We Do Not Sell These Services
Worth saying up front, since this is a page about a market we are not in. This site evaluates IBM i security software and vendors. We are not a services provider, we do not take referral arrangements on the assessments described below, and nothing here routes to a sales team. What follows is what the categories actually contain and how we would judge a provider if we were buying.
The Four Things Being Sold
Security AssessmentA point-in-time review of system values, profiles, authorities, and exit points, delivered as findings. Usually fixed-fee and often heavily automated.
RemediationSomebody actually changes the settings, cleans up the authorities, and implements the exit-point controls. Priced by effort, not by report.
Managed Security MonitoringOngoing collection and review of audit journal and exit-point activity, sometimes into a shared SOC, sometimes into your own SIEM.
Audit and Compliance SupportProducing the evidence an external auditor asks for, mapping IBM i controls to a framework, and sitting in the room when the questions start.
The reason to separate them is that they have almost nothing in common commercially. An assessment is a few days of somebody skilled looking at output. Managed monitoring is a multi-year operational relationship. Selling both under the heading of security services is normal in this market and makes comparing two quotes genuinely difficult.
The Assessment Trap
Free or near-free IBM i security assessments are common, and they are usually honest about what they are: a lead generator attached to a software product. That does not make them useless. A scripted assessment will reliably find your default passwords, your *ALLOBJ count, and your open exit points, and those are the findings that matter most anyway.
The trap is treating the report as progress. We have watched shops collect three assessments across five years, each one finding roughly the same things, because nobody was funded to act on any of them. If the assessment is free and the remediation is not budgeted, you have bought a very well-formatted description of a problem you already had.
Our suggestion is unglamorous: agree the remediation budget before you commission the assessment, even roughly. It changes how you read the findings, because you are reading them as a work queue rather than as news.
When Managed Monitoring Earns Its Money
Managed IBM i security monitoring is worth buying under two conditions. The first is that you have nobody who will reliably read an audit report on a schedule, which is more shops than will admit it. The second is that your IBM i is one platform among several and your existing SOC has no idea what a QAUDJRN entry means, which is nearly all SOCs.
It is worth less if you already run a SIEM with IBM i content and someone owns the alerts. At that point you are buying interpretation, not collection, and you should price it that way.
What to Ask Before You Sign
Who Does the Work, and Where
Ask for named IBM i experience, not headcount. This is a small skills pool and subcontracting is common. Find out before the engagement, not during it.
Is Remediation Included or Quoted Later
The single most useful question. Get the answer in writing, with an indicative range, before the assessment starts.
What Happens to Our Audit Data
Where it is stored, for how long, who else can see it, and what you get back if you leave. Audit journal data is sensitive by definition.
Which Product Is This Attached To
Most assessments are tied to a software line. That is fine and worth knowing, because it shapes which findings get emphasised.
What Does Handover Look Like
If your team is meant to run this afterwards, ask what documentation and training is included. Frequently the answer is none.
How Is Success Measured
Number of findings closed beats number of findings raised. Agree the metric at the start or you will be shown the flattering one.
Doing It In-House Instead
A large share of what these engagements deliver is achievable internally, and we would rather say so than pretend otherwise. Confirming your security level, listing profiles with special authorities, finding default passwords, and reviewing exit-point registrations are all things an experienced administrator can do with what IBM already ships. The security tooling covered elsewhere on this site automates the collection and the reporting, which is where the time actually goes.
Where outside help genuinely changes the outcome is in the awkward parts: making the case to management, getting authority changes approved by application owners who do not want them, and having someone with no internal history say out loud that a profile needs to lose *ALLOBJ. Those are political problems dressed as technical ones, and an external report is often the only tool that moves them.
If you are choosing between an assessment and buying software, run the assessment first, but only if the remediation is funded. If it is not funded, spend the money on closing the exit points instead. That is the finding you were going to get anyway.