GS|UK Security Working Group – Next Meeting - Thursday 25th June 2026
25th June 2026, 9:00 am - 5:00 pm
We are pleased to confirm that the next meeting of the GS|UK Security Working Group, is scheduled as follows:
| Date | Thursday 25th June 2026, 09:00 – 17:00 BST (Please note the time zone! The meeting is being run from the UK) |
| Venue | This is an online only meeting via Microsoft Teams |
| CPE/CPD hours | Up to a maximum of 7 hours (full attendance required to claim maximum number of hours) |
This meeting is suitable for anyone with an interest in Mainframe Security, including Mainframe Security Professionals (newbies to experienced), Cyber Security Specialists, System Programmers, Auditors and Managers. Attending this meeting will grow your professional skills and knowledge in the following areas:
- Latest security innovations from vendors and how they help enhance security for your organisation
- Current threats, trends, including regulatory and compliance updates to help you prioritise security and compliance efforts
- Share problems, knowledge, best practices with working group members
- Give feedback to vendors on their offerings, including product direction
- Earn CPE/CPD hours to support maintenance of certifications or an education portfolio
Agenda
(Registration form at the bottom of the page)
| Start | End | Topic | Who |
| 09:00 | 09:15 | Welcome
Kick-off welcome session. |
Sue Parsons
(GS|UK) Rui Feio (GS|UK) |
| 09:15 | 10:00 | What is Z MFA and why should I already be using it?
Beyond passwords, we must standardise enterprise security with Enhanced Authentication options, such as the titular IBM Z MFA. Mainframes sit at the core of global banking, healthcare, and corporate infrastructure, making them top targets for advanced cyber threats but many organisations still rely solely on traditional passwords, which is no longer enough to secure these critical environments. This session explores why implementing Multi-Factor Authentication (MFA) is a vital step in modernizing your mainframe security posture and achieving a true Zero Trust architecture. We will examine how IBM Z MFA goes beyond simple compliance checkmarks to actively prevent credential-based attacks and secure privileged access. Whether you are a security administrator, system programmer, or IT executive, this session will give you insights about single points of failure and a goal defend your most valuable enterprise assets. |
Nial Ashley
(Vertali) |
| 10:00 | 10:15 | Setup next speaker | |
| 10:15 | 11:00 | Moving from password to certificate based authentication – why and how for SSH and HTTPS
This session will show how to switch from UserID and password authentication, to use certificates instead. We’ll look at SSH login and using SSH keys as a warm-up and then look at replacing HTTPS passwords with x509 certificates. Finally, we’ll look at how to replace TSO logins with terminal emulators with x509 certificates. The session is hands on with demos (that I’ll have videos for if the demo Gods decide to slay me as backup) and will be step by step to follow along. At the end folks will have seen us go from three use of passwords (ssh login, z/OSMF login and 3270 TSO login) to end with all 3 working WITHOUT a password!!!!! |
Joe Winchester
(IBM) |
| 11:00 | 11:15 | Setup next speaker | |
| 11:15 | 12:00 | Mainframe Is Not Immune to Ransomware
Mainframes power many of the world’s most critical banking, insurance, government, and enterprise workloads. While they are known for their reliability and strong security controls, they are not isolated from today’s cyber threats. This session explores how recent ransomware and other high-profile cyberattacks could impact mainframe environments, even when the mainframe itself is not the initial target. Through real-world examples, we will examine how attackers exploit third-party tools, backup infrastructure, privileged access, and connected enterprise systems, and how these attack paths can extend to the mainframe ecosystem. Attendees will gain a practical understanding of modern mainframe security, common misconceptions about mainframe immunity, and key strategies for strengthening cyber resilience and recovery confidence in an increasingly connected world. |
Ira Miga
(BMC) |
| 12:00 | 13:00 | Lunch Break | |
| 13:00 | 13:45 | Mainframe TTPs: The Security Black Hole that threatens Economic Stability
The global economy runs on IBM z/OS, yet the industry standard for threat detection – MITRE ATT&CK, has a critical blind spot: the Mainframe. While we meticulously map Tactics, Tools and Procedures (TTPs) for Windows, Linux and Cloud, the platform processing $8 trillion in daily card payments remains a ‘Security Black Hole.’ In this session, I will unveil a new TTP matrix specifically for z/OS bringing together the known attacks and adding my own research, and how it can be used. I’ll move beyond obscurity, mapping real-world mainframe attacks to actionable mitigations, and demonstrating why ignoring these TTPs is a direct threat to economic stability especially in light of the Nation Cyber Security Centres 2026 warning of Nation States pivoting to financial services as part of their attacks on National Critical Infrastructure. Jonathan and Kev will present updates and the way forward for the project as we aim to improve security awareness and further the integration between mainframe payments systems, red-team engagements and traditional security operations centres (SOC). |
Kev Milne
(Neuro Training)
Jonathan Prince (NVISO GmbH) |
| 13:45 | 14:00 | Setup next speaker | |
| 14:00 | 14:45 | Safeguarding Your Data: A Comprehensive Guide to Db2 for z/OS Security Exit Routines
Db2 security exits (connection, sign on, and authorization) are critical components of the Db2 security. Do you fully understand what they do and how? Do you have customized versions? Do you want full control? In this session we will explain the purpose and internals of the security exits, we will navigate through them and will show how open-source tools such as VSCode can significantly help with their comprehension. |
Emil Kotrc
(Broadcom) |
| 14:45 | 15:00 | Setup next speaker | |
| 15:00 | 15:45 | Continuous Compliance: Security Automation with MFPandas
RACF environments often contain thousands of users, groups, permits, and naming conventions. Over time, complexity grows — and so does the risk of configuration drift, audit findings, and undocumented exceptions.
By treating RACF data as analysable dataframes, we can implement “Compliance as Code” principles on z/OS — bringing DevOps-style validation to mainframe security. |
Henri Kuiper
(zdevops) |
| 15:45 | 16:00 | Setup next speaker | |
| 16:00 | 16:45 | RACF Update
Latest RACF Updates, focusing on the RACF support for the IBM zSecure Secret Manager.
|
Mark Nelson
(IBM) |
| 16:45 | 17:00 | End of Meeting
End of meeting session.
|
Sue Parsons
(GS|UK) Rui Feio (GS|UK) |
Note: Agenda and timings are subject to change.
Bookings are closed for this event.