Let's modernize your security
Most IBM i customers have not implemented the platform's latest security features, leaving their systems exposed. Vulnerabilities within the IBM i legacy configuration are well known to attackers. AI compounds these risks exponentially.
Security modernization starts with discovery
Our "deep dive" into your current security configuration will reveal every legacy security risk, providing a detailed roadmap for the future. This includes everything from system values and user profiles to hidden privilege escalation risks, unsecured data, and connection security.
“Our IBM i penetration tests rattle on the front door, garage door, porch windows, etc. and if we can enter the ‘house,’ go looking through the rooms for an ‘open safe’ and view its contents.” ~ Carol Woodbury
Running network penetration tests on IBM i only goes so far because they test for open ports and unsecured services, not access to the actual data itself. In other words, networks scans knock on the door, but we go into the house and look around.
Our IBM i penetration testing protocol attempts to access data using typical end-user profiles that shouldn’t be able to do so.
Pen testing provides peace of mind knowing your security strategy is performing as expected. Or it provides an actionable list of ranked, exploitable issues and guidance on how to resolve them, along with complete documentation and objective proof of vulnerability.
Legacy IBM i security risks create vulnerabilities for user profile hacks, privilege escalation, code injection and more. Until now, bad actors needed special IBM i skills to exploit these vulnerabilities.
Today, AI can make anyone an IBM i expert!
It's time to hunt down and fix the hidden risks on your system:
A roadmap for the future
All Kisco Security Discovery Services are delivered with prioritized remediation actions that provide a detailed roadmap to modernize your security.
Analyze your system’s encrypted connections based on real audit journal data, identifying all unsecured activity, noncompliant TLS versions and out-of-date ciphers.

How secure are your encrypted session? How do you know?
Many IBM i customers assume they're secure because they're running modern 7.5/7.6 releases. In reality, IBM i will accept any inbound TLS or SSL connection that negotiates a default cipher - including outdated TLS 1.2 CBC suites, SHA-1 signatures and RSA key exchange.
Our TLS Scanning service uses your audit journal to provide:
We provide a complete audit report of how users and external systems are accessing your mission-critical data over IBM i network interfaces like SQL, FTP, IFS, TELNET and others.
Do you know how your mission-critical data is being accessed?
Using our SafeNet exit point security running on a free trial license, our discovery team will log all data-access activity through all IBM i network interfaces.
You will get a complete network activity audit report, including:
Optional object-level reporting can tie your network audit back to underlying security for all objects accessed, to give you a complete risk-profile for production data exposed through network interfaces.