top of page

Search Results

Search this site

231 results found with an empty search

  • GoAnywhere: the Swiss Army Knife of Systems Connectivity | GSA

    < News GoAnywhere: the Swiss Army Knife of Systems Connectivity 29 July 2025 When all the buzzwords are said and done, the single biggest advantage of using information technology is enhanced efficiency through automation and connectivity . It’s in precisely these areas where GoAnywhere MFT shines. While GoAnywhere is a Managed File Transfer solution, its usefulness is far broader. It’s a “Swiss Army Knife” for automatically moving files between an organisation’s systems, suppliers and customers. Whether you’re moving data between your ERP , CRM , HRM , SCM , CMS , BI , BPM and ITSM systems, GoAnywhere helps you seamlessly interconnect their outputs and inputs, amplifying IT’s overall speed and efficiency benefits across your business. GoAnywhere not only monitors your various solutions for new output, it also translates that output into the new formats required by your other systems before routing the translated files to their destinations. Automatically. Comprehensive Extract Transfer Load features enable data values to be mapped, formatted and modified between source and target files. Automating with MFT Automation is where GoAnywhere really shines vs less capable Managed File Transfer solutions. It manages recurring and high-volume file transfers and eliminates the need for manual data processing. Surprisingly, there are still some organisations which continue to be dependent on tedious manual file transfer processes, complicated system configurations and manual batches. The reason they remain reliant on such risky approaches is often lost to the past - there’s simply no-one left on staff who was around at the time their systems were initially installed. “However it works … it does work” seems to be the thinking. “If it ain’t broke … don’t fix it” can be seductive when there’s lots else demanding your attention. However, failing to understand file transfer dependencies, and disregarding the need to make them resilient, is a dangerous way to run a business. Small changes in file formats and security protocols, or the unforeseen consequences of a software version update, can cause havoc. Background legacy scripts, homegrown processes, and outdated PC tools are prone to fail for the simplest of reasons. That means systems downtime, lost revenue, distrustful suppliers and unhappy customers. Minor Investment, Major Gain Making the relatively minor investment of time and expense to automate file transfers simplifies and streamlines critical everyday tasks, eliminates human error, saves time and cuts costs. GoAnywhere is more than just a file moving tool. It can monitor folders both on-premises or in the cloud, send you emails and SMS alerts when triggered events occur, and test and debug your automatic file transfer workflows. And, should you ever need to trace the movement of your data – say, for auditing or compliances purposes - GoAnywhere’s comprehensive logging tools and centralised dashboard make this easy. How It Works With GoAnywhere installed, a simple drag-and-drop interface defines how files will be securely and reliably moved between internal systems, supply chain partners and customers. It’s much easier than writing manual scripts, and no programming skills are required. GoAnywhere’s automation enables systems to execute each step of a business process one after the next without human intervention. File movements are monitored and controlled, including sending, retrieving and delivering data. You can schedule when files should be sent or retrieved between systems, users, trading partners, applications, and the cloud. Your business processes are made significantly more efficient. Here to Help At Generic Systems Australia , we’re Australia and New Zealand’s experts in helping business take advantage of every one of GoAnywhere’s many capabilities. We’ve assisted dozens of organisations to make their file transfers resilient, secure and reliable, boosting their efficiency. If you’d like to discuss how we can deliver these advantages to your organisation, please feel welcome to contact me . I’m always happy to have an obligation-free chat and explain how easily we can transition you from your current approach to a new world of productivity. At Generic Systems Australia, we’re your local experts in data transfer. Previous Next

