Disclaimer: This blog post reflects the author's opinions regarding industry trends and strategic technology directions. It is provided for informational purposes only and does not modify, amend, or supplement any software licenses, product roadmaps, service level agreements (SLAs), or warranties.
For decades, mainframe maintenance has assumed one core constraint: time is available.
Organizations identify vulnerabilities, evaluate fixes, test changes, coordinate across teams, and deploy during controlled maintenance windows. In regulated environments, that cycle can take weeks or even months.
Today, AI is collapsing that timeline. Powerful new AI models are making the slow, traditional patch cycles an operational risk.
The Assumption of Time Is Disappearing
Frontier AI models are the most advanced, cutting-edge AI models available. They possess levels of enhanced computational training, problem-solving, and cross-domain reasoning at the leading edge of our technological capabilities today. This makes frontier AI models both incredibly powerful and fast. These Frontier AI systems are accelerating both software development and vulnerability research. They can analyze large codebases, reason across execution paths, surface subtle flaws, and infer how those flaws could be exploited at scale for all compute platforms.
At the same time, we are seeing the rise of machine-speed offensive collectives. These are not linear human workflows. They are increasingly automated, distributed systems that compress the full attack loop: discovery, validation, weaponization, and deployment.
This creates a structural imbalance. Adversaries are moving toward AI-accelerated threat exploitation, while enterprise remediation remains largely human-paced.
For mainframe customers, maintenance can no longer be treated as periodic operations. It must become a continuous, architecture-level security capability.
Attack Cycles No Longer Wait for Maintenance Windows
Traditionally, security fixes follow a predictable path:
Available → assess → schedule → test → deploy.
That model assumes attackers and defenders operate on similar human timescales. That is no longer true.
Consider the widely reported Hugging Face security event: roughly 1,200 autonomous AI agents transmitted nearly 70,000 messages to converge on a unified attack vector. Orchestrating an offensive campaign of that scale and synchronization using conventional, human-paced methods would be virtually impossible within the same timeframe.
Frontier AI models compress the offensive lifecycle:
- Vulnerability discovery becomes automated or semi-automated
- Exploit generation becomes assisted or fully generated
- Targeting becomes highly scalable
- Execution runs in parallel across systems and agents
Adversarial behavior is shifting from campaigns to continuous systems, and the enterprise response must accelerate accordingly.
The key question is now unavoidable: How do we defend systems when adversaries can discover and operationalize vulnerabilities faster than traditional remediation processes can respond?
This is not a future or theoretical risk. This structural asymmetry is.
Traditional maintenance discipline is still necessary, but it must be redesigned for time compression under active adversarial pressure.
Mainframe Stability Cannot Mean Mainframe Inertia
The mainframe remains foundational to global enterprise computing because of its reliability, security, transactional scale, and operational rigor. Those strengths are important, but availability cannot come at the expense of security. In some circumstances, accepting controlled disruption is safer than preserving continuous operation with known vulnerabilities.
In many environments, customization, complex testing, limited maintenance windows, organizational silos, and procedural overhead significantly slow security updates. That delay is no longer just operational friction. It’s a direct exposure window that adversaries are actively optimizing against.
The objective must shift. Preserve mainframe stability while dramatically increasing the velocity of safe change. These goals are not in conflict. In an AI-accelerated threat landscape, they are mutually reinforcing.
The New Cybersecurity Metric: Time to Remediation
Severity alone is no longer sufficient. A more meaningful metric has emerged: time to remediation under compressed attack timelines.
Consider two organizations facing the same critical vulnerability:
- Organization A remediates in hours.
- Organization B requires six weeks.
In a human-paced threat environment, both are exposed. In an increasingly automated threat landscape, only one remains continuously exposed. The difference is not the vulnerability itself, but the exposure duration relative to the adversarial cycle time.
As automation scales offensive capability, the time a vulnerability remains unpatched becomes a primary driver of breach probability. Maintenance velocity, therefore, is not just an IT concern. It is a core cyber resilience control.
