Thursday, May 25, 2017

WannaCry: What IBM i Pros Need To Know

WannaCry: What IBM i Pros Need To Know

May 17, 2017

Last week’s epic WannaCry ransomware attack left hundreds of thousands of people around the world scrambling to recover their data, either by paying the cyber crooks or executing their disaster recovery plan. If you’re an IBM i professional, the question you should be asking yourself is: What if that were me?
Companies in the United States escaped relatively unscathed from the ransomware attack, which exploited a known security vulnerability in the Windows operating system and was based on code that was “weaponized” by the National Security Agency and subsequently stolen by hackers.
There are two main reasons for this. For starters, Americans and American companies tend to have better security than their overseas brethren, experts say. Secondly, the prevalence of old, unsupported or bootlegged copies of Windows is lower in the States than elsewhere (you can thank the Business Software Alliance for that).
While the spread of the WannaCry virus itself is winding down – thanks in part to the quick action of a security researcher who stumbled upon a kill switch written into the virus’s source code – experts are already warning that the next ransomware attack could be even bigger. And considering that the May 12 attack is considered the biggest cyberattack ever, it’s apparent that we’re entering a new era when it comes to cybercrime.

Ransomware Threat To IBM i

As an IBM i professional, you may think that you’re above dealing with the problems of Windows users. But if you think that, you would be wrong. While IBM i itself is not directly susceptible to Windows viruses, its Windows-like Integrated File System (IFS) can store and distribute Windows malware to connected PCs.
And if an IBM i user has his PC’s hard drive mapped into the IFS, then any random piece of malware that lands on the PC can squirrel its way into the IFS and do some damage, including encrypting the data stored in the native IBM i file system, says Robin Tatam, director of security services for HelpSystems.

“There are a couple of angles through which a virus, including ransomware, can potentially impact Power Servers,” he tells IT Jungle. “The virus can spread to the IFS where it can be hosted, expanding the infection outward to connected devices. If malware is activated on a Windows desktop or server with a connection to the IFS, then there is a chance that files in the IFS can be encrypted.
“Ransomware often deletes the original file after encryption,” he continues. “IBM i’s native file system (\QSYS.lib) does not support encrypted files, so that step will fail, but it’s entirely possible that the subsequent delete will succeed. Of course, the deletion event is likely replicated to a backup server eliminating the ability to declare a disaster and perform a role swap.”

WannaCry’s IBM i Impact

It’s not known if WannaCry impacted IBM i shops or encrypted data held on Power Systems-based disks. None of the IBM i security software vendors contacted by IT Jungle for this story knew of any IBM i shops being impacted, or would not disclose it. However, ransomware attacks have been documented on the IBM i server, and the threat is seen by IBM i security experts as increasing.
HelpSystems has seen an uptick in awareness about ransomware since Friday’s WannaCry attack. “Though they weren’t impacted, they saw this as a wake-up call and are now interested in taking action to protect themselves from future threats,” Tatam says. “Unfortunately it can take attacks like these to get people to take action.”
The company recently shared the real-world stories of two IBM i shops that were hit by ransomware. The story starts, as most invariably do, with a user clicking on a malicious link in an email. Unfortunately, the user who clicked on the link had ALLOBJ authority and a mapped drive to a shared folder on the IFS.
The successful phishing attack concluded when the virus encrypted half a million files stored on the IBM i shop’s IFS system during a weekend. The situation grew worse when TPC services went down, nobody could sign on, and batch jobs ended. The company elected not to pay the ransom, and instead executed its disaster recovery plan. Eventually all its data was recovered, but it took nearly a month to do so.
The second victim HelpSystems assisted elected to pay the cyber criminals their blood money instead of rolling back to a previous recovery point. The cost: $200,000 in untraceable Bitcoin, according to the vendor.