  • How Load Balancing optimises your file transfers | GSA

    < News How Load Balancing optimises your file transfers 30 Apr 2024 Network bottlenecks that cause business downtime are the bete noir of corporate IT teams. Businesswire found that 82% of companies experienced at least one downtime incident during the past three years… costing small businesses $660 per minute, and larger organisations $14,000 per minute. Load balancing is a key technique for keeping network traffic flowing. What is Load Balancing? Load balancing is key to “clustering”, where multiple systems work together as a single unit to help ensure high-availability, scalability, and reliability. It’s a technique which enables organisations to distribute workloads and network traffic across multiple servers or network interfaces in a computer cluster. Effective load balancing means that network traffic is always directed to servers which are “available”, should a particular server become overwhelmed or fail. Balancing workloads optimises the performance of systems and applications –– for example, a managed file transfer (MFT) solution for exchanging data –– preventing bottlenecks and other efficiency-sapping impacts. Why Load Balance for File Transfers? Delays in sending files can have significant negative ripple effects throughout an organisation. Incoming orders may not be received, or shipping may be delayed, leading to dissatisfied customers. Delayed financial transactions with trading partners may weaken an organisation’s supply chain. Load balancing helps organisations continue to operate ‘business as usual’ even when a system fails or is inundated with a heavy network workload. Other benefits of load balancing include: Scalability: Load balancers can help organisations adapt to growing and changing conditions and workloads without suffering adverse events. New servers can be seamlessly added to the cluster when more scalability is needed. Performance Optimisation : Traffic is routed to the server most capable of handling a given request based on location or server health. Redundancy: Organisations safeguard themselves, should one server become overloaded or fail, with load balancing enabling processing work to continue without interruption. Using Middleware and Active-Active Framework for Load Balancing A robust managed file transfer solution, such as Fortra’s GoAnywhere MFT, delivers critical load balancing and scaling when installed in a cluster. The solution’s load balancer, GoAnywhere Gateway, serves as both a reverse proxy and load balancer. When paired with Gateway as a load balancer, each inbound file server connection can be distributed to available systems in the environment. MFT workflows performed in a clustering environment gain increased performance and throughput. If a system within a cluster fails, GoAnywhere Gateway automatically routes all new trading partner connections to the remaining systems in the cluster. For mission critical environments and processes, this is an “active-active” framework providing high availability. Enhanced Security GoAnywhere Gateway also provides an extra security layer when exchanging data. The Gateway keeps file sharing services such as FTPS, HTTPS, SFTP servers and any documents secure in the private or internal network. No additional inbound ports need to be opened, which helps organisations meet compliance requirements such as those for PCI DSS, SOX, HIPAA, GLBA, as well as certain privacy laws. This round robin algorithm essentially works like this: For each new FTP, FTPS, or SFTP connection from a trading partner, the Gateway distributes that session sequentially to the next FTP/FTPS/SFTP server within the cluster. HTTP/S, however, is a stateless protocol. It uses the round robin algorithm but will persist each connection for a time to maintain session integrity. HTTP/S sessions typically are only served by one HTTP/S server at a time. If you’d like to discuss how your organisation can reduce downtime through MFT load balancing, please feel welcome to contact our Business Manager, Bradley Copson (mail to: bradley@gensys.com.au ). He’s always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Generic Systems Australia Your Local Experts in Secure Managed File Transfer Previous Next

  • Think Cyber Insurance is “Protection Enough”? Think again! | GSA

    < News Think Cyber Insurance is “Protection Enough”? Think again! 8 Oct 2025 Paying a cyber security insurance premium is no substitute for taking measures to thwart cyber thieves. Almost half of cyber insurance claims are being denied. As cyber breaches have become more common, insurers have become more stringent in their underwriting and assessment practices. Insurers facing payouts are carefully scrutinising claimants’ cyber security practices. If they conclude a company failed to take reasonable precautions to mitigate their cyber risks, they’re denying the claim. No Guarantee Cyber insurance is a critical safety net for a modern organisation. But it’s not a guarantee. A staggering 44% of cyber insurance claims are denied, often due to overlooked policy requirements or inadequate cybersecurity practices. To ensure your claim is honoured in the event of a breach, organisations must proactively ensure their security posture meets their insurer’s expectations. Why Claims Fail Astra Security reports that 27% of data breach claims and 24% of first-party claims are denied due to exclusions in the insurance package. These exclusions often stem from outdated security models, misconfigurations, or failure to meet minimum protection standards. Moreover, 60% of claims involve Business Email Compromise (BEC) or Funds Transfer Fraud (FTF) — two attack vectors that insurers scrutinise particularly heavily. Ransomware, though less frequent, remains on average the costliest type of attack. If your organisation lacks robust defences against these threats, your insurer may argue that you failed to uphold your end of the coverage agreement. How to Ensure a Claim Isn’t Denied 1. Treat Data Transfers Like Cash Transfers Data — like cash — is a high value asset vulnerable to theft, loss, and misuse. Treating data transfers with the same rigor as cash helps ensure accountability, security, and compliance. In today’s digital economy, customer records, intellectual property, financial details, and operational insights are all assets that drive business decisions and revenue. Just as companies protect cash transfers with encryption, audit trails, and multi-party verification, data transfers should be governed by similarly strict protocols. The Australian Cyber Security Centre (ACSC) emphasises that users must be held accountable for all data transfers they perform, especially when moving sensitive or classified information between systems. This mirrors financial accountability, where every dollar moved is tracked, verified, and reconciled 2. Implement and Maintain Strong Cybersecurity Controls Insurers expect you to uphold basic security hygiene. This usually includes: · firewalls and endpoint protection, · Multi Factor Authentication MFA, · up-to-date patching, · incident response plans, · periodic vulnerability assessments, and · employee training on phishing and social engineering. One particular technology — Managed File Transfer (MFT) — can help you embed technical and process protections across your organisation in one fell swoop. MFT provides end-to-end encryption, role-based access controls, built-in audit trails, detailed reporting, automated alerts and notifications, centralised visibility and seamless scaling across both cloud and on-premises systems. 3. Understand Your Policy Details Read the fine print of your insurance policy. Know what’s covered, what’s excluded, and exactly what security standards and regimes you’re expected to maintain. 4. Document Everything Keep detailed records of your cybersecurity efforts. This includes security audits and penetration tests, software update logs, employee training sessions and incident response drills. Documentation is your best legal defence if a claim is challenged. It proves you took reasonable steps to mitigate risk. 5. Stay Ahead of Threats Cyber threats evolve rapidly. Insurers are increasingly using AI to assess risk, and attackers are doing the same. Regularly update your risk models and consider continuous penetration testing to identify and patch vulnerabilities before they’re exploited. 6. Get Local Expert Help Cyber insurance is not a substitute for cyber security — it’s a complement. And, as the old maxim states: “an ounce of prevention is worth a pound of cure”. At Generic Systems Australia we have decades of experience helping Australian and New Zealand organisations bolster their cyber defences through deployment of the world’s leading MFT solution, GoAnywhere . Our Migration Service makes the transition even easier for organisations who want to supplement their IT team with local expertise. We can even write custom Cloud Connectors to extend GoAnywhere’s ability to interface seamlessly with less common cloud platforms. If you’d like a no-cost, no-obligation discussion about how we could help you simply and affordably adopt an advanced MFT solution, please feel welcome to get in touch with me. At Generic Systems Australia, we’re your local experts in Secure Managed File Transfer. Previous Next

