top of page

Search Results

219 results found with an empty search

  • Is It Time Your Company Upgraded from Ad-Hoc File Sharing? | GSA

    < News Is It Time Your Company Upgraded from Ad-Hoc File Sharing? 18 Mar 2025 The Global File Sharing market is booming . Uptake of services such as Dropbox, Google Drive, Box, Microsoft OneDrive, Citrix ShareFile, Egnyte, Zoho Docs, IBM FileNet, SharePoint, Adobe Document Cloud, M-Files, Accellion, Syncplicity, SugarSync, WeTransfer has never been stronger. These "ad-hoc" file-sharing applications are certainly popular. However, are companies that permit their proliferation unwittingly taking risks with their data and foregoing productivity gains? Picking Up Where Ad-Hoc Drops Off Managed File Transfer (MFT) generally outperforms ad-hoc file sharing services due to its enhanced security, automation, and centralised management capabilities. These additional capabilities are crucial for handling sensitive data and ensuring compliance with industry standards. Here's a breakdown of why MFT may be the better solution for your company… Enhanced Security MFT solutions offer robust encryption, secure protocols (like SFTP, FTPS), and robust auditing capabilities, ensuring data confidentiality and integrity. Ad-hoc services, while offering some security features, may lack the comprehensive security controls needed for enterprise-level data protection. Automation and Efficiency MFT platforms automate file transfers, reduce manual errors, and streamline workflows, improving efficiency and reducing IT overhead. Ad-hoc services require more manual intervention and can be less efficient for large-scale or complex file transfers. Centralised Management MFT provides centralised control and visibility over file transfers, allowing IT teams to manage access, monitor activities, and enforce policies. Ad-hoc services often lack this level of control, making it difficult to manage and audit data transfers. Compliance and Auditing MFT solutions facilitate compliance with industry regulations and standards by providing comprehensive audit trails and reporting capabilities. Ad-hoc services may not offer the same level of auditability, making compliance more challenging. Scalability and Reliability MFT platforms are designed to handle large volumes of data and complex transfer scenarios, ensuring scalability and reliability. Ad-hoc services may struggle to handle large files or complex transfers, potentially leading to delays or failures. Free Demonstration? At Generic Systems Australia , we’re your local experts in secure managed file transfer. We have decades of experience helping local companies like yours embrace and leverage MFT’s capabilities and advantages. If you’d like to see first-hand how MFT can keep your data safe and boost your team’s productivity, please feel welcome to get in touch . We can have an obligation-free chat, and I can even arrange a free Proof of Concept for your organisation. Previous Next

  • Asia-Pacific orgs are on Cybercrime Frontline | GSA

    < News Asia-Pacific orgs are on Cybercrime Frontline 12 July 2024 The Asia-Pacific region is the frontline in the fight against cybercriminals. A survey conducted by security firm Kiteworks has found that 72% of organisations in our region experienced four or more cybersecurity incidents in the past year - 20% more than the global average. Data also shows that Asia-Pacific organisations also exchange sensitive content with the highest number of third parties. This could be contributing to the higher-than-average cyberattacks. One of your best defences against hackers is to centrally control the flow of data into and out of your organisation. Managed File Transfer (MFT) software does that for you. At Generic Systems Australia , we’re the Asia-Pacific’s experts on the world’s #1 MFT, GoAnywhere . Let me know if you’d like an obligation-free discussion about how we could help you keep your organisation safe from the cyber crimewave. #MFT #managedfiletransfer #securefiletransfer #sft #cybersecurity #cybercrime Previous Next

  • DATASHEET GA GATEWAY | GSA

    GoAnywhere Gateway provides an additional layer of security when exchanging data with your trading partners, enabling you to keep file sharing services and documents safely in your private/internal network. This datasheet summarises its key technical features. View Report RESOURCES HOME

