Article

File Transfer Security

Topic: SoftwarePublished December 8, 2011
No ratings yet510 viewsSign in to rate

In the vast majority of cases, corporate data breaches are caused inadvertently by well-meaning employees as they exchange data with customers, vendors, and partners. As a result, ad hoc file transfer security has become a critical conce
for Information Security departments at leading companies. Let’s take a look at some of the major concerns:

FTP Replacement

As long as you know the location of the file and the sign-on information for the appropriate server, FTP, or file transfer protocol, is one of the easiest ways to move files from one machine to another. While it’s fairly safe to use FTP practices internally, using this method across an unsecured Internet connection makes the file vulnerable to interception by hackers and corporate information thieves. To protect their electronic resources, companies should provide their employees with easy-to-use tools that encrypt the data before transmittal and provide secure pipes for the actual data transfer.

Email Attachment Management

While most companies have monitored incoming email for spam, malicious code, and other issues for years, many are just beginning to see a need to monitor outgoing email messages as well. Some estimates report that about 80% of information leaks go out through email messages. In some cases, the issue is caused by simple mistakes like entering the wrong email address, but other examples point to outright corporate espionage conducted by insiders passing confidential information to a competitor. The latter breach is often caused by an employee using their private email account through their employer’s Internet connection. The use of filters and other automated processes in addition to the implementation of a strict set of security policies can detect and prevent the majority of email data breaches.

The Importance of Not Putting Files in the DMZ

When non-technical users become frustrated with trying to transfer a file to a customer, they may be tempted to simply put it in the DMZ. Once the data is on the other side of the firewall, it solves the problem for the individuals trying to share information, but it causes a much larger problem for the corporate entity. At this point, the data is left wide open to the entire online world without any protection at all. Any hackers who have been targeting the company or who are randomly trolling TCP/IP addresses could intercept the data just as easily as the authorized parties. In short, any transfer method is better than dropping a file in the DMZ to facilitate access.

Regulatory Compliance

With the exponential growth of data breaches at commercial institutions, every company must be careful to comply with regulations concerning the exposure of certain types of information. In addition to protecting corporate data, companies have a responsibility to keep the personal information of their employees and customers completely secure to prevent identity theft. If a breach does occur, a variety of federal laws including the Privacy Act, the Federal Information Security Management Act, and the Fair Credit Reporting Act come into play. These laws not only require any company that experiences a data breach to notify the affected parties, but also allow individuals to pursue damages in a court of law if they were harmed by the company’s negligence. In extreme cases, criminal charges may apply.
Auditing and Reporting

Since the Enron debacle, both IT reporting requirements and auditing procedures have become much stricter. Third-party agencies like PCI DSS, SOX, and HIPAA are now in full control of ensuring compliance, and they are more than willing to come down hard on any offenders. Although preparing for audits is intended to lead to tighter, more secure systems, this process has added additional overhead for virtually every IT department. At a minimum, strict controls and targeted reporting should be implemented for sensitive data access, privileged user monitoring, and secure web applications.

The importance of file transfer security can’t be overstated. A data breach can not only put your company’s confidential data at risk, but can also lead to legal problems in the event that any personal information is compromised.

Article author

About the Author

Anthony Ricigliano thrives with 25 years of integrating the latest technological advances into business operations; Anthony Ricigliano Profile is a point man capable of establishing and managing state of the art infrastructure to maximize operational efficiencies.

Further reading

Further Reading

4 total

Article

Organizations are starting to scale their cloud native operations. And as they do, the inefficiency of managing dozens of isolated clusters has become an evident problem. As the clusters continue to sprawl, businesses must unite diverse workloads onto shared infrastructure. This is because companies need better resource utilization and centralized governance among other things. But it is imperative to remember that going from a single tenant to a multi-tenant environment need

March 12, 2026

Article

It has been for everyone to see the short product lifecycles and a pressing need for rapid technical scalability that have come to define the modern startup ecosystem. For early-stage companies, the challenge is no longer just conceptualizing a solution. But they must also carry it out with enough precision to withstand high market volatility and fierce competition. We know that internal teams concentrate on core business strategy and fundraising. That still leaves us with th

March 12, 2026

Article

In today’s regulated and data-driven environments, organizations are under constant pressure to ensure that temperature and environmental conditions remain within defined limits. Even small fluctuations can result in product loss, compliance violations, or operational downtime. As a result, many facilities are moving away from manual checks and standalone sensors and adopting comprehensive environmental monitoring solutions instead. An environmental monitor provides rea

March 5, 2026

Article

Organizations have come to rely heavily on large amounts of data in today's competitive markets. But to what end? For starters, to inform strategic decisions and power machine learning models. It goes without saying that the value of these digital assets is completely dependent on the accuracy of the underlying data. So, when data is fragmented or inconsistent across departments, you will obviously have inaccurate reporting and operational inefficiencies at your hands. This c

March 2, 2026