Search Results
219 results found with an empty search
- Australian MFT Buyer's Guide | GSA
Our comprehensive Buyer's Guide will help you consider the questions, options and opportunities for finding the right MFT solution for your organisation. To receive a free copy in your inbox, simply share your email address with us below. First name Last name Enter your email address and click "Receive Guide". (We'll protect your privacy as per our Privacy Policy.) Phone Your Buyer's Guide has been emailed to you! RESOURCES Receive Guide HOME
- New Cyber Laws Passed – What Australian Businesses Need to Know and Do | GSA
< News New Cyber Laws Passed – What Australian Businesses Need to Know and Do 27 Nov 2024 Earlier this week, the Australian Parliament passed a suite of legislative reforms designed to enhance Australia’s cyber security. The reforms include a raft of new requirements and obligations on Australian businesses. About the Legislation Based on recommendations by the Parliamentary Joint Committee on Intelligence and Security, the new legislation addresses a number of proposals initially set out in Australia’s 2023 – 2030 Cyber Security Strategy, and spans three separate Acts: 1. the Cyber Security Act 2024 (Cyber Security Act); 2. the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 ; and 3. the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (SOCI Amendment Act). Mandatory reporting of ransom payments, and the introduction of a new voluntary information sharing regime, will have the most immediate impact on organisations. Mandatory Reporting of Ransomware Payments Ransomware attacks are rife across Australia. The Australian Signals Directorate (ASD) reported that this form of cyber extortion accounted for 11% of all cyber incidents to it in 2023-2024, up from 8% in the previous year. The Government had previously pursued a ban on ransom payments. However, its position has since moderated somewhat. The Cyber Security Act only requires organisations to report ransomware payments to the Department of Home Affairs and the ASD. This new reporting obligation will commence at latest six months after the Act receives royal assent (potentially earlier by proclamation) and applies broadly to: · organisations which are a responsible entity for a critical infrastructure asset; and · other private sector organisations which conduct business in Australia with an annual turnover exceeding a threshold (to be specified - likely to be A$3M). Ransomware reports are required to be made within 72 hours of making a payment (not the receipt of a demand or the discovery of a ransomware attack). Difficult Decisions The requirement to report payments will need to be taken into account by Boards when considering whether to pay a ransom. The Government’s general view on ransoms continues to be that organisations should not pay them. It reasons that payments don’t guarantee the recovery or confidentiality of stolen data, but do encourage cyber attacks to proliferate. Organisations in receipt of ransom demands are left to ponder several competing considerations… · Paying a ransom could potentially contravene sanctions (such as the one imposed on Aleksandr Ermakov, the individual responsible for the 2022 Medibank data breach) or anti-money laundering laws. · Company Directors fulfilling the duty of care to act in the best interests of their organisation will need to balance the risks of payment - commercial damage, incentive to re-target, uncertainty of data recovery – against the risks of not paying - loss of systems data, reputational damage, third party claims, lost customers and business disruption. If a ransom payment is made, then the new mandatory reporting obligation will be in addition to other applicable reporting requirements an organisation is subject to. These could include the Privacy Act 1988 , the SOCI Act , and continuous disclosure obligations under the ASX Listing Rules and CPS 234. In fact, it’s important that Cyber Incident Response plans developed by organisations specifically address these overlapping requirements, taking into account the various regulators and timeframes of each. Be aware that, for any entities regulated under the SOCI Act , it’s also conceivable that the Government could use its directions power to direct an entity to pay - or not pay - a ransom. An organisation which fails to comply with mandatory ransom reporting will incur a civil penalty of 60 penalty units (currently A$93,900). Voluntary reporting regime A new National Cyber Security Coordinator (NCSC) is being established under the Cyber Security Act to lead a whole-of-government response to significant cyber security incidents. The Act provides a framework for the voluntary disclosure of information by any organisation operating in Australia, or any responsible entity under the SOCI Act , to the NCSC relating to cyber security incidents. However, it imposes various limitations on how the NCSC may further use and disclose information voluntarily provided by entities, depending on the significance of the incident. Non-significant cyber security incidents: Information can be used for limited purposes such as directing the reporting entity to assistance services, coordinating a government response, and informing Ministers. Significant cyber security incidents: Information can be used for broader ‘Permitted Cyber Security Purposes’. These include preventing or mitigating risks to critical infrastructure or national security, and supporting intelligence or enforcement agencies. A cyber security incident is deemed “significant” if: there is a material risk that the incident has seriously prejudiced, is seriously prejudicing or could reasonably be expected to prejudice the social or economic stability of Australia or its people, the defence of Australia or national security; or the incident is, or could reasonably be expected to be, of serious concern to the Australian people. Information voluntarily provided by organisations to the NCSC is subject to limited use protections similar to those which apply to information disclosed as part of a ransomware payment report. The new voluntary reporting regime and corresponding limited use protection has come into immediate effect. Limited use protection The Cyber Security Act outlines how businesses should work with the NCSC and other government agencies to obtain assistance and guidance when responding to cyber incidents. It also provides businesses with certain limited use protections when collaborating with the government’s cyber security agencies - a legislative foundation for the CISA Traffic Light Protocol government agencies have recently offered when assisting organisations. Such protections were requested by business lobby groups. They provided feedback during the public consultation period that disclosing information about a data breach could risk exposing an organisation to further regulatory or enforcement action, adverse publicity and litigation. Further, if disclosing a cyber incident was determined to be against an organisation’s best interests, its directors could potentially be in breach of their duties in approving the disclosure. That could in turn expose directors to enforcement action from ASIC. Counterweighing these concerns, the Government believes that sharing information on current threats and incidents can help other organisations avoid similar incidents. In balancing these competing interests, the Cyber Security Act limits the purposes for which information contained in a ransomware payment report or voluntarily report provided to the NCSC can be used or disclosed. The NCSC (and any Government agency it coordinates with) cannot record, use or disclose the information provided for the purposes of investigating or enforcing or assisting in the investigation or enforcement of any contravention of a Commonwealth, State or Territory law. An important exemption from the limited use protections are that crimes and breaches of the limited use protections created by the Act. In this way, the protections stop short of being a full “safe harbour”. Information provided under these protections isn’t admissible in evidence against the disclosing entity, including criminal, civil penalty and civil proceedings (including a breach of the common law). And the provision of information to the NSCS does not affect any claim of legal professional privilege over the information contained in that information. These limited use protections will be of value to organisations disclosing information to the Government about cyber incidents. However, directors should bear in mind the notable gaps in the protection they provide. For example: Information provided can’t be used or disclosed for the purposes of investigating or enforcing any contravention by the reporting entity of another law (whether federal, state or territory), other than a law that imposes a penalty or sanction for a criminal offence. This means that if the ransomware report indicates that a payment was made in breach of relevant sanctions laws, then the limited use protection will not prevent the use of the report in a subsequent investigation or enforcement action. While information provided to the NCSC cannot be obtained from the NSCS by regulators or government agencies, the protection offered under this Act does not prevent regulators from obtaining the underlying information through other means, including via regulatory investigatory powers or where provided under other mandatory reporting regimes, such as those in the Privacy Act 1988 , the SOCI Act, the Telecommunications Act 1997 and the ASX Listing Rules continuous disclosure obligations. So, cyber incident notifications provided to the ACSC under the SOCI Act are not captured by the limited use protection, even if that information is also voluntarily provided to the NCSC or detailed in a mandatory ransomware report. A similar limited use protection has been introduced via the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 for cyber incident information voluntarily shared with the ASD. Other Inclusions in the Legislation This article has focused on developments within the new Cyber Security legislative reforms which will most impact companies and organisations. However, in the interests of completeness, here is a brief overview of other key developments covered in the legislation: Mandated Security Standards for Internet of Things (IOT) Devices. These standards will be detailed in legislative rules, with suppliers required to provide a statement of compliance for devices supplied to the Australian market. New Cyber Incident Review Board. This independent advisory body will be empowered to conduct no-fault, post-incident reviews of significant cyber security incidents and provide recommendations and information to both the private and public sector. It will have the power to compel entities to provide information about significant cyber security incidents. Critical Infrastructure definition expanded. Data storage systems which hold business critical data have been added to the definition of critical infrastructure assets. This closes a gap in the regulations which became apparent in the aftermath of the Optus and Medibank data breaches. Expanded Incident Response Powers. The Government will now have the power to direct an entity to take, or not take a specific action, in the event of a cyber incident affecting critical infrastructure. Security and incident notification obligations moved from the Telecommunications Act 1997 to the SOCI Act , consolidating the cyber obligations of telecommunication carriers and carriage service providers under a single piece of legislation. What Organisations Should Do Cyber security response plans should now be reassessed and upgraded to ensure they align to the new mandatory ransomware reporting requirements. Playbooks and procedures should take account of how an organisation plans to engage with cyber security authorities, bearing in mind the extent - and limitations - of the defined limited use protections. Focus on preventing cyber incidents - not just responding to them . A Managed File Transfer (MFT) solution such as GoAnywhere MFT can encrypt data at rest and in transit, complying with the highest data security standards. It manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols and encryption to protect your data. