Ransomware on the Mainframe: Can Your Business Survive the Worst Day?

Ransomware doesn’t stop at distributed systems—and the stakes are even higher on the mainframe. Join cybersecurity leaders from BMC and Dell to explore how organizations are protecting transaction integrity, detecting threats earlier, and recovering faster than ever.

Key Takeaways:

  • The evolving ransomware threat landscape for mainframes
  • Designing layered detection and prevention frameworks
  • Incident response playbooks that actually work
  • Strategies for rapid, reliable recovery

Speakers

Ken Chism,
Director of worldwide cybersecurity sales, BMC Software

Joe Steiner,
CTO, Dell Technologies

event summary

Why cyber resilience is redefining mainframe recovery in the ransomware era

As ransomware threats grow more sophisticated and regulatory scrutiny intensifies, organizations must rethink how they protect critical systems. Industry experts explore the evolving realities of cyber resilience, recovery readiness, and operational continuity for business-critical mainframe environments.

core insights

Building resilience beyond traditional disaster recovery

The discussion highlights how ransomware has shifted recovery planning from infrastructure availability to business survivability.

1

Recovery readiness now drives resilience strategies

Traditional disaster recovery plans were designed for system outages, not malicious data corruption. Organizations now need recovery processes that account for compromised production and secondary environments while proving recoverability under regulatory requirements.

2

Insider risks have become a critical attack vector

The most concerning ransomware scenarios increasingly involve trusted access being misused. Detecting abnormal behavior, monitoring suspicious activity, and identifying insider threats early are becoming essential components of cyber resilience strategies.

3

Recovery speed alone is no longer enough

Organizations must recover clean data, remove persistent malware, and restore business transactions without loss. Success depends on combining immutable backups, forensic analysis, and transaction recovery capabilities into a coordinated process.

Organizations can no longer assume that backups alone will protect critical operations. Buyers and technology leaders must prioritize recovery validation, operational resilience, and the ability to restore trusted business data under real-world attack conditions. [ransome | Txt]

Key takeaways:

  • Establish immutable backup strategies that remain isolated from ransomware impacts.
  • Implement continuous monitoring to detect suspicious behavior before an attack escalates. 
  • Practice ransomware recovery exercises to reduce response and isolation times. 
  • Validate recovery workflows through forensic analysis to identify clean recovery points. 
  • Preserve transaction integrity by incorporating continuous log capture and replay capabilities into recovery plans. 

“The best response to a ransomware attack is to stop it before it happens.”

Ken Chism, BMC Software

Bring order to complex workflows

Control-M orchestrates workflows across applications, data platforms, and business systems; not just individual processes.