Kyndryl Report: As AI Broadens Modernization Agenda, Leaders Prioritize Business Outcomes Over Replacing Legacy Systems
Kyndryl has released its first global Modernization Report, which found that as organizations expand investments across legacy and modern platforms, modernization increasingly requires business orchestration, not technology consolidation.
“AI is creating new possibilities and raising expectations for the business outcomes technology should deliver,” said Martin Schroeter, Chairman and CEO, Kyndryl. “Modernization is about preparing for what comes next, and the leaders making the most progress are investing across their technology environments—strengthening resilience and putting those investments to work where they deliver the greatest value.”
Based on insights from 2,000 business and technology leaders across five continents and 12 industries, the research shows how AI is reshaping investment priorities across infrastructure and applications, while also challenging organizations’ operating models.
According to the report’s findings, the need to adopt AI now outranks priorities to reduce spending, replace legacy systems, or address a shrinking pool of legacy systems expertise. AI is the top driver of increased mainframe and edge computing use, the second-biggest driver for SaaS and private cloud expansion, and the leading reason organizations are upgrading their networks and application portfolios. Every organization with a mainframe now reports plans to deploy AI to the platform.
Together, these trends are creating more complex technology environments and new operational challenges for technology leaders.
Nearly half of respondents said they are behind schedule on their modernization goals. Agentic AI, which can autonomously plan and execute tasks, is emerging as a way to modernize faster. Ten percent of organizations have deployed agentic AI in production for modernization, applying it to typically time- and skills-intensive tasks of dependency mapping, code conversion, and generating documentation. Early adopters reported stronger outcomes, with 67% saying they are ahead of or on track with modernization goals, compared with 51% of other organizations.
The research also highlights what is slowing organizations down. Just 9% said they fully understand their applications’ dependencies, and one-quarter say they have large numbers of undocumented applications.
Among other findings, Kyndryl’s study shows that:
Modernization has become a business-wide priority, not just a technical one
The findings underscore the growing demands on CIOs, who must advance several priorities at once: AI adoption, cyber resilience, regulatory compliance, operational efficiency, and business growth. Respondents named nine distinct stakeholder groups with control over modernization, from CIOs and CTOs to boards of directors and finance and compliance teams. Modernization has outgrown the IT department and become a board-level business decision. Its growing importance also requires organizations to coordinate decision-making across more stakeholders without sacrificing speed.
Global events shape technology decisions alongside cost and performance
Sovereignty considerations are a growing factor in modernization strategies. While 65% of organizations address sovereignty selectively or primarily through a compliance lens, 63% expect sovereign cloud usage to increase and 55% expect sovereignty and regulatory requirements to place greater demands on their network architectures. The findings suggest that the geographic location of where technology runs is increasingly being shaped by governance and geopolitical considerations alongside performance, cost and innovation.
Complexity keeps compounding
The findings challenge the long-held assumption that digital transformation would lead organizations to gradually migrate toward a single preferred technology environment. Instead, their technology environments are becoming more distributed and complex as they prepare for AI. Mission-critical applications are distributed almost evenly across public cloud, private cloud, mainframe and on-premises environments, creating an increasingly hybrid enterprise. As digital transformation extends across the business, it must be underpinned by strategic, governance, and operational coordination—including a more integrated approach to cyber resilience as AI-driven threats accelerate and broaden.
Read more about Kyndryl’s 2026 Modernization Report.
Source: Kyndryl
IBM Expands Its Digital Banking Infrastructure with Swift Integration and Digital Asset Haven On-Premises
IBM has announced two key capabilities designed to help financial institutions, governments, and other regulated organizations provide digital asset services while prioritizing enterprise-grade security and control. In a beta offering, IBM Digital Asset Haven clients can now connect to permissioned blockchain networks, including Swift’s blockchain-based shared ledger. IBM is also extending IBM Digital Asset Haven to an on-premises beta deployment option, enabling clients to manage digital asset operations entirely within their own data centers.
According to J.P. Morgan Payments, 93% of financial institutions are modernizing their payments infrastructure¹ as banks look to move money more efficiently across borders and manage a growing range of digital assets. This shift is increasing demand for infrastructure that can support new forms of digital transactions while meeting banks’ security, compliance, and operational requirements.
IBM advances cross-border payments with Swift’s ledger
IBM Digital Asset Haven now enables clients to connect to Swift’s blockchain-based shared ledger. Swift is the globally inclusive cooperative that connects 12,500 financial institutions across 200+ markets. With the beta release of the IBM Digital Asset Haven ISO 20022 Messaging Adapter feature, institutions can instruct tokenized deposit transactions using standard ISO 20022 messages through the shared ledger infrastructure, allowing them to build on existing payment message formats and operational processes instead of blockchain-specific workflows. Swift’s ledger supports bank-issued tokenized deposits and participating IBM clients can move digital assets 24 hours a day, 7 days a week, ahead of final settlement through existing systems, while continuing to use established Swift standards and banks’ own compliance processes.