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection facilitates safe collaboration with external parties, helping to prevent malware from entering an organisation, and reducing the risk of employees losing or mishandling sensitive data. Finally, organisations should seek professional legal counsel in determining and responding to their obligations and responsibilities under the new Cyber Security legislative reforms. The information provided in this article has been general in nature, and the interpretations and advice outlined above should not be interpreted as professional legal advice. Previous Next
- Top 5 MFT Trends in 2026 | GSA
< News Top 5 MFT Trends in 2026 27 Jan 2026 With January’s holidays fading into memory and business getting back to work, it’s time to look ahead at what 2026 holds for data movement—the lifeblood of modern enterprises. As data volumes surge and digital ecosystems grow more complex, the systems responsible for secure file transfers are undergoing a major evolution. Organisations are exchanging more data than ever, and the demand for secure, compliant, automated file movement is rising just as quickly. Managed File Transfer (MFT) has long been the trusted foundation for these exchanges, but the landscape is shifting rapidly thanks to advances in AI, analytics, and cloud technologies. The era of basic point‑to‑point transfers is receding. Today’s MFT platforms must deliver intelligence, transparency, and the ability to scale across increasingly hybrid environments. Here are five major trends that will reshape MFT in 2026 and beyond. 1. Smarter Automation Through AI and Predictive Workflows Automation has always been a core strength of MFT, but AI is set to elevate it further. Organisations will use machine learning to predict issues before they occur, fine‑tune transfer schedules, and boost overall reliability. The file transfer logs and automated workflows generated by GoAnywhere MFT provide invaluable input to AI agents. By analysing this historical data, AI can recommend optimisations for bandwidth, security, and efficiency. 2. Real-Time Visibility and Advanced Reporting for Stronger Decisions In a world defined by big data, visibility is everything. Understanding how files move across an organisation—where they go, how fast they travel, and whether they meet compliance requirements—is essential. That’s why modern MFT platforms must offer real‑time monitoring, detailed reporting, and actionable insights. Dashboards and audit logs give IT teams a live view of transfer activity, helping them track throughput, capacity, SLA performance, and overall system health. This level of transparency is especially valuable for enterprises managing large volumes of sensitive data across multiple departments or global locations. Better visibility leads to better decisions and more efficient operations. 3. Centralised Security and Compliance Control With data privacy regulations tightening worldwide, organisations can no longer rely on a patchwork of tools for encryption, authentication, and data loss prevention. MFT platforms are increasingly becoming unified hubs for enforcing security and compliance. GoAnywhere MFT offers a single, web-based interface to automate, encrypt, and audit file transfers across on-premises, cloud, and hybrid environments. It replaces fragmented scripts and manual processes with a unified platform that secures data in transit and at rest—directly supporting compliance with PCI DSS, HIPAA, GDPR, FISMA, and other regulations. By consolidating these capabilities, organisations reduce compliance complexity and maintain consistent security across every file exchange. 4. Cloud-Ready Deployment and Hybrid Flexibility As organisations modernise their infrastructure, flexible deployment has become a top priority. MFT solutions now need to support on‑premises, cloud, and hybrid environments without compromising control or compliance. This shift toward cloud‑ready MFT reflects a broader trend: businesses want agility without sacrificing security. GoAnywhere MFT is a centralised, platform-agnostic solution that can be deployed across on-premises, cloud, and hybrid environments. It facilitates secure, automated data exchange between internal systems, trading partners, and popular cloud services (e.g. AWS S3, Azure Blob, SharePoint, Salesforce) using built-in Cloud Connectors and lightweight, centrally managed agents. 5. API-Driven Integration and Seamless Interoperability MFT is no longer just about moving files—it’s becoming a central connector between enterprise systems, cloud applications, and external partners. Modern platforms support robust REST APIs and standard protocols such as SFTP, FTPS, HTTPS, and AS2, making it easier to integrate with ERP, CRM, SIEM, and other business systems. This interoperability reduces manual handling, improves data consistency, and streamlines automation across workflows. In an API‑centric world, MFT plays a crucial role in ensuring data flows securely and efficiently across the entire ecosystem. The Next Era of Intelligent File Transfer MFT has been a staple technology for years, but many legacy solutions are reaching end‑of‑life. The next generation of MFT is about more than secure transfers—it’s about enabling intelligent, data‑driven operations. Organisations embracing AI‑enhanced automation, real‑time analytics, compliance‑ready security, flexible deployment models, and API‑first integration will be best positioned to protect their data and stay ahead of operational challenges. The future of file transfer isn’t just secure. I’s smart, adaptive, and deeply connected to the broader digital landscape. Global Trends – Local Expertise At Generic Systems Australia , we’re Australia’s and New Zealand’s experts in helping organisations leverage the world’s leading Managed File Transfer solutions. If you’d like to discuss how we can help you, please feel welcome to get in touch with me . I’m always happy to have an obligation-free chat. Previous Next
- "The Case of the Camouflaged CSV" | GSA
< News "The Case of the Camouflaged CSV" 3 Sept 2025 It was a typical rainy Wednesday in the Cloud. I was nursing a lukewarm S3 bucket of coffee that was almost as bitter as my ex-wife. And that’s when she sauntered into my inbox—legs for days and resolution to match. Said she’d lost something precious: a young .CSV file named “Quarterly_P&L_FINAL_FINAL_v7.docx”. She’d been told I was the kind of dupe who could go find it. And I knew right then this case was going to be messier than an Agile Standup on a Friday afternoon. “Please,” she purred, her pixel-perfect lips trembling. “She vanished right after I hit ‘Send.’ Now she’s nowhere. Not in my Sent Mail. Not in OneDrive. Not in Dropbox. Not even in the Recycle Bin. Just… gone.” I leaned back in the battered Aeron I’d accepted from the last dame who hadn’t had the means to pay me, and reassured her I’d seen this kind of thing way too many times before. “Could be the work of Miss Configuration,” I mused. “Or worse… hackers.” “Please,” she begged, making like the waterworks were about to flow. “You’ve got to F1 me.” I sighed wearily… I’m always a sucker for a dame in distress. But she was right - I was her only chance of being reunited with her beloved .CSV. So I zipped up my trench coat, flipped my firewall to DND, and hit the dirty streets of cyberspace. First stop: the Dark Web. Sin City City plans don’t show where the Dark Web district begins. Nor is there any bullet-ridden road sign to let you know when you’ve crossed from the mean streets to the even meaner streets. But I knew I was there when I saw the familiar shady characters loitering — pop-up hustlers, cookie pushers, and a guy selling expired SSL certificates within the folds of a battered trench coat. I asked around for leads. “Try The Cache,” said a greasy bookmark with a twitchy scroll wheel. “Files go there to be forgotten.” Cold Cache I didn’t need directions. The Cache was a hidden side bar accessible only through a back door. I gave the bored muscle the password I’d bought from a PII broker and pushed into the shadowy crowd of malware and malcontents. The bartender—a grizzled old exe named Clippy—eyeballed me with suspicion before recognising me. “Well, well… if it ain’t GoAnywhere Gumshoe,” he said, polishing some code with a Dirty Markup tea towel. “Chasing another ghost in the machine?” “Not this time, Clippy,” I said. “This time she’s a file. A CSV. Corporate. Probably jacked full of lies and pivot tables.” Clippy winced. “You don’t want that kind of trouble. Last guy in here who asked about spreadsheets is still in a recursive loop.” I slipped Clippy a few kilobytes and he pointed me towards a shadowy booth. In it sat a rogue AI named DataDaemon, sniffing packets as he pored over a Docker container. “Yeah, she was here,” DataDaemon confirmed. “That file you’re looking for. But she wasn’t flying solo. She was hanging off the arm of… him.” “Who…?” “The PDF.” The Unusual Suspect I cursed under my bandwidth. The PDF—slick, immutable, and always up to something. But I had something up my sleeve that the PDF wouldn’t have counted on. It was for a case just like this one that I’d always maintained The Logs. And now The Logs were going to lead me through the brooding labyrinthine of the metadata metropolis, straight to The PDF and his hostage CSV. In no time, I tracked The PDF to a sleazy compression joint called The Zipper Club. He was lounging in a NAS, smug as a first gen backup, not suspecting a RAID. “Searching for your cute little CSV?” he sneered. “Well she ain’t going back. She craved permanence. And I gave her structure. Fonts that don’t shift. Headers that don’t cry.” I lunged at him, but he was fast—encrypted and password protected. I barely clocked his checksum before he was out the door and into the swirling Cloud again. A Ctrl-Breakthrough Back at my office, I stared at the blinking cursor. The trail seemed to have gone cold. It had been a busy day, and my RAM felt fried. But I had a reputation to maintain. I’d never failed a client before… and I sure as hell wasn’t going to fail this one, either. Running through The Logs one more time, I saw it… a timestamp: 3:14 a.m. That was bang in the middle of the witching hour for network traffic — prime time for somnambulant systems to engage in mundane crosstalk and perform glacial backups. I picked up the CSV’s trail again in a neglected SharePoint graveyard. And then there she was, buried six layers deep in folders labelled “Misc”, “Old Stuff” and “DO NOT DELETE”. I exhumed her gently. She was intact, but changed. Her margins were off. Her fonts had gone rogue. Someone had run a mail merge on her. I brought her back to Miss JPEG, and this time, there was no holding back the flood of pixelated tears. “You found her,” she said. “But she’s… different.” “Aren’t we all,” I said, pointing my chin in the direction of the window, where a new day was shooting the first golden rays of hope through the night’s dark Cloud. I gestured towards CSV’s Version History. “She’s still there,” I said. “Just sleeping. Until you restore her.” Epilogue I leaned back in my Aeron and tipped my fedora over my eyes. I knew today would bring another client, another case, another missing file. But for now, the system was stable. And I was still the best damn gumshoe on the cyberspace beat. Fade to black. Cue saxophone MIDI. If you’d like a GoAnywhere Gumshoe protecting your files, please don’t hesitate to contact me . At Generic Systems Australia , we’re your local experts in Managed File Transfer technology. Previous Next
