How Managed File Transfer Changed My Life

Tuesday, January 24, 2012 Posted by
In addition to being one of Linoma Software’s expert bloggers, Daniel Cheney is also in the IT trenches, and it was here that he first discovered the impact the switch to a managed file transfer solution had on his daily work life.
_ _ _ _ _ _ _ _ _ _

As a technology administrator at a major healthcare administration company, sending and receiving sensitive files between various systems used to be a daily grind and a consistent source of stress. We were using PC-based freeware FTP tools and the built in FTP functions on the IBM iSeries. The best we could do with scripting was to use CL command scripts to call the FTP function and hard code the login information. RPG programs would then call the CL scripts and retrieve and send the needed files, but there were insufficient logs and alerts for such automated activities.

managed file transfer, secure file transfer, secure ftpThe biggest headache for me was that these scripts, and the resultant sending of files, had to be error-free and reliable! Add to that the pressure of knowing how critical exchanging files is to the operation of the business and the challenge of  having a single person responsible for its success — it all became an unrealistic expectation.  On top of this, because most of these files are sent over the Internet, and because of the inadequate tools we had at hand, the security of our FTP processes was insufficient.

I knew it was time to find a better solution and after doing some evaluation of available managed file transfer products for IBM iSeries, I selected GoAnywhere™ Director from Linoma Software.

Our installation of GoAnywhere Director made a huge difference almost immediately.

First, Director provides me with all the possible security protocols available, including SFTP, FTPS, and standard FTP with PGP encryption.  It also has powerful scripting functions to login to HTTP and HTTPS sessions in order to automate logins to partner sites for file transfers.

Director makes it possible to automate all of the company’s file transfers with a schedule and log so we know the path and time of every transaction.  Alerts are automatically sent to us if there are any problems, or if we wish, every time it succeeds.  Responsibility can be distributed to various departments as needed to receive these alerts and/or to begin the execution of the transfers when ready.

The simple-to-navigate web interface makes it easy for any user to view, verify, change and execute these file transfers.  The scripting is easy for the average user to setup. If there are any challenges that we come up against with our file transfer processes, Linoma support has always been extremely effective at showing me how to do a successful execution.

I know how frustrating it can be to initiate, monitor, and track the ever increasing number of file transfers my company requires, especially without an all-in-one tool like managed file transfer.  It amazes me how many IT people still don’t realize there’s a better way to do things — a way that gives them more control, and more time to devote to all the other projects demanding their attention.  I know managed file transfer — and specifically GoAnywhere Director — changed my life at work.  I hope more of my IT colleagues discover the advantages soon.

GoAnywhere Director Version 4.0 Released

Tuesday, January 3, 2012 Posted by

There’s no better way to kick off the new year than with a new release of Linoma Software’s GoAnywhere™ Director, our popular managed file transfer software.

managed file transfer, secure file transfer

GoAnywhere Director is the flagship component of the GoAnywhere managed file transfer suite, and it’s used by thousands of enterprise customers who need to initiate secure file transfers as part of their daily workflow.

Whether exchanging data with trading partners, vendors, customers, or even other servers, GoAnywhere Director is the preferred solution for our clients in both the IBM Power Systems environment as well as Linux, Windows, Solaris and others because it simplifies, automates and secures file transfers efficiently, while still remaining affordable.

Director 4.0 has added a variety of features to improve the user experience, including enhanced job controls, custom add-ons, new options for holiday calendars for scheduling, and more than 30 additional advanced functions.

For more details, check out our latest announcement, or dig deeper by reviewing the software release notes.

If you’ve been considering a different solution for handling your secure file transfers, we invite you to begin 2012 by investigating GoAnywhere. Learn more about our managed file transfer solution, or simply request a free trial.

Latin American Bankers to Discuss Data Security

Monday, September 12, 2011 Posted by

This week, bankers and banking security experts from the U.S. and Latin America will gather at the InterContinental Hotel in Miami for one of the largest annual bank security conferences for senior Latin American bankers. CELAES 2011, the 26th Annual Conference of Banking Safety takes place September 15-16.