Announced at Sibos 2025 and designed in collaboration with more than 40 financial institutions worldwide, Swift’s ledger moved from concept to activation within nine months and is being put to first use by 17 first-mover institutions piloting tokenized deposit transactions. Financial institutions already participating in the program have successfully tested tokenized deposits on the Swift shared ledger with IBM Digital Asset Haven, demonstrating how banks can use existing standards and compliance processes to explore new models for moving money digitally.
IBM Digital Asset Haven extends to on-premises beta deployment
IBM is also extending Digital Asset Haven, a platform built to help banks, governments, and other regulated organizations manage and secure digital assets, to an on-premises beta deployment for clients. This deployment allows organizations to manage digital assets such as stablecoins and tokenized deposits entirely within their own environments.
Since launching IBM Digital Asset Haven SaaS and hybrid deployment options in October 2025, banking and payment institutions across multiple continents have begun implementing digital asset use cases with IBM Digital Asset Haven.
The new on-premises deployment option is designed to run entirely inside a client’s own data center on IBM Z and IBM LinuxONE with no dependency on public cloud infrastructure. Clients can deploy it on compatible IBM infrastructure already in their environment or add new capacity based on their requirements.
IBM Digital Asset Haven on-premises differentiates from existing deployment options by being built to combine client control with increased performance, speed, and scale for digital asset operations, while prioritizing enterprise-grade security. IBM Digital Asset Haven’s on-premises key features include:
- Client-Controlled Deployment keeps both the solution layer and the key management layer entirely inside the client’s own IBM LinuxONE or IBM Z environment, with configurations achieving industry-leading 99.999999% availability2.
- Hardware-Backed Security protects keys using IBM Crypto Express HSMs embedded in LinuxONE, with confidential computing and secured environment partitioning isolating production, test, and development environments.
- Structured Key Ceremonies and Cold Storage follow formal, auditable processes used to generate root certificate authority keys, producing documentation clients can present to regulators, with support for IBM Offline Signing Orchestrator cold storage operations.
- Consistent Experience Across Deployments carries the same architecture, APIs, and workflows as Haven’s SaaS and Hybrid SaaS options, so clients can move between deployment models without rewriting applications.
“The financial services industry is entering a new era where tokenized and traditional assets will need to move side by side,” said Tom McPherson, General Manager, IBM Z and LinuxONE. “As institutions modernize payments and prepare for a future of always-on transactions, they need infrastructure that combines innovation with the security, resiliency, and regulatory compliance requirements of regulated banking. By connecting to Swift’s shared ledger and extending IBM Digital Asset Haven to on-premises environments, IBM is helping clients participate in emerging digital asset networks while prioritizing control of their most critical financial operations.”
Source: IBM
Rocket Software Advances Governed, Agentic AI on the Mainframe with Rocket® EVA™
Rocket Software has announced the expansion of Rocket® EVA™, its agentic AI platform for mission critical systems. The expanded platform provides governed, auditable AI agents on the mainframe to correlate and reason across operational data and automate operational tasks within enterprise-defined policies. The latest capabilities expand the operational use cases teams can address with EVA, helping enterprises put agentic AI to work across mission-critical environments.
As enterprises bring AI to the mainframe, specialized expertise remains a significant challenge. According to a Hanover Research study for Rocket Software, 81% of financial services IT leaders report a very or extremely significant mainframe skills gap, while 87% believe AI will help address it over the next two years.
“Enterprises have relied on the mainframe to run their mission-critical workloads for decades,” said Milan Shetti, president and CEO of Rocket Software. “AI promises to unlock even more value from these environments, but only if enterprises can deploy it securely and without disruption. We’re helping customers apply agentic AI to mission-critical systems with speed, confidence, and control, closing the skills gap and putting that expertise within reach of every enterprise team.”
Backed by Rocket Software’s mainframe expertise, modernization portfolio and purpose-built AI architecture, EVA enables agents to understand and act on mainframe environments in real time. Global organizations across financial services, government, insurance, retail, and telecommunications are participating in EVA pilots. The focused pilot program enables customers to validate high-value operational use cases with their own data and move from installation to actionable insights within days, not weeks.
