Kisco Systems

IBM i Security Discovery Services

Security Services : Discovery

Let's modernize your security

Most IBM i customers have not implemented the platform's latest security features, leaving their systems exposed. Vulnerabilities within the IBM i legacy configuration are well known to attackers. AI compounds these risks exponentially.

Security modernization starts with discovery

Our "deep dive" into your current security configuration will reveal every legacy security risk, providing a detailed roadmap for the future. This includes everything from system values and user profiles to hidden privilege escalation risks, unsecured data, and connection security.


Contact Kisco




Detect your weaknesses before an attacker has the chance to exploit them



IBM i Penetration Testing

“Our IBM i penetration tests rattle on the front door, garage door, porch windows, etc. and if we can enter the ‘house,’ go looking through the rooms for an ‘open safe’ and view its contents.” ~ Carol Woodbury

Running network penetration tests on IBM i only goes so far because they test for open ports and unsecured services, not access to the actual data itself. In other words, networks scans knock on the door, but we go into the house and look around.

Our IBM i penetration testing protocol attempts to access data using typical end-user profiles that shouldn’t be able to do so.

Pen testing provides peace of mind knowing your security strategy is performing as expected. Or it provides an actionable list of ranked, exploitable issues and guidance on how to resolve them, along with complete documentation and objective proof of vulnerability.

IBM i Security Assessments

Legacy IBM i security risks create vulnerabilities for user profile hacks, privilege escalation, code injection and more. Until now, bad actors needed special IBM i skills to exploit these vulnerabilities.

Today, AI can make anyone an IBM i expert!

It's time to hunt down and fix the hidden risks on your system:

  • System-level security settings
  • User access and permissions
  • Privilege escalation
  • Code injection
  • Data at risk
  • Ransomware exposure
  • Encrypted connections

A roadmap for the future

All Kisco Security Discovery Services are delivered with prioritized remediation actions that provide a detailed roadmap to modernize your security.


IBM i TLS Scanning

Analyze your system’s encrypted connections based on real audit journal data, identifying all unsecured activity, noncompliant TLS versions and out-of-date ciphers.

How secure are your encrypted session? How do you know?

Many IBM i customers assume they're secure because they're running modern 7.5/7.6 releases. In reality, IBM i will accept any inbound TLS or SSL connection that negotiates a default cipher - including outdated TLS 1.2 CBC suites, SHA-1 signatures and RSA key exchange.

Our TLS Scanning service uses your audit journal to provide:

  • Complete overview of secured and unsecured sessions
  • Analysis of all TLS and cipher suites for every connection
  • Risk classification and score for every connection
  • Detailed information about job and processes that rely on unsecured or outdated connections
  • A TLS remediation roadmap

IBM i Network Connection Audit

We provide a complete audit report of how users and external systems are accessing your mission-critical data over IBM i network interfaces like SQL, FTP, IFS, TELNET and others.

Do you know how your mission-critical data is being accessed?

Using our SafeNet exit point security running on a free trial license, our discovery team will log all data-access activity through all IBM i network interfaces.

You will get a complete network activity audit report, including:

  • All network interfaces (exit points) accessed
  • All data objects accessed (DB2 and IFS)
  • All SQL commands executed
  • User and program access
  • Source IP addresses
  • SQL special registers

Optional object-level reporting can tie your network audit back to underlying security for all objects accessed, to give you a complete risk-profile for production data exposed through network interfaces.