Sunday, 26 February 2023

Bigger Together: How to Maximize Mainframe’s Value

Greg Lotko, SVP and General Manager, Mainframe Software Division, Broadcom Inc, used this year’s Arcati Mainframe Yearbook to suggest that the further we evolve as a digital society, the more proof we see of a basic truth: Mainframe systems play a central role in many of the most fundamental aspects of our lives and work. The platform underpins today’s society.

The Mainframe is a modern marvel with state-of-the-art hardware and software that drive successful businesses on a global scale. Enterprises trust it and consumers transact on it every day with complete confidence. It’s a true workhorse, found in nearly every industry – and for good reason. It has unmatched capability and value.

Beyond the Mainframe’s impressive technological credentials, it’s really the people – the community of developers, engineers, data scientists, and system programmers – who leverage it to power progress. Working together, the community’s expertise, dedication, passion, and ingenuity are what bring this technology to life for businesses around the world.

Competitive forces are fiercer than ever. The ability to achieve and maintain leadership requires continuous transformation. Transformation of business models, processes, and services – and of the right technology stack to support it all. You’d better be transforming because you can bet everyone around you is. It’s more than a choice. It’s a necessity. And it’s how you move forward. You have to be anticipating the future and thinking about what’s next. That awareness is crucial.

The implications of transformation are different for every organization. This doesn’t mean throwing away the technology investments you’ve made, but rather improving and building on them. Sometimes the key to moving forward is with new technologies. Sometimes it’s with a tried-and-true platform. Most often the right answer is a combination of both.

As we surge toward the future, the need for increasing scale and speed will continue to drive change across all industries. Look at the finance, travel, and retail industries as examples. Customers demand faster, more connected experiences. The Mainframe is an essential part of that customer experience. Consider the Mainframe’s role in processing nearly 90% of all credit card transactions, not to mention doing much of the heavy lifting for airline reservations, banking, healthcare and supply chain systems.

As Mainframe expands its integration with Hybrid Cloud, the value of the platform expands as well. An open and connected Mainframe allows developers and IT of all generations to use common tools and strategies that allow visionary work in fields ranging from AI and machine learning to cyberthreat defence, data management, and much more. All while leveraging Mainframe’s inherent strengths.

When most people think of the Mainframe, they concentrate on what’s inside, but, the inherent strengths of the Mainframe include far more than the technology.

Yes, the Mainframe delivers unparalleled performance, scalability, efficiency, security, and reliability. More importantly, it’s the people – those who develop the hardware, write the code for middleware, and develop the applications – who fuel business value.

This community brings forth their know-how, experience, and commitment to continuously strengthen and evolve the IT backbone of our society. And these same people are sharing their knowledge, passing it forward to train the next generation of talent for tomorrow. These are Mainframers.

Being a Mainframer is more than working with the platform, it’s knowing that the platform is bigger on the outside. That it’s the hardware, software, and even more so the people – together – working to drive greater business value and meaningful impact on the world around us.

Our full potential is realized when we work together towards a common business goal. It’s being able to link the known with the new, so that we can build on today’s IT investments to create even greater value tomorrow. It’s this kind of bigger, collaborative thinking that empowers businesses into the future.

Let’s go BIGGER!

You can read the full article from Greg Lotko here.

Sunday, 5 February 2023

The NeverEnding Story: Optimizing and Securing the Modern Mainframe

Mark Wilson, Vertali’s Technical Director, wrote in this year’s Arcati Mainframe Yearbook that the task list for mainframers is never ending, whether that means prioritizing cyber resilience, implementing data loss prevention, or optimizing project work and BAU activity. There’s clearly a continuing demand for specialist skills and expertise.

2022 began with pandemic restrictions still in place and ended with a controversial World Cup. War came to Eastern Europe, precipitating an energy crisis. The UK had three different Prime Ministers in 50 days. A global recession may be imminent. And the mainframe has continued to do what it does: a strategic platform for the ages, the single answer to multiple questions, as relevant in the digital world as the analogue. Mainframes have traditionally accounted for up to two-thirds of the world’s IT production workloads but well below 10% of IT spend. However, the mainframe is being modernized, upgraded, optimized, and outsourced. And people want help to do that.

Talking to clients and partners has raised a myriad of issues: the continuing changes required by digital transformation, the role of the modern mainframe, and of course cyber security. Let’s take a quick look at two topics we’re asked about regularly. The first is reasonably specific: Data Loss Prevention (DLP). The second is wider ranging: how to build cyber resilience for mainframe infrastructure, data, and processes.