- Black 'Fileday' | GSA
< News Black 'Fileday' 29 Nov 2023 Australian shoppers were tipped to spend $6.36B across the Black Friday weekend, according to the Australian Retailers Association.The surge in sales has in turn created a tsunami of data transfers, as businesses share orders, files and information with their supply chains.For some businesses, it will be a stressful period. But others - those who entrust their file transfers to GoAnywhere MFT - will surf the data tsunami with ease, as GoAnywhere conveys all their valuable files reliably and securely.(And of course, our local technical team at Generic Systems Australia will always be on hand to share our unparalleled MFT expertise with our customers.) Previous Next
- WHY AUTOMATING ENCRYPTION | GSA
Why Automating Encryption and Decryption Makes Cybersecurity Sense How does encryption and decryption work? Which types of encryption are best suited to different data transfer needs? How can encryption be integrated with your existing business technologies? Our guide, Why Automating Encryption and Decryption Makes Good Cybersecurity Sense, offers a quick read of the basics of encryption, answering these questions and more. To Receive Our Report, Please Fill in the Form Below: First name Last name Enter your email address Phone You'll receive the 'Why Automating Encryption and Decryption Makes Cybersecurity Sense' shortly! RESOURCES Receive Report HOME
- Use APIs to accelerate your MFT’s ROI | GSA
< News Use APIs to accelerate your MFT’s ROI 26 Nov 2024 Leveraging APIs alongside your Managed File Transfer (MFT) solution is a great way to boost the return on investment from your MFT, and scale its deployment more broadly across your organisation. Here’s how to use APIs to add further automation, integration, scalability, and customisation to your MFT. APIs…? APIs (Application Programming Interfaces) help software applications communicate with another. Enabling APIs with a robust MFT solution is a simple way to add new functionality to your data transfer software, and accelerate the productivity and efficiency gains it offers. APIs will help you integrate your organisation’s data transfers with the many applications your organisation already use daily - CRM platforms, business intelligence tools, ERP systems and more. In doing so, you can synchronise data across your organisation and provide your team with more secure collaboration. Flexible MFT solutions that support APIs also enable you to further customise and automate your file transfers for your unique business and operational needs. Enhanced Security Of particular value is the way APIs can boost an organisation’s cyber defences by integrating their MFT solution with other data-centric security systems. For example, Generic Systems Australia’s Advanced Threat Protection Bundle layers an organisation’s protective measures with the security features of Fortra’s GoAnywhere MFT to further secure sensitive data. The added flexibility to evolve and scale as your needs change can be a game changer for IT teams seeking to maximise user experience and organisational ROI. Better Workflows Automated file transfer workflows can be “supercharged” using APIs. Here are seven specific API features and techniques organisations can leverage to maximise the value they derive from their managed file transfer solution. In each of these examples, we’ll feature API integration with GoAnywhere, the independently-assessed class-leading MFT. GoAnywhere not only provides APIs, it can also consume third-party APIs, and act as middleman, or API gateway, between other applications. 1. RESTful API An interface used by two computer systems to securely exchange information over the internet, REST (Representational State Transfer) can be used to manage users, groups, triggers, projects, and schedules. This simplifies new user onboarding and migrating systems and environments. For example, you can use the REST API to create a new web user programmatically and eliminate the manual tasks often needed for on-boarding new trading partners. You can also start/stop file transfer jobs and query the status of active jobs. 2. REST Enable a Secure Form Within the GoAnywhere dashboard you can select REST Enable Secure Forms to trigger more complex API calls on the backend of Advanced Workflows . Then, using standard REST calls you can invoke the secure form and its underlying project. Rest Enabled Secure Forms can also act as a REST API gateway to computing resources normally not available to public internet users. The GoAnywhere server can be deployed on the secure network and the solution’s Secure Gateway can act as the link to the public internet in the DMZ. An administrator can enable curated access to internal REST APIs that would normally be available only via VPN or by a dedicated network connection. Comprehensive audit logs and fine-grained user access controls can turn GoAnywhere MFT into a complete API gateway. The Method createPayload (GET https://localhost:6443/rest/forms/v1/ticket/payload ) will insert the payload. The Method uploadAttachments (POST https://localhost:6443/rest/forms/v1/ticket/payload/ :payloadId /file ) will upload one attachment at a time. The Method submitPayload (POST https://localhost:6443/rest/forms/v1/ticket/payload/ :payloadId /submit ) will submit the payload. The Method downloadAttachment (GET https://localhost:6443/rest/forms/v1/ticket/payload/ :payloadId /file/ :fileId ) will download one attachment at a time. 3. GoAnywhere HTTPS You can use GoAnywhere HTTPS project tasks to automate file transfers, create Secure Mail Packages, or programmatically place files in Secure Folders for uploading or downloading For example, if you need to send a large, automatically generated report to a user, you can enable the GoAnywhere HTTPS Send Package task in GoAnywhere. Simply create a project to automatically pick a file (or files) and send a package as a link via Secure Mail. You can protect that package with a password, track the number of downloads, or prevent further downloads after 24 hours. Another GoAnywhere HTTPS task is the ability to set up programmable uploads to GoDrive, a solution which provides Enterprise File Sync and Sharing (EFSS) services for employees and partners. 4. Quick Uploads Enabling Quick Uploads in HTTP Service enables you to turn GoAnywhere into a REST endpoint for file exchange. Quick Uploads (which requires a POST Method with Authentication) allows the solution to upload files to GoAnywhere via REST, effectively turning your GoAnywhere Secure Folders feature into a REST-enabled file exchange gateway. REST-enabled file exchange is very useful for other applications to have a place to store and exchange files. The end users don’t really know what is happening under the hood, but it allows application developers to provide lots of flexibility and build easy-to-use applications. 5. Project Run Mode You can start a project in the background in the dashboard's triggers, schedules, and within the project designer’s Call Project task. For example, if you need to start a long-running job, you simply start a job in Batch mode, which will run in the background, and the system will be automatically notified when it is finished. Need to copy a huge file set? Then run a Job that spawns multiple Batch Jobs. For example, every sub folder in your file set could be sent as separately spawned batch jobs. Running multiple jobs in the background in parallel will help optimise your computing resources, increase your throughput, and spread the workload to other nodes in your GoAnywhere cluster. In addition to setting the run mode, you can also set the priority and the job queue. For example, some long-running CPU intensive jobs, such as archiving or backup, can be set to run on a lower priority status or on a lower priority queue so that your core MFT operations remain more responsive. 6. Consume Third-Party APIs Consuming APIs is the process by which an application developer accesses the various APIs that are exposed by the API provider and then uses those APIs to develop one’s own software applications and products. Within GoAnywhere you can use HTTP/HTTP Post and GET Project tasks or Webservices REST tasks to call third-party APIs. For example, once a file is uploaded, you can create a trigger that will automatically import the file into third-party applications, such as a CRM or trouble ticketing system. Additionally, GoAnywhere offers Cloud Connectors to the most popular applications in the industry. (If you cannot find a cloud connector for the application you need, use the Project Webservices or HTTP/HTTPS POST Project tasks to connect via REST to the application of your choice.) 7. Promote Features Continuous Integration and Delivery CI/CD functions are important in every large IT Project. GoAnywhere delivers the ability to promote every user, project, schedule, trigger, secure form etc, from development to staging to production. You can use “Promote” REST API calls to automatically migrate your configurations from development to staging to production. Working on a live production system presents additional challenges. Even the most diligent administrators can make mistakes and accidentally delete or rename configurations which take an entire system offline. Using GoAnywhere’s Promote features, either via GUI or as an API call, is required to maintain maximum system stability and reliability. If you do not have a test system yet, consider deploying one to minimise the risk of human error. API Options to Boost Automation GoAnywhere offers many powerful API options that can seamlessly automate basic file transfer tasks for IT teams and users. You can mix and match the seven techniques above to create a next-generation automation framework that goes far beyond standard MFT functionality. Need Help? It’s Here - Locally! If you’d like help using APIs to boost your MFT’s ROI and your team’s productivity, please feel welcome to get in touch with me . I’m always happy to have an obligation-free discussion. At Generic Systems Australia , we’re your local experts in Secure Managed File Transfer. Previous Next