Ounces Of Prevention

While having the IFS contents of an IBM i server encrypted by ransomware is a definite possibility, it’s more common to see Windows servers impacted at IBM i shops, says Jim Kandrac, president of UCG Technologies. “iSeries is generally not affected. It’s usually SQL Server or other systems,” he says.
One UCG customer was hit with ransomware on its various secondary Windows servers that fed data into its core IBM i server. “It literally brought a $100 million company down to its knees,” Kandrac says.
Cyber criminals demanded $300 in Bitcoin to decrypt victims’ files as part of the massive WannaCry attack on May 12.
UCG rolled out a ransomware training offering in 2015 through a partnership with KnowBe4, a Tampa, Florida, company that works with the notorious hacker Kevin Mitnick to train employees not to click on email links.
The offering, which involves real-world testing to expose click-happy individuals, is included with UCG’s cloud-based backup services. Interest in the offering started out relatively low, but has been gaining in recent months. “Either people get it, they don’t get it, or something happens,” Kandrac says.

Prepping For Ransomware

Patrick Townsend, the CEO and founder of IBM i encryption specialist Townsend Security Solutions, offered IT Jungle several tips for IBM i shops to deal with the ransomware epidemic.
“First, it is crucial to be sure that you are automatically applying updates to Windows (and Mac!) on your users’ PCs,” Townsend says. “It is one of the highest priority tasks according to many cyber security recommendations. Users access their IBM i applications from their PCs and the PC is the weak link. So fixing this first is critical.”
And don’t overlook the importance of end user education. “Users need to be reminded that they are the first line of defense when it comes to ransomware,” Townsend says. “IBM i customers should have a user education program in place and be sure that all employees are getting and absorbing that education.”
It’s also important to have routine backups of user PCs, he adds. “IBM i customers are good at having routine backups of their IBM i servers, but user PCs often contain important business information,” he says.
Don’t forget to tighten up your IFS security. “Many IBM i customers have mounted IFS drives enabled by default,” Townsend says. “Ransomware sees a mounted IBM i IFS directory as just another target. You can easily lose important information on the IBM i through poor IFS security.”
Last but not least, consider getting a Bitcoin account, which can enable you to pay the ransom in a pinch. “I know that law enforcement recommends not paying ransoms, and I think that is generally good advice,” Townsend says. “But if you are subject to a devastating ransomware attack I think you should have all options available to you.”
In the WannaCry case, cyber thieves were charging $300 in Bitcoin to decrypt hard drives. For an organization like Britain’s National Health Services, which was hit with the ransomware as a result of its use of old Windows XP machines, paying $300 may be preferable to enacting a time-consuming DR plan.

Shore Up IBM i Security

HelpSystems’ Tatam adds a few more pieces of technical advice for properly configuring the security controls in IBM i.
“First, I always recommend that an exit program be assigned to the *FILESVR exit point to restrict user (or viral!) access to IFS and the associated file systems,” he says. “This is part of an overall control that should be applied to all network services, including FTP and ODBC.”
IBM i shops should also leverage the QPWFSERVER authorization list to limit who can access the native \QSYS.lib directory structure through the file server. “This activity is rarely required for business purposes and can prevent impact on traditional files,” he says. “Note that this control is not effective against users that have *ALLOBJ special authority.”
Tatam also advises that profiles don’t include unnecessary access to the file systems or data. “People often think that attacks come in anonymously, but that’s rarely true,” he says. “At some point, credentials are being compromised or leveraged so ensuring that security best practices are followed for user connections, password policy, and object permissions is critical.”
Too many IBM i shops run with their systems basically wide open, which can make it easier for ransomware to spread. Following best security practices for IBM i would drastically shrink the attack surfaces that cyber criminals exploit with ransomware schemes, which was a $1-billion business last year and looks poised to grow dramatically this year.

https://www.itjungle.com/2017/05/17/wannacry-ibm-pros-need-know/

Tuesday, April 4, 2017

Why run SAP HANA on Power

Why run SAP HANA on Power



http://www-03.ibm.com/systems/ae/power/solutions/bigdata-analytics/sap-hana/

Tuesday, January 24, 2017

UK.gov still drowning in legacy tech because no one's boarding Blighty's £700m data centre Ark

https://www.theregister.co.uk/2017/01/23/untying_the_government/

UK.gov still drowning in legacy tech because no one's boarding Blighty's £700m data centre Ark

