Market

IBM i and AS/400 Security Services

IBM i security services fall into four buckets that get sold as if they were one: assessment, remediation, managed monitoring, and audit support. Knowing which one you are buying is most of the work, because the failure mode in this market is paying for a report when what you needed was somebody to do the fixing.

Last verified

We Do Not Sell These Services

Worth saying up front, since this is a page about a market we are not in. This site evaluates IBM i security software and vendors. We are not a services provider, we do not take referral arrangements on the assessments described below, and nothing here routes to a sales team. What follows is what the categories actually contain and how we would judge a provider if we were buying.

The Four Things Being Sold

Security AssessmentA point-in-time review of system values, profiles, authorities, and exit points, delivered as findings. Usually fixed-fee and often heavily automated.
RemediationSomebody actually changes the settings, cleans up the authorities, and implements the exit-point controls. Priced by effort, not by report.
Managed Security MonitoringOngoing collection and review of audit journal and exit-point activity, sometimes into a shared SOC, sometimes into your own SIEM.
Audit and Compliance SupportProducing the evidence an external auditor asks for, mapping IBM i controls to a framework, and sitting in the room when the questions start.

The reason to separate them is that they have almost nothing in common commercially. An assessment is a few days of somebody skilled looking at output. Managed monitoring is a multi-year operational relationship. Selling both under the heading of security services is normal in this market and makes comparing two quotes genuinely difficult.

The Assessment Trap

Free or near-free IBM i security assessments are common, and they are usually honest about what they are: a lead generator attached to a software product. That does not make them useless. A scripted assessment will reliably find your default passwords, your *ALLOBJ count, and your open exit points, and those are the findings that matter most anyway.

The trap is treating the report as progress. We have watched shops collect three assessments across five years, each one finding roughly the same things, because nobody was funded to act on any of them. If the assessment is free and the remediation is not budgeted, you have bought a very well-formatted description of a problem you already had.

Our suggestion is unglamorous: agree the remediation budget before you commission the assessment, even roughly. It changes how you read the findings, because you are reading them as a work queue rather than as news.

When Managed Monitoring Earns Its Money

Managed IBM i security monitoring is worth buying under two conditions. The first is that you have nobody who will reliably read an audit report on a schedule, which is more shops than will admit it. The second is that your IBM i is one platform among several and your existing SOC has no idea what a QAUDJRN entry means, which is nearly all SOCs.

It is worth less if you already run a SIEM with IBM i content and someone owns the alerts. At that point you are buying interpretation, not collection, and you should price it that way.

What to Ask Before You Sign

Who Does the Work, and Where

Ask for named IBM i experience, not headcount. This is a small skills pool and subcontracting is common. Find out before the engagement, not during it.

Is Remediation Included or Quoted Later

The single most useful question. Get the answer in writing, with an indicative range, before the assessment starts.

What Happens to Our Audit Data

Where it is stored, for how long, who else can see it, and what you get back if you leave. Audit journal data is sensitive by definition.

Which Product Is This Attached To

Most assessments are tied to a software line. That is fine and worth knowing, because it shapes which findings get emphasised.

What Does Handover Look Like

If your team is meant to run this afterwards, ask what documentation and training is included. Frequently the answer is none.

How Is Success Measured

Number of findings closed beats number of findings raised. Agree the metric at the start or you will be shown the flattering one.

Doing It In-House Instead

A large share of what these engagements deliver is achievable internally, and we would rather say so than pretend otherwise. Confirming your security level, listing profiles with special authorities, finding default passwords, and reviewing exit-point registrations are all things an experienced administrator can do with what IBM already ships. The security tooling covered elsewhere on this site automates the collection and the reporting, which is where the time actually goes.

Where outside help genuinely changes the outcome is in the awkward parts: making the case to management, getting authority changes approved by application owners who do not want them, and having someone with no internal history say out loud that a profile needs to lose *ALLOBJ. Those are political problems dressed as technical ones, and an external report is often the only tool that moves them.

If you are choosing between an assessment and buying software, run the assessment first, but only if the remediation is funded. If it is not funded, spend the money on closing the exit points instead. That is the finding you were going to get anyway.