Given that Latin America has one of the highest rates of users who access banking online through computers and mobile technology, bankers have plenty of reason to stay on top of the latest cyber threats and security measures.

The Florida International Bankers Association (FIBA) and the Federation of Latin American Banks (La Federación Latinoamericana de Bancos – FELABAN) are hosting this unique joint Spanish/English conference. Attendees can participate in a variety of educational sessions on best practices for banking security, as well as gain access to vendors offering the latest security hardware, software cloud computing strategies for the banking sector.

Cyber crime is not just Latin America’s concern

data security A large portion of this year’s conference is devoted to preventing data breaches through security management of data, cloud services, electronic fraud detection and risk mitigation.

What makes Latin America’s challenges relevant is that the tactics developed by the cyber criminals that thrive there can be used on any financial system in the world. Conferences like the  CELAES 2011 conference helps educate and present solutions to banking executives in Latin America and help close the doors on cyber criminals.

Cyber crime in Latin America’s financial industry remains a serious concern for a variety of reasons. The developing legal systems in many Latin American countries are adding laws to combat cyber crime, but enforcement is lacking. This is further compounded by the absence of the “personal privacy” notion within many of the governing entities in some Latin American countries. Another issue for the Latin American financial sector, according to Frost & Sullivan, is that 70% of people making online transactions believe that the bank or service provider is responsible for fraud and protecting their online security.

Phishing, fraud and malware are common

Crime organizations and cartels present in Latin America have contributed to or funded cybercrime networks, making Latin America a haven for illegal electronic activity. Not only are these organizations stealing money and account information through online phishing/fraud, Bloomberg reports that one Mexican cartel is openly selling their own pirated versions of Microsoft products. Sold for a fraction of the retail cost, who knows what Trojans and back doors are included as “features.”

The ESET Trends and monthly Threat Reports calculate that 1 in 20 computers in Latin America are infected and the spread of malware is gaining speed as USB devices and now gaming consoles account for 40% of malware propagation. The growing number of infected machines gives the attackers a strong network of resources for both direct and indirect attacks on the financial sector.

The same PCI Data Security Standards required for financial institutions in North America are making an impact in Latin America. Financial institutions are realizing that they are less susceptible to a breach during a cyber attack when they’ve spent the time and resources to implement even a few of the PCI requirements like network monitoring, complex passwords and data encryption of account and payment information (PCI DSS requirements now apply to International payment processing).

Linoma Software is part of the solution

data securityDuring the conference Linoma Software’s partner Green Light Technology, a conference sponsor and a respected solutions provider for  the Latin American banking industry, will present Crypto Complete for database encryption and the GoAnywhere secure managed file transfer solutions. Both products protect and encrypt sensitive data, reduce access to primary systems, provide data workflow automation and detailed audit features.

Thanks to the efforts of FIBA, FELABAN and cooperation among international agencies, Latin American banking and finance representatives have the opportunity to fight back against cyber criminals, and the lessons learned will benefit all of us.

Managed File Transfer Solution Now on Video

Wednesday, August 17, 2011 Posted by

We’re always looking for new ways to illustrate the power and versatility of our GoAnywhere suite of secure file transfer and encryption solutions.  Very simply, GoAnywhere helps you streamline, encrypt and automate your file transfer processes to save time and money while meeting ever-growing compliance requirements.

Still, we find it’s sometimes challenging to quickly explain the power and convenience of our managed file transfer software, so we’re excited to introduce some brand new videos to showcase the flexibility and control GoAnywhere clients have.

GoAnywhere secure file transfer software solution

GoAnywhere’s suite of secure file transfer solutions helps you manage all of your organization’s inbound and outbound file transfers — both internally as well as with external trading partners.

With support for virtually any platform and protocol, including FTP, FTPS, SFTP, HTTP/S, AS2, SMTP and ZIP, GoAnywhere puts local control of the entire process into one intuitive dashboard.  GoAnywhere eliminates the need for custom scripts, generates detailed audit logs, and provides a rich catalog of features for comprehensive management, all without additional hardware or specialized skills.

If you’d like to test drive a free trial, let us know.  We’d also love to hear what you think of our videos!