  • NEW CYBER LAWS PASSED | GSA

    New Cyber Laws Passed – What Australian Businesses Need to Know and Do Earlier this week, the Australian Parliament passed a suite of legislative reforms designed to enhance Australia’s cyber security. The reforms include a raft of new requirements and obligations on Australian businesses. About the Legislation Based on recommendations by the Parliamentary Joint Committee on Intelligence and Security, the new legislation addresses a number of proposals initially set out in Australia’s 2023 – 2030 Cyber Security Strategy, and spans three separate Acts: the Cyber Security Act 2024 (Cyber Security Act); the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024; and the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (SOCI Amendment Act). Mandatory reporting of ransom payments, and the introduction of a new voluntary information sharing regime, will have the most immediate impact on organisations. Mandatory reporting of ransomware payments Ransomware attacks are rife across Australia. The Australian Signals Directorate (ASD) reported that this form of cyber extortion accounted for 11% of all cyber incidents to it in 2023-2024, up from 8% in the previous year. The Government had previously pursued a ban on ransom payments. However, its position has since moderated somewhat. The Cyber Security Act only requires organisations to report ransomware payments to the Department of Home Affairs and the ASD. This new reporting obligation will commence at latest six months after the Act receives royal assent (potentially earlier by proclamation) and applies broadly to: organisations which are a responsible entity for a critical infrastructure asset; and other private sector organisations which conduct business in Australia with an annual turnover exceeding a threshold (to be specified - likely to be A$3M). Ransomware reports are required to be made within 72 hours of making a payment (not the receipt of a demand or the discovery of a ransomware attack). Difficult Decisions The requirement to report payments will need to be taken into account by Boards when considering whether to pay a ransom. The Government’s general view on ransoms continues to be that organisations should not pay them. It reasons that payments don’t guarantee the recovery or confidentiality of stolen data, but do encourage cyber attacks to proliferate. Organisations in receipt of ransom demands are left to ponder several competing considerations… Paying a ransom could potentially contravene sanctions (such as the one imposed on Aleksandr Ermakov, the individual responsible for the 2022 Medibank data breach) or anti-money laundering laws. Company Directors fulfilling the duty of care to act in the best interests of their organisation will need to balance the risks of payment - commercial damage, incentive to re-target, uncertainty of data recovery – against the risks of not paying - loss of systems data, reputational damage, third party claims, lost customers and business disruption. If a ransom payment is made, then the new mandatory reporting obligation will be in addition to other applicable reporting requirements an organisation is subject to. These could include the Privacy Act 1988, the SOCI Act, and continuous disclosure obligations under the ASX Listing Rules and CPS 234. In fact, it’s important that Cyber Incident Response plans developed by organisations specifically address these overlapping requirements, taking into account the various regulators and timeframes of each. Be aware that, for any entities regulated under the SOCI Act, it’s also conceivable that the Government could use its directions power to direct an entity to pay - or not pay - a ransom. An organisation which fails to comply with mandatory ransom reporting will incur a civil penalty of 60 penalty units (currently A$93,900). Voluntary reporting regime A new National Cyber Security Coordinator (NCSC) is being established under the Cyber Security Act to lead a whole-of-government response to significant cyber security incidents. The Act provides a framework for the voluntary disclosure of information by any organisation operating in Australia, or any responsible entity under the SOCI Act, to the NCSC relating to cyber security incidents. However, it imposes various limitations on how the NCSC may further use and disclose information voluntarily provided by entities, depending on the significance of the incident. Non-significant cyber security incidents: Information can be used for limited purposes such as directing the reporting entity to assistance services, coordinating a government response, and informing Ministers. Significant cyber security incidents: Information can be used for broader ‘Permitted Cyber Security Purposes’. These include preventing or mitigating risks to critical infrastructure or national security, and supporting intelligence or enforcement agencies. A cyber security incident is deemed “significant” if: there is a material risk that the incident has seriously prejudiced, is seriously prejudicing or could reasonably be expected to prejudice the social or economic stability of Australia or its people, the defence of Australia or national security; or the incident is, or could reasonably be expected to be, of serious concern to the Australian people. Information voluntarily provided by organisations to the NCSC is subject to limited use protections similar to those which apply to information disclosed as part of a ransomware payment report. The new voluntary reporting regime and corresponding limited use protection has come into immediate effect. Limited use protection The Cyber Security Act outlines how businesses should work with the NCSC and other government agencies to obtain assistance and guidance when responding to cyber incidents. It also provides businesses with certain limited use protections when collaborating with the government’s cyber security agencies - a legislative foundation for the CISA Traffic Light Protocol government agencies have recently offered when assisting organisations. Such protections were requested by business lobby groups. They provided feedback during the public consultation