Little love for Crown Hosting from Whitehall depts


Analysis Only in IT is “legacy” a pejorative term, where it is used to condemn ageing systems and forgotten workarounds.
In the UK government, as with banks, increasingly difficult-to-maintain mission-critical systems are a huge problem. Not least because of the dwindling number of folk who remember how the damn things work.
One solution to Whitehall’s myriad string and sticky-tape systems was the creation of the Crown Hosting programme in 2015. That was intended to house departments’ legacy systems in facilities run by a joint venture of which the government owned 25 per cent and small data centre biz Ark the remainder.
By “lifting and shifting” all the legacy systems and housing them in one data centre, it was hoped replaceable systems could be identified, contained and run at a much lower cost – with the eventual plan to ditch them entirely.
But since it was announced, that programme has gone eerily quiet.
The Register whipped out the Freedom of Information Act to ask for a list of public sector bodies that have signed up to the arrangement. However, we were told the Cabinet Office could not disclose the customer list for this commercial arrangement because “authorities could be targeted by individuals or groups willing to use malicious or other hostile ways to gain unauthorised access to information (sensitive or otherwise) stored at colocation sites.”
One can’t help wonder why the UK government bothered to announce the deal at all: it was supposedly meant to contain all of government’s data centre estate via Ark's two data centres in Farnborough and Corsham in a deal worth up to £700m.
But there could be another reason why the Cabinet Office veiled the project under a cloak of invisibility (beyond that being its usual modus operandi). According to numerous sources, uptake has so far been extremely low.
One source revealed that the Department for Work and Pensions had intended to shift 250 of its systems to the data centre, but is now migrating just five. That was part of the department’s mega £340m hosting services refresh to tackle its ageing infrastructure. In this instance, the department had hired hundreds of contractors to help it virtualise the current platforms onto the new kit.

Ignore that burning, everything’s fine

At the end of October, several contractors got in touch with The Register to report there had been hundreds of layoffs and hundreds of millions in overspend at the DWP. But that has been vigorously denied by the department. Commenting on the refresh programme, a spokeswoman said of the eight-year SSBA refresh programme: “It is ahead of schedule and has already delivered three large-scale, secured and resilient platforms.”
Reg readers are welcome to ponder the plausibly of a government project of that size being ahead of schedule. Nevertheless, it’s possible some of the systems have been refreshed.
One source told us: “My guess is that it will be the Customer Information System (CIS) that is moving as IBM were already commissioning a replacement [CIS] at Corsham & Farnborough, currently hosted on ancient Sun E25k frames, which have caused serious outages [of] Critical National Infrastructure due to hardware failures.
“Therefore it would it make a lot of sense to put these together in the same data centres. Moving CNI systems to Ark should be a lot more secure."
One contact said part of the problem with Ark for government use was the fact that some of the departments’ legacy kit won’t fit in its racks, while in other cases the hardware is partly or fully owned by a system integrator – making it difficult to shunt their kit somewhere else.
Another said the problem is that the government knows little about its old systems – citing the Home Office’s 1995 Casework Information Database (CID) as an example – and has been patched many times in haste and changed only when legislation requires.