Crypto provides Swiss bank its backup encryption solution

Monday, August 1, 2011 Posted by

When you’re an international bank striving to protect your clients’ data, should you rely on new hardware or a data encryption software solution?

Crypto Complete backup encryptionIn Linoma Software’s latest case study, IDB (Swiss) Bank faced this dilemma, and after careful research, chose Crypto Complete to help them serve the privacy needs of their clients while meeting compliance requirements.  Crypto Complete provides both field and file encryption as well as backup and IFS encryption.

Thanks to the cost-effective backup encryption options Crypto Complete delivers for iSeries users, as well as the attentive support both from Linoma Software and the local team from the European Software Business Development (ESBD), IDBS was up and running quickly with a long-term strategy in place.

To learn more about how IDBS made the decision to choose Crypto Complete, please explore our newly released case study.

Citigroup Breach Triggers Congressional Response

Monday, July 11, 2011 Posted by

The data breach at Citigroup in May – a breach which reportedly exposed an estimated 200,000 customer accounts – has motivated members of the U.S. Congress to re-introduce legislation to penalize the very organizations that have been victimized by hackers.  What are the next steps your company should take?

New bills to protect consumers’ personal dataLinoma Software Managed File Transfer Solutions

Two bills are proposed by both House and Senate legislators.

First, Sen. Patrick Leahy (D-Vt.) has introduced the Personal Data Privacy and Security Act of 2011.  The new bill provides:

  • Tough criminal penalties for individuals who intentionally or willfully conceal a security breach involving personal data;
  • A requirement that companies that maintain personal data establish and implement internal policies to protect data privacy and security; and
  • A requirement that the government ensure sensitive data is protected when the government hires  third-party contractors.

This act would also require, under threat of fine or imprisonment, that businesses and agencies notify affected individuals of a security breach by mail, telephone or email  “without unreasonable delay.” Media notices would be required for breaches involving 5,000 or more people.  The FBI and the Secret Service would need to be notified if the breach affects 10,000 or more people, compromises databases containing the information of one million or more people, or impacts federal databases or law enforcement.

But that’s not the only security bill that has businesses concerned.

In the House, Rep. Mary Bono Mack (R-Ca) is holding hearings in preparation of a bill she’s named The SAFE (Secure and Fortify) Data Act that would also require “reasonable security policies and procedures” to protect consumers and enable disclosures to victims and the Federal Trade Commission within 48 hours of a data breach.

Companies no longer viewed as the victims

All this sounds good from the consumer’s point of view. But what about the expense – and potential Linoma Software GoAnywhere Managed File Transfer Solutionpenalties – suffered by the “owners” of the data: the businesses themselves?

While these bills may address the public’s interest for notification — and indeed they would bring some semblance of a national standard – they also represent an interesting shift in the liabilities that companies will face.  How is that?

Though we currently have no federal data breach notification law, federal policies now view the companies that experience a data breach as the victims of crime. However, under the proposed legislative bills, companies that do not act quickly to appropriately secure the personal data of customers – or fail to report a data breach in a reasonable amount of time – would not only suffer the theft of data, but also be held liable for its loss.

This is a significant shift. Companies are now being viewed not as the owners of consumer data, but merely guardians and trustees whose job it is to protect that data or face criminal penalties. And the message is clear: if companies won’t take adequate precautions to secure the sensitive data of our customers, they’ll pay a hefty price.

Where does your company stand?

In a world in which diligent hackers have the power break into seemingly secure networks and systems, what can your company do?

The challenge is first to determine exactly what qualifies as adequate precautions.

GoAnywhere Secure Managed File Transfer A review of the HIPAA HITECH security provisions that took effect last year provides some insight about what the government considers adequate protection.

HITECH strongly recommends the use of encryption technology. Encryption is a good place for your company to start, especially when dealing with the data your company stores on its servers.  If sensitive data itself is kept securely encrypted, a data breach doesn’t expose the content of the information itself.

Secure managed file transfer protocols – which send data using encryption – is the second place to focus attention.

