VOOZH about

URL: https://thenewstack.io/why-zero-trust-for-mainframes-is-a-financial-institution-imperative/

⇱ Why Zero Trust for Mainframes Is a Financial Institution Imperative - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-01-05 07:41:03
Why Zero Trust for Mainframes Is a Financial Institution Imperative
contributed,sponsor-bmc,sponsored,sponsored-post-contributed,
Linux / Security

Why Zero Trust for Mainframes Is a Financial Institution Imperative

Security by obscurity is inadequate. The reality is that all mainframes today run the same Linux-based capabilities familiar to hackers.
Jan 5th, 2022 7:41am by Chris Perry
👁 Featued image for: Why Zero Trust for Mainframes Is a Financial Institution Imperative
Featured image via Pixabay
BMC sponsored this post.
Chris Perry
Chris Perry is a  cybersecurity strategist, for BMC

Mainframe computers continue to form the backbone of financial service IT operations. According to Constellation Research, 45 of the top 50 banks rely on them for core banking functions. Mainframe systems process approximately $3 trillion in transactions every day, a number that likely understates the impact of mainframes in financial services because it counts only transactions using COBOL.

The need will continue to grow. According to a recent survey by Deloitte, 91% of executives at firms that rely on mainframes identified the expansion of their mainframe footprint as a major priority in the next 12 months.

However, security for mainframes is subject to misconceptions that leave financial institutions exposed. Executives rely too heavily on the idea of “security by obscurity,” which is a way of saying that threat actors avoid attacking mainframes because they are more familiar with Windows or Linux operating systems.

Security by obscurity is inadequate. The reality is that all mainframes today run Unix System Services with the same Linux-based capabilities and tools familiar to hackers. On top of that, mainframes often lack the modern detection and response tools that have become ubiquitous on other parts of the network. This means that attackers who are able to gain access to a mainframe system will be able to maintain persistence and easily expand their initial footprint to gain full control of the platform.

The Risks of Mainframe Trust

To secure their mainframes and remain resilient, financial services firms need to move to a modern Zero Trust architecture, defined by its “Never trust, always verify” mantra. Zero Trust gained popularity as cybersecurity defenders realized they needed more defense in depth. There were too many examples of hackers gaining initial access to an organization through stolen credentials and realizing that they could use those same credentials to gain access to the entire environment. This dramatically reduces the amount of work a hacker must do to steal or destroy sensitive data while limiting the ability of defenders to detect and respond to the breach effectively.

With Zero Trust, you continually assess the user’s identity, the sensitivity of the resources the user interacts with, and the user’s permissions to access those resources. It is designed to prevent privilege escalation and lateral moves within the network that advanced threat actors have so often used successfully. This philosophy, while around for nearly a decade, has gained tremendous momentum in the past year with the U.S. National Security Agency pushing guidance and the White House publishing its own Zero Trust strategy.

Exacerbating Risks

Over-reliance on traditional, perimeter-based security models, which bestow an enormous amount of trust on users, exacerbates the weakness of security by obscurity. It is unfortunately still quite common to hear experienced mainframe professionals claim the mainframe is not at risk because it is not internet-facing. Yet they also connect to the mainframe from a typical laptop, which is one targeted phishing attack away from being the entry point to the mainframe with single-factor credential access.

Inside a poorly configured mainframe, users can access files, export data and make lateral moves to gain more privileges. While the mainframe does have identity access management controls from one of the largest External Security Managers, the reality is that these platforms are almost never assessed by an adversarial-based penetration tester, which means most financial institutions operate daily with a significant number of unknown vulnerabilities on their system. The absence of adequate controls makes this type of system extremely vulnerable to insider threats or threats in which an outside actor gains access to compromised credentials.

As an example, one company did not have modern cybersecurity capabilities on the mainframe and was a victim to a ransomware attack. The hacker used a file-less keylogger on a laptop with access to the mainframe. Over time, they gained access to sensitive passwords and were able to extort a multimillion-dollar ransom after encrypting a mainframe computer. It is quite unlikely these hackers took the ransom and simply retired.

At the end of the day, losing the mainframe to ransomware or another cyberattack would be catastrophic for nearly all financial institutions. If you are a bank that cannot process credit card transactions or allow users to look up their accounts because the mainframe is broken, then you will simply not be able to do business. This mandates that the mainframe receives the same security capabilities and focus as every other server in the enterprise, which are all best served by a Zero Trust architecture.

BMC delivers industry-leading automation, operations, and service management solutions to customers and partners around the world, including 86% of the Forbes Global 50, helping them free up time and space to become an Autonomous Digital Enterprise that conquers the opportunities ahead.
Learn More
The latest from BMC

Walking and Running to Zero Trust

For IT administrators, the core components of a Zero Trust policy for mainframes include robust identity management and heightened device security rules. These components need to govern the interaction between your sensitive data and the people, workloads, networks and devices that access it. There is no such thing as perfect in this domain, but as you start your Zero Trust journey, you can execute small and highly effective solutions before advancing to more complex capabilities.

Below are four immediate actions that can be taken to dramatically improve the resilience of the mainframe environment and move you toward a Zero Trust architecture:

  1. Encryption: Workloads between the mainframe and other environments like cloud should be encrypted. This might sound obvious, but many companies are still running 3270 connections without encryption, which leaves username and password in clear text on the network.

  2. Monitoring: IT administrators need robust visibility across the network to enforce and monitor these policies. Ask yourself if your mainframe data is integrated into your real-time security tools like your enterprise security information event monitor (SIEM). If it’s not, you have a significant risk from this blind spot.

  3. Multifactor authentication (MFA): You cannot allow a single mainframe administrator to be the only gateway between an external threat and privileged control to your mainframe. What happens if this administrator is phished? MFA, while not a panacea, has been shown to dramatically reduce the ability for external threats to compromise credentials and conduct masquerading attacks.

  4. Privileged access management: You don’t want to let security controls limit the necessary agility your operations teams need to do their job. Automate the management of privileged access tied to legitimate and approved service work so the mainframe is maintained smoothly while adhering to the least-privilege principle.

While these policies will drastically improve security, the list is by no means complete, and some of these features are easier to achieve than others. The ultimate goal is that your technology enforces the policy that your data is truly only accessed by those who are appropriately authorized to use it.

What is most important is that you decide that Zero Trust is a critical business goal and form an official initiative, as a Zero Trust architecture will not develop by accident. If your enterprise security team under the CISO already has a Zero Trust initiative, then it is not too late to ensure that the mainframe is part of the deliberate scope. If not, this is the perfect time to start that journey while confirming that all servers, from mainframe to cloud, are equally defended.

BMC delivers industry-leading automation, operations, and service management solutions to customers and partners around the world, including 86% of the Forbes Global 50, helping them free up time and space to become an Autonomous Digital Enterprise that conquers the opportunities ahead.
Learn More
The latest from BMC
TRENDING STORIES
Chris Perry is a cybersecurity strategist, for BMC
Read more from Chris Perry
BMC sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.