Case study

Integrating Mainframe Scanning With Penetration Testing With Rocket® z/Assure® Vulnerability Analysis Program (VAP) 

A major global bank partnered with Rocket Software to transition critical mainframe vulnerability scanning to their penetration testing team using advanced training and innovative tools. Here’s how Rocket z/Assure Vulnerability Analysis Program (VAP) helped. 

Challenge

A global bank needed a streamlined and unified approach to mainframe security while transitioning responsibilities to penetration testers. 

Solution

The bank utilized internal expertise with systems programmers, coupled with Rocket Software solutions and hands-on training, to empower penetration testers and optimize scanning practices. 

Results

Enhanced scanning efficiency, automated vulnerability checks, and seamless task allocation resulted in improved security processes and operational benefits for the bank. 

Getting our penetration testers up to speed on the mainframe seemed like a tall task at the beginning, but it was well worth the time and effort we put into this integration. And, our company is much more secure to show for it.

Chief Information Security Officer (CISO)

Company

Industry: Financial & Banking

A multinational financial institution recognized for its innovative approach to implementing cutting-edge technology within its operations.

 

Challenge

The bank needed to transition mainframe vulnerability scanning from specialized mainframe teams to the penetration testing team while ensuring security standards remained uncompromised. 

Relying on KRI (now part of Rocket Software) to assess mainframe vulnerabilities, the bank identified an opportunity to streamline its processes by transferring scanning tasks to its internal penetration testing team. However, this shift came with challenges. The team lacked experience with mainframe scanning and needed to be quickly upskilled in vulnerability testing and mitigation to ensure a smooth transition. 

 

Solution

A six-month comprehensive training program, supported by Rocket Software, empowered penetration testers to become proficient in mainframe vulnerability scanning and mitigation. 

To achieve their goal, the bank adopted a two-pronged approach. First, they focused on internal talent utilization. Systems programmers played a key role as mentors, teaching mainframe fundamentals and vulnerability testing. Second, the bank leveraged expertise from Rocket Software. With tools like z/Assure VAP, Rocket Software facilitated proper knowledge transfer, while ongoing access to their experts provided timely resolutions to critical challenges. This dual strategy enabled the penetration testing team to build confidence and acquire the skills needed to perform automated vulnerability checks seamlessly. 

Results

The bank achieved streamlined security processes, enhanced penetration testing capabilities, and increased operational efficiency. 

The penetration testing team exceeded expectations by automating vulnerability scanning, reducing manual efforts, and enabling continuous security monitoring for the mainframe. This improved efficiency allowed operations teams to focus on critical tasks while enhancing collaboration with external vendors. The result? A stronger, more proactive security posture for the bank. 

Get Started with Rocket z/Assure Vulnerability Analysis Program (VAP) 

Rocket Software makes complex transformations simple and effective. Whether you're modernizing vulnerability scanning or enhancing team capabilities, we’re here to empower your business with cutting-edge solutions. 

Featured product

Rocket z/Assure Vulnerability Analysis Program (VAP)

VAP helps businesses identify, assess, and mitigate security vulnerabilities within their systems

Downloads