  • Battle “Breach Fatigue” with Managed File Transfer | GSA

    < News Battle “Breach Fatigue” with Managed File Transfer 16 Dec 2025 With the festive season fast approaching, many in business may be left feeling a little fatigued by what has been a hectic business year. But none more so than your beleaguered IT team. In 2025 they’ve been facing relentless waves of cyber-attack. From phishing campaigns to ransomware threats, they’ve needed to maintain constant vigilance to defend against the hordes of cyber criminals eager to steal your organisational data. In a phenomenon known as “Breach Fatigue”, a state of near exhaustion occurs when IT teams become desensitised to the sheer volume of alerts, warnings, and incidents they must manage daily. The consequences are serious: slower response times, overlooked vulnerabilities, and a creeping sense of burnout. Human Toll IT departments are inundated with hundreds of alerts each day, ranging from minor anomalies to potentially serious threats. Over time, the sheer volume of these notifications becomes mentally exhausting, making it increasingly difficult for teams to distinguish genuine risks from false positives. This operational overload not only slows response times but also raises the likelihood of critical signals being overlooked. As fatigue sets in, vigilance naturally declines. Teams may unconsciously lower their guard, treating new alerts as routine rather than recognising the urgency each one demands. This reduced attentiveness can allow real threats to slip through undetected, leaving systems exposed to breaches that could otherwise have been prevented with sharper focus. The constant exposure to high-stakes scenarios also takes a toll on morale. IT professionals working under relentless pressure often experience burnout, which can lead to disengagement or even resignation. When skilled staff leave, organisations face knowledge gaps and weakened defences, compounding the vulnerability created by Breach Fatigue. Financial Toll The financial consequences of this cycle are significant. A single overlooked breach can trigger costly downtime, regulatory fines, and lasting reputational damage. Breach Fatigue magnifies these risks by eroding the organisation’s defensive posture, turning what might have been a manageable incident into a major financial and operational setback. MFT Lightens the Load One way to alleviate Breach Fatigue is by reducing the number of potential breach vectors. Managed File Transfer (MFT) technology provides a secure, automated framework for moving sensitive data across systems, partners, and users. Unlike ad hoc file sharing methods — such as email attachments or unsecured FTP — MFT is designed with security and compliance at its core. MFT solutions encrypt files both in transit and at rest, ensuring that sensitive data cannot be intercepted or tampered with. This reduces the number of alerts IT teams must chase down related to insecure transfers. Instead of tracking multiple file-sharing platforms, IT staff gain a single dashboard to monitor transfers. This consolidation cuts down on noise and helps teams focus on genuine anomalies. By automating repetitive file transfer processes, MFT reduces human error — a common cause of breaches — and frees IT staff to focus on higher-value security work. MFT platforms often include built-in compliance features, such as audit trails and role-based access controls. This not only strengthens security but also reduces the stress of preparing for regulatory audits. Here to Help If you’re considering supporting your hard-working IT team with a Managed File Transfer solution, please feel welcome to get in touch . I’m always available for an obligation-free exploration of how MFT can help your business. I and my team have many years of experience helping companies big and small painlessly and affordably implement MFT solutions. At Generic Systems Australia , we’re your local experts in Managed File Transfer. Previous Next