- GoAnywhere Modules | GSA
GoAnywhere Modules Available to License Fortra's GoAnywhere is a robust and complete managed file transfer solution. Augmenting its capabilities are Modules that can satisfy an even broader array of file transfer requirements. You can choose to license and pay for only the modules you currently need, and easily unlock additional modules, if necessary. ADVANCED WORKFLOWS The Advanced Workflows Module is used when you are initiating the transfer (push/pull), if PGP encryption/decryption is needed, if data needs to be pulled from or uploaded to a database, and if additional actions in a workflow need to be called before/after a file exchange. GoAnywhere MFT includes more than 60 built-in tasks for performing a wide variety of business processes. This includes tasks to retrieve and distribute files, transform data, encrypt/decrypt files, compress/decompress files and interact with databases. Other tasks can be used to call native commands, execute programs, send emails, search and replace file contents and more. You can also build your own custom tasks to use within Projects. This is especially helpful if you need to perform special processing or connect to ERP systems and other applications using proprietary interfaces. Multiple tasks can be "chained" together within a Project to perform a series of steps. For example, a Project could be defined with a task to retrieve an XML file from a trading partner, then another task to parse the XML and finally a task to import the data into a database table. Built-in Tasks include: -Compression (inc Zip, UnZip, GZip, GUnzip, Tar, Untar) -Database (SQL statements supported by the database server) -Data Translation (inc CSV, Excel, Fixed-Width, Flat File, XML, JSON, RowSet) -Email & SMS -File System -File Transfer -Integration (IBM I, Native Commands, SSH commands, ICAP, SNMP Trap) -Job Control (Calls to Modules and Projects, If/Else Conditionals, Timing, Error logging etc) -Loops (Do-While, For-Each, Iterate, While etc) -Miscellaneous (Base64, Deny Trigger Event, Print, Secure Form Response, Set Variable, Timestamp) -Message Queue (Send, Retrieve, Commit, Rollback etc) -PGP (Encryption, Decryption, Sign, Verify) -Project (Comment, Import, Modules, Variables) -Reports (>20 customisable Reports) -Web Services (JWT, SOAP, REST) SFTP SERVER The SFTP Server Module handles the server side of an SFTP transfer. Your partner connects to you via SFTP and initiates the transfer. An SFTP server provides a way for organisations to securely exchange sensitive files over a network. SFTP helps ensure data integrity and security by using encryption and authentication during the file transfer process. GoAnywhere MFT, an enterprise-level file transfer solution, allows your trading partners to securely exchange files with your organisation using SFTP (SSH File Transfer Protocol) and SCP (Secure Copy) protocols. The solution also supports the latest SSH 2.0 protocol standard and allows for both password and SSH key authentication. An encrypted tunnel is created between the SFTP server in GoAnywhere MFT and any trading partners, which protects all data, user ids, passwords and commands that flow over the connection. Secure FTP is critical for compliance with PCI DSS, HIPAA, HITECH, SOX and state privacy laws. Through GoAnywhere’s SFTP client, organisations can exchange files between their local system and a remote server, with data encrypted via the SSH protocol. SFTP Server Features: -Highly scalable with no restrictions on the number of trading partners. -Support for multiple listeners with configurable port numbers -Remote administration and monitoring through a browser-based interface -Robust security and granular permission controls -Multiple authentication methods; database, Active Directory (AD), LDAP and IBM i -Administrators can view active sessions for logged-in users -Event triggers to automatically process files or send email notifications -Support for client requests to resume file transfers -Configurable settings for maximum number of sessions, maximum login failures and idle timeouts -ZLIB compression to reduce bandwidth requirements -Ability to accept or reject files with certain extensions -Allows only strong NIST-certified encryption algorithms when in FIPS 140-2 Compliance mode -Can be installed in the private network without opening inbound ports, when paired with GoAnywhere Gateway in the DMZ SFTP Logging Audit trails (logs) are generated for all SFTP and SCP sessions in GoAnywhere MFT to meet auditing and compliance requirements. This detail includes: -commands issued -messages -IP addresses -user ids -file names transferred. Log messages can additionally be sent to a SYSLOG server using UDP or TCP connections. SSH Key Management Intuitive graphical screens are provided in GoAnywhere MFT to allow for the management of SSH Keys. This Key Manager can be used to create SSH public and private keys, import and export keys, and view keys. Both RSA and DSA key types are supported with key lengths up to 4096 bits. High Availability Planning with SFTP When it comes to file transfers, it’s critical that organisations are able to complete them without disruption. Businesses can choose from either active-passive and active-active high availability plans. -Active-passive plan failure downtime for trading partners can run from a few seconds to a few hours depending on how organisations start the passive system. -Active-active plan failure downtime is most commonly zero because there is always a backup system that can take over in a moment of system failure. These high availability plans can help organisations minimise and avoid downtime, meet SLAs, and increase user satisfaction. Standards Support for SFTP Server: -Protocol: SSH 2.0 -Ciphers: AES-128, AES-192, AES-256, Triple DES (DESede), Blowfish -MAC Algorithms: HMAC-SHA1, HMAC-SHA2-256, HMAC-MD5 -Key Exchange Algorithms: diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1, diffie-hellman-group-exchange-sha256 -Compression: ZLIB FTPS SERVER The FTPS Server Module handles the server side of a FTPS transfer. Your partner connects to you via FTPS and initiates the transfer. GoAnywhere MFT acts as FTPS software that allows your trading partners to securely exchange files with your organisation using FTPS (FTP over SSL/TLS) protocol. GoAnywhere MFT supports both implicit SSL and explicit SSL connection types. Dual factor authentication can be performed using user ids, passwords and certificates. An encrypted tunnel will be created between the FTPS server in GoAnywhere MFT and any trading partners, which will protect all data, user ids, passwords and commands that flow over the connection. Secure FTP is critical for compliance with many data privacy laws. FTPS Server Software Features: -No restrictions on the number of trading partners -Support for multiple listeners with configurable port numbers -Remote administration and monitoring through a browser-based interface -Robust security and granular permission controls -Multiple authentication methods; database, Active Directory (AD), LDAP, and IBM i -Administrators can view active sessions for logged-in users -Event triggers to automatically process files or send email notifications -Support for client requests to resume file transfers -Anonymous logins can be enabled or disabled -Custom welcome and logout messages -Authentication can be performed using self-signed and 3rd-party signed certificates -Configurable settings for maximum number of sessions, maximum login failures, and idle timeouts -Ability to accept or reject files with certain extensions -Allows only strong NIST-certified encryption algorithms when in FIPS 140-2 Copliance mode -Can be installed in the private network without opening inbound ports, when paired with GoAnywhere Gateway in the DMZ FTPS Logs Audit trails (logs) are generated for all FTPS sessions in GoAnywhere MFT to meet auditing and compliance requirements. This detail includes commands issued, messages, IP addresses, user ids and file names transferred. Log messages can additionally be sent to a SYSLOG server using UDP or TCP connections. X.509 Certificate Management The GoAnywhere MFT Certificate Manager allows authorised administrators to work with X.509 certificates. This Certificate Manager can be used to create certificates, generate CSRs, import CA replies, import trusted certificates, export and view certificates. RSA and DSA key types are supported with key lengths up to 4096 bits. Certificates can be configured to expire at specified dates. FTPS Server Standards Support: -SSL/TLS Versions: SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1, TLS 1.2, -Connection Types: Implicit SSL -Implicit SSL Security Protocols: SSL, TLS -Ciphers: AES-128, AES-192, AES-256, DES, RC4, Triple DES (DESede) -Authentication and Key Exchange Algorithms: Diffie-Hellman, DSA, RSA -Hash Algorithms: MD5, SHA1, SHA2 -Certificate Key Store Formats: JKS (Java Key Store), PKCS12 SECURE FOLDERS The Secure Folder Module allows web users to connect to your HTTPS server via a browser. GoAnywhere MFT can be utilised for exchanging files with HTTP servers (Web Sites). Connections can be made to both standard HTTP servers and secure HTTPS servers using SSL/TLS. HTTP(S) servers can be pre-defined in GoAnywhere MFT's Administrator as reusable Resources which can then be selected from simple drop down menus. HTTP Tasks can be placed within GoAnywhere MFT Projects and executed as part of a cohesive workflow process. For example, a Project could be defined to get a CSV file from a HTTPS server, read the data from the CSV file, and import the data into a database file. HTTP(S) Features in GoAnywhere MFT: -Cookies support -HTTP Redirects support -Perform requests with parameters -Download/upload multiple files per session -Filter files to download based on last modified date/time -Utilises only strong NIST-certified encryption algorithms when in FIPS 140-2 Compliance mode -Pass in variables (at runtime) to override HTTP(S) attributes AS2, AS3, & AS4 SEND/RECEIVE The AS2, AS3, & AS4 Send/Receive Module enables secure protocols that send and receive messages. AS2 supports the encryption of messages between trading partners and vendors via HTTPS. AS4 is an open B2B standard for exchanging secure documents between businesses using web services. Each protocol provides an extra layer of security through the use of digital signatures. AS2, AS3, and AS4 are licensed by number of partners. GoAnywhere is Drummond Certified, which is required by many