Living in South Florida, I've spent a lot of my career talking to customers about disaster recovery through the lens of hurricanes. Those conversations are easy because everyone understands the threat. We can watch a storm develop for days. Weather stations track every shift in direction. Data centers activate contingency plans. Business continuity teams prepare for impact. I've talked with customers whose facilities suffered so much damage during a hurricane that storage equipment was literally left hanging from cables after windows failed under hurricane-force winds.
The threat is obvious because you can see it.
What concerns me more these days are the threats that don't show up on radar maps. The ransomware attack quietly spreading through an environment for months before detection. The compromised credential moving laterally through a network. The sensitive data copied somewhere it shouldn't be. The AI project spun up outside governance processes because a team wants answers faster than the business can approve them. The modernization initiative intended to simplify operations that accidentally introduces new risk.
Unlike a hurricane, these threats don't make the evening news. In fact, most organizations hope they never become public at all. Yet for many enterprises, they're becoming more consequential as the natural disasters we've had decades to prepare for.
Rethinking Risk in the Mainframe
Organizations are now shifting how they think about their most important systems, especially the mainframe.
If you have a history with mainframe environments, you know they’ve often felt isolated from the rest of the world. The mainframe sat deep within the data center, accessed by a relatively small number of highly skilled administrators through green-screen terminals. Connectivity was limited. Access was controlled. The environment was less exposed than in the interconnected world we live in today.
Today's mainframe data is everywhere. It's powering mobile banking applications, healthcare systems, retail transactions, fraud detection, government services, customer portals, real-time analytics, and increasingly, artificial intelligence. The systems that once lived quietly in the basement are now feeding decisions across the entire enterprise.
One of the most interesting shifts I've seen over the past few years is that organizations no longer want to move their most valuable data somewhere else so AI can use it. They want AI brought to where their trusted data already resides. Industry studies back that up.
IBM reports that 79% of IT executives consider the mainframe essential to AI-driven innovation, while modernization surveys from groups like Kyndryl show most organizations are already implementing or actively planning AI initiatives tied directly to mainframe environments. That makes sense when you think about where the highest-quality data lives. That’s why mainframe modernization is no longer just about making old systems feel newer, but making sure the systems that hold the most trusted enterprise data can support the next wave of AI, analytics, digital services, and cyber recovery without weakening the controls that made them trusted in the first place.
Mainframe infrastructure is ready for what's coming next, if it can
- Support new AI workloads without compromising governance
- Withstand increasingly sophisticated cyber threats
- Recover quickly and confidently when something goes wrong
- Continue scaling while remaining operationally manageable
- Be trusted
Across Industries, Trust is Key to Compatibility
Hitachi has supported mainframe environments for more than 45 years and follows a two-pillar approach: compatibility with essential IBM mainframe storage capabilities, and innovation that adds new value around performance, availability, recoverability, and management.
That compatibility matters because modernization cannot come at the expense of the operational discipline mainframe teams depend on. Support for IBM mainframe capabilities such as FICON, IFCES, GDPS, HyperSwap, FlashCopy, zHPF, Metro Mirror, and other core functions gives customers a way to evolve the infrastructure around the mainframe without turning modernization into a leap of faith.
Recently, we worked with a banking institution evaluating its next-generation storage platform. The bank entered the process as the expected winner. Instead of relying on vendor presentations and benchmark reports, the bank did something simple: it tested the platforms using its own workloads. Under real-world conditions, assumptions disappeared quickly. What ultimately mattered wasn't who had the better marketing message. It was who could demonstrate results, respond when issues surfaced, and prove their claims under pressure. The lesson was simple: proof beats promises.
I've seen that same pattern play out in government environments. One agency conducted an extremely rigorous procurement process where every capability required documentation and every technical claim required evidence. Another spent more than a year struggling with a migration that promised improvement but delivered higher resource consumption and disappointing response times. When the underlying issues were finally identified and the environment moved to a different platform, performance improved and confidence returned. That is why I've become increasingly convinced that organizations need to stop thinking about availability, security, cyber resilience, modernization, AI readiness, disaster recovery, and operational efficiency as separate initiatives. They're all connected.