Vendors Covering This Control

Fortra (Powertech)

Fortra's Powertech line (formerly HelpSystems, formerly PowerTech Group) is the longest-running dedicated IBM i security vendor and still the largest install base by most industry surveys, including its own annual State of IBM i Security Study. Powertech Multi-Factor Authentication, Authority Broker, Exit Point Manager, and Compliance Monitor are each strong standalone products.

Strengths

  • Largest install base among dedicated IBM i security vendors, with the deepest bench of IBM i-specific security expertise
  • Powertech Authority Broker is a mature, well-regarded privileged access / elevated-authority management product
  • Exit Point Manager provides granular network access control across FTP, ODBC, DDM, and remote command exit points
  • Publishes the annual State of IBM i Security Study, a widely cited independent-feeling data source (though vendor-funded)

Limitations

  • Product line grew through acquisition (PowerTech, Bytware, Robot, Vityl) and integration between modules is less unified than Precisely's single suite
  • Some legacy product UIs (Robot Console-adjacent tooling) show their age relative to newer competitors
  • Full stack pricing across MFA, Authority Broker, Exit Point Manager, and Compliance Monitor adds up for smaller shops

Best fit: Shops that specifically need best-in-class privileged access management (Authority Broker) or exit-point network control, and are comfortable managing several point products rather than one suite.

Precisely (Assure Security)

Precisely's Assure Security suite is the broadest single-vendor IBM i security platform on the market, spanning multi-factor authentication, encryption, compliance monitoring, and access control in one licensing family. It is the platform we point mid-size and enterprise IBM i shops to first when they need one vendor covering the most ground.

Strengths

  • Widest single-suite coverage: MFA, encryption, exit point control, and compliance monitoring under one console
  • Strong native IBM i journal-based monitoring with real-time SIEM forwarding (Splunk, QRadar, Sentinel)
  • Assure Encryption supports field-level and full-database encryption without application changes in most cases
  • Established install base and long IBM i-specific engineering history (originated from Townsend Security and Syncsort lineage)

Limitations

  • Suite pricing and licensing complexity increases as modules are added; full-suite cost is not the cheapest entry point
  • MFA client coverage for legacy green-screen sessions requires exit-point configuration that takes real implementation time
  • Reporting UI is functional but less modern than some newer point-solution dashboards

Best fit: Mid-size to enterprise IBM i shops that want one vendor for MFA, encryption, and compliance monitoring rather than stitching together point products.

Raz-Lee Security (iSecurity)

Raz-Lee's iSecurity suite covers firewall/exit-point control, antivirus, auditing, encryption, and MFA in a modular product line that is popular with mid-market IBM i shops, particularly in Europe. iSecurity Firewall and iSecurity Audit are the most commonly deployed modules.

Strengths

  • iSecurity Firewall gives real-time, rule-based exit-point control with strong logging detail
  • Native IBM i antivirus scanning (iSecurity Anti-Virus) is a differentiator versus vendors that rely on IFS-only scanning
  • Modular licensing lets smaller shops buy only the modules they need rather than a full suite
  • Strong presence and support infrastructure in European IBM i markets

Limitations

  • US market share and analyst mindshare trail Fortra and Precisely
  • Documentation and UI conventions can feel dated compared to Precisely's newer interfaces
  • MFA module is a newer addition to the suite with a shorter track record than Fortra's or Precisely's MFA products

Best fit: Mid-market shops, especially in Europe, that want modular exit-point firewall and native antivirus scanning without committing to a full enterprise suite.

Trinity Guard

Trinity Guard (TGSecure, TGAudit, TGDetect) is a smaller, IBM i-focused vendor built by veterans of the original PowerTech engineering team. Its products are priced aggressively and aimed at shops that want core compliance and threat-detection coverage without enterprise-suite overhead.

Strengths

  • Built by engineers with deep PowerTech/Powertech-era IBM i security experience
  • TGDetect provides real-time threat detection with behavior-based alerting on journal activity
  • Generally lower total cost of ownership than the two larger suite vendors
  • Responsive, IBM i-specialist support with a smaller, more accessible team

Limitations

  • Smaller company footprint means less bench depth for very large, multi-LPAR enterprise rollouts
  • Narrower third-party SIEM and integration ecosystem than Fortra or Precisely
  • Smaller analyst and public case-study presence makes independent verification of claims harder

Best fit: Cost-conscious mid-market shops that want solid compliance monitoring and threat detection without full enterprise-suite pricing.