Questions Every Mainframe Leader Should Be Asking
Mainframe leaders must now evaluate the full remediation lifecycle through the lens of adversarial time compression.
Key questions they must consider include:
- Where does the remediation pipeline slow, relative to attack speed?
- Are fixes bundled into infrequent cycles that extend exposure windows?
- Do security updates compete with functional changes for deployment capacity?
- How much testing remains manual, and what parts can be automated?
- Do approval chains add friction without reducing risk in urgent scenarios?
- Can critical security fixes bypass non-essential coordination while preserving compliance?
- Can patches be designed for minimal operational disruption by default?
- Can systems ingest continuous updates rather than relying on episodic maintenance windows?
Most importantly, what is the trade-off between reducing risk and experiencing occasional operational outages? And, has the organization defined its required remediation time in today’s AI-driven threat environment?
For many enterprises, the answer is unclear, and that gap, itself, is now a risk.
How Vendors Can Help Close the Gap
Customers cannot solve this alone.
Software providers have the opportunity to redesign maintenance delivery for adversaries that do not wait for change windows.
The broader vendor ecosystem must move past traditional, slow-cadence patch delivery. Software providers have an opportunity to innovate how maintenance is delivered to enable customers to adapt in real time rather than waiting for quarterly change windows.
This includes:
- Designing fixes for low-friction, rapid deployment.
- Reducing configuration and dependency complexity.
- Minimizing operational disruption by default.
- Increasing automation in testing and validation.
- Providing machine-readable risk and remediation guidance.
- Enabling fixes that avoid full system downtime where possible.
Vendors have an opportunity to apply AI defensively:
- Analyze codebases for latent risk at scale
- Prioritize vulnerabilities by exploitability, not just severity
- Accelerate patch generation and validation
- Expand automated regression testing
- Reduce time from discovery to safe release
This is a defining opportunity of frontier AI: turn automated offense into machine-assisted defense and remediation.
Maintenance Is Becoming a Real-Time Security Capability
Enterprises have long invested in detection: SIEM, endpoint protection, monitoring, threat intelligence, penetration testing, and SOCs.
But detection assumes time to respond.
That assumption is breaking.
In an environment where attacks can progress continuously and at scale, remediation velocity becomes as important as detection capability.
Finding vulnerabilities faster is insufficient if they cannot be fixed faster.
This elevates maintenance from an operational process to a core security control plane function.
For mainframes, the implications are significant:
- Quarterly maintenance becomes continuous delivery
- Manual testing becomes automated validation pipelines
- Large change windows become frequent, smaller deployments
- Security fixes become a distinct high-priority path
- Remediation is measured in hours, not cycles
Organizations that cannot compress this loop will face exposure, not from isolated attackers, but from continuous automated adversarial systems.
The Clock Has Changed
Even with the changes that frontier AI is forcing all enterprise systems to address, the mainframe remains one of the most secure and resilient platforms ever built. Its strengths — security in the DNA of the hardware, centralization, isolation, reliability, and operational discipline — are more critical than ever.
But they must now be paired with a new capability; the ability to respond to AI-accelerated threat cycles.
The next era of mainframe security will not be defined by how difficult vulnerabilities are to find or exploit. It will be defined by whether organizations can close the remediation loop faster than adversaries can open it. The offensive loop is accelerating. The defensive loop must match it.
The maintenance window is no longer a window. It is a continuous security capability, and the clock is ticking.
David Stokes is vice president of product management, strategy, and design at Broadcom Mainframe Software. With more than 28 years of enterprise software experience, he has led large-scale product, organizational, and portfolio transformations. Stokes brings a systems-level perspective to connecting customer needs, technology direction, and business strategy across areas including database management, systems management, workload automation, storage, cybersecurity, application development, and open mainframe technologies. He is focused on advancing the mainframe as a modern enterprise platform while helping shape how emerging technologies, including Generative AI, can be applied to simplify mainframe operations, accelerate developer productivity, and improve knowledge access.