Mainframe Security
The Mainframe Is Inside the On-Prem Number. Nobody Is Reporting on it.
By SDS • 7 min read • October 2026
Mainframe Security
By SDS • 7 min read • October 2026
IBM and the Ponemon Institute have released the 2026 Cost of a Data Breach Report. It is the 21st annual edition, and this year it covers 602 organizations across 17 industries and 16 countries, based on breaches that occurred between March 2025 and February 2026. The researchers conducted 3,558 interviews to build it.
It is a thorough piece of work. It breaks results out by industry, country, attack vector, who found the breach, how long the breach ran, where the data was stored, and, this year, how the organization uses AI.
It does not break out the mainframe. Not once.
That is not a criticism of the report. Almost no major breach study segments by platform that way. But it leaves a gap worth naming during Cybersecurity Awareness Month, because the report includes a number the mainframe is definitely sitting inside. Read the article, and then take our free online Mainframe Security Assessment.
In this year’s study, 30% of breaches involved data stored on premises. That figure was 28% last year and 20% in 2024. It is going in the wrong direction, and the report is direct about why: on-premises storage remains a target because it places full responsibility for patching, physical security, and access management on the organization’s own staff.
Nobody is claiming that the number is the mainframe. But the mainframe is on-premises, holds the records that matter, and sits inside the 30%.
of breached organizations were not encrypting sensitive data at rest and in motion at the time of breach. Another 10% did not know. Only 37% could say yes
That is more than half of a large sample of enterprises across 17 industries that discovered after the fact that the data taken from them was readable.
The report also quantified the value of encryption. Analyzing 30 contributing factors against the USD $4.99 million global average, it measured what each one added or removed.

These are not exotic controls. They’ve been on every best-practice list for a decade, including ours. The report simply applies a number to each control.
The report’s most consistent theme across twenty-one editions is that breach cost is a function of duration. This year the mean time to identify and contain a breach rose to 247 days, reversing a five-year decline.
Breaches with a lifecycle over 200 days averaged USD 5.65 million. Breaches under 200 days averaged USD 4.32 million. Roughly a third more, for the same class of event, decided by how long it lasted.
What to actually check in October
Five things a mainframe team can verify this month, each mapping to a measured finding above.
SDS has spent more than four decades developing and selling these mainframe controls, so it would be strange not to say where our products land against the findings above.
SDS E-Business Server, VitalSigns for Secure Transfer (VST), and Tectia SSH
PGP encryption for data at rest on z/OS and other platforms. Encrypted file transfer and system automation.
PivX Key Manager and PrivX PAM
Centralized, automated SSH key management and zero-trust privileged access that removes the dependency on standing passwords.
VitalSigns SIEM Agent for z/OS (VSA)
Sends mainframe security events to any enterprise SIEM in real time, which is a prerequisite for the internal team to find them.
IronSphere for z/OS
Automated DISA STIG compliance monitoring, turning a periodic audit into a continuous measurement.
Virtel Web Suite
Comprehensive web-enablement technology that serves legacy mainframe applications as web pages or services over secure HTTPS connections.
Sources
IBM and Ponemon Institute, “Cost of a Data Breach Report 2026: The AI Tipping Point.” Findings referenced above appear on pages 15, 18, 19, 21, 31, 50 and 66.
Figures are global averages across the study population of 602 organizations in 17 industries and 16 countries, and are not specific to any platform, industry or organization.
We offer individualized product demonstrations by request. Your organization can also try SDS Software on your system for 30 days, free of charge.