Close

Mainframe Penetration Testing 101: A Critical Layer in Vulnerability Mgmt.

(OB)

Stream: Melbourne
Time: 12:00 - 12:45


Presentation

Despite their reputation for stability and security, mainframes are not immune to modern cyber threats, misconfigurations, insider risk, or privilege escalation vulnerabilities. Yet many organizations still exclude mainframe systems from standard penetration testing and vulnerability management programs. Attendees will explore how penetration testing methodologies apply within z/OS environments, including assessment areas such as RACF/Top Secret/ACF2 configurations, privileged access controls, network exposure, application vulnerabilities, dataset permissions, batch processes, APIs, and third-party integrations. The session will also address common misconceptions that mainframes are inherently secure simply due to their architecture or limited exposure. Through practical examples and real-world scenarios, this presentation highlights how penetration testing helps organizations identify hidden security gaps, validate control effectiveness, support regulatory compliance, and strengthen overall vulnerability management programs. Attendees will gain a foundational understanding of mainframe-specific testing considerations, common attack paths, governance challenges, and best practices for integrating mainframe assessments into broader enterprise risk management and cybersecurity initiatives. The session is designed for security leaders, auditors, risk professionals, and mainframe administrators seeking to improve their visibility into mainframe penetration testing concepts.

Attachments

There is currently no attachment for Mainframe Penetration Testing 101: A Critical Layer in Vulnerability Mgmt.

Speakers


  • Ray Overby at Rocket Software
  • As the Distinguished Engineer, Security at Rocket Software, Ray oversees security product direction. With over 40 years of experience in IT security, in both hands-on technical development and strategic roles, Ray offers a multidimensional and solutions-driven approach highly valued by clients and third party technology partners. He is a recognized as a global authority in mainframe security, risk, and compliance for IBM zSystem environments. Previously, Ray served as the President and Co-Founder of Key Resources Inc (acquired by Rocket Software in 2023).


    Email: roverby@rocketsoftware.com

    Feedback

    Click here to give some Feedback so we can make it even better next year!