period that disclosing information about a data breach could risk exposing an organisation to further regulatory or enforcement action, adverse publicity and litigation. Further, if disclosing a cyber incident was determined to be against an organisation’s best interests, its directors could potentially be in breach of their duties in approving the disclosure. That could in turn expose directors to enforcement action from ASIC. Counterweighing these concerns, the Government believes that sharing information on current threats and incidents can help other organisations avoid similar incidents. In balancing these competing interests, the Cyber Security Act limits the purposes for which information contained in a ransomware payment report or voluntarily report provided to the NCSC can be used or disclosed. The NCSC (and any Government agency it coordinates with) cannot record, use or disclose the information provided for the purposes of investigating or enforcing or assisting in the investigation or enforcement of any contravention of a Commonwealth, State or Territory law. An important exemption from the limited use protections are that crimes and breaches of the limited use protections created by the Act. In this way, the protections stop short of being a full “safe harbour”. Information provided under these protections isn’t admissible in evidence against the disclosing entity, including criminal, civil penalty and civil proceedings (including a breach of the common law). And, the provision of information to the NSCS does not affect any claim of legal professional privilege over the information contained in that information. These limited use protections will be of value to organisations disclosing information to the Government about cyber incidents. However, directors should bear in mind the notable gaps in the protection they provide. For example: Information provided can’t be used or disclosed for the purposes of investigating or enforcing any contravention by the reporting entity of another law (whether federal, state or territory), other than a law that imposes a penalty or sanction for a criminal offence. This means that if the ransomware report indicates that a payment was made in breach of relevant sanctions laws, then the limited use protection will not prevent the use of the report in a subsequent investigation or enforcement action. While information provided to the NCSC cannot be obtained from the NSCS by regulators or government agencies, the protection offered under this Act does not prevent regulators from obtaining the underlying information through other means, including via regulatory investigatory powers or where provided under other mandatory reporting regimes, such as those in the Privacy Act 1988, the SOCI Act, the Telecommunications Act 1997 and the ASX Listing Rules continuous disclosure obligations. So, cyber incident notifications provided to the ACSC under the SOCI Act are not captured by the limited use protection, even if that information is also voluntarily provided to the NCSC or detailed in a mandatory ransomware report. A similar limited use protection has been introduced via the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 for cyber incident information voluntarily shared with the ASD. Other Inclusions in the Legislation This article has focused on developments within the new Cyber Security legislative reforms which will most impact companies and organisations. However, in the interests of completeness, here is a brief overview of other key developments covered in the legislation: Mandated Security Standards for Internet of Things (IOT) Devices. These standards will be detailed in legislative rules, with suppliers required to provide a statement of compliance for devices supplied to the Australian market. New Cyber Incident Review Board. This independent advisory body will be empowered to conduct no-fault, post-incident reviews of significant cyber security incidents and provide recommendations and information to both the private and public sector. It will have the power to compel entities to provide information about significant cyber security incidents. Critical Infrastructure definition expanded. Data storage systems which hold business critical data have been added to the definition of critical infrastructure assets. This closes a gap in the regulations which became apparent in the aftermath of the Optus and Medibank data breaches. Expanded Incident Response Powers. The Government will now have the power to direct an entity to take, or not take a specific action, in the event of a cyber incident affecting critical infrastructure. Security and incident notification obligations moved from the Telecommunications Act 1997 to the SOCI Act, consolidating the cyber obligations of telecommunication carriers and carriage service providers under a single piece of legislation. What Organisations Should Do Cyber security response plans should now be reassessed and upgraded to ensure they align to the new mandatory ransomware reporting requirements. Playbooks and procedures should take account of how an organisation plans to engage with cyber security authorities, bearing in mind the extent - and limitations - of the defined limited use protections. Focus on preventing cyber incidents - not just responding to them. A Managed File Transfer (MFT) solution such as GoAnywhere MFT can encrypt data at rest and in transit, complying with the highest data security standards. It manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols and encryption to protect your data. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection facilitates safe collaboration with external parties, helping to prevent malware from entering an organisation, and reducing the risk of employees losing or mishandling sensitive data. Finally, organisations should seek professional legal counsel in determining and responding to their obligations and responsibilities under the new Cyber Security legislative reforms. The information provided in this article has been general in nature, and the interpretations and advice outlined above should not be interpreted as professional legal advice.

