Are you running an old, forgotten FTP server? Would you know if you were? What would you do if you learned you are? What should you do? Before answering that question, we should probably offer a little background on FTP servers to establish context.
File transfer protocol (FTP) is a client-server communications protocol developed in the early 1970s to facilitate the transmission and reception of data files between computers. Back then, there was no public Internet and computer networks were mostly self-contained. But even in the days of rotary telephones and before there was A Galaxy Far, Far Away, the world ran on files, and it was important to be able to send and receive those files electronically over distances that were growing longer.
FTP was created to make it possible to send files over networks, and FTP servers were developed as a tool to facilitate those transfers. No one gave much thought to computer hacking and cybercrime in those days, and so FTP was not developed as a secure protocol, just a useful one. And so, through the 1980s, as computers evolved from mainframes to minis to PCs and more organizations joined the digital age, file transfers became more common, and FTP and FTP servers grew in popularity.

It was during this time that computer hacking became more widespread. Computer networks expanded in both size and complexity, and the Internet allowed organizations to connect and exchange files. The lack of integral, layered security meant clever individuals who understood telephony and computer architectures could find their way into networks and the data stored in those systems. File transfer protocol, which for more than a decade had been a useful tool for sending and receiving data, was now a liability because unencrypted data transferred using FTP could be intercepted and read. Important information like intellectual property, financial accounts, legal documents, and more were vulnerable to prying eyes and the growing scourge of cybercrime.
Unfortunately, many organizations that used FTP servers as their means of transferring files ignored the risks or didn’t even know they were running an FTP server because it existed outside the view of IT management. But threat actors, aware of the widespread use of FTP and FTP servers, began seeking them out and targeting them in cyberattacks.

You Should Invest in a HIPAA Compliant SFTP Server
How widespread? A 2015 study by the University of Michigan entitled FTP: The Forgotten Cloud, found that, worldwide, there were 13.8 million FTP servers in use with more than 600 million data files visible to anyone who could find and gain access to them. A few years later the FBI warned that threat actors were targeting unsecure FTP servers, especially those in use at smaller medical and dental offices using them to send and receive patient information in violation of the Health Insurance Portability and Accountability Act (HIPAA).
The risks associated with FTP are why the secure file transfer protocol (SFTP) was developed in the 1990s to ensure that file transfers are executed over a secure channel and that transport data associated with the transfer of data is encrypted. That is important for verifying the integrity of data and for keeping the nature of a file transfer, and the files being transferred, secure. And just as FTP servers were found to be a high-risk element in file transfer processes of old, SFTP servers are a secure component for those processes today.
Another aspect of FTP servers compounding their risk to enterprise security is the lack of support for security features like file encryption, process automation (to reduce human error), user authentication, and access control. That is why organizations today use secure managed file transfer (MFT) solutions to handle that important task. A secure MFT solution will support SFTP, automate encryption management, support multi-factor authentication (MFA) and access control based on least-privilege, validate recipient identity, and capture process data to support audit reporting. A good MFT solution (like Diplomat MFT) also enables network mapping and reporting, and digital supply chain risk assessments to identify potential vulnerabilities in the systems that receive file transfers.
There is no reason for any organization today to have an active FTP server in its network. If you are aware of the presence of an FTP server in yours, or if you run a scan and find one, you should immediately take steps to retire it, secure all associated data, and conduct a forensic investigation to determine whether it has been compromised.
Contact Coviant Software for help evaluating your options for upgrading from FTP to MFT and making sure your file transfers are secure, efficient, and automated. Book a discussion today.
