Is Your Platform Secure Enough to Modernize?
James Loftus, technical delivery manager at Vertali, explains the question that every mainframe modernization program needs to answer
Mainframe modernization is high on the agenda for organizations in all sectors. And the goals are clear: better integration, greater agility and improved access to data, along with the ability to support cloud, AI and modern development practices.
Indeed, many organizations have reached the point where doing nothing has become the riskier option. For decades, the mainframe has been exceptionally reliable, but the business environment around it has changed. And while the cloud is somebody else’s computer, the mainframe is your computer—your responsibility.
If a company’s cloud service goes down for 20 minutes, it can be front-page news. If a mainframe goes down, operations can grind to a halt. Transactions stop. Supply chains stall. Customers can’t be served. The consequences can stretch far beyond the initial outage.
Your first and greatest responsibility is securing the platform. And “Secure First” doesn’t mean completing every single security initiative before modernization begins. That would be daft. But it does mean establishing essential controls that allow transformation to proceed safely from day one.
Why Modernization Won’t Wait
With an aging workforce, making systems easier to maintain has become a strategic priority. And there’s also technical debt. As core applications have evolved over decades, layers of enhancements, undocumented changes and obsolete interfaces make them increasingly difficult to understand and modify. Yet businesses want to be ever-more agile, launching new products and services quickly. Integration with cloud services, APIs, AI platforms and modern development practices has become a business requirement rather than simply a technology aspiration.
Organizations also want greater cost transparency, with modernization helping to identify inefficiencies and optimize resources. And cyber resilience is a top priority. While the mainframe itself can be highly secure, the surrounding ecosystem, interconnected applications and operational processes all need to be resilient too. Which brings us back to where we started.
In too many cases, the security question isn’t asked early enough. After all, why would you invest in renovating a house and fitting it out with the latest technology and expensive furniture only to leave the front and back doors permanently unlocked and the windows always open?
What Modernization Means
With many organizations concluding that their mainframe remains the best platform for running critical workloads, wholesale migration isn’t necessarily the answer. Modernizing a mainframe isn’t about replacing it. It’s about evolving the mainframe to remain relevant and competitive. This typically involves:
- Enabling APIs and integrating with cloud services
- Introducing DevOps pipelines and automation
- Exposing data for analytics and AI
- Modernizing user interfaces beyond traditional 3270 screens
- Optimizing workloads using LinuxONE, containers and hybrid cloud
A key objective is to turn the mainframe from an isolated platform into a modern, connected part of the wider enterprise. This inevitably raises all-important questions around security and resilience.
Underestimating the Security Challenge
Opening the mainframe to APIs, web services and cloud integration expands the potential attack surface. If existing security weaknesses haven’t been addressed, they can come back to bite you; modernization can expose decades-old vulnerabilities to entirely new attack methods.
Privileged access can become easier to exploit. AI is reducing the time between compromise and exploitation. Attackers can move through interconnected environments far more quickly than organizations relying on traditional controls can detect or contain them.
Modernizing a weak system won’t make it stronger. It can actually make it more vulnerable to abuse. And the technology itself isn’t normally the problem. Issues arise if delivery is prioritized over security (“Do you want it done now, or do you want it done properly?”). Common pitfalls include:
- Prioritizing speed over control
- Opening systems before fully understanding access models
- Lacking real-time monitoring and enforcement
- Having poor visibility of privileged users and sensitive data access
- Yet again: assuming the mainframe is secure by default
This can lead to privilege escalation, undetected insider threats, data leakage, compliance failures … not exactly the outcome you were hoping for when it came to modernizing your platform.
What a ‘Secure First’ Approach Looks Like
This approach doesn’t slow transformation down; it provides the foundations that allow it to happen safely. Before embarking on any significant modernization program, you should already have:
- Real-time alerting and monitoring
- Strong identity and access controls based on role-based access control (RBAC) and least-privilege principles
- Effective privileged user management, with clear visibility of who can do what, when and why
- Data protection through masking, encryption and obfuscation
- Audit and compliance visibility
- Threat detection aligned with modern attack patterns including AI-driven threats
Returning to our house analogy, you wouldn’t start adding fancy new decorations and detailing before checking the foundations first. The same principle applies to the mainframe. Secure the platform first, then build on it.
Secure First. Modernize With Confidence.
Mainframe modernization isn’t simply about adopting new technologies. It’s about enabling critical systems to participate safely in a connected enterprise. Every API, cloud integration and AI initiative increases opportunity but also increases responsibility.
Organizations that modernize first and secure later can discover they’re trying to retrofit protection onto an architecture that’s become more exposed.
Organizations that secure first create a platform that’s ready for transformation. Identity and access are under control. Privileged activity is visible. Data is protected. Monitoring is continuous. Modernization becomes something you can accelerate with confidence.
Security doesn’t delay transformation. It enables it.