  • INFO TECH REPORT 24 | GSA

    Independent Info-Tech MFT Quadrant Report (2024) Once again, respected tech analysts Info-Tech have evaluated the most popular MFT software and vendors, and found that GoAnywhere is the top MFT solution. Here’s their 2024 independent report. To receive a Complimentary Copy of the Report, simply submit your email address below: First name Last name Enter your email address Phone You'll receive the 'Independent Info-Tech MFT Quadrant Report' shortly! RESOURCES Receive Report HOME

  • Why Your Business Can't Rely on Employee Cybersecurity Training | GSA

    < News Why Your Business Can't Rely on Employee Cybersecurity Training 29 Oct 2025 The employee cyber security training programs implemented by most large companies don’t reduce the risk of their employees falling for phishing scams. That’s the shocking conclusion of recent research evaluating the effectiveness of two common types of cybersecurity training.  Phishing is a deceptive tactic in which attackers impersonate trusted entities to trick individuals into revealing sensitive information like passwords, credit card numbers, or personal data.  It continues to be the most common form of cyber attack, and leads to the greatest number of cyber infiltrations. Testing the Defences To test the effectiveness of anti-phishing training, researchers sent 10 different phishing email campaigns to 19,500 employees at UC San Diego Health over an eight month period.  They found that there was no significant relationship between whether an employee had recently completed mandated cybersecurity training and whether they then fell victim to a phishing email. Researchers also tested whether sharing anti-phishing information after an employee fell for a phishing scam improved the employee's ability to detect a subsequent phishing attempt. However, once again, they observed very little difference in repeat failure rates. In fact, embedded phishing training only reduced the likelihood of an employee clicking on a phishing link by a mere 2%. Why training fails Research study co-author Grant Ho said a key reason the anti-phishing training isn’t effective is that most employees don’t engage with embedded training materials.  75% of users in the study engaged with embedded training materials for a minute or less, and a third closed embedded training pages immediately, without reading them. He recommended that organisations refocus their efforts to combat phishing on technical countermeasures. Technical Countermeasures One of the first and best lines of defence against phishing is to prevent malware and suspicious links before they can reach employees’ devices.  At Generic Systems Australia we combine the world’s leading Managed File Transfer solution, GoAnywhere , with Advanced Threat Protection to deliver a proactive, multilayered defence against both external threats and internal data leakage.  GoAnywhere provides secure encryption, access controls and audit trails for file transfers, while ATP enables your organisation’s email system to automatically detect and prevent phishing links and other malware from entering your organisation. Here to Help At Generic Systems Australia we have decades of experience helping Australian and New Zealand organisations protect themselves against malware and other cyber attacks. Our Migration Service makes the transition even easier for organisations who prefer to let their team get on with their regular work rather than taking time out to improve their IT plumbing. If you’d like a no-cost, no-obligation discussion about how we could help you simply and affordably adopt an advanced MFT and ATP solution, please feel welcome to get in touch with me. At Generic Systems Australia, we’re your local experts in Secure Managed File Transfer. Previous Next

