IBM i / AS/400 security

Know exactly where your IBM i stands — and how to keep it secure.

IBM i runs your core business, yet sits in a blind spot of standard security tooling. We give you an evidence-based picture of your current security posture, a prioritised path to fixing it, and the tooling to stay that way — from the team behind 15+ vendor-confirmed IBM i CVEs.

15+public IBM i CVEs reported
300+ISV vulnerabilities in our feed
<60sremote breach to privileged access, demonstrated

Why Silent Signal

We don't read about IBM i security. We research it — from the Licensed Internal Code up to ISV applications.

We actively reverse-engineer the platform, its configuration and its ecosystem, so we find the vulnerabilities that are genuinely exploitable — and report them. The vulnerabilities we report to IBM become public CVEs. Through our Exclusive Vulnerability Feed, customers can mitigate IBM i and ISV vulnerabilities before a vendor fix is available. Compliance tooling checks your configuration against a standard; we know the attack paths, because we built the exploits. Beyond IBM i, our researchers have found and reported vulnerabilities in products from Cisco, Oracle, Symantec, FireEye and Trend Micro.

15+public IBM i CVEs credited to Silent Signal
300+third-party (ISV) IBM i vulnerabilities tracked in our research feed
12+in-depth technical write-ups & advisories published
REcon
TROOPERS
original IBM i research presented at top security conferences

Why now

Regulators now expect your core platform to be tested — not assumed safe.

DORA and NIS2 put operational resilience and ICT risk for critical systems on the board's agenda. IBM i is exactly the kind of system these frameworks — and long-standing standards — expect you to assess.

DORA · operational resilience NIS2 · ICT risk PCI-DSS SOX ISO 27001/27002 COBIT

Market reality

Security gaps on IBM i come from blind spots, not negligence.

Standard scanners, EDR and pentest playbooks were not built for the platform. The result is a critical system that runs the business but is rarely tested the way Windows, Linux or Unix hosts are.

Dangerous myths

  • "IBM i (formerly AS/400) systems are secure by default."
  • "Unlike other systems, IBM i is not susceptible to zero-day vulnerabilities."
  • "No one can penetrate a server inside the corporate network."

What we observe

  • Security testing of IBM i is quite often skipped, or done superficially.
  • Silent Signal has identified and reported critical IBM i vulnerabilities since 2023.
  • Our research feed identifies 300+ vulnerabilities in 3rd-party applications on IBM i.

What you actually get

Solutions, not a stack of problems.

A test that ends with a PDF leaves you to do the hard part alone. We deliver a clear picture of where you stand, a prioritised way to fix it, and the means to keep it fixed — on your real systems.

01 · CLARITY

Know your real posture

An evidence-based picture of your current IBM i security state — what's exposed, what's actually exploitable, and what it means for the business. No guesswork, no assumptions.

02 · DIRECTION

A prioritised path to fixed

Every finding comes with concrete remediation across system, application and configuration layers, ordered by real-world risk — so your team fixes what matters first, not everything at once.

03 · ASSURANCE

Verify on your live systems

iCompliant re-checks your posture non-intrusively on production — no separate test environment, nothing installed on the IBM i, run as often as you like. Confirm fixes actually landed and stay landed.

04 · ADVANTAGE

Protected before the patch

Through the Exclusive Vulnerability Feed you get mitigation guidance for IBM i and ISV zero-days before vendor patches are available — closing the gap others don't even see yet.

How to engage

Three ways in — one continuum of assurance.

From a fast risk snapshot, to continuous configuration assurance, to deep manual attack validation. Most programs combine them.

01
Assess · entry point

Pilot Assessment

A focused single-LPAR scan covering the ~20 most critical pentest-based checks — the attack paths generic compliance tools don't look for — with setup guidance and a one-hour results review.

€2,000€1,500 credited toward a licence within 30 days
Pilot details →
02
Assure · recurring

iCompliant platform

Configuration and hardening assessment from system values to object authorization — run as often as you need, with zero software installed on the target IBM i. Transparent, published pricing.