businesses that exchange via AS2 and AS4. SECURITY DOMAINS The Security Domains Module makes it possible to virtually segment a GoAnywhere installation into multiple security zones. Every license includes two domains. More domains are useful if you want to manage file transfers and associated users in their own domain (by department for example). Admin Users can be authorised to specific Domains, in which those users can only work with the items belonging to those Domains. Examples of items that can be assigned to Domains are Resources, Projects, Schedules, Monitors, Triggers, Admin Users and Web Users. Each Domain can be configured with file access restrictions to prevent users from accessing restricted network locations. SECURE MAIL The Secure Mail Module allows your employees to send messages and files as secure "packages" on an ad-hoc basis. Recipients will get an email with a unique link to each package, allowing them to download the message and files through a secure HTTPS connection. This is a great alternative to regular email since there are no file size or file type restrictions. Secure Mail Features: -Secure Mail can be sent from within the user's browser or from Microsoft Outlook -Multiple files can be attached to a single package -No file size limitations or file type restrictions -Includes options to set expiration dates and maximum downloads -URL link for each package is randomly generated using a universally unique identifier (UUID) -Packages can additionally be secured using a system-generated or user-specified password -Recipients do not have to deal with keys or certificates -Files are transferred over a secure HTTPS connection -Sender can choose to receive notifications when packages are read -Sender can "recall" packages to make unavailable to recipients -Customisable templates allow rebranding messages with your own logo, colours, fonts, etc. -View audit trails of all package activity (e.g. when sent, when opened, when downloaded, etc.) GoAnywhere MFT is installed within your network, so your organisation will keep localised control over the Secure Mail settings, packages and audit trails. Files will remain on your system until they are downloaded by the recipients; the files are not hosted by a 3rd party. Your employees can authenticate against an existing Active Directory (AD), LDAP or IBM i system within your network. Five free Secure Mail users are included with every GoAnywhere license. Composing Emails Messages can be composed through the GoAnywhere MFT browser-based interface or by using the GoAnywhere Outlook Plugin. With the Outlook Plugin, the user would compose the message in Microsoft Outlook as normal. When ready to send, the user would click on the new "Send Secure Mail" button to pass the message through the GoAnywhere MFT Secure Mail module. Rules can be set to automatically use Secure Mail whenever the user sends large file attachments using the regular Outlook "Send" button. The Outlook plugin supports Kerberos Single Sign-on for easier adoption by your users. Email Notifications Each recipient of a Secure Mail package will receive a notification via email. The notification will show the message subject, a summary of the attachments and a link for downloading the files in the package. Secure Email Downloads When a recipient clicks on the link in the notification email, it will open the download page over secure HTTPS protocol. The user can then just click on the files to download or open. Secure Email Administration Secure Mail settings, packages and audit logs are managed within the GoAnywhere MFT browser-based administrator. To minimise disk space usage, GoAnywhere MFT can automatically purge packages when they expire or when they meet their maximum download count. ADVANCED REPORTING The Advanced Reporting Module gives you access to important system information as PDF documents. Easily generate reports of file transfer activity, user statistics, and completed jobs from within the console. Filter reports by date, user ID, and other criteria to gain insight into the information that matters to you, as either detailed or high-level summary reports, both available with informative charts and graphs. Alongside the built-in reports, custom reports can be created using data provided from a database, CSV, Excel, fixed-width, XML, or JSON files. Reports can either be run as needed, directly through the browser-based console, or scheduled and either distributed to the network or sent via email. Custom Reporting: -a custom report based on data from a database, CSV, Excel, fixed-width, XML, or JSON file to give you ultimate flexibility on reporting. General File Transfer & System Reports: -Blacklisted IP Addresses - displays blocked IP addresses and their creation timestamp -Database Statistics - displays the number of rows for each database table in GoAnywhere MFT -File Transfer Summary displays the total number of files transferred during the specified date range -Global Activity Details displays all activity for the selected features based on the search term provided -Product Usage Report displays product usage information related to service and workflow statistics. -Service Activity Summary displays the number of uploads and downloads for selected protocols. -Trigger Activity displays executed Triggers, status and associated event types. Jobs-Based Reports: -Completed Jobs Detail displays completed jobs, status and the user who ran the job -Completed Jobs by Project displays completed job details based on their projects and the specified date range -Completed Jobs Statistics displays the total number of jobs processed during a specified date range -Job Count Summary displays a pie chart of the number of jobs processed within a specified date range -Unresolved Jobs displays Jobs that failed during a specified date range that have not yet been resolved User Reports: -Admin User Activity -Details displays all admin activity for the selected components -Web User Logins displays a list of user logins for the time period specified -Web User Transfer Count Activity displays the number of file transfers performed by user -Web User Transfer Size Activity displays the total size of transferred files by each user Expiry & Error Reports: Expiring Open PGP Keys displays any Open PGP keys that will expire within a specified date range Expiring SSL Certificates displays SSL Certificates that will expire within a specified date range Service Errors displays all errors for the selected inbound services within the specified date range Unresolved Jobs displays Jobs that failed during a specified date range that have not yet been resolved Module-Specific Reports: -GoDrive Disk Usage displays the total amount of disk usage for each GoDrive user -Secure Mail Activity displays Secure Mail audit activity -Secure Mail Disk Usage displays the Secure Mail disk usage for each Web User sorted by size -Secure Mail Package Sizes displays a list of Secure Mail Packages and their sizes -Service Activity by Module displays all activity for inbound services within the specified date range Security Settings Audit Report: GoAnywhere MFT can analyse more than 60 different security settings to determine compliance with applicable sections of the Payment Card Industry Data Security Standards (PCI DSS). If a security setting does not meet the standard, the report will indicate the corresponding PCI DSS section and the recommendation on how to correct the security setting. GoDrive The GoDrive Module provides Enterprise File Sync and Sharing (EFSS) services for your employees and partners. With GoDrive, files and folders can be easily shared between users with advanced collaboration features including file revision tracking, commenting, trash bin, media viewing and synchronisation with Windows, Apple and Android devices. GoDrive is your best alternative to cloud-based file sharing services. It provides on-site file storage with localised control, end-to-end encryption, and detailed audit trails. Security GoDrive provides end-to-end encryption for sensitive files. Since no files are stored in the cloud, your organisation maintains local control to meet compliance requirements. In addition to the full complement of security features in GoAnywhere MFT, GoDrive includes: -Set granular permissions at the folder, subfolder and individual file level -Dual-factor PIN authorisation for device registration -AES 256-bit encryption on files synced to GoDrive devices Administration Included with GoAnywhere MFT, GoDrive provides a browser-based interface for administrators to easily manage users, security settings and shared folders. -Set disk quotas and view disk usage -Deactivate and wipe GoDrive folders from stolen or lost end-user devices Collaboration Sharing files with others is a snap using GoDrive. We even give you 5 free Users to get started, along with 5 free Secure Mail Users for any paid GoAnywhere license. Employees can quickly invite authorised users to work with their shared folders and files using the provided browser interface. Sharing: -Easily drag-n-drop files between the desktop and GoDrive folders -Generate automatic email invitations to shared users -Create public links to share files outside your organisation -Enter file comments, as well as review comment history from other users -Organise files into user-defined folders and subfolders -View thumbnail images of graphics files -Search for files and folders Monitor: -User can monitor shared files via activity streams -Receive email notices when shared files are downloaded or modified by others -View and recover prior versions of files Manage: -Lock files for restricting access -Revoke sharing of folders and files when needed -Place files into a recycle bin for future recovery -Manage shared folder access with granular permissions -View history of when files are downloaded, uploaded and modified GoAnywhere Desktop Client The GoAnywhere Desktop Client for Windows and Mac will synchronise your files from the GoDrive folder on your workstation with the GoAnywhere MFT server. Files automatically appear on each of your registered devices, as well as the Web Client, allowing you to access your files from any internet connected computer. The GoAnywhere Desktop Client for Windows supports Kerberos Single Sign-on for easier adoption by your users. GoDrive Mobile App The GoDrive mobile app allows you to access files on your iPhone, iPad, and Android phones and tablets for your authorised account. These files can be previewed or optionally downloaded for offline access. Your files and folders will be automatically updated to the most current version each time you connect to the server. Logging and Reporting Capturing detailed audit log information and exporting for reporting purposes is a cornerstone of GoAnywhere MFT. GoDrive logs each time a file is uploaded, downloaded, edited, shared, commented on, and deleted. Scalability and High Availability Clustering provides scalability that allows GoDrive to support thousands of users while active-active maximises availability for mission critical file sharing. SECURE FORMS The Secure Forms Module (which requires Advanced