  • Email Overload Creating Cyber Complacency in Australia | GSA

    < News Email Overload Creating Cyber Complacency in Australia 23 Oct 2024 Australians send and receive 8.1 billion emails each day. That makes us the 10th most prolific emailers in the world. And that’s a problem . It’s not just the inbox clutter we’re experiencing (or perhaps, contributing to). It’s the cyber security complacency it’s creating. You see, email continues to represent the single biggest threat to your organisation’s cyber security. The more emails we receive, the greater the risk that a cybercriminal will gain access to your organisation’s data and secrets. Proven Danger Real world tests have proven that the threat posed by Australians’ “email encumbrance” is real. Proofpoint conducted 183 million phishing simulations earlier this year. They observed that almost one in six recipients of a suspicious phishing email failed to protect their organisation’s valuable data. Recipients variously clicked malicious links, succumbed to a bogus password reset, or downloaded ransomware. What leads employees to fall for phishing and malware…? It’s “breach fatigue” – employees who have become complacent and careless about cybersecurity. Cyber Complacency Professor Sanjay Jha, UNSW Lead of the Cybersecurity Cooperative Research Centre, said: “It’s human nature that you start to just get used to certain things. (But) phishing attacks continue. In fact they are getting ever more innovative.” He urged companies to do more to keep personal data safe from hackers. “The problem is that ICT systems are very complex and every day new applications are deployed, and new information is stored and exchanged.” Whole-of-Enterprise Email Protection With escalating email volumes creating a high and persistent risk of cyber incursion, organisations need a systematic way for employees to securely and reliably exchange files and emails with external third parties. Thankfully, there are technical safeguards you can put in place to prevent your employees from accidentally - or negligently, or maliciously - allowing cyber criminals in. Not only will they help protect your organisation from cyber criminals, as a bonus, they’ll also improve your employees’ efficiency. Our SFT Threat Protection Bundle enables your organisation’s email system to automatically detect and prevent phishing links and other malware from entering your organisation. Better still, it can also automatically detect and prevent employees from sharing malware or sensitive information. Active Threat Protection If an employee - knowingly or unknowingly - attempts to share a file containing malware, the files are intercepted and “sanitised”. That is to say: their malicious elements are automatically removed. The SFT Threat Protection Bundle can also go a step further and automatically detect and prevent employees from sharing sensitive information. For example, let’s say a folder has Word or PDF documents, or Jpeg images, which contain Personally Identifiable Information. If an employee attempts to transmit any of these files, a secure ICAP gateway will automatically inspect and block the transfer. Or if you prefer, the gateway can be configured to automatically redact (i.e. mask out) sensitive information from documents and image files while still permitting the remainder of the file to be shared. Free Demonstration If you’d like to see first-hand how our SFT Threat Protection Bundle can help keep your organisation’s data safe, and help beleaguered employees keep their guards up, why not get in touch and have an obligation-free chat with me? At Generic Systems Australia , we’re your local experts in secure managed file transfer. PS: In the three minutes it took you to read this article, almost a billion new emails were sent around the world - many of them to and from Australians! Previous Next

  • Migration Services make upgrading easy | GSA

    < News Migration Services make upgrading easy 17 Mar 2024 Are you attracted to the security and efficiency of a Managed File Transfer solution… but a little worried about the potential disruption of installing one? You needn’t be! Our technical experts at Generic Systems Australia have decades of experience migrating clients from handwritten scripts, outdated integration packages and other legacy software - and everything in between. So it’s no surprise that many of our clients prefer to leave the changeover to us and our Migration Services. Our technical experts can quickly and efficiently install GoAnywhere MFT – the world’s leading file transfer solution – and then configure it to replace all your existing scripts, integration packages and other file transfer middleware. You and your team can keep on doing what you do best – free of distractions – while we do what we do best. Once you have GoAnywhere MFT installed, you may be pleasantly surprised at just how simple it is to set up further automated file transfers into the future. GoAnywhere features an easy-to-understand drag-and-drop interface to create automatic file translation and transfer workflows. In fact, configuring workflows is so easy that most users quickly learn to do it themselves, freeing up your technical staff to focus on other important work. If you’d like to discuss how your organisation’s file transfers can be made more efficient and secure, please feel free to contact our Business Manager , Bradley Copson (mail to: bradley@gensys.com.au ). He’s always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Generic Systems Australia Your Local Experts in Secure Managed File TransferMore Resources at: www.gensys.com.au (Covering Post by Bradley a few days later) Talking to clients, I sometimes sense they’re worried about the perceived complexity of moving from their existing ad-hoc file transfers to a modern, secure and efficient Managed File Transfer solution. I reassure them that they needn’t be concerned. Our technical experts at Generic Systems Australia have decades of experience migrating clients from handwritten scripts, outdated integration packages and other legacy software - and everything in between. This article explains the benefits and advantages of using our Migration Services . #MFT #managedfiletransfer #securefiletransfer #sft #cybersecurity #datatransfer Previous Next

