How can financial institutions modernise without compromising resilience?
Mainframes still power 90 percent of global card transactions. Modernising them means balancing security, DORA and NIS2 compliance, and innovation against decades-old systems.
Mainframe systems remain central to the function of many of the financial world’s mission-critical systems. Each day, mainframes power 90 percent of all credit card transactions across the globe. These systems, some of which are decades old, continue to function as pillars of the financial services industry's most critical systems.
As guardians of valuable sensitive information, financial institutions are prime targets for hackers and are subject to many global and regional regulations, all the while building on systems put in place decades ago. As global regulations and new technologies rapidly evolve, the financial services sector is being increasingly pushed to consider its IT modernisation strategies. In fact, research reveals that modernisation has moved to the top of the C-suite agenda, with planned investments projected to reach 25-30 percent of IT budgets over the next two years.
A well-crafted IT modernisation strategy must balance security, compliance, innovation and legacy system realities. Failing to get this balance right can lead to crippling fines for non-compliance with regional regulations like DORA and NIS2, weakened cyber resilience, and lasting reputational damage.
The core of financial transactions: the mainframe
Mainframes store a wealth of valuable data while setting the benchmark for uptime in high-stakes environments. They are a popular choice for financial institutions because they can handle transaction-heavy workloads at scale with precision and reliability. The data they store can also be a valuable resource for business intelligence and AI initiatives. By continuing to invest in mainframe technology, these organisations are therefore optimising their operational resilience and competitive decision-making processes.
As the topic of IT infrastructure modernisation increasingly dominates boardroom conversations, assessing the role of the mainframe within broader infrastructure strategies has become unavoidable. For example, despite AI readiness being a top priority for organisations, only 25 percent of IT leaders currently feel confident that their infrastructure can support AI workloads. Organisations are increasingly evaluating a range of modernisation approaches to ensure the right workloads run in the environments best suited to their business, regulatory, and operational requirements.
New Paths to Modernisation
As financial institutions evaluate their long-term infrastructure strategies, many are considering alternatives that extend beyond traditional mainframe deployments. These approaches range from large-scale application replacement initiatives to replatforming strategies that preserve existing business value while enabling greater flexibility.
Some organisations pursue large-scale replacement or rewrite initiatives as part of modernisation programmes. While these approaches aim to deliver a fully transformed future-state architecture, they also require organisations to recreate years or decades of embedded business processes, regulatory controls, and operational expertise. For financial institutions, where availability, auditability, and resilience are mission-critical, these initiatives often demand substantial investment, extensive testing, and long transformation timelines. The challenge is not simply migrating applications. It is reproducing the operational characteristics and business outcomes those systems have evolved to deliver over decades of production use.
The costs of misconfiguration in complex rewrite projects can be more than just directly financial – they also risk data leaks, loss of business due to temporary outages, and even regulatory fines if compliance is compromised. In fact, according to Forrester, rewrite projects can take up to six attempts before achieving results, with 90 percent failing the first time. These difficulties can stem from a lack of talent or skills, complex technology environments, and heightened security concerns.
Between large-scale replacement initiatives and modernisation in place lies another path: replatforming transaction applications onto modern runtime environments. This approach enables organisations to preserve proven business logic while increasing flexibility around infrastructure, skills, development practices, and future innovation initiatives. Rather than recreating applications from scratch, organisations can retain decades of business value while expanding their options for where and how transaction workloads run.
Modernising in place
Many financial institutions instead choose to extend and modernise applications while continuing to run core transaction processing on the mainframe. This approach allows organisations to introduce modern development practices, APIs, automation, AI-assisted tooling, and improved user experiences without fundamentally changing the underlying transaction environment. For organisations whose competitive advantage is built on highly optimised transaction systems, preserving the operational resilience, performance, and security of the mainframe can be as important as introducing new technologies.
For organisations whose core business processes remain deeply embedded in mainframe environments, modernisation in place often provides a practical path to introducing new capabilities while minimising disruption to mission-critical operations.
This approach allows organisations to combine the stability of the mainframe with modern innovation, while progressing at their own pace. In an industry that is constantly developing, mainframes hold and protect complex transactional rules and handle high-volume inputs and outputs. This kind of steady reliability is key for financial institutions dealing with massive volumes of sensitive information and their customers who rely on continuous access to their assets. Institutions can therefore utilise this approach to respond to changing regulatory and customer demands without compromising the stability and integrity of the systems that enable those daily core transactions.
The hybrid cloud approach
As financial institutions navigate the complexities of modernisation, cloud platforms present an appealing solution. This is due to the cloud’s ability to dynamically scale resources to meet fluctuating demand and effectively avoid the costs associated with maintaining peak capacity year-round. The size of the global market for cloud migration services is currently valued at $11.84 billion, and is expected to reach $42.92 in 2033, demonstrating strong market demand.
For many financial institutions, hybrid cloud strategies offer flexibility rather than replacement. By placing the right workloads in the right environments, organisations can take advantage of cloud-based analytics, AI services, modern development ecosystems, and elastic capacity while continuing to leverage the resilience and transaction-processing strengths of existing core systems.
Rather than viewing modernisation as a destination, many institutions now see hybrid cloud as an operating model that allows them to evolve over time. This approach provides the freedom to modernise applications incrementally, manage risk more effectively, and align technology decisions with business objectives, regulatory requirements, and customer expectations.
However, a challenge that emerges when migrating processes to the cloud is the management of data across the different environments. Institutions should not underestimate the importance of data discovery as a means to understand the environment, manage risks proactively, improve compliance and enhance data security.
Security and compliance
Regardless of the approach, modernisation is not without its challenges. Security and compliance remain top priorities, particularly when it comes to protecting sensitive financial data and personal information. With just 24 percent of IT leaders feeling extremely confident in their organisations’ ability to address security vulnerabilities over the next year, it comes as no surprise that this ranks as the biggest concern moving forwards. For the financial services sector, however, compliance and security are non-negotiable. A systems breach can rapidly downgrade a financial institution’s reputation, cause long-term harm to customers and lead to crippling fines.
Increasingly, organisations are recognising that security is not just about protecting systems from attack. It is also about continuously validating that controls are functioning as intended, identifying vulnerabilities before they become incidents, and demonstrating compliance to regulators and auditors.
As cyber threats and regulatory expectations evolve, financial institutions require greater visibility into their security posture and operational resilience across both traditional and modern environments. This is particularly important in highly regulated sectors such as financial services, where organisations must not only maintain security controls, but also demonstrate their effectiveness through ongoing governance, auditing, and compliance activities.
Mainframes are widely recognised as the gold standard for highly securable environments, thanks to their centralised processing and storage architecture. This centralisation minimises attack surfaces, incorporates built-in encryption, and features granular access controls which aids organisations in boosting their cyber resilience and meet the requirements prescribed in industry regulations including NIS2 and the EU’s DORA.
Ultimately, financial institutions find themselves at a critical crossroads. Modernisation is no longer simply about replacing technology. It is about determining how to preserve resilience, security, compliance, and business value while enabling innovation, AI adoption, and future growth.
The most successful organisations will take a strategic approach that aligns modernisation methods to specific business needs, whether that involves modernising in place, replatforming, embracing hybrid cloud models, or a combination of these approaches. By viewing modernisation as a continuous journey rather than a single destination, financial institutions can evolve with confidence while maintaining the operational foundations their customers depend on.