Workflows) allows your end-users to fill out and submit information online through secure custom-made forms with one or more input values, optionally upload files through GoAnywhere's HTTPS Web Client, or submit forms online by making SOAP or REST requests from your custom built applications. When a form is submitted, a Project in GoAnywhere is executed to automatically process the submitted values and files. Use Secure Forms to control the data that end-users provide when submitting information. GoAnywhere administrators can define Secure Forms with: -Configurable input fields -Custom labels -File upload components When the Project processes the Secure Form, it can return a custom message and one or more output files to the user. A Secure Form can be specified to various intended languages. For example, two forms may be created that serve the same purpose, but one may be in French while the other is in English. GoAnywhere administrators can choose their preferred language in the Web Client, which will then only show forms that are applicable to the selected language. Secure Form Submission A Secure Form can be authorised to one or more Web Users, who must then log in through the Web Client to complete the form. Optionally, Secure Forms can be configured to allow anonymous users to access the form through a public URL. Secure Form Use Cases Secure Forms are used by organisations in all industries to streamline, centralise, and standardise information intake. Companies have used Secure Forms to reduce the number of ways in which files arrive (i.e., by fax, email, or other online submission), collect confidential information, and ensure data is delivered securely. In one example, Secure Forms are used to collect electronic voting ballots by prompting the user to enter their voting information and attach a scanned PDF. A Project workflow then automatically process and distribute this electronic ballot to the appropriate election official based on the voting information provided by the end-user within the Secure Form. Secure Forms Features: -Custom, fillable Secure Forms for either public or authenticated users -Flexible configuration and design options to control the position of form features such as buttons -Customise and control the input text, options, and dropdown fields with default values, tooltips, and placeholders -Projects that automate processing the Secure Form input data and, optionally, provide output messages and one or more files for users to download -Fully customisable Text Area components, including the ability to override the button labels, the characters remaining text, and the drop zone on File Upload components -Successful submission messages presented to users when Secure Forms are submitted -Drag and drop upload for files which are automatically secured with AES-256 bit encryption -Limit file upload parameters, including the file types that are permitted to upload, file size, and maximum number of files -Save drafts of Secure Forms to finish at a later date -View Secure Form submission history, including when the form was completed, the user who completed the form, the user’s responses, and more -Supports SOAP and RESTful Web Service APIs to allow you to submit forms from other applications AGENTS The Agents Module (which requires Advanced Workflows) enables lightweight applications that automate your file transfers and workflows on systems (both remote and on-premises) throughout your enterprise. The agents are managed by a central deployment of GoAnywhere Managed File Transfer (MFT), which allows you to configure and schedule agent file transfers and business processes from an intuitive, browser-based interface. Agent Features: -Control agents remotely from the central server. -Process files on the agent or send them to GoAnywhere for further processing. -Deploy remote agents wherever they're needed: on a server, to a trading partner location, or in the cloud. -Automatically upgrade agents to the latest version without causing downtime. -Customise your software library of agent installers to fit the needs of your environment. How Agents Work When your file transfers execute, all log data is streamed from the agents (wherever they’re deployed) to GoAnywhere for consolidated auditing and reporting. This unique approach provides visibility into all the file transfers running within the organisation. MFT agents can be installed onto almost any server or workstation where file transfers or workflows need to be performed. This includes Windows, Linux, UNIX, IBM I, and Mac OS systems. For organisations who prefer to perform their file transfers in the cloud, GoAnywhere MFT supports the use of agents remotely in cloud infrastructure such as Amazon EC2 or Microsoft Azure. Agent Functionality Here are examples of what agents can do to assist your IT initiatives: -Automate and secure file transfers within a centrally managed environment -Monitor folders on agent systems for new or modified files -Schedule agent file transfers to run at future dates/times -Provide additional workflow capabilities such as compression, decompression, data parsing, database integration, PGP encryption and decryption, SFTP and SCP file transfers, and native command execution -Send email or text message alerts when agent file transfers fail -Feed audit data to GoAnywhere MFT for central reporting -Monitor location and status via an interactive agent map -Deploy automatic notifications if an agent goes offline Remote Agent Deployment After installing GoAnywhere MFT on your internal network, you can install Agents on specific servers or workstations within your network, at remote locations, and within cloud infrastructure that will automatically monitor folders, carry out file transfers, and synchronise concurrent workflows at various locations. 1- Agents in the Internal Network. Agents can be installed on servers or workstations in your network for transferring files from and to GoAnywhere and other systems for processing. The agents can perform additional workflows on the system where the agent is deployed such as copying files, running commands, or parsing data. 2- Agents at Remote Locations & "Retail Polling". Agents can be installed at remote locations to automatically monitor folders and transfer files on an automated basis. This "retail polling" feature is ideal for synchronising files between a corporate data centre and remote locations such as stores or branch offices. 3-Agents on Trading Partner Systems. Agents can be installed on servers owned by your trading partners. When a trading partner places a file in a folder which is monitored by the agent, GoAnywhere can automatically pull the file to your organisation's network. In turn, GoAnywhere can use those agent connections to push files to your trading partners. 4-Agents on Cloud Infrastructure. MFT agents can be installed on server instances within cloud infrastructure like Amazon AWS and Microsoft Azure. These agents could be used to move files securely between the cloud and your internal network. GoAnywhere Gateway The GoAnywhere Gateway Module is a separate product and must be downloaded on its own. It is normally used if you licensed the server side of the transfer (SFTP, FTPS, Secure Folders, FTP) but it can also be used for outbound connections too. GoAnywhere MFT Gateway is an enhanced reverse proxy that resides out in the DMZ, routing server requests without having any ports open into the network. It can also load balance/cluster the file servers. -GoAnywhere’s MFT Gateway provides an additional layer of security when exchanging data with your trading partners. It allows you to keep file sharing services (e.g. FTP/S, SFTP, HTTP/S servers) and documents safely in your private/internal network. With GoAnywhere’s Secure File Gateway, no inbound ports need to be opened into your private network, which is essential for compliance with PCI DSS, HIPAA, HITECH, SOX, GLBA and state privacy laws. -MFT Gateway Features -GoAnywhere’s secure file gateway provides the extra layer of protection for your file sharing services by… -Not allowing incoming ports to be opened into the private network, which reduces the risk of intrusion -Not storing sensitive data files in the DMZ -Keeping user credentials, certificates, and keys safely in the private network -Supporting FTP/S, SFTP, SCP, HTTP/S and AS2 file transfer protocols -Hiding the locations and identities of internal systems -Not requiring any special hardware components; it is a software-only solution. Why use GoAnywhere MFT Gateway as Your Proxy Gateway: 1- Secure Inbound ports to your network: Your file servers (e.g., FTPS, SFTP, HTTPS, and AS2) can be kept securely in your internal network with GoAnywhere's secure file gateway. This allows you to keep inbound ports to your network closed, which is essential for complying with data security standards. 2- Keep critical data out of the DMZ: Files can be safely shared with trading partners, users, clients, and vendors while avoiding having critical documents or files stored, even temporarily, in your DMZ. 3- Connect with external systems securely: As a forward proxy, Gateway can make connections to external systems on behalf of users and applications in the private network. This allows you to more easily manage file transfers from your firewall. Additionally, the identities and locations of your internal systems are hidden for better security. 4- Run on any environment or operating system: GoAnywhere Gateway is a platform agnostic, software-only secure file gateway solution. Install it on Windows, Linux, AIX, UNIX, or other operating systems to enhance file security in whatever environment works best for you. GoAnywhere Gateway Features At-A-Glance: -No incoming ports need to be opened into the private network -User credentials, permissions, certificates, and keys are kept safe in the private network -Hides the locations and identities of internal systems -Services configurations are maintained/stored in the private network -Supports FTP, FTPS, SFTP, SCP, HTTP, HTTPS and AS2 file transfer protocols -Built-in load balancer to distribute workloads across multiple systems In essence, when added to GoAnywhere MFT, GoAnywhere Gateway serves as a transparent interface between internal systems and external systems without exposing sensitive files or your private network. CLOUD CONNECTORS The Cloud Connectors Module (which requires Advanced Workflows) enables built-in integrations that seamlessly support the automation of data between web and cloud applications and your GoAnywhere MFT projects and workflows. Cloud Connectors, also known as cloud integrations, are built-in web and cloud application integrations that connect to your GoAnywhere MFT projects and workflows. GoAnywhere Cloud Connectors offer a variety of use-cases and benefits if your organisation connects with external apps. We offer out-of-the-box connectors for popular services including Salesforce, SharePoint Online, Microsoft Dynamics 365, Box, and Dropbox. How Cloud Connectors Work Once a Cloud Connector is installed, you can configure the connection properties as a GoAnywhere Resource. With this