Mainframe data loss is fundamentally a business problem. Prevention is better than cure, which means focusing on the risk of exfiltration. DLP is about detecting, identifying, and preventing potentially damaging data breaches, data exfiltration, and the unwanted destruction of sensitive data. Effective DLP means securing and protecting your data, and complying with the necessary legislation and regulatory requirements. Gartner estimated that by 2021, 90% of organizations would have implemented at least one form of integrated DLP. But analysts also say the market has reached maturity, with competitive solutions difficult to distinguish from each other, with innovation in functionality stalling.

We should be doing everything in our power to prevent the unauthorized and illicit removal and transfer of data outside organizational boundaries, so avoiding the customer, financial, and reputational damage that can result. Data loss may come through a ransomware attack or data exfiltration via malware, and can be the result of outside attacks or insider threats. There are many ways to get data off a mainframe: FTP, SMTP, NJE (Network Job Entry), IND$FILE for mainframe to PC file transfers, commercial products like XCOM and Connect Direct, and what about HTTP and HTTPS in a connected world? And who believes READ access to data is a good idea, as a rule? If I can READ something, I can copy it.

We need to reframe DLP as a strategy, a journey, rather than a product-led approach. We should not look to DLP as a magic bullet to protect sensitive information. It requires a more informed approach. This often starts with a pen test or security assessment. And a DLP strategy has to extend in different ways across different domains: network, cloud, endpoints, and storage, ideally as part of a managed approach to security (and cyber resilience – see below). It means properly understanding our networks, and who or what is connecting to our mainframes, monitoring network activity in real-time. We can make much better use of tools already out there, using solutions that feed into a comprehensive DLP strategy.

You can start by asking a few searching questions:

  • What do we define as sensitive information? (The types of data classified as sensitive need to be revisited frequently.)
  • How do we currently track (and understand) data access, movement, and usage?
  • In what ways do we restrict access to our data?

We also need to be able to automatically detect and respond to threats: connecting the mainframe to an Extended Detection and Response (XDR) approach. It’s a very good idea to integrate the mainframe with third-party solutions such as tools for IP Filtering, Intrusion Detection Services, z/OS Encrypted Connection Monitoring (zERT), and Network Management APIs (NMIs) in IBM z/OS Communications Server.

Why risk being caught out? Vulnerabilities almost certainly exist, and you may be at risk of data loss. It could only be a matter of time before a bad actor gets in. Of course, there’s much more you can do…

Moving on, it’s been said that resilience ultimately comes from recovery. We live in a complex, ever-evolving world in which the very best cyber defence is not a guarantee against a successful attack.

Cyber resilience is about adapting fast and recovering fast as you respond to a disruptive event. Business continuity today is impossible without a strong cyber resilience plan. It’s part-and-parcel of continuously protecting the business and maintaining a hardened security stance. How can you ensure this resilience, securing mainframe systems and data from attack and other threats and, crucially, resume operations quickly and effectively if a successful attack breaches your defences?

The US National Institute of Standards and Technology (NIST) defines cyber resilience as “The ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources”. Noting that cyber resilience extends beyond deliberate attack, IBM says it “brings business continuity, information systems security and organizational resilience together… the ability to continue delivering intended outcomes despite experiencing challenging cyber events, such as cyberattacks, natural disasters, or economic slumps”.

The European Union is also proposing an EU Cyber Resilience Act (CRA), “the first horizontal regulation to introduce security requirements for connected devices and related services… Hardware and software products are increasingly subject to successful cyberattacks, leading to an estimated global annual cost of cybercrime of €5.5 trillion [in] 2021.”

We are indeed seeing increasing demand from mainframe organizations who want to prepare, protect, detect, respond, and recover from cyber threats, internal and external, intended or accidental. We recommend a two-pronged approach: developing a tailored Cyber Resilience Strategy then building, executing, and regularly updating a robust Cyber Resilience Plan based on that strategy.

A viable Cyber Resilience Strategy depends on the smooth collaboration of several preventative, detective, and responsive approaches, understanding the interrelationships between these elements and how each one complements the functions of the others. Creating your tailored strategy will therefore draw on existing operational disciplines such as Business Continuity (BC), Disaster Recovery (DR), Incident Response (IR), and Cybersecurity Planning. These elements already exist in most organizations but are siloed. We need to bring them together.

