Sunday, 4 July 2021

Mainframes not going away any time soon

The latest research about mainframe market size, market share, application analysis, regional outlook, growth trends, key players, competitive strategies, and forecasts for 2021 to 2029 have been published by Research and Markets.

They say that the global mainframe market is projected to witness a substantial growth, growing at a compound annual growth rate (CAGR) of 3.2 percent during the forecast period from 2021 to 2029, according to a new report added to ResearchAndMarkets.com website.

Not surprisingly, they say that, based on geography, North America led the overall mainframe market accounting for the largest market share in 2020. The region is likely to remain market leader throughout the forecast period from 2021 to 2029. 

The presence of some major players, such as IBM, BMC Software, Dell, and Hitachi Vantara, also supports the growth of the market and is expected to provide lucrative opportunities in the years to come, according to the report. In North America, the USA dominated the regional mainframe market in 2020, and is projected to reign throughout the forecast period from 2021 to 2029, the report claimed.

The report informs us that mainframe manufacturers are adopting strategies like new product development and partnerships to cater for the needs of their customers and gain competitive advantage over other players. The major players in the mainframe market include Atos SE, BMC Software, CA Technologies, Cognizant, Dell, DXC Technology Company, FUJITSU, HCL Technologies Limited, Hitachi Vantara Corporation, Infosys Limited, IBM, LzLabs GmbH, Redcentric, Unisys, ViON, and Wipro, among others.

The full report looks at segmentation by product type, including Z Systems, GS 21 Series, and others. There’s end-use vertical segment, including BFSI, Healthcare, Defense & Government, Retail, Public Utilities, and others (Academics and Research, etc). And there is geography, looking at North America (USA and Rest of North America), Europe (UK, Germany, France, Rest of Europe), Asia Pacific (Japan, China, India, Rest of APAC), and the rest of the world (Middle East & Africa, Latin America).

The list of key questions answered in the report are:

  • What was the market size of mainframe market in 2020 and forecast up to 2029?
  • What are the key factors driving the global mainframe market?
  • What are the key market trends and high-growth opportunities observed in the mainframe market?
  • What are the drivers of the mainframe market?
  • Which is the largest regional market for mainframe market?
  • Which segment will grow at a faster pace? Why?
  • Which region will drive the market growth? Why?
  • Which players are leading the mainframe market?
  • What are the sustainability strategies adopted by the key players operating in the market?

The trouble with any report like this, certainly looking towards the end of the decade is that, obviously, it cannot predict unexpected events. Its biggest assumption is that life will pretty much carry on as normal – and not allow for pandemics and other crises occurring. However, as that’s the way all of us plan for the future, that’s not too much of a criticism.

The good news for those of us who work in the mainframe world is that the predictions are that the mainframe market will continue to grow over the next eight years, which indicates that we will still be in paid employment for the foreseeable future. Although, perhaps our employment prospects might become in doubt as AI and machine learning make experienced mainframers less needed to run these new machines of the future.

And, there’s always the possibility that mainframes will be replaced by fully functional quantum computers in a few years’ time. And that will have a devasting effect on predictions for the mainframe marketplace by the end of the decade.

Perhaps many mainframers are simply hoping that the industry will still be around until it’s time for them to retire!

 

Sunday, 27 June 2021

Computing tomorrow


Following the announcement of a £210 million partnership between the UK government and IBM to support businesses in the adoption of new digital technologies, we wondered what the future of computing might look like.

Amanda Solloway, the science minister, explained that the investment will be put towards the new Hartree National Centre for Digital Innovation (HNCDI). Based in Daresbury, Cheshire, HNCDI will enable businesses to acquire the skills, knowledge and technical capability required to adopt digital technologies like supercomputing, data analytics, artificial intelligence (AI), and quantum computing – according to their website.

The website goes on to say that HNCDI will help organizations and individuals with an appetite for change, who are ready to innovate and create useful solutions, enhance and adapt products and processes, adopt new digital technologies, and expand into new markets. They say they will work with start-ups and SMEs to large corporates, and public sector organizations such as NHS Trusts and local government. And, they offer training on an individual and group basis.

The UK government is investing £172 million over five years through UK Research and Innovation (UKRI), and IBM is contributing £38 million. In addition, 60 more scientists, interns, and students will join IBM Research and the Hartree Centre in the joint Science and Technology Facilities Council (STFC) – IBM Programme.