  • Global Insurer Uses GoAnywhere to Replace Legacy File Transfers | GSA

    < Case Studies Global Insurer Uses GoAnywhere to Replace Legacy File Transfers Instead of copying and piecing together scripts for file transfers - a process which took 30-60 minutes per script – this global insurance company now uses GoAnywhere to automate and make secure its file transfer task in less than five minutes. Discovering the many other ways they could leverage GoAnywhere’s advanced features was a bonus. Decades of experience helping Asia-Pacific customers have established Generic Systems Australia as our region’s local experts in secure managed file transfer. In this case study, we share how a global insurance company is saving time and money – and avoiding headaches – by using GoAnywhere MFT , the world’s leading MFT solution . For one global insurance company, having file transfer processes that work seamlessly is non-negotiable. Between needing to share data with the company’s national office, running a collaboration with a car rental company, and catering to more than a million customers, they need their file transfers to run smoothly and securely. However, the legacy systems and processes they had in place prior to 2018 were frustrating, to say the least. One of the company’s applications engineers couldn’t believe the file transfer processes they had to deal with before switching to managed file transfer software. "We had a server where a bunch of batch scripts ran and transferred files to vendors," he said. "We wrote manual scripts — 50 or 60 of them — that all ran from Task Scheduler." Because their setup lacked security and encryption features, critical information wasn’t always protected during batch transfers. Their setup didn’t have alerting or reporting abilities either. It quickly became clear that better cybersecurity strategies were needed to protect their file transfers. Convoluted Clustering The engineer’s team also wanted to cluster their systems, so the bank files they exchanged wouldn’t be interrupted by system failure or downtime. But making Task Scheduler cluster aware required knowledge of PowerShell. "It was this huge, long convoluted process," he said. "And with security in mind, we had to implement a DMZ secure gateway server to go along with a new file transfer server. Jobs would have to be scheduled on two different sets of task schedulers." The design files they created to make clustering work were crazy. There had to be an easier way. Back to Basics For this insurance company, it was time to unravel their processes and systems and go back to the basics that mattered: encryption, automation, alerting, and reporting. If they could find a solution that did all these things simply and efficiently… that would be a win. And win they did. After evaluating several managed file transfer (MFT) solutions, the engineer tried GoAnywhere MFT, the class-leading cybersecurity solution. More than Transfers The engineer and his team discovered many additional benefits during their trial of GoAnywhere: Ease of Use: GoAnywhere was powerful but not overly technical. The software was a breeze to install and easy to use. Focused on What Matters: The team was pleased to see GoAnywhere support extra functionality, like user-to-user collaboration, but even more pleased to find that GoAnywhere never lost sight of their bread-and-butter requirements: automation, auditing, and secure file transfers. Out-of-the-Box Project Designers: GoAnywhere included a drag-and-drop project designer for workflows and automation. This eliminated the need for scripting and programming. Affordability: Finally, the cost beat out the competition. GoAnywhere offered the insurance company a positive ROI that they could achieve quickly and efficiently with less of a learning curve—while still boasting all the features and functionality of other comparable solutions. A Fresh Start with MFT Once GoAnywhere was fully implemented, the global insurance company couldn’t imagine life without it. Now they meet requirements and complete key projects via several of GoAnywhere’s features: PCI DSS Compliance: The insurance company is PCI DSS certified. To ensure their member information is protected as much as possible, they are required to go above and beyond PCI DSS requirements to ensure their file transfers are compliant. GoAnywhere MFT supports PCI DSS compliance efforts through encryption, secure, industry-standard file transfer protocols, access controls for sensitive data, and detailed logging/reporting. Google Integration: After implementing GoAnywhere, the insurance company installed GoAnywhere’s Google Cloud Storage Connector. This cloud integration allows them to pull data from the cloud from two vendors they’ve partnered with. Each month, GoAnywhere transfers a file generated in-house to a Google storage bucket. Once the files are in the bucket, two of their vendors apply logic to the data for marketing purposes. The file finishes processing using the Google compute engine before GoAnywhere pulls the file back into the company’s enterprise data warehouse (EDW) system. AWS Integration: GoAnywhere’s Amazon AWS integration fulfills an important project in their environment. "We’ve used [the Amazon AWS integration] since day one," explained the company’s engineer. "It was one of the selling features for us." Improved Visibility & Centralisation Before GoAnywhere came into the picture, the engineer and a co-worker relied on Task Scheduler and batch file transfers to send and retrieve sensitive data. Their legacy setup did not have alerting, notifications, or reporting functionality. They’d need to spend precious time tracking down issues or digging into different data sources to regain some visibility. This lack of clarity was a source of frustration. A big selling point for this insurance company was GoAnywhere’s ability to provide visibility into all areas of their file transfer processes, including the data movement happening on-premises, within their cloud environment, and to their web applications. Not only does this visibility help the engineer’s team know when and where files are sent, it gives them flexibility to train new employees if needed. "Say I need more help and we’re hiring someone else," he explained. "I can say [to that new hire,] ‘Everything’s in GoAnywhere. All our jobs, anything that’s incoming, all the users. You can see who has access, you can see the agents we have deployed and what they’re doing.’ Having that [data] in a central place is just so much easier than what we’ve used in the past." Remote MFT Agents GoAnywhere’s MFT Agents module allows admins to remotely control automated file transfers and file processing from a central GoAnywhere server. With MFT agents in place, this insurance company has improved its overall security posture. They can move sensitive files between restricted servers without having to rely on insecure methods or window transfers. All of these transfers are automated, secured, and can be audited. Set for Success Instead of copying and piecing together scripts to send new file transfers (a process that took 30-60 minutes per script before), GoAnywhere can create a job in under five minutes. The team has utilised several areas of the software in a short amount of time and have exciting use cases in mind for the future. Of his favourite thing about GoAnywhere, the engineer said: "I love that I’m not on a batch file trying to deduce what’s going on. I can just visualise something [the workflow] and say ‘oh, this is what it needs.’ I can just set up a job and my coworker knows about it because now we get an email notification if it fails... Compared to what we had before, [our file transfer process] is where we need it to be." Previous Next