If data is encrypted when it is being securely transmitted between business partners, the value of that data should it be breached – through hacking, theft, or other malicious actions – is worthless.  Encryption and secure managed file transfers can dramatically minimize the holes of technical breaches, significantly reducing an organization’s liability.

Preventing exposure

The Citigroup data breach has rekindled the momentum for a nationwide, cross-industry data breach reporting standard. This standard will not to eliminate the physical breaches themselves. What’s needed is legislation to encourage companies secure the underlying data that is the target of the hackers.

Isn’t it time for your company to take a serious look at its liabilities and to investigate how encryption and managed file transfers can close these important security holes?

Top 10 Healthcare Data Breaches in 2010

Monday, June 6, 2011 Posted by

Most data breaches are caused by simple acts of carelessness.

Last March the Ponemon Institute released its findings for the 2010 Annual Study: U.S. Cost of a Data Breach. The study — based on the actual data breach experiences of 51 U.S. companies from 15 different industry sectors — revealed that data breaches grew more costly for the fifth year in a row. They jumped from $204 per compromised record in 2009 to $214 in 2010.

The increase in cost, however, pales in comparison to the reputational cost of companies that have been victimized, particularly in the healthcare sector.

HITECH builds Wall of Shame

Consider that the U.S. Department of Health and Human Services has begun posting the data breaches affecting 500 or more individuals as required by section 13402(e)(4) of the HITECH Act.  The New York Times has labeled this site “The Wall of Shame”.  Why? Because if patients have no faith in electronic record-keeping, the future of healthcare record automation will be jeopardized: Law suits and government regulation will bury any cost-savings.

The Back Stories of Healthcare Data Breaches

What are the stories behind the most severe healthcare sector data breaches reported in 2010?  Here are the ten most expensive stories, in ascending order of cost, documented in the Privacy Rights Clearing House database. While they’re sober reminders of the problem of keeping data secure, they’re also instructive: none of these breaches were malicious hacks, but were instead the results of theft, poor record-keeping policies, and simple human error.

(Note that the estimate of liability uses the $214/ record cost identified by the Ponemon Institute in its annual report. We have purposely not published the names of the reporting institutions.)

10th Most Expensive: Physician Computer Theft Exposes 25,000

On June 29th of 2010 a thief stole four computers from a physician specialist’s office in Fort Worth, Texas.  This theft resulted in an estimated 25,000 patient records being exposed.  The patient records contained addresses, Social Security numbers and dates of birth. Estimated liability: $5,350,000.

9th: Medical Center Theft Exposes 39,000

On the weekend of May 22nd, 2010 two computers were stolen from a medical center in the Bronx. Names, medical record numbers, Social Security numbers, dates of birth, insurers, and hospital admission dates of patients were known to be on the computers.  Total records compromised: 39,000. Estimated liability: $8,346,000.

8th: Optometrist’s Computer Theft Exposes 40,000

A computer stolen from an Optometry office in Santa Clara, California on Friday April 2nd, 2010 contained patient names, addresses, phone numbers, email addresses, birth dates, family member names, medical insurance information, medical records, and in some cases, Social Security numbers. Though the files were password protected, they were not encrypted.  A total of 40,000 records were lost, with an estimated liability of $8,560,000.

7th: Medical Records Found at Dump Expose 44,600

Medical records were found at a public dump in Georgetown, Massachusetts on August 13th, 2010. The records contained names, addresses, diagnosis, Social Security numbers, and insurance information. A medical billing company that had worked for multiple hospitals was responsible for depositing the records at the dump. The exposure required the hospitals to notify patients – an effort that continues to this date.  The total number of records known to have been exposed is 44,600, but the search continues.  Estimated liability: $9,544,400.

6th: Consultant Laptop Stolen Exposing 76,000

On March 20th, 2010, in Chicago, Illinois, a contractor working for a large dental chain found his laptop stolen.  The computer held a database containing the personal information of approximately 76,000 clients, including first names, last names and Social Security numbers. Estimated liability: $16,264,000.