The expanded EVA platform includes the launch of Rocket® PlanGuard™, a new security layer that puts a policy checkpoint between AI reasoning and system execution, extending auditable, highly scoped agent access to mainframe resources. PlanGuard adds a policy decision point and identity controls to ensure AI-driven actions remain within approved boundaries while maintaining enterprise control.
Putting agentic AI to work across core operations
According to Hanover Research, 94% of financial services IT leaders rank enhancing IT operations with AI as a high or top priority. EVA uses natural language to apply AI to operational challenges that have traditionally required specialized expertise, multiple tools and significant manual analysis, significantly lightening the burden on IT teams. According to a recent Rocket survey of mainframe AI use, Rocket customers are seeing early success with EVA across a range of high-value operational use cases, including:
- Operations/Diagnostics: Identifies and correlates operational issues across systems to accelerate analysis and resolution, with use cases spanning job failure pattern analysis, operational dashboard and KPI generation, end-to-end agentic workflow automation, end-of-month financial reporting analysis, IBM® CICS® online banking application optimization, and IBM CICS queue and backlog analysis.
- Security: Protects critical systems and data with vulnerability detection, automated compliance, and intelligent patch management, and identification of emerging risks associated with Post Quantum Cryptography (PQC).
- Batch processing: Assists teams in monitoring batch performance against SLAs, identify critical failures and investigate root causes faster through AI-assisted analysis.
- Application/Configuration management: Helps pinpoint performance and configuration issues through high CPU utilization analysis and IBM® Db2® data sharing, buffer pool and cache degradation.
- Data: Advances Rocket’s vision for unified enterprise data access, enabling more intelligent delivery and streamlined output management across the enterprise.
- Together, these use cases show how EVA can reduce manual investigation and accelerate the path from operational issue to root cause and resolution.
Capabilities for mainframe professionals
EVA combines AI-powered assistance with governed access to help mainframe professionals work more efficiently while maintaining enterprise control:
- Reduce Mean Time to Resolution (MTTR): Quickly diagnose and resolve operational issues by connecting data, context, and expertise across mainframe and distributed environments, helping teams move from problem identification to resolution faster.
- Improve visibility: Surface insights from logs, metrics, applications, and system data through a conversational experience, making it easier to understand system health, identify dependencies, and detect issues before they escalate.
- Preserve expertise: Capture and operationalize institutional knowledge, enabling team members of all experience levels to benefit from the expertise of seasoned professionals and reducing reliance on a shrinking pool of specialists.
- Governed mainframe access: Keeps AI-driven actions within patent-pending defined policy boundaries through contextual, just-in-time authorization, with activity logged for auditability and human oversight supported where required.
- The expansion also extends Rocket’s model-agnostic architecture with a lightweight, standards-based approach to connecting z/OS® data. By simplifying access to operational and enterprise data while maintaining governance and control, EVA enables organizations to accelerate AI adoption across core business systems with less complexity and risk.
Source: Rocket Software
IBM Vault Premium Package for z/OS 5.0: One package to discover, automate, and govern every credential on IBM Z
Overview
Every IBM Z environment runs on credentials: TLS certificates rotating on unpredictable schedules, secrets embedded in application datasets, and encryption keys distributed across systems and clouds. Managing them manually across separate tools creates the exact gap that compliance failures and security incidents exploit: a credential that expired unnoticed, a secret that was never revoked, a key whose rotation no one could verify.
Vault Premium Package for z/OS 5.0, closes that gap. z/OS security administrators and CISO offices gain a single, policy-driven package that automates certificate lifecycle management, centralizes secrets discovery and governance, and unifies encryption key orchestration across their IBM Z estate, under one entitlement, with one consistent policy model.
Automated certificate lifecycle management
TLS certificate expiry is no longer a periodic risk: it is an operational obligation with a hard deadline. The CA/Browser Forum is reducing the maximum validity of public TLS certificates to 47 days, with the transition already underway and full enforcement by 2029. At that frequency, manual certificate rotation at IBM Z scale is not feasible.
Vault Premium Package for z/OS (previously branded as “IBM zSecure Secret Manager”) automates the complete certificate lifecycle for RACF-managed TLS certificates: issuance, rotation, and revocation occur without manual intervention. When a certificate requires renewal, the package automatically generates a signing request, submits it to the appropriate CA, and stores the signed certificate back in RACF, end to end.
The outcome for z/OS Security Administrators:
- Certificate rotation is policy-driven, not calendar-driven, helping to eliminate the operational overhead of tracking hundreds of individual renewal dates.
- Automated renewal extends consistently across all systems in a sysplex, enforcing policy sysplex-wide per RACF database, designed to remove gaps at the boundary.