From €12,000per year · unlimited scans
Explore iCompliant →
03
Validate · manual

Penetration testing

Assumed-breach IBM i penetration testing that traces low-privileged credentials through to realistic, business-impacting attack paths — built on our own lab, tools and methodology.

Scopedquoted per engagement
Pentest scope →

Assessment & remediation

Penetration testing vs. iCompliant — match the method to the decision.

They answer different questions. Penetration testing proves what an attacker can do; iCompliant keeps the whole system continuously in a defensible state.

DimensionPenetration testingiCompliant
ObjectiveIdentify and exploit vulnerabilitiesAssess and review the security configuration
AutomationManual testing and human-driven analysisAutomated process using specialised tools
ApproachSimulate real-world attacksComprehensive examination of the system
IntrusivenessIntrusive and aggressive testingNon-intrusive
FrequencyPeriodically, or before major updatesRegularly, to maintain security posture
ScopeSpecific targets or applicationsCovers the whole system
Time & resourcesTime-consuming and resource-intensiveQuicker, requires fewer resources
MethodologyMix of black-box and grey-box testingWhite-box audit
ReportVulnerabilities, impact, remediationVulnerabilities, impact, remediation
CostHigher — manual effort and expertiseOften more cost-effective
Penetration testing details → iCompliant details →

How an engagement works

From first call to verified fixes.

STEP 01

Scope

A short scoping call defines targets, LPARs and goals — and which path fits (pilot, assessment or pentest).

STEP 02

Assess

We test from an assumed-breach position and/or run iCompliant — remotely, over a connection you provide.

STEP 03

Prioritise

You receive findings with business impact and concrete remediation, ordered by real-world risk.

STEP 04

Re-verify

Confirm fixes landed — and stay landed — by re-running iCompliant on your live systems, as often as you need.

Proof, independently verified

Don't take our word for it — take IBM's.

These are recent highlights of a much larger public record. Every advisory links to IBM's own CVE notice; every write-up is published in full. Nothing here is marketing — it's all verifiable.

Browse the full research library →

In their words

What clients say.

Published testimonials from Silent Signal's clients, attributed by sector. IBM i runs in exactly these environments — finance, regulated industry — where reports must satisfy auditors and tests must not disrupt production.

The works were done punctually. The tests did not cause any side effects. All our audit requirements have been met. The report is clear, understandable and makes sense to us.
— Financial sector
The Silent Signal team does nothing that others do — however they only do what others in this country cannot.
— IT sector
The success of the project along with the quality and professionalism impressed us. There's no question who we'll ask for such jobs and recommend to others in the future.
— Financial sector

Verbatim from Silent Signal's published client references.

On-demand webinar

Live IBM i hacking: demystifying IBM i system security

Why does IBM i need to be secured — and why wasn't it an issue for the past 35 years? We have proven that breaking into an IBM i system remotely and escalating to a privileged user is possible, and can take less than a minute. We're white-hat hackers: every finding has been reported and vendor-patched with a CVE.

CIOs and CISOs have long struggled to gain visibility into mission-critical data held in proven, heart-of-the-infrastructure systems like IBM i. It's time to shift the paradigm — we show you why and how.

Request webinar access →
  • Get a realistic view of IBM i system security.
  • Build a bridge between IBM i admins and security teams — feeding a prioritised, actionable list into your existing security dashboard.
  • Reduce the attack surface and break exploit chains.
  • Always have a Plan B for backup, with systems back up and running within 20 minutes.

SPEAKERS

Bálint Varga-Perke

Co-founder & IT security expert, Silent Signal

Jack Wilkins

Technical consultant, Chilli IT

What drives us

Evidence, not reputation.

What we believe

That passionate hackers provide unique insight into the security of all layers of IT systems through world-class research — to find the vulnerabilities that matter.

Our mission

To hold IBM i to the same security standard as every other tier-one system: find the genuinely exploitable vulnerabilities before attackers do, and give defenders a clear, prioritised path to fix them.

Our vision

An IBM i ecosystem secured on evidence — assessed and proven, not assumed safe by reputation.

Get started

Ready to see what's on your IBM i?

Start with a Pilot Assessment, request an iCompliant demo, or scope a penetration test. One conversation tells you where you stand.

Request a demo or scoping call