5th: Lost CDs Expose 130,495

On June 30th, 2010 a medical center in the Bronx reported that it had failed to receive multiple CDs containing patient personal information that was sent to it by its billing associate.  These CDs were lost in transit. Information of 130,495 patients included the dates of birth, driver’s license numbers, descriptions of medical procedures, addresses, and Social Security numbers.  Estimated liability of $27,925,930.

4th: Portable Hard Drive Theft Exposes 180,111

In Westmont, Illinois, a medical management resources company reported on May 10, 2010 that a portable hard drive had been stolen after a break-in.  The company believes the hard drive contained personally identifiable information about patients including name, address, phone, date of birth, and Social Security number. The company acknowledged that this hard drive had no encryption.  As a result, 180,111 records were exposed, creating an estimated liability of $38,543,754.

3rd: Leased Digital Copier Leaks 409,262

On April 10th, 2010 a New York managed care service in the Bronx reported that it was notifying 409,262 current and former customers, employees, providers, applicants for jobs, plan members, and applicants for coverage that their personal data might have been accidentally leaked through a leased digital copier. The exposure resulted because the hard drive of the leased digital copier had not been erased when returned to the warehouse. Estimated liability: $87,582,068.

2nd: Training Center Hard Drive Theft Center Exposes 1,023,209

The theft of 57 hard drives from a medical insurance company’s Tennessee training facility in October of 2010 put at risk the private information of an estimated 1,023,209. customers in at least 32 states. The hard drives contained audio files and video files as well as data containing customers’ personal data and diagnostic information, date of birth, and Social Security numbers, names and insurance ID numbers. That data was encoded but not encrypted. Estimated liability to date: $218,966,726.

Most Expensive of 2010: Two Laptops Stolen Exposes 860,000

A Gainsville, Florida health insurance company reported in November of 2010 that two stolen laptops contained the protected information of 1.2 million people.  This is an on-going story, as new estimates are calculated.  To date, the estimated liability is $256,800,000.

Preventing Exposure: Data Encryption

These cases document that the majority of the data breaches which occurred in 2010 were not the result of hacking activities, or even unauthorized access by personnel. The greatest data losses were simply the result of computer theft of portable devices and misplaced media.  Had the contents of the files been encrypted, this could have significantly reduced the risks and liabilities of these data losses.

Time and time again, industry experts point to data encryption as the key method by which organizations can prevent inadvertent exposure of sensitive data.

Of course, no healthcare organization wants to be listed on the US Department of Health and Humans Services’ Wall of Shame.  And the costs – in dollars and in reputation – can be extraordinary.

Isn’t it about time your management got serious about data encryption?

Driving Securely Through “The Cloud ”

Monday, May 23, 2011 Posted by

The Cloud“Cloud Computing” is not for everything and not for everyone, but it has made a permanent mark in the lexicon of technology services.

What is Cloud Computing?

In simplistic terms, the Cloud is any application, file host, or virtual computer that is accessed solely via the Internet. The hardware and software actually running those services could be anywhere and therefore is referred to as being in “the Cloud.” The Cloud originally was the graphic reference for the Internet in a corporation’s network diagram, but now it refers to the services available via the Internet.

Security Concerns in the Cloud

Security professionals have always had concerns over remote file hosting sites (FHSs) and the recent Tech News about services like RapidShare and Dropbox came to light this week confirmed some of those concerns. Data security in the cloud is like a verbal agreement – as good as the paper it’s written on. Yet the general public and some individuals in large corporations flock to these services daily – completely unaware of the security risks or understanding how “The Cloud” works. Personally Identifiable Information and other sensitive data is floating around and often falls out of the cloud, landing in the wrong hands.

Regardless of the encryption or security practices professed by a Cloud provider, once the data leaves your network, you no longer own, control, or are able to audit that data. In the case of a subpoena at a data center, a cyber attack or when a device is stolen from a Cloud host, that data has been compromised.

There are great advantages and cost-savings to using Cloud based options to accomplish certain business goals. Renting processing time and applications can work out to a lower Total Cost of Ownership, but beaware of the strings attached. I have taken many applications for test-drives in the Cloud, but when I am responsible for transferring sensitive data on which my employer’s integrity and liability are on the line, I prefer using a secure managed file transfer product to drive through the Cloud.

