top of page

How Does Bulk Data Leave Your Network - and Would You See It?

24 Aug 2026

Here's a question I suggest IT and security leaders ask… because it's clarifying in a way that most audit checklists aren't:


“If 200 gigabytes of your most sensitive data left your network tonight, how would it get out - and who, if anyone, would notice before Monday?”

Most organisations have a confident answer for the front door. Firewalls, email filtering, endpoint protection, maybe a DLP tool with a dashboard someone checks occasionally. But bulk data almost never leaves through the front door. It leaves through channels the business built itself, uses every day, and has largely stopped looking at.


The channels nobody owns

Walk through any mid-sized or large organisation and you'll find the same picture.


The scheduled transfers nobody remembers.

Somewhere on a server is a script written years ago by someone who has since left that pushes files to a partner, a bureau, a payroll provider, an offshore processor. It runs at 2am. It works, so nobody touches it. Nobody reviews what it sends, whether the credentials have ever been rotated, or whether the counterparty at the other end is still who you think it is. 


Multiply that by every integration the business has ever built, and you have dozens or hundreds of standing pipes out of your network with no single owner and no consolidated record.


Email and its attachments.

Email is the default bulk transfer tool of every organisation on earth. Spreadsheets full of customer records go out one attachment at a time, and because each individual send looks routine, the aggregate is invisible. 


Ask yourself: could anyone in your organisation tell you how much structured customer data left via email last quarter? In most places the honest answer is that no one even knows to ask that question.


Cloud sync and personal accounts.

A well-meaning employee under deadline pressure shares a folder from a personal file-sharing account because the corporate way was too slow. 


Shadow IT isn't malicious - it's a service gap. Every gap your sanctioned tools leave, your people will fill with something you can't see, and the data that flows through it never appears in any log you control.


The legacy FTP server.

Many organisations still run one - often internet-facing, often on default configurations, often "temporarily" kept alive for one partner who never migrated. It has no meaningful audit trail, and in the industry's recent breach history, unmanaged transfer endpoints have been among the most reliably exploited assets on the perimeter.


Legitimate credentials, illegitimate use.

This is one that should genuinely worry you. Modern data theft rarely looks like an exotic hack. Attackers – and occasionally, insiders - use valid accounts and ordinary tools to move data out through the same channels the business uses, precisely because that traffic blends in. 


The overwhelming majority of ransomware incidents now involve data being stolen before anything is encrypted, because stolen data is the real leverage. The exfiltration phase often runs for days. In network terms, it frequently looks like just another big transfer – because, mechanically, that's exactly what it is.


The visibility test

So: would you see it?


Here's a practical test. For your organisation, right now, try to answer four questions.


One: how many distinct channels exist by which a file larger than 1GB can leave your network? 


Two: for what percentage of them is there a complete, centralised record of what was sent, by whom, to where? 


Three: if a service account that normally transfers 50MB a night suddenly transferred 500GB, would anything alert? 


Four: after an incident, could you reconstruct - with evidence, not inference - exactly which records left?


Most organisations can't answer the first question, which makes the other three academic. And that's an architecture failure. Data leaves through many doors, and no one is responsible for all of them. And under Australia's current regulatory settings - APRA's CPS 234 and CPS 230, the SOCI Act's risk management obligations, a Privacy Act with real teeth - "we couldn't see it" has stopped being an explanation and started being the finding.


Managed File Transfer (MFT) locks down the exits

Invisible data exfiltration is the problem MFT exists to solve. It collapses the many unmanaged doors into one governed one.


A properly deployed MFT platform gives you a single controlled channel for bulk data movement: the 2am scripts become defined, documented workflows; the partner connections run through one gateway instead of a dozen forgotten endpoints; the ad hoc human sends get a sanctioned secure option easy enough that people stop reaching for personal tools. It gives you identity and policy at the point of movement -  every transfer tied to an authenticated user or service, governed by role-based permissions, encrypted in transit and at rest. It gives you a complete audit trail: one record of what moved, who moved it, where it went, feeding your SIEM so the 500GB anomaly is a same-day alert rather than a discovery made weeks later from someone else's breach notification. And it lets you decommission the legacy attack surface - the old FTP server, the scattered scripts, the standing exceptions in the firewall - which is often the single biggest risk reduction in the whole exercise.


MFT doesn't make exfiltration impossible. But what it does is change the answer to the opening question. Bulk data can still leave your network - but through a channel you own, under policies you set, leaving evidence you hold. The difference between "would you see it?" being a nervous silence and being a confident yes is, in most organisations, less about buying more detection and more about finally governing the doors.


If you're not sure how many doors your own network has, that's a conversation worth having before someone else finds them for you. 


On Hand in Your Time Zone

At Generic Systems Australia, we’re Australia’s and New Zealand’s deep local experts in MFT.  One of Fortra’s top ten MFT partners globally, we have decades of experience helping businesses just like yours implement MFT solutions that close the door on invisible data exfiltration.


Get in touch if you’d like to discuss MFT further.  No obligation, just an introductory sharing of information and perspectives.


 

bottom of page