  • GoAnywhere V7.7 released – with Fortra Threat Brain protection | GSA

    < News GoAnywhere V7.7 released – with Fortra Threat Brain protection 13 Dec 2024 Great news for our GoAnywhere MFT customers, with your software now able to leverage insights from Fortra Threat Brain to further protect your managed file transfers. Fortra Threat Brain is a comprehensive cyber security information hub, fed by telemetry from the Fortra’s expansive portfolio of products as well as insights from across the dark web, social media, and law enforcement. It brings together a team of threat intelligence analysts and partners, an expansive portfolio of AI-enabled cybersecurity products, and a vast array of intelligence sources, to provide even stronger protection for your valuable data. The up-to-date threat intelligence from Fortra Threat Brain enables GoAnywhere to reject HTTP/S service connections flagged as malicious. That includes connections to GoAnywhere’s Web Client, AS2, AS4, and any other endpoints that run on the HTTPS service. Extended file transfer protection is just one of many enhancements available in GoAnywhere Version 7.7, now released to customers for download. (And if you’d like our help with upgrading, be sure to check out our GSA Annual Upgrade & Health Check Service .) Previous Next

  • Secure Your Email with these 6 Steps | GSA

    < News Secure Your Email with these 6 Steps 16 Apr 2024 Secure Your Email in 6 Steps Email continues to be the world’s most frequently-used tool for collaboration. In fact, research group Radicati predict 376 billion emails will be sent by 4.5 billion users by the end of next year. Email’s enduring popularity makes it a prime target for cyber criminals. Phishing attacks, spam, and viruses, as well as compromised business emails being used as a gateway to other forms of data loss, can turn email from a collaboration tool into a weapon used against you. Balancing risk vs restraint With so much at stake, IT teams need to carefully balance the minimisation of email risks against the potential for placing draconian restraints on their organisation’s ability to efficiently conduct business. Secure Email Gateways –– such as the Clearswift Secure Email Gateway –– help organisations achieve the right balance for them, enforcing protective email policies without overburdening IT departments, email administrators and messaging teams. Handle with Care Email attachments continue to be a particular risk, and so, managing their transmission warrants particular care. A secure alternative to emailing files, such as the Secure Mail module in GoAnywhere MFT, enables employees to easily send files to other individuals via a secure link with a specific expiry date. Because it is much more secure than traditional email, Secure Mail doesn’t limit the size or types of files being transmitted –– a drawback of many email clients such as Outlook and Gmail. 6 Steps to Secure Email From our many years of helping organisations protect their valuable data, we recommend IT teams define robust email security policies and determine what’s required from their email security defence, by following these six easy steps: 1. Define which data needs to be protected 2. Be clear about the dangers 3. Establish a robust and sustainable email security policy 4. Close the zero-day window 5. Encrypt sensitive data 6. Monitor behaviour and performance --- If you’d like to discuss how your organisation’s email can be made more secure –– without impeding your team’s efficiency ––p lease feel free to contact me , Bradley Copson (mail to: bradley@gensys.com.au ). I’m always happy to have an obligation-free discussion, explain how we can transition you from your existing approaches hassle-free, and offer you a zero-cost Proof of Concept. Generic Systems Australia Your Local Experts in Secure Managed File Transfer #MFT #managedfiletransfer #securefiletransfer #sft #cybersecurity #datatransfer Previous Next

bottom of page