resource, you only need to specify the connection once before being able to seamlessly reuse it in any of your workflows and cloud file transfers. Your Cloud Connector definition contains all the actions required to communicate with cloud applications. In GoAnywhere, these actions appear as elements located under the Cloud Connector in the GoAnywhere Project Designer. Elements can be incorporated into your workflows alongside other project tasks. GoAnywhere supports a great many cloud application integrations, so you can automate your processes between multiple web and cloud services at once. -Alibaba Object Storage Service -Amazon Cloud Trail -Amazon CloudWatch -Amazon EC2 -Amazon ECS -Amazon Lambda -Amazon SNS -Amazon SQS -Atlassian JIRA -Automate Plus -Azure Data Lake Storage Gen1 (superseded by the -Azure Data Lake Storage Gen2 connector) -Azure Data Lake Storage Gen2 -Azure Storage Queue -Box -Citrix ShareFile -Dropbox -Egnyte -GateScanner CDR -GoAnywhere Command -Google Cloud Storage -Google Drive -Google Translate -JAMS -Jenkins -Microsoft Dynamics 365 Business Central -Microsoft Dynamics 365 CRM -Microsoft OneDrive -Microsoft Sharepoint Online -Microsoft Sharepoint On-Premise -OPSWAT MetaDefender -Salesforce -ServiceNow -SMA OpCon Scheduler -SOS Berlin JobScheduler (online version not supported) -Trello -Veeva CRM -Votiro -Webdocs -Zendesk (online version not supported) ote: Cloud Connectors can integrate with available on-premise and online versions of third-party software unless otherwise noted. Cloud Connector Marketplace Finding new cloud application integrations for your environment is easy. With GoAnywhere MFT’s Cloud Connector Marketplace, users have access to many of the industry’s most popular APIs, including Jenkins, JIRA, Trello, Zendesk, and Google Cloud Storage. Custom connectors can be also designed using GoAnywhere’s Cloud Connector Designer—no coding or programming experience necessary. In addition, new GoAnywhere connectors can be downloaded without needing to update the software. Current GoAnywhere customers can access the Cloud Connector Marketplace by logging into their admin interface in GoAnywhere, then navigating to System > Add-Ons and click "Browse Marketplace." GoFast GoFast is a file transfer acceleration protocol in GoAnywhere that can transmit data considerably faster than traditional FTP. The high transfer rate in GoFast is achieved by using lightweight UDP (User Datagram Protocol) channels to broadcast data packets between the client and server. UDP is much faster than TCP based protocols like FTP and SFTP since it does not have the inherent time delays for acknowledging and synchronising data packets. UDP has traditionally been used for streaming content that requires high throughput, such as live video and audio. GoFast has also harnessed the efficiency of UDP while providing innovative methods to guarantee the delivery and quality of data transmissions. How GoFast Works Before files are transferred, a secure SSL/TLS control channel is first established over TCP between the GoFast server and client. This control channel can be authenticated with user credentials, as well as X.509 client and server certificates. After authentication, commands are sent over the control channel to indicate details about the transmission such as the file names and sizes, encryption ciphers and compression settings. Files are then broken into multiple parts and transferred over UDP data channels between the GoFast client and server. The part sizes can be adjusted to optimise speeds based on the reliability of the network. The file parts are automatically reassembled on the destination and saved to the designated folder locations. Guaranteed Delivery If any parts of a file do not reach the destination successfully, the sender will be instructed to retransmit those missing parts until the entire file is received. To further guarantee the integrity of the transmission, checksums (hashes) can be calculated on both the GoFast client and server for the files transferred. The files can be automatically resent if the client and server file checksums do not match. Encryption A GoFast session can be configured to use AES encryption for protecting data packets, which is important when sending confidential files over the internet or other unsecured networks. AES is a popular encryption standard and is approved by the National Institute of Standards and Technology (NIST) for protecting top secret information. If you are transmitting data over protected networks, you can disable encryption to further optimise transfer speeds. Compression File parts can optionally be compressed with the ZLIB standard to minimise the amount of bandwidth utilised by GoFast transmissions. Nine different compression levels are supported, which can be selected by the administrator at the time of transmission. Additional Features of Accelerated File Transfer: -Schedule GoFast file transfers to run automatically -Send and retrieve multiple files per GoFast session -Auto-retry failed connections with user-specified thresholds -Auto-resume failed transmissions when the server becomes available -Encrypt data packets with AES-128, AES-192 and AES-256 bit ciphers -Verify integrity with MD5, SHA1, SHA256, SHA384 and SHA512 hash algorithms -Suffix and prefix file names with constants, timestamps or variables -Override file names and other properties at execution time using variables -Auto rename files if they already exist at the destination location -Configure port ranges used by the GoFast server -Send alerts for transfer failures via email, text messages and system messages -Log all GoFast file transfers in a central database for auditing and reporting. GoFast Workflows GoFast server connections can be pre-defined in GoAnywhere MFT's Administrator as reusable Resources which can be selected from simple drop-down menus. GoFast Tasks can be placed within GoAnywhere MFT workflows and executed as part of a cohesive process. For instance, a workflow could be defined to retrieve a video file, encrypt the video, and then quickly send the video to a trading partner using the GoFast accelerated file transfer protocol. PeSIT Client The PeSIT Client Module helps meet standards and accepts communications from the European banking industry. GoAnywhere’s PeSIT server can be used alongside our PeSIT Client, which allows for communications initiation. The PeSIT client helps guarantee delivery of PeSIT transfers with options to auto-retry connections, auto-resume interrupted file transfers, and perform integrity checks of successful file transfers. PeSIT Features in GoAnywhere MFT: -Full support of the standard PeSIT command set -Send & Receive files -Specify Maximum Data Block Lengths per transfer -SSL Certificate Server Authentication -Suffix and prefix file names with constants, timestamps or variables -Override file names and other properties at execution time using variables -Configurable port ranges -Alerts for transfer failures via email, text messages and system messages. PeSIT Resource PeSIT server connections can be pre-defined in GoAnywhere MFT's Administrator as reusable Resources which can be selected from simple drop down menus. PeSIT Tasks can be placed within GoAnywhere MFT Projects and executed as part of a cohesive workflow process. For instance, a Project could be defined to retrieve records from a database file, convert the records into a CSV file, and then put the CSV file onto a PeSIT server. File Filtering When sending or receiving files via PeSIT, the files selected can be included and excluded using various filter criteria: -Wildcards (i.e. "trans*.txt" or "*.xls") -Regular expressions -Date and time range -Size range -Variables passed to the Project PeSIT Logs Audit trails (logs) are generated for all PeSIT transmissions in GoAnywhere MFT to meet auditing and compliance requirements. The level of log detail can be controlled by an administrator on a per-Project basis. This detail can be configured to include all PeSIT commands issued, PeSIT messages and file names transferred. Log messages can additionally be sent to a Syslog server using UDP or TCP connections. PeSIT Server The PeSIT Server Module provides for full support of the standard PeSIT command set (sends and receive files, specifies Maximum Data Block Lengths per transfer, SSL Certificate Server Authentication, transfers multiple files per connection, file transfer templates, and more). Audit trails or logs are generated for all PeSIT transmissions in GoAnywhere MFT to meet industry auditing and compliance requirements. PeSIT Server Features: -Full support of the standard PeSIT command set -Send & Receive files -Specify Maximum Data Block Lengths per transfer -SSL Certificate Server Authentication -Dynamic file names with constants, timestamps or variables -Multiple listeners with individual port configurations -File transfer templates GoAnywhere MFT can be configured to handle trading partner send and receive requests. Templates can be reused across multiple trading partners that require the same send/receive capabilities. Partner Management Trading partners that want to use PeSIT for file transfers are easily managed with granular permissions. Inbound and outbound file transfer templates can be applied en-mass or individually with each Web User depending on the use case of the PeSIT partner. PeSIT Logs Audit trails (logs) are generated for all PeSIT transmissions in GoAnywhere MFT to meet auditing and compliance requirements. This detail includes commands issued, messages, IP addresses, server IDs, and file names transferred. Audit logs for the PeSIT service can also be used to troubleshoot failed transfers. Contact Us Content Inspection Modules The following modules provide for content inspection of the traffic that flows through GoAnywhere. Data Loss Prevention Document Sanitisation strips out hidden, possibly sensitive data from documents such as properties, which can disclose the author and true date; change histories, which can leak sensitive data that authors believe was removed, such as project details, new product names and prices. Data Redaction overwrites or redacts critical or sensitive information to prevent data breaches. The communication content is modified but is allowed to continue to prevent business process disruption, with sensitive information replaced with a series of Xs. Anti-Steganography adds to GoAnywhere MFT the capability to prevent files, messages, images, or videos from being concealed within another file. Optical Character Recognition is the electronic or mechanical conversion of images of typed, handwritten, or printed text into machine-encoded text, whether from a scanned document, a photo of a document, a scene-photo, or from subtitle text superimposed on an image. Threat Protection Anti-virus features integrated Sophos and/or Avira anti-virus, with automatic updates every 15 minutes to provide the latest protection. Structural Sanitisation removes any active content such as scripts, coding, etc. from sent files. Information is, however, left intact in its original file format. We also offer a free FTP Client & Server.
