Stream: Melbourne
Time: 15:30 - 16:15
This 45-minute session explores a severe but technically plausible attack against SighberBank, a fictional major UK bank whose mainframe supports customer accounts, cards, ATMs, online banking, payroll, batch processing and payment services. During financial year-end processing, a nation-state uses autonomous AI models to accelerate reconnaissance, analyse stolen documentation, interpret mainframe responses and move through trusted identities faster than defenders can react. A short demonstration shows how weak API authorisation, lost caller identity and exposed COBOL fields can allow a request to pass through z/OS Connect, CICS and Db2 into a trusted batch workflow. The chain continues through JES, SURROGAT, IKJEFT01, RACF administration and interference with controls surrounding ICSF. The session will clearly separate realistic RACF and ICSF risks from exaggerated claims about bypassing mainframe systems. The technical attack is interwoven with the human cost of a seven-day disruption. Mainframe operators, SOC analysts, payment teams, call-centre staff and executives struggle to determine which systems and transactions remain trustworthy. Meanwhile, a young family faces missing salaries, failed cards, unavailable cash, a missed mortgage payment and the growing paralysis affecting shops, businesses and other banks. Attendees will learn where the attack should have been stopped, how identity and authority change across modern-to-legacy interfaces, what evidence defenders should correlate, and why the most dangerous mainframe incident may be one where the system continues running but the organisation can no longer trust its output. Most importantly it will bring to life the actual stresses on individuals and the economy of a successful attack.
There is currently no attachment for The Day The Mainframe Stood Still: How a real, plausible attack would affect us
Threat Intelligence Manager, Cyber Mentor, Penetration Tester, mainframe enthusiast, and author using my 30+ years of experience to pass on my knowledge as best I can! I've worked in financial services for 20 years and consultancy for the other 10, mostly in Offensive Cyber Security and Technical Risk Management. I started working with mainframes just under three years ago and I find them fascinating as well as vital. I'm currently writing on a book for No Starch Press and have ran Mainframe Pen testing courses.
Jonathan spends his time breaking the systems enterprises trust most but understand least. Specializing in IBM z/OS and IBM i security, he researches privilege escalation, authorization flaws, and attack paths on platforms the industry forgot to threat-model. He runs a home lab with two AS/400s and enterprise gear to test these ideas in practice. His work applies modern offensive security methods to legacy platforms, showing how the path from a compromised account to mainframe domination may be far shorter than most defenders want to believe.
Click here to give some Feedback so we can make it even better next year!