Banking & Finance Institute Secures Mainframe Communications
A large financial institution transitions from FTP to SFTP (Secure File Transfer Protocol) to protect their mainframe architecture.
Customer
-
One of the biggest banks and financial service providers in Australia
-
10,000+ employees
- 15+ LPARs
Challenge: Secure sensitive financial data and transition from FTP to SFTP
Security
Security is a non-negotiable issue for the bank. The IBM mainframe hosts multiple z/OS systems, and it needs to keep its data-in-transit encrypted and secure during credit card usage, management of investment capital, and ATM functions.
Large data transfers
The new server solution must be capable of automatic daily transmission of huge amounts of files - the bank cannot afford any system downtime. A customer unable to check their account balance or withdraw money from an ATM will, potentially, change banks.
Transition from FTP to SFTP
The goal is to transition to more secure mainframe communications, from File Transfer Protocol (FTP) to SFTP (Secure File Transfer Protocol), ensuring that sensitive financial information within the mainframe architecture is protected.
Solution: Automated FTP-SFTP conversion and mainframe security with Tectia
The bank decided to choose Tectia® SSH Server for IBM z/OS solution for several reasons:
FIPS compliance
Compliance with FIPS-certified cryptography regulations and PKI support with X.509 certificates enable Tectia z/OS to encrypt any transparent data-in-transit automatically, including user ID and password.
It also meets internal and external compliance requirements including PCI DSS, SOX, HIPAA, FIPS, FISMA, and many others.
Zero-downtime deployment
There was no downtime during installation, providing a reliable and simple solution to encrypt FTP to the required SFTP.
The whole deployment took only a few weeks, and Tectia Server worked seamlessly right away without the need for a system shutdown or start-up.
Accelerated operations
When IBM Crypto Express Card (CEX) is installed, the Tectia z/OS can direct or off-load cipher functions to the co-processors in CEX via ICSF, helping to reduce CPU usage and accelerate cryptographic operations within the hardware environment. Thus increasing energy efficiency.
“We have looked at different solutions on the market, but we found Tectia z/OS remains the simplest and most direct answer to our problems.”
Benefits
Secure and compliant data transfers
Save time and secure your file transfers with automated FTP-SFTP conversion support. Protect sensitive mainframe data in transit with fully encrypted SCP command-line tools, ensuring compliance with PCI-DSS, SOX, HIPAA, FIPS, FISMA, and more.
Reliable file transfers
Handle multi-terabyte file transfers and complex workloads without interruption, ensuring core business processes run smoothly.
Fast installation and deployment
By providing a configurable interface and an ISPF application, Tectia makes it easy to install, configure, and manage SSH environments efficiently. The easy-to-use application reduces setup time and ensures teams can start protecting data quickly.
