of any organizational initiative. It determines the existing or emerging culture and whether adopting a framework leads to meaningful change or wasted effort. The DVMS treats culture not as an afterthought but as a core element, embedded into every capability, influencing how teams work, decisions are made, and change takes hold.
Teams that learn, adapt, and own outcomes build trust. They avoid the resistance, confusion, and rework often resulting from top-down mandates lacking context or buy-in.
Leadership defines what gets rewarded, what gets ignored, and how teams interpret risk and responsibility. The DVMS supports this by equipping leaders to align expectations, shape behaviors, and reinforce the outcomes they want to see.
The DVMS helps them do this without new org charts or tools.
From Metrics to Meaningful Outcomes
The value of ITSM isn’t how many tickets get closed. It’s the confidence and trust stakeholders have in the resilience and reliability of the services that support outcomes, assured by evidence and accountability.
The DVMS helps teams shift focus. Instead of asking, “Did we follow the process?” they ask, “Did the process help us protect what matters: trust, resilience, and the outcomes we depend on?”
This elevates compliance as one part of assurance, reframes control as enablement, and positions the DVMS, not ITSM alone, as a strategic approach to managing risk and delivering value.
Use What You Have
The DVMS works with existing investments. It doesn’t replace frameworks; rather, it helps teams use them more effectively and efficiently.
If you already track performance, DVMS links it to value. If you have a risk model, the DVMS brings that model into everyday decision-making, where it can guide priorities and tradeoffs.
It also reinforces strategy-risk thinking, ensuring that every risk decision is grounded in strategic purpose and that every strategic initiative is risk-informed. It reveals what’s missing: misalignment, gaps in assurance, and the disconnect between expectations and delivery.
Start Small, Scale What Works
You don’t need to do everything at once.
Start with culture. Understand how people work, decide, and learn.
Map current practices to the seven capabilities. Align strengths and gaps to the outcomes that matter.
Introduce assurance through QO–QM. Begin with one or two critical services. Link strategic intent to operational reality.
Then scale and build on what works.
A Smarter Path Forward
Digital business risk isn’t going away. Neither is the demand for speed, resilience, and trust.
The DVMS gives ITSM leaders a way to meet those demands. It builds on what exists. It brings trust, assurance, and shared outcomes – the things that matter – into daily activities.
It helps organizations shift from reactive service management to resilient value delivery.
That’s not a new framework. It’s a more innovative way to use the ones you already have.
About the Author

David Moskowitz – Founding Member and Chief Content Architect, at the DVMS Institute
David is a Founding Member and Executive Director of the DVMS Institute LLC. He is the lead author of the “Digital Value Management System®” publication series which include the *Fundamentals of Adopting the NIST Cybersecurity Framework* and *A Practitioner’s Guide to Adapting the NIST Cybersecurity Framework*, and Thriving on the Edge of Chaos published by TSO
DVMS Cyber Resilience Professional Accredited Certification Training
Designing a Governance Overlay System that Transforms Digital Services into Resilient, Assured, and Accountable (GRAA) Digital Business Outcomes
From Visibility to Viability – The Dual Pillars of Cyber Resilience
Explainer Video – The Dual Pillars of Cyber Resilience
As enterprises accelerated their adoption of complex, cloud-native architectures, they encountered a new order of complexity. Infrastructure dissolved into services, workloads became ephemeral, and security boundaries blurred. In that environment, Wiz emerged as a transformational force in cloud technical security, offering radical visibility and risk prioritization across multi-cloud ecosystems.
At the same time, a broader and more consequential challenge emerged, one that extends well beyond isolated technical misconfigurations or discrete vulnerabilities.
Modern organizations function as dynamic, highly interconnected digital ecosystems shaped by siloed frameworks, technologies, applications, processes, data flows, and human actors, all operating in continuous interaction. Within this complexity, risks and outcomes are not confined to individual components; they arise from the relationships and dependencies between them.
This is the domain in which the Digital Value Management System® (DVMS) operates.
While Wiz redefined how organizations see and secure cloud environments, DVMS is redefining how enterprises govern, assure, and account for resilient digital value as an integrated dimension of digital business performance.
The Digital Value Management System® (DVMS)
Explainer Video – What is a Digital Value Management System (DVMS)
The DVMS is a governance overlay system that transforms digital services into resilient, assured, and accountable (GRAA) digital business outcomes.
At its core, the DVMS is a simple but powerful integration of:
- Governance Intent – shared expectations and accountabilities
- Operational Capabilities – how the digital business performs under stress
- Assurance Evidence – proof that outcomes are achieved and accountable
- Cultural Learning – for governance and operational fine-tuning
The DVMS GRAA Engine
Explainer Video – How a DVMS GRAA Engine Works
The overlay GRAA engine is powered by four DVMS models:
Create, Protect, and Deliver (CPD) – The CPD Model™ is a systems-based model within the DVMS that links strategy-risk and governance to execution to create, protect, and deliver digital business value as an integrated, continuously adaptive capability.
Minimum Viable Capabilities (MVC) – The Minimum Viable Capabilities (MVCs) model supports the seven essential, system-level organizational capabilities—Govern, Assure, Plan, Design, Change, Execute, and Innovate—required to reliably create, protect, and deliver digital business value in alignment with strategy-risk intent.
3D Knowledge (3DK) – The 3D Knowledge Model is a systems-thinking framework that maps team knowledge over time (past, present, future), cross-team collaboration, and alignment to strategic intent to ensure that organizational behavior, learning, and execution remain integrated and adaptive in delivering digital business value.