Systems from the 1990s

“It uses old versions of everything at every layer of its architecture," we're told.
"There probably isn’t anyone who really knows how it works. Worse, CID isn’t just ‘CID’ – it’s a system that interacts and exchanges data with dozens of other systems, some inside the immigration department, some in the rest of the Home Office and some across government. So when you move ‘CID’ you are moving a living thing.
“Many of these systems don’t even have true disaster recovery – the ideal option would be to move the disaster recovery (DR) to the Crown Hosting site and fail over to it, so avoiding lots of hassle. But in the 1990s and 2000s government tended not to build real DR (in the sense of active / active or even active / near active).”
As a sidenote, the CID system was to be replaced by an Immigration Case Work (ICW) system in December 2008 by IBM that was intended to support applications for visas and immigration. However, the department was forced to write off £347m in 2013. The National Audit Office noted in 2014 that the CID system is plagued by problems such as freezing, a lack of interface with other systems, and a lack of controls.
According to one of our sources, the Home Office is still working on its Ark transition, building a couple of environments there for production services, but have yet to move anything. “I’ve done a lot of hosting moves in my time and, unless the folks doing it have also done a lot, they will massively underestimate how hard it is, especially if the hosting and the apps people are separate companies,” a contact told us.
For him, a failure to migrate the legacy kit comes down to "the cost being too big, with a relatively long-term payback, while managing an awful lot of risk, particularly the risk that it just won’t work because you don’t understand how the system works.”
No doubt many poor souls tasked with working out legacy replacements would love nothing more than to pull the plug, throw it in a skip and install something else. But unfortunately when it comes to mission-critical legacy gear, that particular Gordian Knot can’t be cut. ®

Wednesday, January 11, 2017

How Mainframes Prevent Data Breaches


As 2017 begins, let's talk about how using mainframes to process and protect data can keep hackers from having another banner year.

2016 was a strange year marked by everything from election surprises to a seemingly endless spate of celebrity deaths. But when historians look back at this mirum anno—weird year—it may end up being known as the year of the data breach.
Of course, this sort of thing isn’t restricted to 2016, but its impact on the world was hard to ignore. Among government organizations, the IRS and FBI suffered data breaches, and corporate victims included LinkedIn, Target, Verizon and Yahoo. Literally millions of people had their private information exposed to black hats, thieves and other ne’er-do-wells of the digital world. This epidemic of data theft calls upon security experts to get serious about creating new solutions.
You don’t need to hack my computer (in fact, please don’t do that!) to discover I’m going to advocate for one piece of established technology in particular: mainframes. The term “Big Iron” conveys strength and security for a reason. Housing all of one’s data in a single, powerful machine lowers the overall vulnerability of that data. Protecting a single mainframe is much easier than defending data spread out to all corners of a company firewall, and it carries the added advantage of the mainframe’s processing power helping to prevent fraud and other malfeasance.
“But isn’t that putting all your eggs in one basket?” I hear you saying to your computer screen. If it were, the basket is incredibly powerful and easy to secure: it’s more a vault than basket. And it’s still a better idea than spreading data where it can’t all be strictly monitored in real time, allowing hackers to sneak in through various weak points. Don’t forget that all of those ETL scripts are exacerbating the issue by making lots of copies of sensitive data and sending it out to more places and opportunities to be hacked.

Experiencing DB2 Performance Problems or DB2 Memory Utilization Challenges?

The Buffer Pool Tool for DB2
This is why I strongly recommend keeping your data and analytics together—to reduce the potential breach points. Housing data across multiple systems is a governance nightmare because widespread data gets breached in small clusters all the time, making it hard to track the origin of the hacks.
Blockchain on mainframes
Mainframes also make it easier to implement security measures such as Blockchain to prevent hackers from tampering with the files they access. Created to protect the security of Bitcoin and dark web transactions, Blockchain essentially keeps data from being altered without authorization.
Today, Blockchain is stepping out of the shadows, having been adopted by IBM and financial institutions such as JPMorgan Chase to ensure the ironclad integrity of their data. Experts predict Blockchain will soon help protect patient information in the healthcare system, and from there perhaps facilitate a period of more secure data.
I say “a period” because no safe is uncrackable, no firewall unbreachable, and no system foolproof. Eventually the bad guys will find a way around every new protection. That’s why security experts all say it’s not about 100 percent safety but about making every system as arduous to crack as you can.
Yes, hackers will try to exploit weaknesses in Blockchain or breach the security of a mighty mainframe, but these systems working in tandem can create enough of a roadblock to discourage their efforts, or slow those efforts long enough for security to kick in. No data is ever completely safe, but any data is a whole lot safer in the care of Big Iron.
This Blog by Bryan Smith is re-posted with the author's permission. It was originally posted here.