Your strategy defines how and what you will develop, and the priorities of your Cyber Resilience Plan. Developing plans that are clearly documented, updated, and regularly tested is achieved through a balanced program of activities. These include cybersecurity planning, business continuity and disaster recovery (BCDR) plans, incident response plans, periodic Business Impact Analysis (BIA) and Risk Analysis, regular testing, and stakeholder engagement. An important part of the process is educating and updating the senior leadership team on the threat landscape, based on the assumption that a breach will take place. We need to explain the risks and impacts of not having a strong strategy and plan, quantifying benefits wherever possible in monetary terms. Cyber resilience can help to significantly reduce financial loss and reputational damage.

You can also explore and deploy tools to support cyber resilience that work for you. These might include IBM z Cyber Vault (“reduce time to recovery from days to minutes”), Dell’s Data Protector for z Systems (zDP), which has been described as a “mainframe data recovery game changer”, as well as tools from Maintegrity, Action Software, New Era, Vanguard, BMC, and others.

When it comes to effective cyber resilience, a flexible approach is required, one that may include: identifying and documenting the most critical elements to your business; input from diverse stakeholders; performing a risk analysis and risk rating of systems, applications, and data (pen tests and security assessments may be part of this); ensuring your strategy and plan align with wider cyber related requirements eg GDPR, NIS Directive; and documenting, testing, refining, and updating – and continuing to do so.

When it comes to cyber security and optimizing mainframe operations in general, simply because the task is like painting the Forth Bridge – said to be never ending – doesn’t mean we shouldn’t be constantly scrubbing away the old, reinforcing and repairing, and providing new layers of protection. With the continuing role of the mainframe, at the heart of so many organizations and activities, these aren’t really technical issues or security problems anymore: they are business issues that go to the heart of successful operations, great customer service, and commercial resilience.

You can find out more about Mark Wilson and read the full article from Verali here.

Sunday, 29 January 2023

The Arcati Mainframe Yearbook 2023 – user survey findings

The Arcati Mainframe Yearbook 2023 is now available for download from https://itech-ed.com/arcati/ – and it’s FREE. Each new Yearbook is always greeted with enthusiasm by mainframers everywhere because it is such a unique source of information. And each year, many people find the results of the user survey especially interesting.

This year, the results came from the 100 respondents who completed the survey between the 21 October 2022 and the 25 November 2022. Just over half (55 percent) were from North America. 15 percent were from the Asia/Pacific region, and another 15 percent of respondents were from Europe. 10 percent were from South America. And five percent were from the Middle East/Africa. The largest group of respondents were from companies with over 10,000 employees worldwide (31 percent). Just over a fifth (21 percent) had 200 to 1000 employees. And 16 percent of respondents were each from companies with under 200 staff, between a thousand and five thousand, and, lastly, between 5000 and 10,000 employees worldwide.

It was an interesting survey this year, seeing how various sites are adopting the new technologies – although Java has been around for 25 years – and how the world of the mainframe seems to be integrating with cloud computing in a hybrid environment. Clearly, working with mainframes is an interesting way to spend your day – particularly as they are able to reach out to the cloud, mobile devices, and Internet of Things (IoT) devices, and the way DevOps practices can speed up what was a very slow process of application development. CICS, IMS, and Db2 continue to have quarterly updates that add value to the products.

In terms of what’s new (or, perhaps more correctly, what appears on a lot of PowerPoint slides), the survey found that 56 percent of sites are already using Splunk or equivalent. And a further 12 percent said that they were planning to use it. The survey also found that 67 percent of sites were already using DevOps (up from 44 percent last year), with a further 13 percent planning to use it. And 62 percent of all respondents (up from 53 percent last year) said that they were already reusing APIs to speed up application development, with a further 19 percent of sites planning to reuse APIs. Blockchain has been in the news a lot, but doesn’t seem to be close to mainstream, yet. Seven percent of sites reported already using it (last year no-one did), and only seven percent are planning to use it. With Docker, we found that 20 percent of respondents were already using it (up from 17 percent last year) with 47 percent at the planning stage.

Zowe, the open-source way of accessing mainframes, was introduced in 2018. 38 percent of sites said that they are already using it (double last year’s figure of 19 percent), with a massive 31 percent of sites having plans to make use of it in the coming year. Open-source technology is now becoming commonplace on mainframes.

When it comes to Web-enabling subsystems, we found that 80 percent of organizations were Web-enabling CICS. 65 percent of sites are Web-enabling Db2. 45 percent of sites are Web-enabling IMS. 50 percent are Web-enabling WebSphere Application Server. We also found that 39 percent of sites already use Liberty (well up from 8 percent last year), with 15 percent planning to install it.

