Security has been a primary concern amongst IBM i enterprises for a number of years according to Fortra’s IBM i Marketplace Surveys (except for the notable exception of this year where the skills gap surpassed it).
AI is a subject that’s created a great deal of buzz in the IBM i community over the past 12-months.
We’ve covered the expansion of AI in our community regularly, including the news that IBM themselves have released applications such IBM i Bob to assist developers for instance.
However, news from IBM last month presents another angle on AI with one in four malicious breaches were AI-enabled according to data released by IBM in 12-months preceding July 2026.
That’s a 56% increase from the year before.
IBM estimates that those breaches cost businesses an average of $6 million each. To make matters worse, those costs are about $1 million more than the global average.
How does the growth in AI-enabled breaches impact enterprises operating IBM i?
Moving from assumed security to managed, measurable protection in the age of AI
IBM i has a long standing reputation as one of the most secure and resilient enterprises platforms available.
For many organisations, it continues to run the applications that matter most:
- ERP systems
- Warehouse management software
- Finance and billing systems
- Manufacturing software
- Transport management and distribution applications
- Pricing and stock management
- And, a whole host of other business-critical operational workflows.
However, that cyber security reputation can also create a dangerous assumption.
IBM i can be an extremely secure platform. But, like any system, it still needs the right locks, keys and monitoring in place to safeguard that level of security.
Its inherent security credentials, however, does not remove the need for good security governance.
As with any application, security governance is more effective when the right controls are properly configured, actively managed and regularly reviewed.
In other words IBM i is secureable, but it is not automatically secure.
That distinction matters now more than ever because of AI. In the past, IBM i may have benefited from a degree of obscurity. Considered by some as a legacy platform, many attackers lacked the knowledge of IBM i architecture itself.
They didn’t understand the commands, exit points, the Integrated File System, how user profiles are set-up, object authority or the special authorities needed to target it effectively.
AI weakens that obscurity advantage.
Attackers can now use AI tools to understand unfamiliar platforms faster, interpret configuration weaknesses, automate research and accelerate the process of looking for poor controls.
IBM’s 2026 X Force Threat Intelligence Index reported that attackers are exploiting basic security gaps at higher rates, accelerated by AI tools that help identify weaknesses faster. IBM also reported a 44% increase in attacks that began with exploitation of public facing applications, and a 49% year on year increase in active ransomware and extortion groups.
This does not mean IBM i has become an insecure platform.
What it does mean is that businesses running IBM i applications can no longer rely on reputation, obscurity or historical confidence.
IBM i security now needs to be visible, tested, monitored and evidenced.
The IBM i Threat Landscape Has Changed
AI has meant that the wider threat landscape has changed. IBM i estates now sit inside a much faster and noisier security environment.
Firstly, the rise in attacks exploiting public facing applications. IBM’s X-Force Threat Intelligence Index reported a 44 percent increase in attacks exploiting public facing applications.
That matters because modern IBM i estates are often connected to web portals, APIs, cloud platforms, reporting tools and integration layers.

Ransomware too is on the rise with IBM reporting a 49 percent increase in active ransomware and extortion groups. Ransomware is no longer something organisations can think of only as a desktop or Windows problem.
IBM i can still be exposed through file shares, the IFS, compromised credentials, excessive authority and connected systems.
And then there’s software vulnerabilities.
Verizon’s Data Breach Investigation Report stated that 31 percent of breaches now start with software vulnerabilities. That reinforces the need to understand where systems are exposed, how access is controlled and whether security settings are being actively reviewed.
Finally, Verizon reported that 48 percent of breaches now involve ransomware. That’s why monitoring, alerting, access control and data protection are vitally important for your IBM i security strategy.
The IBM i security misconception
IBM i is often described as secure by design. That is fair, but not entirely complete.
A better description is that IBM i is highly secureable.
It has strong native security capabilities, but those capabilities need to be configured, maintained and continually reviewed.
A business may have IBM i applications that power much of their operation, with exceptional reliability and years of uninterrupted uptime, but still carry avoidable security risks.
Common issues include:
- Over privileged user profiles
- Excessive use of special authorities
- Shared or generic accounts
- Weak control over FTP, ODBC, Telnet and other exit points
- Limited visibility of Integrated File System activity
- Sensitive data held in clear text
- Audit journals that are collected but not actively reviewed
- Security reporting that is manual, infrequent or dependent on one specialist
- Limited integration between IBM i activity and enterprise SIEM tools
- Lack of real time alerting when suspicious activity occurs.
The result?
A gap between the security IBM i can provide and the security the organisation can prove it has in place.