The Unknown IBM i – Part 2

The Unknown IBM i – Part 2

“COOL” IBM i Technology We Take For Granted That Saves You $85,000 Per Year
Some of you may recall I posted “The Unknown IBM I” blog on August 15, 2016.
It began:
“Many of you may be old enough to remember the Gong Show and the “Unknown Comic” who wore a paper bag over his head. You could not see his face, so you did not know who he really was. That was part of the gag.
 “I have a similar tale. Too bad the punchline of this real story is so true.”
Well, here is Part 2.
This last week I was talking to several technology writers. They all have strong Microsoft backgrounds. Besides writing about technology they all had brought technology projects to life.
As I described some of the high-level difference between IBM i and Windows, I was surprised with their amazement that IBM i had an integrated SQL relational database. To them, this concept was stunning.
I further explained that the IBM i single-level storage and data management architecture.
For example, I explained how the IBM i would manage object within the system. Frequently-needed object stayed in memory for fast access. Commonly-used data and program objects are stored on the physical disk units outside edge for faster access. Infrequently-used objects are stored deeper inside the physical disk drive – closer to the center – because it takes the disk access arms longer to retrieve --- which is infrequent.
In this way, the IBM i manages itself for optimal performance. No extra staff is required for load-balancing or system tuning.
Their response?
“COOL!”
I continued. This is more than just “cool” technology. It has REAL economic advantages that too many technical or business people do not recognize.
It saves business money!
How much?
Depending on skill-level and location, a systems engineer earns between $65,000 - $130,000 per year. Most commonly about $85,000 per year. In most cases, this is an IT staff member an IBM i user does not need.
In other words, most small-to-medium sized IBM i users do not have to pay an extra $85,000 per year to keep their server optimally running.
At that point they offered something I had NOT heard before from folks with a strong Windows background.
“If we had that technology in our past projects, we could have deployed our project faster and with far fewer hurdles than we encountered,” they volunteered.
So, these IBM i features would have made project deployment way easier…not just less expensive.
“Yes!” they said.
They explained they could have benefited from the OS-integrated SQL relational data base without setup delays that could range from several weeks to several months.
They would have also benefited from proper SQL setup and system self-management.
So, I asked, you would have been able to bring your technology projects to life faster and with fewer holdups?
“Yes! We sure wish we had something like that.”
Just as these technologists were unaware…and amazed…with the IBM i capabilities, my sense is that most IBM i users and management are also unaware of the extraordinary IBM i features.
We need to educate and remind our teams about what makes the IBM i so exceptional.
So, when someone suggests “we need to get off the IBM i and go to Windows because the hardware is so much cheaper”, we can remind them that they could be paying lots more in staffing, delays, and extra support to minimize disruption, prevent viruses and malware, improve load-balancing.
Cheaper hardware without IBM i architecture may cost LOADS MORE – in staffing, delays and on-going support.

Tuesday, November 15, 2016

Where Is The ROI To Leave IBM i In Favor Of Another Platform?

Where Is The ROI To Leave IBM i In Favor Of Another Platform?

