Fresche Solutions latest Fresche Talks on IBM i cloud security explored a common and recurring theme amongst IBM i shops:
The tools and hosting arrangements that IBM i teams assume are covering them often stop short of the platform itself.
You can watch the full 30-minute recording at Fresche Talks: IBM i Cloud Security
However, in this article we look at five of the questions the session answered directly, with the practical implications for IBM i decision-makers and the technical teams who have to act on them.
Do CrowdStrike and Arctic Wolf cover IBM i security?
CrowdStrike runs agents on Windows and Linux, not IBM i, there is no native endpoint, so IBM i coverage must be explicitly configured and verified with external monitoring put in place.
Arctic Wolf doesn’t have native IBM i coverage either, though it can ingest events through SIEM integration if the IBM i is set up to send them.
For a technical lead, this means the mission-critical server is invisible to tools the rest of the security stack depends on.
For a business leader, it means the platform running core operations, the one enterprise-wide monitoring was supposed to cover, is sitting outside it.
If your enterprise security review assumed IBM i was included because “everything” reports to the SOC, that assumption is the gap.
Why does IBM i security matter if we don’t store card or personal data?
A common reason teams deprioritise IBM i security is that card data sits in a separate payment platform and personal data sits in HR systems, so the IBM i itself looks low-risk.
The session addressed this directly: ransomware doesn’t need sensitive data to cause damage, it needs availability.
If the IFS gets encrypted, then this can disrupt applications and halt business processes, disrupting operations.
The cost of monitoring the platform is small next to the cost of it going down.
That’s a business continuity argument, not a data protection one, and it applies even to organisations confident they’re out of scope for PCI or GDPR on IBM i specifically.
How do you Get IBM i security events into a corporate SOC?
IBM i doesn’t forward events to a SOC by default. Getting there means building or buying a way to send SIEM events, typically in Syslog format, from the platform to wherever the SOC team is watching.
The detail that matters here is quality, not just connectivity.
IBM i journals can carry a very large number of data columns, and a SOC team is rarely staffed with IBM i specialists.
Sending raw, unclassified event data creates the same problem security teams have run into elsewhere: real signals buried in noise, discovered too late.
The practical requirement is events that are pre-classified and escalated by severity, in language a generalist SOC analyst can act on without needing to be an IBM i expert first.
This is a large part of what Fresche Security’s SIEM integration is built to do: incorporate IBM i logs into existing enterprise monitoring, with pre-built reports rather than raw journal dumps landing on a SOC analyst’s desk.
Does Hosting IBM i in the Cloud Make It Secure?
Hosting infrastructure and LPAR security are two different things, and cloud providers only cover the first by default.
A SOC-compliant cloud environment secures the physical and network layer.
What happens inside the LPAR, user privileges, library permissions, IFS access, system value configuration, is a separate layer that needs its own setup.
MFA at login is a good example of where the gap shows up. Once a user authenticates for the day, most environments don’t re-authenticate them.
If that user’s device is compromised through a phishing link during that window, the attacker is now operating with an authenticated session, and infrastructure-level cloud security has nothing to say about it.
Compliance regulations bear this out. PCI, SOX, HIPAA and GLBA all include IBM i-specific technical controls, session timeout after inactivity, encryption of sensitive fields, documented access control, that a cloud provider’s infrastructure certification doesn’t automatically satisfy.
This is precisely the layer Fresche Security’s access management (inactivity and timeout session lockdown), MFA and field-level encryption features are built to close.
What are early warning signs of a ransomware attack on IBM i?
Three signals came up repeatedly in the session:
- Strange or altered data appearing in IFS files, particularly if it’s spreading across more files over time rather than isolated to one or two. That progressive pattern is consistent with staged ransomware encryption rather than a one-off error.
- Unexplained CPU usage from an unrecognised job. The session’s advice was to treat this as suspicious by default rather than assuming it’s a vendor process, and to trace it back to the source before deciding it’s benign.
- A spike in invalid sign-on attempts, especially repeated attempts against the same account or one with elevated privileges. Tony described a real case where a client’s invalid sign-on attempts, once traced by IP address, turned out to originate from an attack based in China.
The response recommendation was consistent across all three: assume compromise rather than dismiss the anomaly, investigate the source, and restrict accounts so they can only perform the specific activities they need, which limits what a hijacked or impersonated account can actually do.
The session also flagged that recovery depends on backups that haven’t themselves been compromised.
One case discussed involved backups being affected alongside the live system, which meant reconstructing around six months of data by hand rather than restoring it.
What this means for IBM i teams
Put together, the session’s answers point to the same conclusion from different angles: enterprise security tooling and cloud hosting cover real ground, but neither one reaches into the LPAR by default.
Closing that gap means exit point monitoring, SIEM-ready event classification, MFA, field-level encryption and documented access control configured specifically for IBM i, not assumed as a side effect of everything else.
If you want a clear picture of where your own environment stands, Proximity offers Fresche Security, the same IBM i security suite referenced in this session, including a free audit covering 47 key security points with a pass/fail report you can act on.
Get in touch to arrange an audit or talk to our team about where your IBM i currently sits.
You can catch up on other Fresche Talks here.



