TechChannel: Why Mainframe Security Postures Vary So Widely
NetSPI’s Director of Mainframe Penetration Testing, Phil Young, spoke with TechChannel’s Andrew Wig about why mainframe security postures vary widely. He highlights common omissions, such as FTPS, MFA, output security, data access controls, stronger passwords, AES hashing, and TSO pre-prompt. In addition, he explains how disruption fears, silos, and legacy processes let risks persist, despite clear and often simple fixes.
Read the preview below or find the full story online here.
+++
As a penetration tester responsible for probing mainframe systems for vulnerabilities, Phil Young is a sandcastle’s worst nightmare.
“Sometimes I feel like I’m coming in and someone’s built a really beautiful castle, and I’m coming in and kicking it down and saying, you didn’t put up a fence. And now they have to really go back and build a fence and rethink their controls,” Young, director of mainframe penetration testing at NetSPI, tells TechChannel.
Some mainframes are locked down like a vault. Some are riddled with misconfigurations. But why do these security postures vary so widely? From his 20 years spent plumbing the depths of mainframe environments to identify security gaps, Young has some answers. Many of them lie in the nooks and crannies of vast, complex systems.
“So many potential gaps, thus so many potential security configurations,” says Young.
Read the full article here.
Authors:
Explore More News
NetSPI Expands Suite of AI-Powered Continuous Pentesting Services as Organizational Attack Surfaces Grow
NetSPI expands suite of Human-Led, AI-Powered Continuous Pentesting Services, including a first-of-its-kind AI Findings Validation service, as well as continuous testing for web applications and internal networks.
AI’s Role in the Next Era of Pentesting
This article discusses how AI can accelerate penetration testing, but without human expertise to validate findings and apply business context, organizations risk confusing faster output with stronger security.
Why Continuous Security Validation is Becoming a Security Imperative
CTO Magazine interviewed NetSPI's Field CISO, Nabil Hannan, for a June 11, 2026, article about how cloud-native architectures, continuous deployment pipelines, APIs, and AI-assisted development have accelerated change across enterprise environments.