Mainframe systems remain central to the function of many of the financial world’s mission-critical systems. Each day, mainframes power 90 percent of all credit card transactions across the globe. These systems, some decades old, continue to function as pillars of the financial services industry’s most critical systems.
As guardians of sensitive information, financial institutions are prime targets for hackers. They are subject to many global and regional regulations, all the while building on systems put in place decades ago. As global regulations and new technologies rapidly evolve, the financial services sector is being increasingly pushed to consider its IT modernisation strategies. In fact, research reveals that modernisation has moved to the top of the C-suite agenda. Planned investment is projected to reach 25-30 percent of IT budgets over the next two years.
A well-crafted IT modernisation strategy must balance security, compliance, innovation and legacy system realities. Failing to get this balance right can lead to crippling fines for non-compliance with regional regulations like DORA and NIS2, weakened cybersecurity resilience, and lasting reputational damage.
The core of financial transactions: the mainframe
Mainframes store a wealth of valuable data while setting the benchmark for uptime in high-stakes environments. They are a popular choice for financial institutions because they can handle transaction-heavy workloads at scale with precision and reliability. The data they store can also be a valuable resource for business intelligence and AI initiatives. By continuing to invest in mainframe technology, these organisations are therefore optimising their operational resilience and competitive decision-making processes.
As the topic of IT infrastructure modernisation increasingly dominates boardroom conversations, assessing the role of the mainframe within broader infrastructure strategies has become unavoidable. For example, despite AI readiness being a top priority for organisations, only 25 percent of IT leaders currently feel confident that their infrastructure can support AI workloads. Businesses face key decisions regarding their IT modernisation strategies. These include choosing between modernising off the mainframe, modernising in place, or adopting a hybrid cloud model.
Moving off the mainframe
Some organisations have chosen to move away from the mainframe entirely, opting for a full-scale re-platform. While this can be a reasonable choice for a small percentage of cases, it is considered the riskiest and most expensive way to modernise. This is because of the significant disruptions to daily operations. Institutions that move away from the mainframe without a sound strategy raise the risk levels of the modernisation process. This can be catastrophic in the financial services sector.
The costs of misconfiguration in complex rewrite projects can be more than just directly financial. They also risk data leaks, loss of business due to temporary outages, and even regulatory fines if compliance is compromised. In fact, according to Forrester, rewrite projects can take up to six attempts before achieving results, with 90 percent failing the first time. These difficulties can stem from a lack of talent or skills, complex technology environments, and heightened security concerns.
Modernising in place for resilience
Discarding the mainframe entirely also overlooks its intrinsic value: decades of embedded business logic, compliance, resilience, and performance honed over time. Rather than eliminate this data, the more sustainable course is to evolve it – making it observable, testable, and adaptable. The goal is to retain what works and modernise what holds progress back.
Due to the sheer scale of the existing IT infrastructure and the associated risk factors of a re-platform, many financial organisations choose to modernise in place. This is an especially popular choice for institutions whose core processes are embedded in mainframe systems. By choosing this approach, they have a foundation in place whereby they can smoothly adopt next-generation technologies.
This evolutionary approach allows organisations to combine the stability of the mainframe with modern innovation, while progressing at their own pace. In an industry that is constantly developing, mainframes hold and protect complex transactional rules and handle high-volume inputs and outputs. This kind of steady reliability is key for financial institutions dealing with massive volumes of sensitive information. And their customers who rely on continuous access to their assets. Institutions can therefore utilise this approach to respond to changing regulatory and customer demands. And without compromising the stability and integrity of the systems that enable those daily core transactions.
The hybrid cloud approach
As financial institutions navigate the complexities of modernisation, cloud platforms present an appealing solution. This is due to the cloud’s ability to dynamically scale resources to meet fluctuating demand and effectively avoid the costs associated with maintaining peak capacity year-round. The size of the global market for cloud migration services is currently valued at $11.84 billion. It is expected to reach $42.92 in 2033, demonstrating strong market demand.
The hybrid cloud can be particularly suitable for institutions that are choosing to keep their mainframe systems. And those also looking to innovate beyond the required levels prescribed by regulatory compliance standards. Moving to the hybrid cloud enables them to take advantage of advanced analytics and AI, while still benefiting from the security of the mainframe. For many institutions, the historical data and easily securable environment the mainframe provides are far too important to completely dispose of, while the cloud accelerates data processing considerably. Faster data processing means workflows can be optimised across the whole organisation. This enables institutions to manage market volatility with greater agility.
However, a challenge that emerges when migrating processes to the cloud is the management of data across the different environments. Institutions should not underestimate the importance of data discovery as a means to understand the environment, manage risks proactively, improve compliance and enhance data security.
Security and compliance
Regardless of the approach, modernisation is not without its challenges. Security and compliance remain top priorities, particularly when it comes to protecting sensitive financial data and personal information. With just 24 percent of IT leaders feeling extremely confident in their organisations’ ability to address security vulnerabilities over the next year, it comes as no surprise that this ranks as the biggest concern moving forward. For the financial services sector, however, compliance and security are non-negotiable. A systems breach can rapidly downgrade a financial institution’s reputation, cause long-term harm to customers and lead to crippling fines.
It therefore makes sense that the financial services sector is reluctant to part ways with mainframes which are widely recognised as the gold standard for highly securable environments, thanks to their centralised processing and storage architecture. This centralisation minimises attack surfaces, incorporates built-in encryption, and features granular access controls which aids organisations in boosting their cyber resilience and meet the requirements prescribed in industry regulations including NIS2 and the EU’s DORA act.
Ultimately, financial institutions find themselves at a critical crossroads. Mainframe modernisation isn’t merely a technical update; it represents a crucial balancing act of optimising what’s working and determining where to evolve in other directions, such as the cloud. The future lies in adopting a strategic and measured approach that incorporates various modernisation methods over time. Viewing modernisation as a continuous process aligned to the needs of the organisation empowers institutions to achieve greater efficiency and speed, without compromising the stability that has long been their hallmark.
Learn more at rocketsoftware.com
- Cybersecurity in FinTech
- Digital Payments

































































































































































































