Written by Jack Opgenorth on February 5, 2026
Security is at the forefront of every Business in the Information Age. Most everyone has received that awful notification that our personal information has been ‘compromised’. The ITRC statistics are frightening (ITRC Report). IBM and other IT providers continue to provide improvements in the solutions for protecting our digital assets. The cost of a security Breach now exceeds $10M in the US. While those costs are significant, implementation of security, like every other change, should be evaluated as part of the deployment. Incorrectly implementing new technologies can result in excessive and avoidable costs.
In this brief, I’ll provide some ways to ‘identify’ z/OS traffic that is at risk, I’ll reference IBM’s technology for implementing and managing ciphers, and I’ll introduce a few key performance metrics and resources that can ensure you are implementing tighter z/OS traffic security in a cost competitive way.
In a previous blog, I’ve covered the commonly used metric for IBM software licensing, and how you can track and report on your results using those measurements to help the business side of the house understand what’s behind the z/OS costs. There are numerous ways to reduce your mainframe costs that we have covered in the past. I’ll link to those resources throughout this blog.
Keep a Watchful Eye
Your primary TCPIP stack address spaces should be proactively measured for CPU consumption. I’ve seen similar patterns (Figure 1) using IBM Z IntelliMagic Vision in customer sites and have helped customers set up proactive dashboards along with implementing daily reviews of TCPIP address space consumption using change detection reporting, along with TCPIP traffic patterns, and zERT protocol activity as a way to keep your eyes out for changes.
Let’s be honest, which protocols and ciphers the security team is implementing has not been on every performance, capacity and system administration professional’s check box other than getting it done to Security’s satisfaction. Getting security to accept my latest password is hard enough on most days. Is it 15 characters? Do I use my password encryption for this site? That type of mindset needs to change when it’s for z/OS systemwide changes and the IntelliMagic team would welcome opportunities to help customers assess, review, and implement reporting that will enable a more proactive approach to implementing the best and latest security protocols, ciphers, etc. This includes evaluating test traffic before moving to production.
Looking at Figure 1 below is exactly why this is true. Unfortunately, the significant TCPIP CPU change (greater than 50% or 30 MSUs) in one customer’s environment is not a unique event. I’ve observed this type of scenario for customers running z14s and z15s.