While we were working from home over a Teams meeting, we started kicking around some ideas of what the future of computing, that they might be researching, would look like. Here are some of the things that were said.

Quantum computing is an obvious goal. The benefits of getting workable quantum computing are enormous, and companies like IBM and Google are regularly making small changes to how the define and measure quantum computing and then making announcements. Quantum computing will be a complete breakthrough in computing when it comes because so much more computing power will become available. One of the consequences of that is that many levels of encryption will be broken by a quantum computer in a relative short period of time (it would currently take hundreds of years using the available technology to break the encryption in use). So, that has worrying implications.

Artificial Intelligence is another obvious goal. AI and Machine Learning mean that computers can not only do straightforward repetitive tasks, but can also learn, make decisions, and perform more complex tasks. This, in turn, allows things to happen more quickly (computers work faster than people, and for longer hours). It should make our lives easier. Cars really could drive themselves, planes could fly themselves, etc. The downside is, of course, that fewer people would be needed because the ‘machines’ would be doing the work. And this has a huge impact on the economy. And, according to the movies, could lead to the formation of Skynet and the arrival of the Terminators!

Data analytics is something that many organizations are enjoying the benefits from using. The traditional model of selling is that person A makes a product and takes it to person B. Person B sells the product in their shop to Person C, who then takes it away and uses it. Data Analytics allows Person B to see what types of product Person C has been buying and is able to suggest to them other products that they might like. And they can do this with vouchers, on social media, via an app on their phone, etc. It’s a way of understanding customers and encouraging them to buy more from you rather than your competitors. Using the information available from data analytics helps a company be more competitive and therefore successful than its rivals.

Supercomputing is all about getting as much computing power as possible so it can be used to answer difficult questions like, “what will the weather be like tomorrow?” IBM has its Blue Gene/P supercomputer and Summit. Other names you’ll hear are Cray and Fugaku Systems. It’s thought that quantum computers could replace the need for supercomputers.

In the near future, mainframes are likely to continue running the amount of work they do. It’s also likely that mainframes and distributed systems will continue offloading parts of their work to the cloud. Replicating data to the cloud makes restoring data quicker and easier and is vital in a business continuity situation.

Security seems to be the biggest challenge. Any computer that people can use (and that’s all of them) is likely to be hacked. Employees, in an unguarded moment, are likely to click on a link or click on an attachment and download a piece of malware that could start the attack. It’s not just the software on a laptop that can be attacked, but the firmware can be as well – meaning that extra levels of security are required. And trusted members of staff can be cynically manipulated by bad actors to steal data or give them access. New security terms are being coined all the time to describe where the focus for security should be placed. Things like ZTA (Zero-Trust Architecture), SASE (Secure Access Service Edge), APM (Application Performance Monitoring), XDR (Extended Detection and Response), and CASB (Cloud Access Security Broker), to name but a few.

Computers getting smarter clearly has a positive impact on businesses and, indirectly, everyone. It makes life easier for them. The downside, unless steps are taken, is that smarter computers make life easier for hackers. As mentioned earlier, quantum computers could break through quite sophisticated levels of encryption. Criminals could use data analytics techniques to identify people who they could most easily manipulate to perform criminal acts. And AI could lead to various doomsday scenarios.

This has been the case with every development ever. It can be used for good or bad. Let’s hope that the developments coming from HNCDI are used for our good.

Sunday, 20 June 2021

Auditors, compliance, and the mainframe

Mainframes have been successfully keeping organizations in business for over 50 years. Let’s just look at some statistics. Mainframes are used by 71 percent of Fortune 500 companies. They handle 90 percent of all credit card transactions. Each IBM z15 mainframe can handle 19 billion business transactions a day. And mainframes handle 68 percent of the world’s production IT workloads, yet they account for only 6 percent of IT costs.

Drilling down on those figures we find that in terms of ATMs and IMS:

  •         $7.7 trillion credit card payments (annual)
  •         29 billion ATM transactions (annual)
  •         12.6 billion transactions (daily)
  •         87% of CC Transactions done on z/OS.

