The Plain English Version

ITIL is the most widely used framework for running IT as a service: keeping systems available, handling incidents and requests, and changing things without breaking them. If your organisation has a service desk, ticket priorities, and change approval, you are already living some of ITIL.

The current edition, ITIL 4, frames everything around co-creating value: IT exists to enable outcomes the business wants, not to run technology for its own sake.

Who Uses ITIL?

Internal IT departments, managed service providers, and any organisation where "the system is down" has a cost. MSPs in particular are expected to demonstrate ITIL-aligned processes in contracts and service reviews.

The Practices You Will Meet First

  • Incident management - Restoring service fast when something breaks, with priorities and escalation
  • Problem management - Finding and fixing the root cause behind repeat incidents
  • Change enablement - Assessing and authorising changes so fixes do not cause the next outage
  • Service level management - Agreeing what good service means and measuring against it
  • Service desk and request management - The front door for users, with everything logged

Why This Matters for Security

Security incidents ride on ITIL rails: detection feeds incident management, forensics feeds problem management, and remediation lands as changes. Auditors assessing ISO 27001 or NIS2 incident handling routinely test whether the service management process underneath actually works. Weak change control is also one of the most common root causes in breach post-mortems.

Getting Prepared

Start with the practices that hurt most: a disciplined incident process with clear priorities, and change control that is light enough to be followed and strong enough to matter. Measure a handful of things honestly, resolution time, change failure rate, recurring incidents, and improve from evidence rather than adopting the full framework in one go.