Rethinking secure file transfer for a cross-domain world
The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.
<![CDATA[ <article> <p>The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.</p><p>That warning applies to all organizations relying on cross-domain processes to move data between environments with different security levels, and especially to complex cyber-physical systems where data flows between standard IT and operational technology (OT) assets.</p><p><a href="https://www.techradar.com/best/best-ways-to-transfer-files-online">File transfer</a> is one of these fundamental processes but remains one of the most often overlooked.</p><p>Every <a href="https://www.techradar.com/best/best-billing-and-invoicing-software">invoice</a> sent to a supplier, every firmware update pushed to a factory floor, every report shared with a regulator is data crossing between systems with different levels of trust.</p><p>For years, file transfer security has been treated as a solved problem. Enterprises were happy to encrypt the channel, confirm delivery, and move on. That approach made sense when systems were simpler, and threats moved more slowly. However, it no longer reflects reality.</p><h2 id="why-perimeter-based-trust-no-longer-holds">Why perimeter-based trust no longer holds</h2><p>Most file transfer platforms were never built with security as the primary goal. They were built to move data reliably between systems, encrypt the connection, confirm that a file arrived, and log that the job was done. Whether the file itself was safe was rarely part of the equation.</p><p>That gap provides a consistent way for cyber attackers to gain a foothold in their targets' systems. A file transfer platform sits between organizations by design, trusted by both sides precisely because it's meant to be routine infrastructure.</p><p>The traditional Managed File Transfer (MFT) model is built to automate file delivery, not to defend against attack. As such, it leaves the process exposed to a familiar set of threats, from man-in-the-middle interception and credential theft to <a href="https://www.techradar.com/best/best-malware-removal">malware</a> covertly embedded in an otherwise ordinary file. Attackers don't need to break the platform itself, only to exploit the assumption that whatever moves through it can be trusted.</p><p>As we've seen with incidents like 2023's MoveIT supply chain cyberattack and last year's SharePoint breach, a single vulnerability in a widely used transfer tool can give attackers access to thousands of organizations at once, simply because every one of them assumed the platform itself could be trusted.</p><p>That assumption is exactly what attackers are counting on. Securing the channel a file travels through was never the same as securing the file.</p><h2 id="the-shrinking-window-to-respond">The shrinking window to respond</h2><p>File security has always been a blind spot, but it's become much more critical in recent years as the attack lifecycle continues to accelerate. Newly disclosed vulnerabilities are now routinely exploited within 48 hours of becoming public, leaving little room for <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> by organizations to prepare, or even notice before they're targeted.</p><p>Detection, by contrast, still moves comparatively slowly. Breaches involving file-based attacks can go unnoticed for months, giving an intruder ample time to move laterally, extract data, or embed themselves further into connected systems before anyone realizes something is wrong.</p><p>It's not simply that attackers are fast, but that most organizations still treat file movement as something to review after the fact rather than control at the point of entry. By the time a malicious file is identified, the damage has often already been done.</p><p>This is why proactive, layered controls around every file entering or leaving the business matter more than ever. Waiting to react is not a viable strategy.</p><h2 id="establishing-continuous-file-verification">Establishing continuous file verification </h2><p>Closing this gap means shifting towards a security-first MFT process, where every file, user, and workflow is treated as a potential point of exposure rather than assumed safe by default.</p><p>Prevention is by design, rather than protection bolted on afterwards as with most traditional MFT models. And that starts with looking inside the file, not just authenticating the channel it arrives through.</p><p>Deep content inspection examines the file's actual structure, identifying hidden or malicious elements that a simple scan would miss. Alongside this, automated vulnerability detection and malware prevention should apply to every file by default, not as an optional extra reserved for high-risk transfers. Even the most innocuous file can now serve as a powerful attack vector – in fact, threat actors are counting on it.</p><p>Likewise, savvier attackers are actively designing payloads to evade detection, so standard processes need <a href="https://www.techradar.com/best/best-backup-software">backup</a>. Potentially malicious files need to be tested in a safe, isolated environment where their behavior can be observed before they ever reach a live system. This kind of sandboxing catches clues missed by reputation checks and static scanning, revealing intent rather than simply checking for known signatures.</p><p>A Content Disarm and Reconstruction (CDR) process is a valuable addition here, deconstructing files and sanitizing them by removing any active content without harming function.</p><p>However, none of this works as a single checkpoint. Each of these controls needs to feed into a continuous process, where a file is validated at every stage of its journey rather than cleared once and trusted from that point on. These capabilities should also be paired with constant monitoring and detailed audit visibility, so that if something does slip through, organizations know exactly what moved, where it went, and what it touched.</p><p>As a result, organizations can reliably build confidence in data as it crosses between environments, rather than assuming that confidence once and carrying it forward unchecked.</p><h2 id="closing-the-loop-on-trust">Closing the loop on trust</h2><p>The NCSC's warning and guidance on cross-domain systems point to the same conclusion: security built on fixed boundaries can no longer keep pace with how data actually moves.</p><p>File transfer is where that principle emerges most often in daily practice. Trust that was once given on principle must now be earned at every crossing. That shift, more than any single tool, is what will define resilient file transfer going forward.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've reviewed, rated, and ranked the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> </article> ]]>
Read the full article on TechRadar
Read Full Article →