Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Secure Z Systems Data and Reduce Resource Demands

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

Mainframe computing systems were once considered relatively safe from cyberattacks, but threats to these critically important business assets are becoming more prevalent and more serious every day.

Protecting customer information and intellectual property housed in mainframes is more important than ever, but many mainframe encryption solutions only protect a subset of data types or apply to limited use cases, and often create performance issues.

PK Protect is different. Providing data-level encryption for IBM z Systems mainframes, PK Protect is the most flexible, high-performance z Systems encryption solution available today.

The Mainframe Stopped Being Safe by Obscurity

Z systems were long treated as inherently secure, on the reasoning that few attackers understood them. Threats to these systems have become both more common and more serious, and the assumption has not aged well.

What has not changed is what they hold. Customer information and intellectual property on a mainframe are typically the oldest, most complete and most regulated records an organization has.

Why Many Mainframe Encryption Options Disappoint

Three limitations recur. Some solutions protect only a subset of data types. Some apply to a narrow set of use cases and leave the rest uncovered. And many introduce performance problems, which on a platform billed by consumption is a direct cost rather than an inconvenience.

Any of the three tends to produce the same outcome: encryption deployed narrowly, and a compliance position that depends on nobody asking about the remainder.

What PK Encrypt for Z Does Differently

It provides data-level encryption for IBM Z systems across both structured and unstructured data, rather than choosing between them.

Encryption can be embedded directly into applications where that is the right place for it, and mainframe databases can be secured with field-level, length-preserving encryption, so dependent programs continue to accept the values they receive.

Keys That Manage Themselves

Smartkey technology generates, synchronizes and exchanges encryption keys automatically according to the organization’s security policy, which keeps the process invisible to end users.

Storage is flexible in the way large estates require. Keys can sit in purpose-built hardware security modules on Z systems hardware, and they interoperate with third-party dedicated key management appliances, so a mainframe programme does not have to become a separate key silo.

Compression Before Encryption

Files are compressed before they are encrypted, which reduces data volumes rather than increasing them.

That ordering is the reason the resource question improves rather than worsens. Encrypting first produces incompressible output, so any solution that encrypts before compressing is choosing to carry the full volume through storage, transmission and backup.

Protected Data That Other Platforms Can Still Use

Coverage extends across Z system operating systems including z/OS and Linux on Z, and authorized users can access protected data from any enterprise computing platform.

That last point is what keeps mainframe encryption from becoming an island. Data that can only be read back on the system that encrypted it protects the record and blocks the workflows the record exists to support.

Why Data-Level Rather Than Disk-Level

Full-disk and volume encryption protect against the theft of hardware and nothing else. Once the system is running, every process with access reads plaintext, which on a shared platform is a substantial set of processes.

Data-level encryption keeps the protection attached to the record itself, so a file extracted from a protected volume and sent somewhere is still protected, and access remains a policy decision rather than a consequence of where the data happens to sit.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.