That gap is becoming more dangerous because AI reduces the effort needed to understand enterprise systems. What once required niche knowledge can now be researched, summarised and partially automated much more quickly.
The AI factor: why obscurity is no longer enough
For many years, IBM i has worked in its favour. It is not as widely understood as mainstream Windows, Linux or cloud platforms. You only need to look at the ageing IBM i developer talent pool and see why so many IT leaders view the skills gap as their number one concern.
Attackers looking for easy opportunities focused elsewhere, but that’s no longer the case. AI changes the risk equation:
1. Platform knowledge is easier to access
An attacker no longer needs to be an experienced IBM i administrator to begin learning the basics of the platform. AI tools can explain IBM i concepts, commands, object authorities, user profiles, exit points, the IFS and common configuration issues to the wannabe cyber criminal. This does not give an attacker instant expertise, but it significantly lowers the barrier to entry.
2. Reconnaissance can be accelerated
AI can help attackers organise research, generate checklists, interpret technical information and suggest areas of vulnerability to investigate. For IBM i, that could include exposed services, weak password policies, mapped file shares, overly powerful user profiles, unsecured exit points or poor monitoring.
Again, AI does not create weakness, but it does make weaknesses easier to find and understand.
3. Attacks can become faster and more repeatable
The wider threat landscape is already moving in this direction. As mentioned earlier Verizon’s Data Breach Investigations Report states that 31% of breaches now start with software vulnerabilities and 48% involve ransomware. It also notes that generative AI is helping attackers work faster across techniques such as spotting security gaps and writing malware.
For IBM i environments, the lesson is clear: security through obscurity is no longer a credible strategy.
Organisations should assume that platform knowledge is increasingly available, and that weak configuration can be discovered faster than before. The correct response is not panic. It is discipline.
IBM i security should be assessed, hardened, monitored and reported in a way that reflects the modern threat landscape.
Why native controls alone may not be enough
IBM i includes strong native security features, including user profiles, object level authority, special authorities, system values, auditing and journaling. These are valuable and should remain part of any IBM i security strategy.
However, native capability is not the same as operational security.
The challenge is not simply whether IBM i has security controls. It is whether those controls are correctly configured, consistently applied, monitored in real time and understood by the people responsible for risk.
For example, an organisation may technically have audit journals enabled, but if nobody reviews the activity, the business may still miss suspicious behaviour.
A user may have high authority levels for historical reasons, but if that authority is never reviewed, it becomes a standing risk. A file share may have been created for a valid reason years ago, but if it remains open today, it can increase exposure.
AI increases the importance of this issue because attackers are becoming faster at identifying weak points. The more quickly an attacker can understand a system, the more important it becomes for defenders to remove unnecessary exposure before it is exploited.
In many IBM i estates, the challenge is not a lack of security commands, it is the need to make security visible, consistent, repeatable and reportable.
Understanding the modern IBM i risk landscape
There are several reasons why IBM i security needs more active management in the face of AI threats.
1. IBM i systems are more connected
Many IBM i applications now exchange data with web portals, BI tools, cloud systems, integration platforms, warehouse systems, third party software, managed service providers and desktop tools. Connections such as FTP, Telnet, ODBC, API and web services are critical to business success, but they also create routes into the system.
2. Ransomware has changed the conversation
Ransomware is no longer just a Windows problem. IBM i may not be attacked in exactly the same way as a desktop estate, but it can still be exposed through file shares, the IFS, compromised credentials, excessive authority and connected systems.
3. AI is reducing the attacker’s learning curve
IBM i used to require specialist knowledge to understand it, however, AI makes the first stage of learning much easier.
An attacker can use AI to understand IBM i terminology, identify likely weak points, generate questions, structure a reconnaissance plan and interpret results. That means poor configuration, excessive authority and exposed access routes are less likely to remain hidden simply because the platform is unfamiliar.
4. Auditors expect evidence
For many organisations, especially those operating under GDPR, PCI, SOX, HIPAA or internal governance standards, it is not enough to say that IBM i is secure. Auditors need evidence.
They need to know who has access, what users can do, what has changed, what sensitive data exists, how access is controlled and whether exceptions are being reviewed.
5. IBM i skills are becoming more concentrated
Many IBM i environments rely on a small number of experienced people who understand the platform, the applications and the security model. That knowledge is valuable, but it can also create operational risk.
Security tools helps reduce dependency on individual knowledge by providing dashboards, reports, alerts and repeatable processes that can be understood by IBM i specialists, security teams, auditors and business stakeholders.
