Stream: Magny-Cours
Time: 14:15 - 15:00
Modern-day mainframes are no longer isolated legacy systems hidden away in the network or data centre. As organisations embrace and accelerate digital transformation, mainframes are increasingly exposed through APIs, middleware, and Continuous Integration/Continuous Development pipelines, becoming increasingly interconnected with an organisation’s IT estate. This session explores how mainframe modernisation is expanding the mainframe attack surface across identities, interfaces, and enterprise integrations. We’ll show how trust relationships and integration points can create pathways that bypass traditional security assumptions. Drawing on real-world assessment experience, we will demonstrate how weaknesses in non-mainframe elements of an organisation’s IT estate can increasingly translate into risk for some of its most critical systems. The session will provide practical guidance and direction for securing the modern mainframe estate. Attendees will walk away with an understanding of how their organisation can move beyond compliance-focused assessments, towards continuous, intelligence-led testing of security controls and security monitoring, in a manner that meets the challenges of today's interconnected environments and AI-driven threats.
There is currently no attachment for From Audit to Adversary: A Strategic Approach to Mainframe Security Testing
James Boorman is a security consultant specialising in mainframe security. Over the past several years, James has spent his time untangling the web that is mainframe security within large international organisations; delivering assessments as well as training to identify the hidden risks within these overlooked but undoubtedly critical platforms driving global economies.
Click here to give some Feedback so we can make it even better next year!