Busting Mainframe Pentest Myths: What Really Happens Start to Finish
Are you pentest curious? Have you ever wondered what happens during a mainframe pentest, how those pesky testers seem to be able to find holes to worm themselves through? Then this talk is for you.
Philip will walk through a complete mainframe penetration test from first conversation to final report – scoping calls, access provisioning, enumeration, exploitation, and reporting. Along the way, he’ll dismantle the most persistent misconceptions that keep organizations from testing their most critical systems: why production testing is safer than most clients fear, why compliance isn’t the same as security, and why the hardest part of a mainframe pentest is often just getting a TSO account and OMVS segment (not really).
This isn’t a theoretical walkthrough. It’s drawn from Phil’s real engagement experience and the moments where the pentest exposed gaps that neither the mainframe team nor the CISO knew existed.
You’ll leave with a clear picture of what a modern mainframe pentest looks like, how to make the case for one internally, and what to do with the results when you get them.