Arcati 2026 | Security, Risk, and Resilience

Feb 19, 2026

Security and risk management remain central to how organizations operate and evolve their mainframe environments. In the 2026 Arcati Mainframe User Survey, respondents describe security as an embedded operational discipline that shapes priorities, tooling, and governance over time.

The data reflect managed risk rather than instability. Security is treated as continuous stewardship aligned with the mainframe’s role in supporting sensitive, high-impact workloads.

Security Priorities Reflect Targeted Focus

Respondents were asked to identify the security capabilities that represent the highest priorities within their mainframe environments.

Security Priorities

Figure 8.1: Mainframe Security Capabilities Ranked as Highest Priority (2026)
Question: Which security capabilities are the highest priorities in your organization’s mainframe environment? (Select up to five)

Responses cluster around protection of core workloads, access control, monitoring, and governance. Organizations are not attempting to treat every possible threat equally. Instead, priorities reflect structured risk assessment tied to business continuity and regulatory obligations. This suggests security investment is focused and deliberate.

From Priority to Practice: Security Tools in Active Use

The data show broad deployment of security controls across access management, monitoring, governance, and protection. Many organizations report using multiple categories of tools, indicating layered approaches rather than reliance on a single mechanism. Surprisingly, only 20% use MFA, 22% use Privileged Access Management, and 23% use SIEM/security monitoring integration. 

Security in these environments may be operationalized through daily system management, but there is room for improvement.

Security Tools in Use

Figure 8.2: Mainframe Security Tools and Capabilities Actively in Use (2026)
Question: Which Mainframe Security Tools and Capabilities are you actively using? (Select all that apply)

Incident Trends Suggest Stability

To understand whether security concerns translate into operational disruption, respondents were asked about changes in cybersecurity incidents that affected business-critical mainframe workloads over the past 12–24 months.

The responses indicate relative stability rather than escalation, with more than 60% citing no change or a decline in incidents. While it reveals that security actively managed, the survey provides no evidence of widespread increases in events affecting core mainframe systems. This reinforces a consistent pattern: the mainframe continues to operate within defined risk parameters even as the surrounding environment becomes more complex.

Incidents Affecting Mainframe

Figure 8.4: Change in Cybersecurity Incidents Affecting Business-Critical Mainframe Workloads (2026)
Question: In the past 12–24 months, how has the number of cybersecurity incidents affecting your business-critical mainframe workloads changed?

Confidence in the future of IBM Z remains strong, with organizations prioritizing investments in cryptography, automation, and security solutions — including those delivered by vendors such as ASPG — to improve efficiency and resilience. As hybrid integration expands, strengthening security across mainframe and cloud ecosystems becomes even more critical.

Greg Thomason

z/OS Product Manager, ASPG

Concern Is Broad but Not Alarmist

Respondents were also asked how worried their organizations are about specific risk categories.

Across most categories, the dominant response is “somewhat worried” rather than “very worried.” Higher-intensity concern clusters around ecosystem-driven risks, including third-party exposure, regulatory compliance, ransomware, and supply chain vulnerabilities.

Concerns intrinsic to the mainframe itself, including unplanned downtime or legacy vulnerabilities, are rated at lower intensity by comparison. This distribution suggests awareness without acute alarm. Risk attention is concentrated at integration boundaries and external dependencies rather than at the core platform.

Security as a Stabilizing Influence

Across the 2026 data, security does not appear as a catalyst for platform exit or rapid architectural upheaval. Instead, it functions as a stabilizing force. Security considerations reinforce incremental modernization, disciplined change management, and continued reliance on the mainframe for high-impact workloads.

Protection and continuity are treated as foundational. Modernization occurs within that framework, not outside it.

The next section examines how economic considerations and long-term planning shape mainframe investment decisions.

                    From Our Report Sponsor

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Sign up to receive the latest mainframe information

This field is for validation purposes and should be left unchanged.

Read More

Arcati 2026 | Artificial Intelligence and the Mainframe

Arcati 2026 | Economics, Cost, and Value

Purpose: How organizations justify investment In the 2026 Arcati Mainframe User Survey, economic considerations appear to be a boundary condition rather than a primary driver of platform change. Cost influences timing and scope, but it does not dominate strategy...

Arcati 2026 | Artificial Intelligence and the Mainframe

Arcati 2026 | Hybrid Integration and Architecture

The 2025 Arcati report established that hybrid architecture had become the dominant model for organizations running IBM Z. The new 2026 survey reinforces that conclusion and advances it. Across the 2026 responses, the mainframe is consistently described as operating...

Arcati 2026 | Artificial Intelligence and the Mainframe

Arcati 2026 | Workforce and Operating Constraints

Mainframe modernization, upgrade cadence, and tooling decisions are shaped as much by workforce structure as by technology. The 2026 survey reflects a notable shift in respondent mix while reinforcing continuity in operating models. Importantly, the 2026 workforce...