Skip to content

Does your Mainframe have a potential Security Blind Spot?

Mainframe User Access & Cyber Resiliency

Since the introduction of Cyber Resiliency guidelines by APRA (Australian Prudential Regulatory Authority) of the Cross-Industry Prudential Standard (CPS) 234 (Information Security) in 2019 and more recently CPS 230 (Operational Risk Management) in 2025, increasing pressure is being applied to the industries where they apply, to comply with these recommendations along with the ability to validate and report on how and when they were tested to confirm an organisation’s ongoing Cyber Resiliency.

With the advent of more Cyber Attacks across the globe, Vertali believes organisations should no longer just declare they are “resilient” but be able to demonstrate it through tests, audits, incident logs and evidence-based reporting.

Organisations who still rely on the Mainframe for the processing of high volumes of their business transactions are not immune to Cyber Attacks and must be more vigilant as ever, as this platform is no longer an isolated silo, but part of a much broader network. This is why Vertali is a strong advocate of regular platform Security Assessments and Penetration Testing, to identify such vulnerabilities and remediate them immediately, before it’s too late and you are caught in a Ransomware attack.

Now, in many mainframe environments, the point of vulnerability does not necessarily come from the operating system (z/OS) itself but in fact from the user access layer (network) – scattered TN3270 emulators, distributed communication layers, uneven patch cycles, heterogeneous configurations, sometimes unencrypted sessions … all potential access points that complicate auditability and increase the attack surface.

So, given this point of potential weakness, perhaps we should be drawing more attention to it and therefore, how a more centralized access architecture can automatically reduce complexity, third-party dependencies, compliance issues and “hidden in plain sight” system vulnerabilities.

Our strategic partner for mainframe accessibility and modernisation, Virtel Inc, have written a very interesting article, here, as it relates to the Digital Operational Resilience Act (DORA) that became fully enforceable across the European Union on January 17th, 2025 and aligns somewhat with APRA’s CPS 234/230 and even the recent Hong Kong Computer Infrastructure Bill Cyber Resiliency “benchmarks”. From this date forward, DORA dictates that financial institutions can no longer simply assert that their systems are resilient, they must demonstrate it.

So, here is a question for “Fortress Mainframe” users, have you ever checked the secureness of your user access layer and was it ever designed to withstand the enhanced levels of scrutiny demanded of a modern connected world?

As quoted in the Virtel article:

“… thousands of users access it (mainframe) every day through TN3270 emulators installed machine by machine, maintained on inconsistent update cycles, with configurations that vary by user, by department, and sometimes by geographic site. Each installed emulator is a dependency. An unpatched version is an attack surface. A non-standard configuration is a blind spot in your audit capability.

23% of documented mainframe security incidents originate in the user access layer rather than the infrastructure itself. The fortress holds. The gates are where things go wrong.

(Verizon DBIR: Data Breach investigation Report)

The Virtel article goes on to say:

“The most frequently overlooked attack vector is not a flaw in z/OS. It is an emulator installed on a remote worker’s laptop, running a version that has not been updated in months, transmitting credentials over an unencrypted TN3270 session. Security audits conducted across major European financial institutions consistently surface the same findings – network segregation between mainframe infrastructure and end-user environments is rare, and unencrypted 3270 connections persist in production.”

The findings from the above European financial institution security audits are very disturbing and something that should be viewed as an urgent requirement and validated within the A/NZ and APAC regions, with Cyber Attacks on the rise.

DORA and the Hong Kong (CI) Bill, goes further than Australia’s CPS 234/230 Cyber Resiliency standards, requiring the organisations the standards cover, to conduct regular resiliency tests across their key/all IT infrastructure that Vertali believes should include threat-led penetration tests based on real-world attack scenarios.

The Virtel article goes on to say:

“These tests have a particular value: they surface the gap between what an organization believes its architecture does and what it actually does. In mainframe environments, that gap is often found where nobody was looking.

67% of mainframe organizations that conducted Threat-Led Penetration Tests (TLPT) exercises in 2024 identified vulnerabilities in their user access layer that were previously unknown. The exposed surface was consistently underestimated.

(ENISA Mainframe Threat Landscape Report, 2024)

The intent of this blog is to identify a vulnerability in your core mainframe infrastructure that you may not have even contemplated, that could ultimately expose you to an unwanted Cyber Attack and the business impact these are proving to have financially and reputationally on organisations or fines from the regulatory bodies who are dictating Cyber Resiliency compliance to negate customer exposures and identity theft.

Therefore, perhaps dear reader, as part of your inevitable Mainframe infrastructure modernisation efforts you should consider the following:

  1. A regular full Security Assessment by an organisation skilled in this practise,
  2. Pre- and/or Post-Penetration Tests to identify any vulnerabilities or validate they have been resolved, by someone skilled in this practise,
  3. As part of items 1 and 2, or independently, do an end-to end test of your user access layer (TN3270) and consider centralisation and implementing a solution from say, Virtel, that offers a secure mainframe to end-user browser solution.

If any of this blog or the items mentioned above resonate with you, don’t hesitate to reach out to us at Vertali APAC Pty Ltd to discuss how we can help you validate your Mainframe-centric Cyber Resiliency compliance and contact us atinfoANZ@vertali.com (Australia/New Zealand) or infoAPAC@vertali.com (Asia Pacific region).

Copyright © 2026 Vertali Limited. All rights reserved.

Some content sourced from: https://blog.virtelweb.com/dora-and-mainframe-access-the-security-gap-nobody-is-watching

Back To Top

Based on your location, we think you may prefer the Vertali APAC site where you’ll get regional content, offerings and contacts.

Dismiss