Last week I was talking with an IBM iSeries IT Manager. Specifically, we were talking about his IBM 9406-520, the end of IBM hardware support January 31, 2019, and what his plans were when there would be no more IBM support.
Possible Move To New Platform When IBM Support Ends
“Bob, my management expects to move to a Windows solution by the time IBM hardware support is gone,” he said.
I asked what Windows business applications his company was considering.
“We haven’t even started looking yet,” he responded.
Windows-Based ERP Conversion In 2 Years? Not Likely
Sheepishly I asked him how his company could successfully convert from his 9406-520 to a new Windows-based ERP in about 2 years.
He thought it would be very unlikely. He volunteered that over the years he witnessed many companies move from the IBM i/OS400 platform to other systems. He shared several cases where the transition took 5-7 years and huge sums spent before their systems were working. He told me of others that failed and these companies sold out to competitors.
IBM i To Windows Move 5x-6x More Expensive: Software, Hardware, Infrastructure, Staffing
“Bob, what most people don’t understand is that when they move from the IBM i server to Windows, they spend 5-6 times more on software, hardware, infrastructure and staffing than with IBM i. Worse, they are vulnerable to viruses, hacking and ransomware. I am now a 1-man IT shop that supports everything. Moving to Windows will be like Mario Andretti who needs a pit crew to compete. This company will need at least 3-5 more people to manage the new Windows environment. The new environment will be far more fragile than the IBM system we have now,” he explained.
I then asked what this would mean to him when his company moves to Windows.
IBM IT Manager Chooses Retirement Over Windows Project
“I will most likely retire. By that time I will be 70. My company will no longer have an interest in our IBM i system. And, I don’t want to be part of the Windows project which I expect will take way longer than they think, cost far more than they will be told, and not work like they hope. I have seen and heard this story all too often,” he concluded.
I agreed with him. I explained that over the last 20 years, those companies we worked with that moved off the IBM server took between 7-11 years to fully move to something else.
Fortune 1000 ERP Consultant Agrees
I wrapped up the phone call. Afterwards, I called a friend who consults major Fortune 1000 companies to help with software selection and implementations.
I shared with him this recent case of this user’s company planning to move off the 9406-520 to a Windows solution.
Where Is The ROI?
I told him that I must be missing something, but I could not understand the ROI in the decision to make this change.
Straightforward, he said, “Bob, there is no ROI for these kinds of changes.”
What? I was stunned by his blunt response.
Experienced ERP Consultant Explains
I asked, "As an ERP consultant, you have worked with big, successful and global companies. In your experience as a consultant, you say there is no ROI for these kinds of changes. How come?"
“That’s right, Bob. The people who make these decisions don’t understand the differences between Windows server and IBM server characteristics. IBM servers are designed to handle lots of transactions and big databases quickly and efficiently with a small staff. Windows servers can’t keep up with the IBM server capabilities. So, you have to add more Windows servers, which leads to server sprawl. That leads to more complexity and more staff.
“These decisions to move away from IBM i are generally political instead of based on technology or business. There is NO ROI.
Missing Ingredient – IT Education For Management
My friend continued, “What is often missing is the IT team does not educate the management team about their systems. When I was an IT manager, we would have an annual presentation to our management to educate them about the basics – what is a record, what is a file, what is a database, what is a transaction, and how things work. We would also explain how the IBM i managed the system to avoid the staffing issues and the problems common with Windows servers. My management team understood what they had and continued to invest in their IBM i system with confidence – and with an ROI.”
My friend continued, “I think the missing ingredient is IT education. If business managers had a clear idea of technology, their business goals and how to measure ROI, you would not see these types of sweeping changes to move to new systems. I also believe you would have far fewer delayed conversions and out right failures.”
Have questions or want to learn more? Contact me Bob Losey at blosey@source-data.com

Friday, November 11, 2016

time software vendor HelpSystems thinks the future still looks promising for the


Eye on the i World: HelpSystems Sees IBM i Vendor Consolidation as Healthy for the Market PDF Print E-mail
Analysis - Commentary
Written by John Ghrist   
Sunday, 06 November 2016 23:00

Support MC Press - Visit Our Sponsors

Search Sponsor

POPULAR SEARCHES

Element Break 
The MC Press Bookstore runs promotions throughout the week.
 Element Break

Make sure to stop by and check out these Special Deals:
Weekly Collection Sale - Every week an entire Subject is on sale between 15% to 25% off the Sale Price.
11/07 to 11/11 - 25% OFF all Data Goverance Books.
Monday's Blowout Book - Every Monday check out this DEEPLY discounted book - 50% or more off Sale Price. 11/07 to 11/11 - 50% OFF - Database Design and SQL for DB2
Tuesday's 2-Day Sale - Every Tuesday come check out a very special offer on one of our top selling books. 11/08 to 11/09 - 35% OFF - Advanced Guide to PHP on IBM i
Thursday's 2-Day Sale - Every Thursday come check out a very special offer on one or more of our books.11/10 to 11/11 - 35% OFF - Control Language Programming for IBM i

Element Break 
- NEW BOOKS -
Check out these New MC Press Books


Long-time software vendor HelpSystems thinks the future still looks promising for the IBM i platform.