Mainframes in an organization are just one of the computing platforms people use (along with phones, tablets, laptops, Power systems, etc), and, for a long time, there has been an issue, at many sites, with mainframes being accepted in the enterprise. The reason suggested by 85 percent of sites was that the biggest obstacle was the difficulty in retaining the necessary skills. And this, perhaps, highlights the need for a product like Zowe. 55 percent of sites thought that the biggest obstacles to mainframe acceptance within the enterprise was that it’s too expensive (or appears to be). The figure was 90 percent last year. 50 percent thought the biggest obstacle was a cultural barrier between mainframe and other IT professionals (up from 40 percent last year). 30 percent felt concerns about future availability/support of mainframe apps was an obstacle. 25 percent of respondents thought that a barrier was the mainframe being too complex (or appearing to be too complex). And 10 percent of respondents didn’t think that there were any barriers to mainframe acceptance. Let’s hope that last figure rises in the future.

Reinforcing the value of the mainframe to organizations, the survey found that 94 percent of sites have seen some kind of increase in capacity, and 93 percent have seen an increase in technology costs, but only 77 percent of sites believe their people costs have increased! Interestingly, 67 percent of sites say that the bulk of their IT budget is spent on cloud, leaving 33 percent of sites where the majority of their expenditure is on the mainframe. We’ll track how those values change over the next few years.

But no organization is going to develop an asset unless they view it as having a future, and we all know the mindset that still exists about the mainframe, treating it as little more than your dad’s technology. Unfortunately, the survey found that 53 percent of sites viewed their mainframe as a legacy system. Worryingly, only 10 percent (down from last year’s figure of 17 percent) still viewed mainframes as strategic. 37 percent viewed mainframes as strategic and legacy!

When asked what, in their opinion, are the main benefits to their organization of the mainframe over other platforms, 85 percent of respondents highlighted the benefit of availability. 70 percent of respondents highlighted security. This figure is down from the 100 percent response last year, and yet breaches and ransomware still should be a major concern. 65 percent of respondents identified scalability, with 50 percent highlighting manageability as benefits.

This year’s survey found that the z15 is the most popular model (at 50 percent of sites). The newer z15 Model T02 was found at a quarter of the sites, as was the z14 Model ZR1. The older models (z13s, z13, z12BC, z12 EC, and z114) are still out there and still performing well. It must be noted, when looking at these statistics, that many sites had more than one model of mainframe installed. We were, unfortunately, unable to collect information for z16 usage. In terms of operating system, 40 percent of respondents were using z/OS Version 2.5 (a huge increase on last year’s figure of just seven percent). Another 40 percent of sites are using Version 2.4 (last year it was 57 percent). Lastly, 20 percent were using z/OS Version 2.3.

Looking at hybrid cloud computing, the survey found that 42 percent of respondents currently used their mainframe in a hybrid cloud environment (up from 21 percent last year). A further 16 percent think that they will run a hybrid cloud environment at some time in the future, with 11 percent planning to run a hybrid cloud environment soon. A further 42 percent don’t use hybrid cloud and don’t have any plans to do so. We asked whether respondents use Red Hat OpenShift and/or IBM Cloud Paks on their mainframe. Only 12 percent of sites said yes, with nearly a quarter suggesting that they have plans to do so. We also asked which cloud providers mainframe sites used. Amazon Web Services (AWS) was the most popular at 35 percent, followed by Azure at 25 percent.

Linux is often in the news, so it was interesting to see what our respondents had to say about it. There are considerable cost and management benefits from consolidating distributed Linux workloads onto the mainframe. However, 61 percent of respondents weren’t interested in LinuxONE mainframes. Six percent of sites said they already had one, with 22 percent expecting to get one at some time in the future, and 11 percent expecting to get one in the next year. No sites in the survey said their primary operating system was Linux. Having said that, around a third (31 percent) of respondents said that they run Linux on IBM Z.

Security breaches and ransomware are becoming a major issue – with the average breach costing $4.35 million. Perhaps worryingly, 21 percent of respondents said that they weren’t worried about ransomware. No-one said they had a solution in place, although 79 percent were worried or very worried about it. So, still good news for criminal gangs and rogue nation state hackers.

Mainframes continue to offer a cost-effective, secure, and powerful platform for organizations with the necessary background and expertise in place to support it. It seems that non-mainframe IT staff and managers are not getting the opportunities to find out about the multitude of advantages that using a mainframe can bring to an organization – in terms of security, reliability, availability, flexibility, as well as understanding the true total cost of ownership figures for the platform. Perhaps Zowe will continue to help the mainframe to appear like any other server to a younger generation of programmers and managers.