Mainframe under siege: Big Iron needs big-time cyber resilience
By Mark Wilson, Technical Director, Vertali
Mainframes have always carried a certain reputation. Big iron. Rock solid. Secure by design. The systems quietly humming away in the corner while the rest of IT panicked about the latest breach or ransomware headline. For a long time, that reputation was deserved. Mainframes lived in carefully controlled environments with limited connectivity and strict operational discipline. That world has gone.
The mainframe is now connected to everything, APIs, cloud platforms, distributed apps, Linux and Windows servers, supplier systems, mobile apps. If it can be connected, chances are somebody has connected it to z/OS. While that’s brilliant for business agility, it also means the mainframe now sits slap bang in the middle of the same messy, unpredictable threat landscape as every other platform.
Attackers have figured this out. Modern cybercrime isn’t a lad in a hoodie poking at ports from his bedroom. It’s organized, automated and commercialized. Ransomware-as-a-service has turned attacks into a subscription business model. Add AI into the mix and attacks get faster, smarter and harder to spot. I haven’t even mentioned quantum computing.
Suspected mainframe breaches
The threat is real, from Jaguar Land Rover in 2025 and United Health Group in 2024, back to Equifax in 2017 and the Office of Personnel Management in 2015. With JLR, the attack reportedly began with a social engineering exploit targeting SAP NetWeaver. Attackers moved laterally through connected systems, requiring a z/OS shutdown – a five-week outage. With a complete assembly line shutdown, the estimated revenue hit was more than £2 billion.
Under siege
Attacks rarely begin with the mainframe itself. Usually it starts somewhere mundane: a phishing email, a compromised VPN, an exposed web application, a supplier connection that nobody looked at closely enough. Attackers land in a Windows or Linux environment first, then quietly move sideways through the network looking for something more valuable. That lateral movement is what catches organizations out, especially the ones still assuming the mainframe somehow exists outside the rest of the estate.
Once attackers reach systems connected to the mainframe, things can escalate very quickly. And it’s no longer just about encrypting datasets. Modern attacks layer techniques together:
- Malware implantation
- Compromised backups
- Rogue encryption
- Privilege escalation
- Data exfiltration
- Hidden backdoors
- Delayed “timebomb” triggers
In some cases, it’s less like a smash-and-grab burglary and more like someone sabotaging the brakes on your motorbike while it’s parked in the garage, then waiting until you’re halfway up the road before the wobble starts. Then you’re in real trouble.
Prevention alone is no longer enough. The real challenge is detecting suspicious behaviour quickly enough to stop the damage spreading. Trust but verify.
Speed matters
Traditional mainframe security tooling leans heavily on SMF data and offline analysis. Useful for audits and post-incident investigations but less useful when ransomware is encrypting production data in real time. By the time somebody notices unusual activity, raises a ticket, escalates it, wakes the right person up and starts digging through logs, the damage is usually well underway, if not complete.
The focus is shifting towards real-time detection and automated response. Learn what “normal” looks like across the environment, then react immediately when behaviour changes in suspicious ways. Things like:
- Unexpected spikes in encryption activity
- Abnormal data transfers
- Unusual User behaviour
- Privilege escalation attempts
- User impersonation
- Unexpected configuration changes
- Large outbound data movements
Timing matters. If your response takes hours, you’ve already lost control of the incident.
Limiting the blast radius
Not every attack can be prevented entirely, but limiting the blast radius and fallout is often the difference between a bad afternoon and a catastrophic outage. That means automatically suspending rogue tasks, freezing suspicious user IDs, halting malicious transfers, and isolating compromised activity before it spreads further into the environment. Think of this like hitting a kill switch when the throttle jams open. You may not stop instantly, but you stop the situation getting much worse much more quickly.
Data exfiltration is another focus. For years, ransomware conversations mostly centred around encryption. Now, attackers increasingly steal data first and use the threat of publication as leverage. That creates a different sort of challenge on the mainframe because large-scale data movement isn’t always unusual. Batch jobs, FTP transfers, reporting workloads and integrations all move substantial amounts of data every day. The trick is understanding what’s expected and what isn’t.
This means behavioural monitoring and learning approved workloads over time. Rather than relying purely on static rules, you build an awareness of normal transfer patterns and flag suspicious deviations. That might include:
- Unexpected volumes of outbound data
- Transfers at unusual times
- New or unrecognized endpoints
- Strange SSH or FTP activity
The goal isn’t only visibility, it’s intervention. Spot the abnormal behaviour and stop it before the data disappears out the door. Spot and stop.
In recovery
There’s also a strong emphasis today on recovery. But one of the biggest issues during a cyber incident is uncertainty. Teams don’t immediately know: what was compromised; what changed; which backups are trustworthy; whether malware still exists in the environment; and how far the attack spread. That uncertainty slows recovery dramatically.
We recommend guided recovery and “surgical” restoration rather than blunt force rebuilds. Instead of restoring entire systems blindly and hoping for the best, the focus is on identifying exactly what changed, removing malicious components, and restoring trusted states with more precision. Such an approach includes integration with immutable backups, storage snapshots, and recovery tooling from vendors like IBM, Dell and Hitachi.
The human factor
People are still one of the biggest vulnerabilities in cyber security. Not because they’re incompetent, far from it, but because cyber incidents are chaotic. Information arrives in fragments. Everyone is under pressure. Even experienced operations teams can miss things or make poor decisions when the clock is ticking and senior management is demanding answers every ten minutes. That’s why GUI-driven workflows and guided response processes are so important. The goal is to reduce the operational fog during an incident and help teams to respond consistently under pressure, especially outside specialist mainframe security circles.
Automation also helps close the gap between detection and response. File Integrity Monitoring (FIM), real-time alerting, integration with Splunk and ServiceNow; all of it helps organizations to react faster and coordinate recovery more effectively.
In other words, don’t build your recovery strategy around somebody remembering page 347 of a runbook at three in the morning.
Meanwhile, compliance requirements continue piling up: NIST, DORA, PCI, HIPAA, ISO. Organizations are now expected not just to secure systems, but to prove resilience, recovery capability and continuous monitoring as well.
Changing the mindset
For years, the industry talked mainly about perimeter defences: keeping attackers out. The conversation has changed to:
- Assume compromise is possible
- Detect attacks early
- Contain damage quickly
- Recover precisely
- Restore trusted operations fast
And that requires a different mindset entirely. To address it, you need an end-to-end, multi-vendor, GUI-based solution. Real-time threat interception and automated recovery.
The mainframe is still one of the most resilient and securable platforms. But resilience no longer comes from isolation. It comes from visibility, automation, behavioural awareness, and the ability to respond at machine speed when something abnormal happens. Because modern cyberattacks don’t politely wait for the overnight operations team to finish their coffee before getting started.
For more information email: info@vertali.com