enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

M&T Bank

Beyond the Mainframe: Leadership in Modern Cybersecurity

Byron Smith

Mainframe Security Architect

Leading Security behind the Scenes

In cybersecurity, we often hear about the newest threats, the latest cloud innovations and emerging technologies reshaping the enterprise. Yet behind many of the world's most critical business processes remains a technology platform that quietly powers the global economy: the mainframe.

As I reflect on my ten-year journey at M&T Bank, I am reminded that cybersecurity leadership is not just about defending systems. It is about protecting trust, enabling business outcomes, mentoring future talent and ensuring that critical services remain available when millions of customers depend on them.

Over the past decade, I have had the privilege of working at the intersection of mainframe security, identity and access management (IAM) and enterprise cybersecurity. This experience has given me a unique perspective on both the technical and human elements of securing some of the most important systems in modern banking.

The Invisible Foundation of Modern Banking

Many people associate cybersecurity with cloud platforms, mobile applications or internet-facing systems. What often goes unnoticed is the foundational role mainframes continue to play across financial services.

Mainframes process enormous transaction volumes, support mission-critical applications and maintain the availability and integrity that customers expect when they access their accounts, receive direct deposits, make payments or conduct financial transactions.

The reality is simple: when customers receive their paychecks, access funds or conduct business activities, the process likely involves a mainframe platform.

Throughout my career at M&T Bank, I have witnessed firsthand how the resilience, scalability and security of mainframe systems remain essential to delivering reliable banking services. While technology landscapes evolve, the core business expectation remains unchanged: systems must be secure, available and resilient.

Security Starts With Identity

Cybersecurity begins with identity. Whether supporting employees, contractors, administrators or automated processes, every interaction with an enterprise system starts with answering a fundamental question: Who should have access and what should they be allowed to do?

IAM has become a critical discipline in cybersecurity. The challenge is not simply granting access. It is ensuring that access is appropriate, timely, auditable and aligned with business needs.

“Cybersecurity is a team effort that depends on strong partnerships across security, infrastructure, development, audit and business teams.”

In highly regulated industries like banking, maintaining strong identity governance is essential. Effective IAM programs help organizations enforce least-privilege access principles, reduce insider risk, meet regulatory requirements, support audit readiness and strengthen enterprise resilience.

Over the years, I have worked alongside talented teams focused on balancing security controls with operational efficiency. The most effective security programs are not those that block the business. They are the ones that enable the business to operate securely.

Mainframe Security is Modern Security

One misconception I frequently encounter is that mainframe security is separate from modern cybersecurity. Nothing could be further from the truth.

Today's mainframes are deeply integrated with cloud environments, API ecosystems, enterprise applications and hybrid infrastructures. Security teams must protect these environments using the same foundational principles that apply across the broader cybersecurity landscape: identity-centric security, zero trust principles, continuous monitoring, privileged access management, risk-based decision making and regulatory compliance.

Mainframe professionals are not simply maintaining legacy systems. They are securing highly interconnected enterprise platforms that often process an organization's most sensitive data and highest-value transactions.

As cyber threats continue to evolve, the security capabilities surrounding the mainframe have evolved as well. The platform remains one of the most secure computing environments available, but security is never a destination. It is a continuous journey.

Leadership beyond Technology

While technology has been a significant part of my professional journey, some of the most meaningful experiences have come through community involvement, mentorship and professional advocacy. As an IBM Champion, I have been fortunate to contribute to conversations across the technology community, share knowledge, speak at industry events and help others better understand the strategic importance of the mainframe.

I have also remained active in organizations that support professional development, diversity and STEM advancement. These opportunities have reinforced an important lesson: technical expertise creates opportunities. Leadership multiplies impact.

Some of the most rewarding moments of my career have come from helping students, early-career professionals, and aspiring technologists discover pathways into cybersecurity and enterprise technology. The future of cybersecurity depends not only on securing systems but also on developing people.

Lessons that Continue to Shape My Leadership

At M&T Bank, I have learned that effective cybersecurity leadership extends well beyond technology. The most important lessons have come from understanding how security supports the broader organization, how people work together, and how leaders prepare teams for constant change.

Security is a business enabler. Organizations achieve stronger outcomes when security teams understand business objectives and align protection strategies with operational priorities rather than treating security as a separate function.

Relationships matter. Cybersecurity is a team effort that depends on strong partnerships across security, infrastructure, development, audit and business teams. Collaboration creates better decisions, stronger resilience and more effective risk management.

The pace of technological change has reinforced the importance of continuous learning. Successful professionals remain curious, adaptable and committed to developing new skills because today's solutions may not address tomorrow's challenges.

Investing time in developing others often has a greater longterm impact than any individual technical achievement. Strong teams are built by sharing knowledge, creating opportunities and helping future leaders grow.

The most enduring lesson is that resilience is the true measure of security. The objective is not simply to prevent every attack, but to build systems, processes and teams that can adapt, respond and recover when challenges inevitably arise.

The Future of Cybersecurity

The future of cybersecurity will be shaped by AI, evolving threat actors, cloud adoption, automation and increasingly complex digital ecosystems. Yet many of the fundamental principles that have guided successful security programs for decades will remain unchanged. Strong identity controls, disciplined governance, resilient infrastructure and skilled professionals will continue to be the foundation of enterprise security.

For fellow security leaders, my message is simple: embrace innovation, but never overlook the platforms, people and principles that quietly keep our organizations running every day. Because in cybersecurity, the systems that receive the least attention are often the systems that matter most.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.