This is especially important in the AI era. If attackers can use automation to move faster, defenders also need better tooling, better visibility and better operational discipline.
The business case for IBM i security products
The case for IBM i security products should not be framed only as technology improvement. It is a business risk decision. Dedicated security tooling helps organisations:
- Reduce the risk of unauthorised access
- Limit the impact of compromised accounts
- Improve control over powerful users
- Protect sensitive data
- Monitor network and exit point activity
- Detect suspicious behaviour more quickly
- Produce clearer audit evidence
- Support compliance obligations
- Improve resilience against ransomware and data theft
- Reduce reliance on security through obscurity
- Improve readiness for AI accelerated threats
- Give both IT and business leaders confidence in the security posture of critical systems
An effective IBM i security approach should cover more than one area. It should provide layered protection across users, data, access points, activity, audit and response.
The best IBM i security software tools should help organisations answer these questions:
- Who has access to the IBM i system?
- Which users have powerful authorities?
- Are those authorities still justified?
- Which connections are coming into the system?
- Are FTP, ODBC, Telnet and other exit points controlled?
- Is the IFS exposed through unnecessary shares or excessive authority?
- What sensitive data exists and how is it protected?
- Can suspicious activity be detected quickly?
- Can IBM i security events be passed to the wider security team?
- Can audit and compliance reports be produced easily?
- Can the business prove that controls are operating effectively?
- Can the organisation respond quickly if AI assisted attackers find a weakness?
These questions are difficult to answer consistently with manual checks alone. They require dedicated visibility, automation and governance.
The Fresche Security Suite is designed specifically for IBM i environments, with a suite of tools for IBM i security, which addresses IBM i security as a joined up operational challenge rather than a set of separate technical tasks. It includes:
- Compliance and auditing
- Intrusion detection
- Ransomware protection
- Exit point security
- Data encryption
- SIEM integration
- Multi factor authentication.

Centralised management
Fresche Central provides a single web based console for:
- Monitoring security in complex environments
- Configuring privilege escalation and network security
- Dashboard views
- Access to 360 plus built-in compliance reports.
The module provides visibility for security and IBM i development teams as well as auditors with clear reporting and tools that do not slow down daily operations.
Security management and access controls
Fresche Secure safeguards business critical assets on IBM i by addressing one of the biggest IBM i risks: users or service accounts having more authority than they need, for longer than they need it:
- User profile management
- Access escalation management
- Inactive session lockdown
- Network and exit point security
- Object and IFS and privileged access management.
Auditing and compliance
Fresche Audit supports internal and external audit requirements by simplifying data collection, reporting and regulatory compliance evidence. This is particularly valuable where IBM i underpins regulated business processes, financial systems, supply chain operations or customer data.
Threat detection and alerting
Fresche Detect provides real-time alerts for suspicious system activity, with SIEM integration, email notifications, history log monitoring and command monitoring. This closes the gap between event collection and response and provides instant response.
Data protection
Fresche Encrypt provides field level encryption, masking and scrambling, as well as sensitive field identification assistance and field level change reporting. For many organisations, this is an important step toward protecting the data itself, rather than relying only on perimeter or user access controls.
Multi factor authentication
Fresche MFA adds another layer of authentication for users signing into IBM i, including QR codes, OTP app generated codes and email or text token authentication. This is increasingly important as attackers target credentials and as IBM i systems become more connected to wider business workflows.
Securing your IBM i applications
IBM i remains a strong, resilient and highly capable platform. But no platform should be protected by reputation alone.
The security question for IBM i estates is not simply: “Is IBM i secure?”
A better question is: “Can we prove that our IBM i environment is properly controlled, monitored and protected today?”
That question has become more urgent in the age of AI.
AI does not make IBM i weak. But it does make weak IBM i security easier to understand, easier to probe and easier to exploit.
Platform obscurity is no longer enough. Organisations should assume that attackers can access IBM i knowledge more easily and that poor controls may be discovered faster than they expect.
For many organisations, the answer requires more than native capability and periodic manual review. It requires active monitoring, controlled access, real time alerting, sensitive data protection, audit ready reporting and integration with wider security operations.
The Fresche Security Suite delivers a practical way to strengthen IBM i security across these areas. By combining centralised management, access control, auditing, detection, encryption and MFA, it helps organisations move from assumed security to managed, measurable protection.
For businesses that rely on IBM i to run core operations, that shift is no longer optional. It is part of responsible IT governance.
Learn more about IBM i Security from Fresche and request your demo today to mitigate risk.
Interested in learning more about IBM i security?
Read these articles…