  • Asia-Pacific orgs are on Cybercrime Frontline | GSA

    < News Asia-Pacific orgs are on Cybercrime Frontline 12 July 2024 The Asia-Pacific region is the frontline in the fight against cybercriminals. A survey conducted by security firm Kiteworks has found that 72% of organisations in our region experienced four or more cybersecurity incidents in the past year - 20% more than the global average. Data also shows that Asia-Pacific organisations also exchange sensitive content with the highest number of third parties. This could be contributing to the higher-than-average cyberattacks. One of your best defences against hackers is to centrally control the flow of data into and out of your organisation. Managed File Transfer (MFT) software does that for you. At Generic Systems Australia , we’re the Asia-Pacific’s experts on the world’s #1 MFT, GoAnywhere . Let me know if you’d like an obligation-free discussion about how we could help you keep your organisation safe from the cyber crimewave. #MFT #managedfiletransfer #securefiletransfer #sft #cybersecurity #cybercrime Previous Next

  • Boards Warned on Increased Middle East Cyber Risk | GSA

    < News Boards Warned on Increased Middle East Cyber Risk 2 Apr 2026 Law firm Gilbert & Tobin has issued sage advice for Boards and senior management regarding the heightened cyber security risks from the Middle East conflict. Materially Increased Risk Gilbert & Tobin say the escalating armed conflict in the Middle East has “materially increased cyber risk for Australian organisations”. S&P Global Ratings recently observed that the war and broader geopolitical tensions have driven a significant increase in state-sponsored cyberattacks. Common targets are critical infrastructure, financial services, government and the private sector. The attacks typically attempt to dislocate essential services, disrupt supply chains and destabilise economies. Reports from cyber security specialists indicate an increase in phishing campaigns, ransomware-style attacks, data exfiltration and malware deployment targeting energy systems, financial institutions and government networks. Critically, supply chain links mean organisations well outside the immediate conflict zone, including in Australia and New Zealand, face indirect but material risk. The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has also been actively issuing alerts concerning the exploitation of network infrastructure by sophisticated threat actors, including state-sponsored groups. This is not a hypothetical risk. Modern conflicts routinely extend into cyberspace. For affected organisations, the consequences can include mandatory regulatory reporting obligations, enforcement actions, economic and reputational harm and litigation. Actions You Should Take Gilbert & Tobin recommend the following immediate steps: Board acknowledgement and oversight Boards should formally acknowledge the heightened external cyber threat environment at their next meeting. Directors should require the Chief Information Technology Officer and Chief Information Security Officer to review their organisation's current exposure to the external threat landscape and report back to the board on assessed risk and actions being taken. The reporting should address the adequacy of existing security controls, any gaps identified and a timeline for remediation. Active board engagement on cyber risk is increasingly expected by regulators and is consistent with good corporate governance. Proactive threat intelligence and risk posture review CITOs and CISOs should proactively review threat intelligence feeds from the ACSC, industry information-sharing bodies and trusted commercial threat intelligence providers. This includes monitoring for indicators of compromise associated with state-sponsored and hacktivist groups linked to the conflict, reviewing the organisation's risk posture against current attack vectors (including spear-phishing, ransomware and exploitation of network edge devices) and ensuring that detection and monitoring capabilities are calibrated to the heightened threat level. Organisations should ensure they are subscribed to ACSC alert service and are acting promptly on advisories. Organisations using a Managed Services Provider should engage with them to understand how they can support this review and uplift. Cyber insurance policy review Organisations should urgently review their cyber insurance policies for exclusions relating to war, armed conflict, or nation-state actors. In the current environment, where the lines between criminal cybercrime and state-sponsored operations are increasingly blurred, there is a real risk that insurers may seek to rely on these exclusions to deny or limit claims. Incident response plan testing Organisations should test their cyber incident response plans now. This includes conducting tabletop exercises that simulate scenarios relevant to the current threat environment, such as a ransomware attack attributed to a state-linked actor, or a supply chain compromise originating from a conflict-affected region. Organisations should proactively identify key response contacts, including forensic vendors, external legal counsel, insurers and relevant regulatory notification contacts and ensure those details are current and accessible. Supply chain and third-party risk assessment Organisations should review their supply chain and third-party dependencies for exposure to the conflict and associated cyber threats. Threat actors are known to exploit interconnections between organisations. Compromised suppliers and service providers can have cascading effects. Your review should prioritise third parties with operations in, or connections to, the affected region, as well as critical technology and infrastructure providers. Local Support Generic Systems Australia is always available to help Australian and New Zealand organisations enhance their cyber security through the world’s leading Managed File Transfer solution, GoAnywhere MFT . If we can help you consider how MFT can affordably bolster your cyber security in these troubled times, please get in touch . Previous Next