With so much work taking place on a mainframe and so much money being transacted, you’d assume that auditors would be all over the mainframe. You’d probably assume that auditors would know almost as much about how mainframes work as systems programmers do. You’d think that they would want to know the tiniest of intricacies in order to assure themselves that corporations using mainframes were absolutely compliant with all the regulations that applied to them – things like the Payment Card Industry Data Security Standard (PCI DSS).

Worryingly, in many cases, auditors are put off by the complexity of mainframes and don’t know the right questions to ask. Not that I’m suggesting that organizations are committing any kind of fraud on their mainframes. What I am suggesting is that they may not be completely compliant with the regulations that apply to them.

The very nub of the problem is that the PCI DSS requires the use of file integrity monitoring (FIM) software on a computing platform, and hardly anyone using an IBM mainframe has that type of software installed. And that seems strange, bearing in mind that mainframes are used by the majority of financial institutions in the world.

Let’s look at those PCI regulations in more detail. Section 10.5.5 asks: “Is file-integrity monitoring or change-detection software used on logs to ensure that existing log data cannot be changed without generating alerts (although new data being added should not cause an alert)?”. And section 11.5 asks: “Is a change-detection mechanism (for example, file-integrity monitoring tools) deployed to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files?”.

Clearly, most sites aren’t compliant because they aren’t running file-integrity monitoring software on their mainframes, and yet these organizations are signing off the section 3 validation form saying that they are. And the person signing is probably the CIO, CFO, or CEO!

Many mainframe sites try to get round this issue with what they call ‘compensating controls’. The truth is that these compensating controls are basically non-existent. The next ploy used by organizations is to keep mainframes ‘out of scope’. But as shown in the figures at the start of this article, that clearly isn’t the case. And, if the auditors understood what was actually happening on the mainframe, they would be able to ask appropriate questions to show that was the case. The question they should be asking is: “If 90 percent of debit and credit transactions end up running on a mainframe, how can mainframes possibly be out of scope of a PCI Audit?”

Worryingly for many mainframe sites and their auditors is that V4.0 of DSS is due out in the next year. It’s unlikely that the rules in 3.2.1 will change. However, what is likely to change is that the enforcement and scrutiny of compensating controls will probably be greatly strengthened.

Focusing on security for a moment. On 12 May, US President Biden issued an executive order, amongst other security measures, to develop a plan to implement Zero Trust Architecture (ZTA) for Federal organizations. And zero-trust seems to be the way that security is going. NIST (The National Institute of Standards and Technology) earlier this year said: “An enterprise monitors integrity and security posture of all owned and associated assets. No asset is inherently trusted.” How do we get to ZTA on a mainframe? PWC recently published some guidelines. Item 2, on their 4-point list. says ‘File Integrity Monitoring’. That, I think, also highlights the pivotal role of file-integrity monitoring in mainframe security.

Lastly, and this is relevant because the majority of ATMs are connected to IMS running on a mainframe, there was advice from the PCI and the ATM Industry Association highlighting the need for file-integrity monitoring software on mainframes running transactions from ATMs. You may remember last October, there was an urgent bulletin from the PCI and the ATM Industry Association – the first ever bulletin issued by the two associations together, which highlights its significance – about cash-out attacks on ATMs. Thieves breached bank or card processor's security to manipulate fraud detection and took lots of cash from a number of ATMs. As we said, most ATM transactions are captured by IMS running on a mainframe. The advice given was that organizations should get file-integrity monitoring (FIM) software to combat the cash out hack.

What is file-integrity monitoring software? As its name suggests, it identifies when a file has been changed. It does this by taking a baseline copy and keeping that securely in a vault. It then checks the baseline copy against the current version at user-defined intervals and alerts when any differences are found. Obviously, lots of changes will be authorized, so, it can check against ServiceNow, BMC Helix, etc to only alert about unauthorized changes. More advanced FIM software can identify exactly what has been changed, when it was changed, and who by. And, following agreed policies, it can have the userid of the culprit suspended and the changes backed out. Ransomware attacks now corrupt backups before encrypting data. Advanced FIM software can check backups at regular intervals to identify if any unauthorized changes have been made and so help stop ransomware attacks. And it can do all this very quickly.

Putting it all together, it seems that the PCI, the US government, NIST, PWC, and others are looking at FIM as part of the answer to mainframe security. It seems that auditors need to be better prepared to ask more searching questions about mainframe compliance with agreed standards. And it seems that mainframe sites need to realize the benefits they will get from using FIM software.