Skip to content

GS|UK Security Working Group – Next Meeting - Thursday 25th June 2026

25th June 2026, 9:00 am - 5:00 pm

We are pleased to confirm that the next meeting of the GS|UK Security Working Group, is scheduled as follows:

Date Thursday 25th June 2026, 09:00 – 17:00 BST (Please note the time zone! The meeting is being run from the UK)
Venue This is an online only meeting via Microsoft Teams
CPE/CPD hours Up to a maximum of 7 hours (full attendance required to claim maximum number of hours)

This meeting is suitable for anyone with an interest in Mainframe Security, including Mainframe Security Professionals (newbies to experienced), Cyber Security Specialists, System Programmers, Auditors and Managers. Attending this meeting will grow your professional skills and knowledge in the following areas:

  • Latest security innovations from vendors and how they help enhance security for your organisation
  • Current threats, trends, including regulatory and compliance updates to help you prioritise security and compliance efforts
  • Share problems, knowledge, best practices with working group members
  • Give feedback to vendors on their offerings, including product direction
  • Earn CPE/CPD hours to support maintenance of certifications or an education portfolio

Agenda

(Registration form at the bottom of the page)

Start End Topic Who
09:00 09:15 Welcome

Kick-off welcome session.

Sue Parsons

(GS|UK)

Rui Feio

(GS|UK)

09:15 10:00 What is Z MFA and why should I already be using it?

Beyond passwords, we must standardise enterprise security with Enhanced  Authentication options, such as the titular IBM Z MFA.

Mainframes sit at the core of global banking, healthcare, and corporate infrastructure, making them top targets for advanced cyber threats but many organisations still rely solely on traditional passwords, which is no longer enough to secure these critical environments.

This session explores why implementing Multi-Factor Authentication (MFA) is a vital step in modernizing your mainframe security posture and achieving a true Zero Trust architecture.

We will examine how IBM Z MFA goes beyond simple compliance checkmarks to actively prevent credential-based attacks and secure privileged access.

Whether you are a security administrator, system programmer, or IT executive, this session will give you insights about single points of failure and a goal defend your most valuable enterprise assets. 

Nial Ashley

(Vertali)

10:00 10:15 Setup next speaker  
10:15 11:00 Moving from password to certificate based authentication – why and how for SSH and HTTPS

This session will show how to switch from UserID and password authentication, to use certificates instead.

We’ll look at SSH login and using SSH keys as a warm-up and then look at replacing HTTPS passwords with x509 certificates.

Finally, we’ll look at how to replace TSO logins with terminal emulators with x509 certificates.

The session is hands on with demos (that I’ll have videos for if the demo Gods decide to slay me as backup) and will be step by step to follow along.

At the end folks will have seen us go from three use of passwords (ssh login, z/OSMF login and 3270 TSO login) to end with all 3 working WITHOUT a password!!!!! 

Joe Winchester

(IBM)

11:00 11:15 Setup next speaker  
11:15 12:00 Mainframe Is Not Immune to Ransomware

Mainframes power many of the world’s most critical banking, insurance, government, and enterprise workloads. While they are known for their reliability and strong security controls, they are not isolated from today’s cyber threats.

This session explores how recent ransomware and other high-profile cyberattacks could impact mainframe environments, even when the mainframe itself is not the initial target. Through real-world examples, we will examine how attackers exploit third-party tools, backup infrastructure, privileged access, and connected enterprise systems, and how these attack paths can extend to the mainframe ecosystem.

Attendees will gain a practical understanding of modern mainframe security, common misconceptions about mainframe immunity, and key strategies for strengthening cyber resilience and recovery confidence in an increasingly connected world.

Ira Miga

(BMC)

12:00 13:00 Lunch Break  
13:00 13:45 Mainframe TTPs: The Security Black Hole that threatens Economic Stability

The global economy runs on IBM z/OS, yet the industry standard for threat detection – MITRE ATT&CK, has a critical blind spot: the Mainframe. While we meticulously map Tactics, Tools and Procedures (TTPs) for Windows, Linux and Cloud, the platform processing $8 trillion in daily card payments remains a ‘Security Black Hole.’ In this session, I will unveil a new TTP matrix specifically for z/OS bringing together the known attacks and adding my own research, and how it can be used. I’ll move beyond obscurity, mapping real-world mainframe attacks to actionable mitigations, and demonstrating why ignoring these TTPs is a direct threat to economic stability especially in light of the Nation Cyber Security Centres 2026 warning of Nation States pivoting to financial services as part of their attacks on National Critical Infrastructure.

Jonathan and Kev will present updates and the way forward for the project as we aim to improve security awareness and further the integration between mainframe payments systems, red-team engagements and traditional security operations centres (SOC).

Kev Milne

(Neuro Training)

 

Jonathan Prince

(NVISO GmbH)

13:45 14:00 Setup next speaker  
14:00 14:45 Safeguarding Your Data: A Comprehensive Guide to Db2 for z/OS Security Exit Routines

Db2 security exits (connection, sign on, and authorization) are critical components of the Db2 security. Do you fully understand what they do and how? Do you have customized versions? Do you want full control? In this session we will explain the purpose and internals of the security exits, we will navigate through them and will show how open-source tools such as VSCode can significantly help with their comprehension.

Emil Kotrc

(Broadcom)

14:45 15:00 Setup next speaker  
15:00 15:45 Continuous Compliance: Security Automation with MFPandas

RACF environments often contain thousands of users, groups, permits, and naming conventions. Over time, complexity grows — and so does the risk of configuration drift, audit findings, and undocumented exceptions.
What if RACF compliance checks could be automated, repeatable, and version-controlled?
In this session, the creator of MFPandas (formerly known as pyRACF) demonstrates how to transform RACF data into structured datasets using Python and pandas, enabling automated compliance validation against:

  • Internal naming standards
  • Segregation-of-duties rules
  • External audit requirements
  • Security baselines and conventions

By treating RACF data as analysable dataframes, we can implement “Compliance as Code” principles on z/OS — bringing DevOps-style validation to mainframe security.
The session includes live demonstrations and practical implementation patterns that attendees can adapt directly within their own environments.

Henri Kuiper

(zdevops)

15:45 16:00 Setup next speaker  
16:00 16:45 RACF Update

Latest RACF Updates, focusing on the RACF support for the IBM zSecure Secret Manager.

 

Mark Nelson

(IBM)

16:45 17:00 End of Meeting

End of meeting session.

 

Sue Parsons

(GS|UK)

Rui Feio

(GS|UK)

 Note: Agenda and timings are subject to change.

Bookings are closed for this event.

Back To Top