  • SES Encrypts and Audits Global Client Data | GSA

    < Case Studies SES Encrypts and Audits Global Client Data Decad es of experience helping Asia-Pacific customers have established Generic Systems Australia as our region’s local experts in secure managed file transfer. In this case study, we share how global experts in operational resilience – SES – take advantage of GoAnywhere MFT , the world’s leading MFT solution , to manage the transfer of more than 2,000 files daily. Software escrow agreements are becoming increasingly common for organisations worldwide. Medium and large enterprises, especially those in retail, energy, and financing, rely on these agreements to provide coverage for the unique source code, files, and other software assets critical to a company’s intellectual property. To prevent loss of this information during sudden downtime, a data breach, or natural disaster, organisations create a software escrow agreement with a third-party vendor to protect and back up their data. The third party then takes the data, creates an inventory of everything that’s to be escrowed, and puts the source code and other assets into a vault for maximum protection. SES is a third-party vendor that provides software escrow agreements, intellectual property protection, and cybersecurity risk management globally. Based in Manchester, UK, SES has more than twenty years of experience providing security to more than 2,500 professionals in 40+ countries. "Dealing with software escrow agreements is our bread and butter," said Tom Sweet, Information Security and Systems Manager at SES. It’s an area of constant growth and adjusting to keep clients happy and source code regularly updated. We are continually developing and innovating.” Often, SES does this with tools such as GoAnywhere MFT. For SES, GoAnywhere Managed File Transfer (MFT) has been a well-used and finely-tuned addition to its cybersecurity solutions. With the software in place, it performs on average nearly 2,000 uploads for clients per day — a mix of small and large files — as well as help monthly and quarterly businesses with their source code deposits. Switched from Manual File Transfers to Managed File Transfer Before GoAnywhere came into the picture, SES used a web gateway, an AWS-backed instance, to receive source code for its clients. It also occasionally used old-fashioned file transfer methods: physical disks and SD cards that were tracked, signed for, and had a direct chain of custody which could be followed. While this mixed process — AWS-backed instance and physical mail — worked at the time, it still lacked the ability to track user and file transfer activity. Having an audit trail was important to the business. When auditing also became a client requirement, SES looked for a way to streamline, structure, encrypt, and audit the exchange of data. SES handled a high volume of file transfers and needed robust security practices for the data it processed and stored every week. So the it was time to find a centralised solution which could do all of this and meet its trading partners’ needs. The tracked-and-signed file transfer processes SES used led to an evaluation of GoAnywhere MFT, a robust and fast-growing product which used similar techniques (tracking, signing, and a clear chain of custody) for sensitive file transfers. GoAnywhere was a hit. It took Tom Sweet mere days to learn the product. He attended two webinars, then jumped in and followed his intuition. The turnaround had to be quick, but the learning curve was straightforward. SES implemented GoAnywhere across its Linux systems and has depended on it ever since for day-to-day file transfers, streamlined encryption, and consistent auditing. Benefit#1: File Encryption and Security With GoAnywhere fully implemented, SES has been able to ensure all file transfers sent by its clients are encrypted in transit and sent to the right place. SES has also ensured that encryption keys are held separately. These are just two of the strict requirements SES needs to follow for its clients in order to stand out in a sea of escrow and backup service platforms. "It’s risk versus security," Tom said. "With HR and payroll data, the risk is high, so the security needs to be high as well."nearly 2,000 uploads for clients per day — a mix of small and large files — as well as help monthly and quarterly businesses with their source code deposits. Benefit#2: Fast File Transfer & Trading Partner Setup New trading partners and file transfer users can be set up in minutes. "Less than that if I’m rushed," Tom said. "The quickest ones we’ve had people test: I’ve sent the email saying here’s your username, sent the password out over SMS, and people test the log-in within 10 minutes." Sweet uses private and public keys to ensure the encryption and validity of the new transfers he creates. When the file transfers are executed, most run, start to finish, in less than 30 minutes. Benefit #3: Ease of Use & Automation "The main thing we use GoAnywhere for is managing users, auditing the logs, and giving users a secure