Trust in data means very little if applications aren't available. Availability doesn't help much if compromised data goes undetected. Security is incomplete if recovery takes days or weeks. AI creates risk when it operates on bad or ungoverned data. And resilience requires much more than a storage array—it requires confidence in the entire path that data travels.
This is where architecture starts to matter.
Cyber Resilience is a Practice, Not a Solution
When customers ask me about cyber resilience, they're often looking for a single technology that will solve the problem. In reality, cyber resilience is built across multiple layers. Data moves from IBM Z systems across FICON and Fibre Channel fabrics, into storage platforms, replication environments, cyber recovery vaults, and business continuity processes. Every one of those layers matters because attackers are not just trying to encrypt production data anymore. They’re also looking for backups, credentials, recovery paths, and weak points in the broader operating model.
That’s one reason I like the way Hitachi frames mainframe cyber resiliency: create consistent, immutable production images in a protected fortress that is separated from the mainframe environment.
This “fortress” concept gives organizations multiple protected images to choose from, supports recovery to different storage if the primary environment is unavailable, and adds administrative separation from the mainframe team. That separation may sound like a small architectural detail, but during a cyber event it can be the difference between having recovery options and discovering that every path depends on the same compromised environment. That means:
- Images cannot be accessed, modified, or deleted during the retention period.
- Logical corruption cannot be replicated
- Images can be mounted for validation, forensic analysis, surgical restore, or full restore
- Teams can inspect the data, determine where corruption started, and choose the cleanest recovery point before bringing data back into production.
Moving Data Securely
Hitachi Vantara introduced 100% data accessibility with its first generation of RAID in 1995, brought thin provisioning to mainframe storage, and has continued to advance replication, availability, and management capabilities for IBM Z environments. Those details matter because confidence in modernization comes from tested engineering, not slogans.
High speed reliable and secure networking are also important. For organizations replicating data between data centers, the goal is simple: move protected data securely and reliably over distance. Fibre Channel and FCIP extension help reduce the effects of distance, latency, and packet loss so recovery points can be maintained more consistently at a secondary site.
Brocade Fibre Channel fabrics help protect the path that data travels. The SAN is no longer just plumbing. It is part of the security, availability, and business continuity story. Secure boot, firmware integrity, encrypted transport, visibility, and operational intelligence all help keep data moving safely from production to recovery.
That becomes especially important in ransomware scenarios. Immutable snapshots can help preserve clean recovery points, but those recovery points still depend on secure, reliable data movement across the broader infrastructure. Storage, SAN, replication, and recovery processes all have to work together if organizations want continuity, compliance, and operational confidence when something goes wrong.
Ready to Defend Against the Coming Storm?
Ultimately, I don't think modernization is about replacing the mainframe. It's about building the trust and resilience necessary to continue using it as the strategic asset it has always been. And it's about recognizing that the systems running our businesses are more connected—and therefore more exposed—than at any point in their history.
The strongest modernization strategies I see preserve what the mainframe does best while improving everything around it: compatibility, data movement, recovery validation, cyber isolation, observability, operational automation, and integration with modern data and AI initiatives. That is a very different conversation from “move off the mainframe.”
Because unlike hurricanes, the most significant threats many organizations face today are often invisible. And in my experience, the hardest risks to manage are usually the ones you don't see coming.
Learn how Hitachi Vantara can help bolster the infrastructure around your most trusted data and prepare for what comes next. Meet us at SHARE Pittsburgh at Booth #304 from August 17 – 20, 2026.
Laura Tuller
Laura Tuller specializes in mainframe and high-end storage architectures, cyber resiliency, hybrid cloud modernization, and data platform strategy. She helps customers align technology investments with business outcomes.