As any long-time observer of the IBM i can tell you, a significant feature of its market over its recent history has been the consolidation of companies offering software and other solutions to the user base.

HelpSystems, a Minnesota-based company that started out specializing in automated operations solutions for IBM i, has been part of the consolidation movement. HelpSystems acquired security experts The PowerTech Group in 2008, Safestone in 2012, and SkyView Partners in 2015. Also, HelpSystems bought document management solution provider RJS Software Systems in 2014 and systems management specialist Halcyon Software in 2015, as well as both file-transfer and encryption vendor Linoma Software and server-monitoring solution provider Tango/04 Computing Group earlier this year, although many of these companies offer non-IBM i products as well. The company purchased IBM's business intelligence portfolio ShowCase in 2013 and the RODIN suite from Coglin Mill in 2014. In addition, HelpSystems bought Windows workflow software provider Network Automation (AutoMate) in 2014, Windows/Linux-based network monitoring company Dartware (InterMapper) in 2013, and Armenia-based outsourcing service company Sourcio in 2016.

HelpSystems' CEO Chris Heim and Executive Vice President for Technical Solutions Tom Huntington recently took time to answer some questions about this and other issues facing the IBM i market.

IBM i Is Still a Thousand-Vendor Market
"We have played a tiny role in the consolidation of software sources in the IBM i market," Heim modestly points out. "HelpSystems has bought fewer than 10 vendors. According to some industry sources, there were as many as 8,000 software vendors for the IBM i at its peak. Today, some estimates put that number around 1,000."

Nevertheless, despite its small role in the consolidation movement, HelpSystems sees that change as beneficial.

"We believe that both the long-term and short impact effect of multiple vendor acquisitions by HelpSystems and other companies is healthy. The IBM i market is unique, and many of the founders of IBM i software companies are reaching retirement age," Heim notes. "When HelpSystems acquires these companies, their customers are assured that their products will continue to be enhanced, supported, and sold both now and in the future, and we have ten years of experience on some of the products demonstrating this fact.

"Our customers also have strategies within their companies to reduce their overall number of vendors and want to see solutions integrated together. Acquisitions enable customers to consolidate vendors and see integrated solutions that can accomplish things collectively that individual products cannot.

"Finally, exits are good for a market. If entrepreneurs see a market where you can create a great product and company and then later sell it for a profit, they are apt to invest in new companies in the space. If you never have exits, you will not see new investment flow into a market," Heim concludes.

Outside Funding May Also Help the i Market
In keeping with the idea of new investment flows to the i market, HelpSystems itself was acquired by investment firm H.I.G. Capital in October 2015. Heim and Huntington stress that the purchase will result in no changes to HelpSystems' strategy or outlook.

"We have a long-term partner in H.I.G., and they are very committed to the growth of HelpSystems," the executives emphasize. "We will continue to expand our offerings in the years to come to meet our customers’ needs. HelpSystems remains very committed to the IBM i market, and H.I.G. is supportive of this strategy. This is demonstrated by the fact that since we have partnered with H.I.G., we have bought Tango, Linoma, and BugBusters Software Engineering, all of which have IBM i products."

"The larger goal in our acquisitions is that our customers want a broad range of solutions to solve their challenges and prefer not to have to manage hundreds of vendors to do so," Heim points out. "They want their solutions to work together, see continued enhancements, and be backed by world-class support. They also want to be able to buy a product today and ensure that their investment will be protected in the years to come. We believe if we meet our customers’ needs here, we will continue to be a growing and successful organization over the long haul."

Heim and Huntington also think their company's expansion hasn't significantly altered its brand.