gateway into our systems that would normally be firewalled," Tom, said. All of this is simple with GoAnywhere, and he believes the product’s biggest strength is its ease of use. Whether he needs to streamline, update, or re-deploy the product across systems and users, the process has been painless. Automation is another huge benefit of GoAnywhere. SES use GoAnywhere to do the heavy lifting for SaaS-based clients. These clients transfer large amounts of source code end data that are pushed into a SaaS escrow and captured in real time. "We help these clients configure a script that connects over SFTP to a GoAnywhere service," Tom said. "GoAnywhere then audits those transfers." The product securely transfers and audits at the same time, all automatically for nearly 60 clients who need their source code updated on a daily or monthly frequency. This enables SES to automate on Windows and Linux to meet the security requirements of each client. GoAnywhere’s granular security controls enabled Sweet to make GoAnywhere as safe and security-driven as possible against internal risks and user errors. "I stripped it back to who can do what," he said. Previously shared passwords were locked down. Web users were restricted to only the areas of the product they needed, and file storage was controlled — files could only be stored in the right areas of the network. "If someone in a company wanted access to the transfers, or to the systems, they could break the loop to that cycle. So that’s why we vault [client data] and back it up in an encrypted format. We make sure the file transfers are encrypted; that’s key too." Benefit#4: Regulation Compliance Many SES clients have compliance requirements which SES must meet. To achieve these needs, SES has applied ISO 27001 compliance across all clients to ensure all information sent between SES and other companies is secure. "ISO 27001 mandates that we create policies, processes, and procedures which we can prove using evidence-based systems," Tom said. "This says, ‘Okay, by default, you [the client] get all of this [security]. All files will be encrypted, and all second factor messages will be sent out-of-band so they aren’t sent over the same method of communication, and so on." Meanwhile, while encryption is the same and applied for everyone, clients can choose if they want to use multi-factor authentication (MFA) with passwords or SSH keys for an extra layer of security. GoAnywhere offers multi-factor authentication methods, including keys and certificates, for increased file protection. SES also uses GoAnywhere to encrypt every backup of escrow data that is then kept in offline vaults. "This ensures there’s 99.9% availability," Tom said. "No one thinks escrow is important until it’s too late," he added, so SES provides these offline backups with GoAnywhere’s help to give organisations peace of mind. Benefit#5: Auditing and Administration One of the biggest justifications for purchasing GoAnywhere was its auditing functionality. Tom and his team uses these audit logs to see who is connecting to their SFTP servers, what they’re doing on those servers, and how much they’ve done. This level of detail is critical, especially when dealing with sensitive escrow documents, software assets, and source code. "The log-in and auditing process in GoAnywhere is important for our information security standards. We audit the transfers not just to be able to take them securely, but also to prove who has been on and transferred what and when. The audit trail is important." If Sweet needs to change something, GoAnywhere makes it easy. Admins can make modifications or adjustments to their processes to keep constant with security requirements. "We can do this with GoAnywhere very easily," he said. "Then we just send out a new host key to our clients." What’s Next: Remote Agents and Advanced Workflows Right now, SES retrieves files from clients. But in the near future, it hopes to roll out GoAnywhere Remote Agents and GoAnywhere Advanced Workflows for customers who want zero involvement in the file transfer process. With these features enabled, Sweet and his team will be able to pull data from each client when needed without requiring manual work or engagement on their end. "Remote agents and advanced workflows will enable us to go out, talk to, and pull the requests for daily, weekly, or monthly file transfers," Tom explained. One Admin, One Product Tom Sweet has used GoAnywhere for four years. As the main product administrator, he’s always looking for new ways to implement the software, integrate it with other web and cloud services, roll it out as part of security-client processes, and improve the success of GoAnywhere at SES. "I want to get as much out of the product as I can," Tom said, reflecting on being the singular admin for GoAnywhere. "The more I push it out, the more we get a better return from our customer experience." And for any organisation — SES included — customer satisfaction is top priority. GoAnywhere’s encryption, automation, and ease of use help make that happen. Previous Next

