Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Keep it Simple for Security

by | Mar 4, 2025

Keep it Simple for SecurityA couple years ago, I wrote a post entitled, “Don’t Sacrifice Security on the Altar of Convenience.” It was a simple message intended to highlight the risk of taking digital hygiene shortcuts, inspired by the compromise of two well-known managed file transfer (MFT) products that resulted in data breaches affecting thousands of organizations and tens of millions of people. Whether it is the design of a product or its use, shortcuts lead to security disasters.

Make Their Lives Easier

Recently, The HIPAA Journal reported on an international industry survey that found 65% of employees “bypass their organization’s security policies to improve productivity and make their lives easier.” What’s more, most of the employees surveyed had privileged access to sensitive or regulated data.

The risk of these revelations is illustrated in another article in The HIPAA Journal that detailed five recent healthcare data breaches, including two that involved compromised email accounts in which patient protected health information (PHI) was apparently found.

I don’t have any special insights into these breaches, and so I won’t speculate on the specific nature of the incidents in the article. However, when I read that patient data was found in compromised email accounts, I am reminded of the many conversations we’ve had with organizations that came to us looking for a way to avoid that very situation. Healthcare organizations, financial institutions, and others whose day-to-day operations require that they send, receive, archive, and retrieve files replete with sensitive, highly regulated data were concerned that their people were sending that information over email because they either didn’t have a secure, managed file transfer solution, or the one they had was difficult to use.

“When a product is difficult to use, it discourages its use and encourages workarounds. It is a paradox that makes the organization more vulnerable by creating an environment that incentivizes risky behavior for the sake of efficiency.”

Our position has always been that even products designed and tested to be secure are inherently vulnerable if they are not easy to use. That’s because when a product is difficult to use, it discourages its use and encourages workarounds. It is a paradox that makes the organization more vulnerable by creating an environment that incentivizes risky behavior for the sake of efficiency. And the survey cited in The HIPAA Journal confirms this paradox by reporting that two-thirds of employees admit to using workarounds to “improve productivity and make their lives easier.”

Simple is More Secure

But simple doesn’t have to be unsecure. At Coviant Software we’ve spent the last twenty years listening to our customers, tracking security trends, and a operating with the dogged belief that security should never be sacrificed on the altar of convenience. That is why Diplomat MFT wins praise for its intuitive user interface, tight integration with popular tools and services, and a rich set of automated features that virtually eliminate the risk of human error by minimizing the need for manual tasks. We also design our products to avoid common deployment flaws that end up exposing sensitive information to public-facing networks during the file transfer process (the very thing that resulted in thousands of companies getting breached, and tens of millions of people put at risk thanks to vulnerable MFT product deployments).

Coviant Software doesn’t use internet-facing administrative dashboards and interfaces. What we do use includes:

  • Process automations that ensure all files are encrypted using OpenPGP and SFTP

  • Recipient verification with transfer confirmation or trouble notification to comms channel of your choice (email, Teams, Slack, text, etc.)

  • Multifactor authentication and role-based administrative privileges

  • Support for time-based, one-time passwords and all the popular authentication apps

  • Job monitor with full process data capture for forensics and compliance auditability

  • Integration with cloud services and most business and productivity applications

You would think that all these features would make Diplomat MFT cumbersome to use, but because we spend a lot of time talking to our customers and listening to their ideas and input, the opposite is true. These features often function automatically, seamlessly, and invisibly, requiring no manual intervention by users. All told, Diplomat MFT helps organizations close a major security gap by enabling reliable, secure, and automated file transfers that keep data safe while allowing staff to remain efficient and productive with their primary tasks.

Beyond Healthcare File Security

Because the article that caught my attention was published in The HIPAA Journal, the focus of the incidents was healthcare and a failure to protect electronic health records (EHRs) and protected healthcare information (PHI). But the fact is, every organization that transfers data in the course of doing business shares information that needs to be protected. It could be healthcare data, personally identifiable information (PII), financial data, or intellectual property.

Whatever the circumstances, it’s better to keep the information safe, and it’s safest when every step of the process is automated, simple, and secure. Talk to us if you need to improve your data transfer practices. We think you’ll be pleased to learn how easy Diplomat MFT can make it. And we think you’ll be also pleased to learn that we can do it for a lot less than you’d expect. Contact us for more information, or to take Diplomat MFT for a free test drive.