What the ECB’s AI Cybersecurity Letter Means for Mainframe Security

Blog Article·6 min
betasystems_portraits-leon-stamm.jpg
Leon Stamm
VP of Marketing, Beta Systems
Follow me for more content

Key Takeaways

  • The ECB is requiring major financial institutions to address AI-enabled cyber threats, which are significantly reducing the time between vulnerability discovery and attack.

  • For banks relying on IBM Z, RACF security is a crucial part of the cyber threat assessment, and special attention should be given to user access, secure configuration, comprehensive logging, and continuous monitoring.

  • A RACF security audit provides an evidence baseline for identifying weaknesses and prioritizing remediation, while Beta Access can support ongoing analysis, auditing, and reporting.

The ECB is asking major financial institutions to respond to AI-enabled cyber threats with a concrete action plan by 31 October 2026. In essence, it’s asking how well you actually know the security posture of your RACF environment. In this article, we examine a few of the most important points in the ECB letter as they relate to mainframe security.

Website Blog AI Cyber Threads EU

AI-Enabled Cyber Security Threats

In its July 2026 letter on AI-enabled cybersecurity threats, the European Central Bank warns that emerging AI models can identify software vulnerabilities and generate working exploits at unprecedented speed. The result is a compressed window between the discovery of a vulnerability and its potential exploitation. The ECB is describing this as a long-term change in the threat landscape.

What This Letter Means for Your Management

The ECB expects these companies to assess the impact of the evolving threat landscape and develop a comprehensive action plan with concrete measures, resources, responsibilities, and implementation timelines. The deadline for submission to the respective Joint Supervisory Team is 31 October 2026.

For CEOs in particular, it is crucial to update the cybersecurity strategy and be honest about where their weaknesses are and what they are doing to address them.

ECB Recommendations

The ECB's recommendations cover a broad cybersecurity landscape, from vulnerability and patch management to third-party risk, infrastructure modernization, incident response, and overall visibility.

  1. One standout recommendation is to strengthen monitoring of application and access logs, as well as other indicators, particularly for critical internal systems.

  2. It highlights zero-trust principles and continuous verification of users, applications, and service accounts.

  3. In addition, it calls for “strong baseline controls,” specifically secure configuration, robust access controls based on least privilege, and comprehensive logging.

For banks whose critical business processes depend on IBM Z, that should put the RACF environment at the forefront of the threat assessment. RACF determines who and what can access critical mainframe resources, but management should ask whether these access controls are as secure as we think they are.

  • Who has access?

  • Is access to critical resources still justified?

  • Can we detect RACF security threats quickly enough?

A RACF Security Audit with Beta Systems

A RACF security audit can establish the current state of the mainframe access-control environment, identify weaknesses, and provide a fact-based foundation for remediation priorities in line with the ECB initiative.

At Beta Systems, we offer RACF audit services designed to examine a client’s RACF environment and identify security weaknesses for remediation. This report creates a documented baseline from which the organization can prioritize where to take immediate action.

An audit is most valuable when it starts an improvement cycle rather than a one-off exercise, and this is where Beta Access can make a difference.

Pro Tip

Don’t treat your RACF security assessment as a one-off compliance exercise. Use it to establish a measurable baseline, then continuously monitor access and critical security events to demonstrate ongoing improvement.

Continuously Auditing with Beta Access

Beta Access provides a central point of control for RACF environments and combines RACF administration, analysis, auditing, reporting and monitoring capabilities. Organizations can analyze RACF databases, SMF data and z/OS environment settings, while auditors can generate reports without requiring direct access to the z/OS environment or specialist RACF knowledge.

For the requirements highlighted by the ECB, three capabilities are particularly relevant:

1. Turn access-control assumptions into evidence

The ECB emphasizes robust access controls, low-privilege rights, secure configuration, and comprehensive logging as baseline elements of your cybersecurity strategy.

Beta Access provides visibility into RACF information and enables organizations to analyze permissions and RACF configuration rather than relying solely on assumptions about how the environment was originally designed. Changes made through Beta Access are also captured and logged in a dedicated relational database, providing administrators and auditors with an accessible record of RACF data and changes.

For management, that means a straightforward way to gather evidence on control effectiveness and areas for improvement.

2. Benchmark RACF security against STIG recommendations

Beta Access supports security analysis using Security Technical Implementation Guide (STIG) recommendations. Beta Systems' current STIG capabilities can cover approximately 80% of relevant STIG requirements, providing banks with a structured way to assess RACF security controls and identify deviations for further investigation.

For executive stakeholders, a dashboard that provides a consistent view of the data is also considerably more actionable than hundreds of individual RACF settings.

3. Move from periodic review to real-time monitoring

The ECB specifically calls on banks to strengthen monitoring and detection as AI increases the speed at which attacks can develop.

Beta Access Monitor provides real-time alerts for critical RACF and security-relevant events, including unauthorized access to sensitive data or changes to critical user attributes. Events can be escalated to defined recipients or operations monitoring systems.

When attackers can operate faster, security teams need to reduce the time between event, visibility, and response. Mainframe access monitoring should be part of that process.

Conclusion

  • With October just around the corner, banks need to begin preparing a response to the ECB initiative, which asks them to present how they will adapt to a changing threat landscape moving at AI speed. The plan should combine strategic initiatives with concrete metrics that demonstrate measurable progress. For the mainframe, a RACF security assessment is one such metric.

    Beta Systems can help banks start with a focused RACF Audit Service to identify weaknesses in the existing environment and establish a security baseline. From there, Beta Access can support ongoing analysis, STIG-based reporting, centralized RACF management, and real-time monitoring of critical security events to address the control expectations set out in the ECB letter.

    Talk to Beta Systems about a RACF security assessment and find out how Beta Access can turn your mainframe access controls into a measurable part of your ECB cybersecurity action plan.

Ready to Improve Your Cyber Security in the Age of AI?

Contact our team to see how Beta Access can become an integral part of your cybersecurity strategy.

Author

betasystems_portraits-leon-stamm.jpg
Leon Stamm
VP of Marketing, Beta Systems

Further Resources

Blog Article
Website Blog AI Cyber Threads EU

How to Proactively Address AI-Enabled Cyber Threats Before the ECB Demands It

AI-enabled cyber threats are here, and they require immediate, strategic action. This is the stark warning the European Central Bank (ECB) has issued to major financial institutions. This warning cannot be put off; it is now imperative and fundamentally shifts the speed and scale of cyber risks. This article takes a deep dive into why your board needs to fully understand the implications now, not after an incident or a supervisory finding.
Blog Article
rechenzentren_wandel_blogpost.jpg

Data Centers in Transition: How Data, AI and Sustainability Shape the Future

Data centers are at a turning point: The constant increase in data volumes, the growing demand for AI applications and the growing complexity of hybrid IT landscapes are shaping the industry. While hyperscalers like Amazon are investing billions in IT infrastructure expansion, traditional data center operators need to adapt to keep pace with the demands of modern technologies. This article offers a glimpse into the future of data centers and highlights the most exciting trends and challenges.
Blog Article
mainframe_ibm_beta_systems_iam_ag.jpg

Do More at the Core with IBM z17™

As organizations continue to balance innovation, operational efficiency, and security, the need for infrastructure that can support AI at enterprise scale has never been greater. IBM has introduced IBM z17™, designed to help organizations accelerate growth, transform operations, and protect critical data in an increasingly complex digital landscape.