Question Outcome / Question Metric (QO/QM) – The QO/QM approach supports governance as testable intent by defining a clear Question Outcome (QO), the specific value or resilience condition that must be true at a given boundary, and pairing it with one or more Question Metrics (QM) that provide observable, decision-relevant evidence that the system can actually create, protect, and deliver that outcome under complex, living system operating conditions
The models then work together to operationalize the capabilities below that will transform digital strategy into governed, resilient, assured, and accountable digital value outcomes
A Governance Overlay that replaces fragmentation with unity. The DVMS provides organizations with a structured way to connect strategy with day-to-day execution. Leaders gain a consistent mechanism to direct, measure, and validate performance across every system responsible for digital value.
A Behavioral Engine that drives high-trust, high-velocity decision-making. The DVMS embeds decision models and behavioral patterns that help teams think clearly and act confidently, even in uncertain situations. It is engineered to reduce friction, prevent blame-based cultures, and strengthen organizational reliability.
A Learning System that makes culture measurable, adaptable, and scalable. Culture becomes a managed asset—not an abstract concept. The DVMS provides a repeatable way to observe behavior, collect evidence, learn from outcomes, and evolve faster than threats, disruptions, or market shifts.
DVMS Benefits – Organizational and Leadership
Explainer Video – DVMS Organization and Leadership Benefits
Instead of replacing existing operational frameworks and platforms, the DVMS elevates them, connecting and contextualizing their data into actionable intelligence that enables organizations to:
- Maintain Operational Stability Amidst Constant Digital Disruption
- Deliver Digital Value and Trust Across Complex Digital Ecosystems
- Satisfy Critical Regulatory and Certification Requirements
- Leverage Cyber Resilience as a Competitive Advantage
For the CEO, the DVMS provides a clear line of sight between digital operations, business performance, and strategic outcomes—turning governance and resilience into enablers of growth and innovation rather than cost centers.
For the Board of Directors, the DVMS provides ongoing assurance that the organization’s digital assets, operations, and ecosystem are governed, protected, and resilient—supported by evidence-based reporting that directly links operational integrity to enterprise value and stakeholder trust.
For the CIO, CRO, CISO, and Auditors, the DVMS provides a unified approach to organizational digital value management, operational resilience, and regulatory compliance.
DVMS – Accredited Certification Training Programs
Explainer Video – The DVMS Training Pathway to Cyber Resilience
The DVMS Institute’s accredited (APMG International) and certified (NCSC/GCHQ) training programs equip enterprises with the skills to build a governance overlay system that transforms digital services into resilient, assured, and accountable digital business outcomes.
Through structured learning, applied certification, and authoritative publications, the Institute teaches a disciplined, outcome-driven approach to managing resilience as an integrated dimension of digital business performance.
DVMS Cyber Resilience Awareness Training
The DVMS Cyber Resilience Awareness non-certification course and its accompanying body of knowledge publication educate all employees on the fundamentals of digital business, its associated risks, the NIST Cybersecurity Framework, and their role within a shared model of governance, resilience, assurance, and accountability for resilience in complex digital ecosystems.
DVMS NISTCSF Cyber Resilience Foundation Certification Training
The DVMS NISTCSF Cyber Resilience Foundation certification training course and its accompanying body of knowledge publications provide ITSM, GRC, Cybersecurity, and Business professionals with a detailed understanding of the NIST Cybersecurity Framework and its role in a shared model of governance, resilience, assurance, and accountability for achieving resilience in complex digital ecosystems.
DVMS Cyber Resilience Practitioner Certification Training
The DVMS Practitioner certification training course and its accompanying body of knowledge publications teach ITSM, GRC, Cybersecurity, and Business practitioners how to build a unified governance, resilience, assurance, and accountability system designed to operationalize resilience in complex digital ecosystems.
Launching A DVMS Program
Explainer Video – Scaling a DVMS Program
The DVMS FastTrack is a phased, iterative approach that helps organizations mature a DVMS program over time, rather than trying to do everything simultaneously. This approach breaks the DVMS journey into manageable phases of success.
It all starts with selecting the first digital service you want to operationalize with the new DVMS capabilities. That service will then serve as the blueprint for operationalizing DVMS across the remaining services.
DVMS Institute White Papers – The Assurance Mandate Series
Explainer Video – From Compliance Rituals to Evidence-Based Resilience
The whitepapers below present a clear progression from compliance-driven thinking to a modern system of Governance, Resilience, Assurance, and Accountability (GRAA). Together, they define an evidence-based approach to building and governing resilient digital enterprises.
The Assurance Mandate Paper explains why traditional compliance artifacts offer reassurance, not proof, and challenges boards to demand evidence that value can be created, protected, and delivered under stress.
The Assurance in Action Paper shows how DVMS turns intent into execution by translating outcomes into Minimum Viable Capabilities, aligning frameworks through the Create–Protect–Deliver model, and producing measurable assurance evidence of real performance.
The Governing by Assurance Paper extends this model to policy and regulation, positioning DVMS as a learning overlay that links governance intent, operational capability, and auditable evidence—enabling outcome-based governance and proof of resilience through measurable performance data.
Company Brochures and Presentation
- DVMS One Pager
- DVMS Briefing Paper
- DVMS Company Brochure
- DVMS Product Brochure
- DVMS Company Presentation
Explainer Videos
- DVMS Architecture Video: David Moskowitz explains the DVMS System
- DVMS Case Study Video: Dr. Joseph Baugh Shares His DVMS Story.
- DVMS Overlay Model – What is an Overlay Model
- DVMS MVC ZX Model – Powers the CPD
- DVMS CPD Model – Powers DVMS Operations
- DVMS 3D Knowledge Model – Powers the DVMS Culture
- DVMS FastTrack Model – Enables A Phased DVMS Adoption
Digital Value Management System® is a registered trademark of the DVMS Institute LLC.
® DVMS Institute 2025 All Rights Reserved