  • Secret Ransomware Payments Rife: Survey | GSA

    < News Secret Ransomware Payments Rife: Survey 19 Aug 2024 Pervasive cyberattacks are leading most companies to pay ransoms and break their “Do Not Pay” policies, according to recent research. A poll of IT and security decision-makers conducted by Cohesity found that that most companies have paid a ransom in the last two years. In fact, 79% of respondents said their company had been the victim of a ransomware attack during the second half of 2023. The breadth of an organisation’s “attack surfaces” depends on the size and scope of its data environments. However, 78% of respondents said their data security risk had increased faster than the growth in the data they manage. They also said their organisation’s cyber resilience and data security strategies had not kept pace with emerging threats – only 21% had full confidence in their company’s cyber resilience strategy. Slow Recovery, Lack of Testing Cyber resilience is a critical element of business continuity, and encompasses a company’s ability to recover their data and restore business processes when they suffer a cyberattack or IT outage. Key insights from the survey on this point included: All respondents said they need more than 24 hours to recover data and restore business processes. Only 7% said their company could recover data and restore business processes within 1-3 days. 35% said they could recover and restore in 4 to 6 days, while 34% need 1-2 weeks, and 23% need more than 3 weeks. Only 12% of those surveyed said their company had stress-tested their data security, data management, and data recovery processes or solutions in the six months prior to being surveyed. 46% hadn’t tested in more than 12 months. Secret Ransom Payments While 84% had a “do not pay” policy, Cohesity reported that 94% of respondents divulged that their company would pay a ransom to recover data and restore business processes. 5% said “maybe, depending on the ransom amount”. Two thirds said their company would be willing to pay over US$3M to recover data and restore business processes, and a third said their company would be willing to pay over $5M. Don’t Pay: Prevent! The volume, frequency, and sophistication of ransomware attacks will only increase. And paying ransoms only encourages cyberthieves to escalate their efforts. Worse, if ransoms are seen as “easy money”, new miscreants will be tempted to acquire ransomware tools from the dark web and join the cyber crimewave. Rather than investing in ransoms, organisations need to invest in their cyber resilience. That starts with keeping thieves at bay - protecting valuable data where it is stored, and when it is transferred – and building organisational capability in rapidly responding to and recovering from cyberattacks. Building cyber resilience need not be a drag on an organisation’s efficiency. Automation can ensure data is protected at rest and in motion, requiring little to no manual management. For example, Managed File Transfer (MFT) solutions such as the class-leading GoAnywhere MFT encrypt data at rest and in transit, complying with the highest data security standards (including the US’s and Europe’s HIPAA, HITECH, PCI DSS, SOX, and GDPR). MFT manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols such as SFTP, FTPS, and AS2 to send files securely, and encryption standards such as Open PGP and AES to protect data in transit and at rest. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection enables safe collaboration with external parties, preventing malware from entering your organisation, and reducing opportunities for employees to lose or mishandle sensitive data. Local Expertise Ready to Help Generic Systems Australia are your local experts in Managed File Transfer and Advanced Threat Protection. We’ve assisted hundreds of organisations across the Asia-Pacific region to secure their data, keep cybercriminals at bay… and keep ransomware off the books. If you’d like to discuss improving your cybersecurity, please feel welcome to contact me , Bradley Copson. I’m always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. About the survey: Cohesity’s findings are based on a survey of 902 IT and Security decision-makers (split as close to 50:50 as possible) commissioned by Cohesity and conducted by Censuswide. Survey respondents were polled from businesses in Australia, the United Kingdom, and the United States. The top five industries selected by respondents as best representing the industry their company operates in were: IT & Telecommunications, Finance, Healthcare, Finance, HR, and Manufacturing & Utilities. Previous Next

  • GoAnywhere's Cloud Connectors | GSA

    < News GoAnywhere's Cloud Connectors 17 Mar 2024 Seamlessly integrate GoAnywhere with External Services via Cloud Connectors Cloud Connectors enable you to easily and securely transfer files between your organisation and external cloud services and applications. Also referred to as “cloud integrations”, Cloud Connectors offer out-of-the-box connectors for GoAnywhere to popular services including Salesforce, SharePoint Online, Microsoft Dynamics 365, Box, and Dropbox. For example: Let’s say one of your trading partners requests an important file and wants you to share it via a folder in Dropbox. Or perhaps you have contacts or billing information you want to update automatically in Salesforce. Cloud Connectors enable you to easily do so. Broad Range Cloud Connectors are easily downloaded from GoAnywhere MFT’s integrated Marketplace, which features Connectors for the most commonly used cloud services. These include: • Alibaba Object Storage Service • Amazon Cloud Trail, CloudWatch, EC2, Lambda, SNS, and SQS • Atlassian JIRA • Automate Plus • Azure Data Lake Storage Gen1 (superseded by Gen2) and Storage Queue • Box • Citrix ShareFile • Dropbox • Egnyte • GateScanner CDR • GoAnywhere Command • Google Cloud Storage, Drive, and Translate • JAMS • Jenkins • Microsoft Dynamics 365 Business Central, 365 CRM, OneDrive, Sharepoint Online and Sharepoint On-Premise • OPSWAT MetaDefender • Salesforce • ServiceNow • SMA OpCon Scheduler • SOS Berlin JobScheduler (Online version not supported) • Trello • Veeva CRM • Votiro • Webdocs • Zendesk (Online version not supported) Cloud Connectors can integrate with available on-premise and online versions of third-party software unless otherwise noted. How to Configure Cloud Connectors Once a Cloud Connector is installed, you can configure the connection properties as a GoAnywhere Resource. With this resource, you only need to specify the connection once before being able to seamlessly reuse it in any of your workflows and cloud file transfers. A Cloud Connector definition contains the various actions required to communicate with cloud applications. For example: authentication logging file transfer file management and error handling. In GoAnywhere, these actions appear as elements located under the Cloud Connector in the GoAnywhere Project Designer. Elements can be incorporated into your workflows alongside other project tasks, and processes can even be automated between multiple web and cloud services at once. New GoAnywhere connectors can be downloaded without needing to update the software. No Connector? No problem! While GoAnywhere Marketplace contains a broad array of Cloud Connectors, you may also want to connect to a unique external service. Custom connectors are the answer! At Generic Systems Australia, we can design and develop Custom Connectors for you, using GoAnywhere’s Cloud Connector Designer. If you’d like to discuss how your organisation’s file transfers to external cloud providers can be made more efficient and secure, please feel to contact our Business Manager, Bradley Copson (mail to: bradley@gensys.com.au ). He’s always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Generic Systems Australia Your Local Experts in Managed File Transfer #MFT #managedfiletransfer #securefiletransfer #sft #cybersecurity #datatransfer Previous Next

bottom of page