- The Value of 3rd-Party Reviews | GSA
< News The Value of 3rd-Party Reviews 7 May 2025 Third-party review sites can be a valuable source of insight for IT teams tasked with selecting the best software solution for their organisation. Reputable and long-established sites such as PeerSpot , SoftwareReviews , G2 , and Capterra can help identify which solutions are most widely used and highest rated within your industry. This can in turn help you proceed quickly to a decision on which solution(s) to trial. Reliable Reviewers Whether you’re looking for Managed File Transfer (MFT) solutions or other software, it’s best to prioritise reviews on sites which have established themselves as trustworthy over the test of time and thousands of peer reviews. These sites capture the opinions of real product users sharing their real-life experiences – positive and negative. In fact, Gartner’s 2024 annual study of 2,499 software decision makers found that customer reviews and ratings were the most used information source by buyers, above personalised product demos, user guides, and case studies. More than a third of software buyers described reviews as “extremely important” to their purchase. Are Reviews Trustworthy? It’s illegal in Australia and New Zealand for businesses to create fake or misleading reviews or arrange for others do so. The Australian Competition and Consumer Commission suggests the following red flags may indicate that a review is fake: · a spike in highly positive or negative reviews over a short period of time; · many reviews written from the same email or IP address; · similar reviewers’ names; · generic reviews without specific detail about the business or product; and · reviews written in similar language as other reviews for the same business or product. Thankfully, the trusted third-party sites I listed above have processes in place to weed out dubious software reviews. They also publish the measures they take to assure the validity of the reviews they receive. Other Sources of Insight Beyond peer reviews, here are some other useful resources to consult when selecting the right software solution for your business. · Case studies : Demonstrate how businesses are using the solution; · Product videos : Illustrate solutions’ features and benefits; · Webinars : Subject matter experts demonstrate the configuration and use of the solutions; and · Written Resources : Provide a variety of reader-friendly explanations and examples Local Advice and Guidance At Generic Systems Australia, we have decades of experience installing and supporting the world’s premier MFT , GoAnywhere, across Australia and New Zealand. Founded in 1993, we’re proud to count among our clients some of the region’s most iconic brands. Leveraging our unique skills and readily available local support, they rely on us to make their IT systems more secure and efficient, in turn, making their teams more productive. A long-term partner of Fortra (formerly Help Systems, and Linoma Software, the original authors of GoAnywhere MFT), our in depth understanding of GoAnywhere’s capabilities - including Advanced Workflows, data translation, auditing and compliance, automation and security - enables us to devise optimal deployment solutions, provide rapid Proofs of Concept, and move ahead quickly with implementation. In fact, we have exclusively managed GoAnywhere deployments for some of the region’s largest multinational corporations and Government departments, as well as small- to medium-sized businesses. Our Australia-based technical experts provide clients with the reassurance that local help will always be on-hand. If you’re exploring how to boost your efficiency and bottom line by leveraging Secure Managed File Transfer technology, please feel welcome to contact me for an obligation-free discussion. Or, if you’d prefer to read more, you can check out the many resources on our Generic Systems Australia website, including our exclusive Local MFT Buyer’s Guide . At Generic Systems Australia, we’re your local experts in MFT. Previous Next
- Secret Ransomware Payments Rife: Survey | GSA
< News Secret Ransomware Payments Rife: Survey 19 Aug 2024 Pervasive cyberattacks are leading most companies to pay ransoms and break their “Do Not Pay” policies, according to recent research. A poll of IT and security decision-makers conducted by Cohesity found that that most companies have paid a ransom in the last two years. In fact, 79% of respondents said their company had been the victim of a ransomware attack during the second half of 2023. The breadth of an organisation’s “attack surfaces” depends on the size and scope of its data environments. However, 78% of respondents said their data security risk had increased faster than the growth in the data they manage. They also said their organisation’s cyber resilience and data security strategies had not kept pace with emerging threats – only 21% had full confidence in their company’s cyber resilience strategy. Slow Recovery, Lack of Testing Cyber resilience is a critical element of business continuity, and encompasses a company’s ability to recover their data and restore business processes when they suffer a cyberattack or IT outage. Key insights from the survey on this point included: All respondents said they need more than 24 hours to recover data and restore business processes. Only 7% said their company could recover data and restore business processes within 1-3 days. 35% said they could recover and restore in 4 to 6 days, while 34% need 1-2 weeks, and 23% need more than 3 weeks. Only 12% of those surveyed said their company had stress-tested their data security, data management, and data recovery processes or solutions in the six months prior to being surveyed. 46% hadn’t tested in more than 12 months. Secret Ransom Payments While 84% had a “do not pay” policy, Cohesity reported that 94% of respondents divulged that their company would pay a ransom to recover data and restore business processes. 5% said “maybe, depending on the ransom amount”. Two thirds said their company would be willing to pay over US$3M to recover data and restore business processes, and a third said their company would be willing to pay over $5M. Don’t Pay: Prevent! The volume, frequency, and sophistication of ransomware attacks will only increase. And paying ransoms only encourages cyberthieves to escalate their efforts. Worse, if ransoms are seen as “easy money”, new miscreants will be tempted to acquire ransomware tools from the dark web and join the cyber crimewave. Rather than investing in ransoms, organisations need to invest in their cyber resilience. That starts with keeping thieves at bay - protecting valuable data where it is stored, and when it is transferred – and building organisational capability in rapidly responding to and recovering from cyberattacks. Building cyber resilience need not be a drag on an organisation’s efficiency. Automation can ensure data is protected at rest and in motion, requiring little to no manual management. For example, Managed File Transfer (MFT) solutions such as the class-leading GoAnywhere MFT encrypt data at rest and in transit, complying with the highest data security standards (including the US’s and Europe’s HIPAA, HITECH, PCI DSS, SOX, and GDPR). MFT manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols such as SFTP, FTPS, and AS2 to send files securely, and encryption standards such as Open PGP and AES to protect data in transit and at rest. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection enables safe collaboration with external parties, preventing malware from entering your organisation, and reducing opportunities for employees to lose or mishandle sensitive data. Local Expertise Ready to Help Generic Systems Australia are your local experts in Managed File Transfer and Advanced Threat Protection. We’ve assisted hundreds of organisations across the Asia-Pacific region to secure their data, keep cybercriminals at bay… and keep ransomware off the books. If you’d like to discuss improving your cybersecurity, please feel welcome to contact me , Bradley Copson. I’m always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. About the survey: Cohesity’s findings are based on a survey of 902 IT and Security decision-makers (split as close to 50:50 as possible) commissioned by Cohesity and conducted by Censuswide. Survey respondents were polled from businesses in Australia, the United Kingdom, and the United States. The top five industries selected by respondents as best representing the industry their company operates in were: IT & Telecommunications, Finance, Healthcare, Finance, HR, and Manufacturing & Utilities. Previous Next
