CIO Brief: Managed File Transfer — The Forgotten Crown Jewel
Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.
The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of which didn't know their vendors used it. File transfer systems quietly hold some of a company's most sensitive data.
Why file transfer systems are crown jewels
Payroll files, benefits data, customer records and financial reports pass through file transfer tools. These systems face the internet by design, often keep files longer than needed, and get less attention than email or ERP systems.
The business impact
- Mass data theft and public extortion.
- Notification obligations for data you held for others.
- Third-party exposure through vendors using the same tool.
Questions to ask your team
- Which file transfer tools do we run, and are they internet-facing?
- How long do files stay on them?
- Which of our vendors (payroll, benefits, banks) use file transfer tools to exchange our data?
- How quickly did we act when MOVEit was announced?
What good looks like
A known list of file transfer systems, short file retention, emergency patching, restricted access, and vendor reviews that include how they exchange your data.
The decision
Ask for files on transfer platforms to be deleted after a short period — days, not months. Data that isn't there can't be stolen.
- MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims Incident Teardowns
- How to Inventory Internet-Facing File Transfer and Integration Services How-To & Hardening
- Detecting File Transfer Zero-Day Exploitation: Sentinel and GuardDuty Detections Detection & Response