- Centralized secrets discovery and governance
Vault Premium Package for z/OS replaces scattered distribution with a single encrypted system of record, and adds active discovery to surface what already exists:
- Discovery capabilities scan z/OS datasets and USS to locate and inventory RACF-managed certificates and supported secret types, giving Security Administrators expanded visibility ahead of audits.
- A single encrypted system of record replaces manual key rings and dataset-based distribution for passwords, API keys, and certificates.
- Expanded z/OS USS components, packaged without requiring a separate installation, enable native secrets delivery directly into z/OS workloads, with no container infrastructure required.
- Distributed applications gain auditable, credential-free connectivity to IBM Z: the package brokers RACF credentials and generates PassTickets dynamically, eliminating the need to embed credentials in application code or configuration files.
- Unified encryption key orchestration
Encryption keys distributed across on-premises systems, IBM Cloud, AWS KMS, Azure Key Vault, and Google Cloud create governance gaps that increase compliance exposure and complicate audit responses.
Vault Premium Package for z/OS brings key generation, rotation, backup, and recovery under a single comprehensive policy model:
- Unified governance spans on-premises z/OS systems and major public cloud environments, including IBM Cloud, AWS KMS, Azure Key Vault, and Google Cloud.
- Full support for key management for IBM Z Pervasive Encryption and z/OS data set encryption.
- A consistent policy framework means a change in key rotation policy propagates across the estate, not just to the systems where it was remembered to apply.
Why this matters
Credential risk on IBM Z rarely comes from a single missed renewal or a single exposed secret. It comes from not knowing a credential existed, from policy enforced on one system but not another, or from a manual process that worked until the person who ran it left. Certificate expiry, secrets sprawl, and key governance gaps are not separate problems: they are the same problem, credentials operating outside a consistent policy framework.
At the same time, the external environment is not waiting. The 47-day TLS certificate mandate is in motion. Multi-cloud key management is a compliance expectation, not a future consideration. Centralized secrets management has become the default standard on distributed platforms.
Meeting that standard on IBM Z has, until now, required assembling and operating three separate tools: zSecure Secret Manager, a standalone key orchestration product, and a secrets management platform, each with its own purchase, its own policy model, and its own manual processes. Vault Premium Package for z/OS replaces that assembly with one package: discover, automate, and govern, for every credential across the IBM Z estate.
Rebranding and repackaging information
IBM zSecure Secret Manager has been renamed to IBM Vault Premium Package for z/OS. All capabilities that zSecure Secret Manager clients rely on, certificate lifecycle automation, secrets management, and discovery, are included in Vault Premium Package for z/OS, alongside the new key orchestration and expanded secrets capabilities described in this announcement. Existing zSecure Secret Manager clients are not losing any functionality; their entitlement is being renamed and repackaged as part of this comprehensive offering.
Source: IBM
IBM COBOL Elevate for z/OS Now Available
In July, IBM announced COBOL Elevate for z/OS, a comprehensive solution designed to help organizations modernize business-critical COBOL applications through automated performance optimization, accelerated compiler upgrades and actionable performance insights.
COBOL applications remain foundational to many of the world’s most important business systems. As organizations continue to modernize their IT environments, they face increasing pressure to improve application performance, maintain supported software levels, and reduce reliance on specialized skills while continuing to deliver uninterrupted business operations.
IBM COBOL Elevate for z/OS helps address these challenges by bringing together automation, analytics and AI-assisted capabilities in a single solution. Designed for organizations running COBOL applications on IBM Z, it helps to simplify modernization efforts and aims to improve application quality, developer productivity and operational efficiency.
IBM z17 is the industry’s leading platform for business‑critical COBOL applications, bringing together specialized hardware and a next‑generation COBOL compiler to deliver unmatched performance, resilience, and efficiency. Explore IBM COBOL Elevate with the new z17 single frame & rackmount to maximize the value of existing investment and tap into new COBOL capabilities to accelerate the modernization journey.
Organizations are looking for practical ways to modernize existing applications while maintaining the reliability and resilience that their businesses depend on.
IBM COBOL Elevate for z/OS is built to help address key COBOL application modernization challenges by:
- Optimizing COBOL application performance by fully leveraging Z platform capabilities, maximizing ROI
- Supporting proactive performance management
- Accelerating COBOL application modernization and compiler upgrade initiatives
- Reducing dependency on scarce COBOL skills and development resources
- Together, these capabilities are designed to help organizations modernize with greater speed while continuing to leverage the business logic and operational stability embedded within their COBOL applications.
IBM COBOL Elevate for z/OS 1.1 reached general availability on 18 September 2026.
Source: IBM








0 Comments