"HelpSystems has always been known for high-quality products and world-class support," Huntington maintains. "This was initially for the Robot product line, but we have extended these foundational items to all our acquisitions. So the foundational elements of our brand have not changed, but now our brand is also known for being a broad solution provider for the IBM i."

HelpSystems Supports IBM's Strategic Direction
Heim and Huntington emphasize that their company's support remains strong.

"We have been very impressed over the last couple of years about the IBM i product introductions and future roadmaps from IBM. We believe IBM fully recognizes the strong and loyal customers for this platform. The combination of IBM i, AIX, and Linux on POWER has enabled IBM to compete with Intel in offering world-class technology for the data center. We believe IBM should continue this investment as it helps keep our IBM i environment involved in newer technology like storage area networks and solid-state storage drives, along with improved speeds for business intelligence and other workloads on IBM i."

The executives declined to comment directly on IBM's strategy for using the Watson platform for cloud and data analytics but did say that "…while we are fully supportive of IBM and its strategy with Watson, we also believe we will continue to be a strong and growing company regardless of our Watson strategy.

"We want to unlock further value from our customers' data, both inside our products and within our customers' larger organization, so we are very much aligned with this larger direction of IBM," the executives added.

HelpSystems' Views IBM i Market as Stable
Despite the increasing prevalence of other platforms in IBM i shops, the HelpSystems executives don't see this as a threat.

"Virtually 100 percent of our customers have mixed environments, and this reflects the IT world of today," Heim observes. "IT organizations have a heterogeneous mix of platforms, and it is our job as a vendor to simplify their administration and operation of all of them."

"We do a fair amount of research on this marketplace and share the results of this research both with IBM and the broader market," Heim adds. "We see a very stable market and our research is showing that there are more companies adding workloads [to the IBM i] than migrating completely off the platform. In fact, 22 percent of the IBM i marketplace is actually growing their workloads on the IBM i. Our annual IBM i Marketplace Survey revealed these numbers. We are firm believers in the long-term future of the IBM i market."

When asked if HelpSystems sees any differences in the outlook for software sales as opposed to services sales in the IBM i market, Huntington remarked, "For us, both models are growing."

In comparing the relative balance of its business in cloud services licensing versus on-site licensing, Huntington offered, "We help customers, mainly managed service providers, to oversee the infrastructure that runs their public or private clouds. We provide the security, monitoring, and automation for these environments on IBM i."

Commenting on how well HelpSystems has been able to adapt its product offerings to mobile devices, Huntington said, "We have our InSite framework that we are extending across all our products. The framework is web-based and supports all mobile devices. Our customers have asked for this feature, and we are responding."

HelpSystems Backs COMMON
HelpSystems remains strong in its support for COMMON.

"IBM i customer loyalty cannot be denied and is very unique in the technology world," Heim observes. "COMMON helps to solidify this loyalty. Not all customers can afford to travel to COMMON events, but for those that can, it is definitely a good investment in learning. We are very active at COMMON and have a large number of speakers providing workshops. Short of IBM, we are probably the company with the largest number of speakers and average about 14 sessions at most COMMON conferences. Locally, two of our team members (split presidency) help to run the QUSER user group for IBM i in the greater Minneapolis area. Several of our experts speak and vend at other regional user groups on IBM i like OCEAN, TUG, NEUG, Omni, and others. Fall of 2016 we are sponsoring two students to attend Fall COMMON in Columbus, Ohio, for free. For Spring COMMON, we have sponsored the John Earl (founder of PowerTech) Annual Speaker Award, which pays for one speaker’s fee for COMMON each year.

"As for our own product training, we offer both scheduled training and onsite training for most of our products and offer consulting services for those that want even more of a fast start. Different customers have different needs relative to education and consulting, and we need to support this myriad of wants. We conduct webinars that are free on topics like security, backups, SQL, work management, and other areas of our expertise. This helps bring free education to the marketplace for those that cannot afford to travel to conferences," Huntington concludes.