A Secure File Transfer Solution

Connections that are configured correctly will securely send and retrieve files that meet or exceed compliance requirements. The GoAnywhere managed file transfer solution easily encrypts, securely sends and processes data over your existing Internet connection. The GoAnywhere Director automated file transfer application also securely transforms data between platforms and provides native XML scripting.

Subscribe to this Blog for the next installment: Fuel Efficient Hybrid-Clouds and Going Green with Server Virtualization.


Managed File Transfer Streamlines HIPAA/HITECH Complexity

Monday, May 9, 2011 Posted by

Managed File Transfer (MFT) systems are great for policy enforcement, access authentication, risk reduction, and more. But for HIPAA and HITECH requirements, MFT shines as a work-flow automation tool.

MFT as the B2B Enabler

It shines because Managed File Transfer systems are actually automation platforms that can help companies streamline the secure transfer of data between business partners. How? It removes many of the configuration steps traditionally required for complex Business-to-Business (B2B) processes, keeping it straightforward and manageable.

Transferring patient information is a difficult challenge which many healthcare institutions are facing. Data standards were supposed to simplify this communication between healthcare institutions and their partners. But ask any technical professional about the underlying variability of data formats, and you’ll hear a tale of potential confusion and complexity.

Nightmares of Compliance

The HITECH regulations within HIPAA require the security and privacy of healthcare records, strongly suggesting the use of data encryption. These records may travel between various healthcare-related partners including hospitals, clinics, payment processors and insurers. Each partner may require their own unique data format, and each may prefer a different encryption technique or transport protocol.

Considering these differing requirements, adding each new trading partner has traditionally needed the attention of in-house programming or manual processes, which has become hugely inefficient. Furthermore, if the new trading partner is not implemented properly, this can also create the potential for errors that may lead to data exposures. Any exposures could move the healthcare institution out of HIPAA/HITECH compliance and may cost them severely.

Simplifying and Integrating Information Transfer

A Managed File Transfer (MFT) solution can significantly reduce the potential for errors and automate those processes. With a good MFT solution, any authorized personnel should be able to quickly build transfer configurations for each healthcare business partner. This should allow for quick selection of strong encryption methods (e.g. Open PGP, SFTP, FTPS, HTTPS) based on the partner’s requirements, so that HITECH requirements are maintained. At the same time, a MFT solution creates a visible audit trail to ensure that compliance is sustained.

But, perhaps just as important, a good Managed File Transfer solution is constructed as a modular tool that can be easily integrated into existing software suites and workflow processes. In fact, a good MFT is like a plug-able transfer platform that brings the variability of all kinds of B2B communications under real management.

Now extend the MFT concept beyond the healthcare business sector, into manufacturing, finance, distribution, etc. Suddenly MFT isn’t a niche’ utility, but a productivity and automation tool that has myriad uses in multiple B2B environments.

A Day-to-day Technical Solution

Perhaps this is why the Gartner Group has identified Managed File Transfer as one of the key technologies that will propel businesses in the coming years. It’s more than just a utility suite: It’s a system that can be utilized over and over as an integral part of an organization’s solutions to automate and secure B2B relationships. In other words, MFT isn’t just for specialized compliance requirements, but a lynch-pin of efficient B2B communications technology that can bring real cost savings to every organization.

Healthcare Case Study Utilizing a MFT Solution: Bristol Hospital Takes No Risks with Sensitive Data

Data Breach: Are You Next (or Again)?

Monday, April 25, 2011 Posted by

A data breach is closer than you think. As the percentage of data breaches increase, the risk of organizations losing your sensitive data also increases. No one wants to receive the news that some or all of their personally identifiable information (PII) was stolen. There are people who are victims of various phishing scams, but it is more likely that your information will be leaked or stolen from an organization.

The health care industry is currently in the spotlight, as they are moving to mandated Electronic Health Records (EHR) and the American National Standards Institute (ANSI) is investigating the two main health care related data privacy concerns today: how to protect patient information and what is the financial harm or cost per record if it is stolen.

The numbers are staggering. According to the Privacy Rights Clearinghouse (www.privacyrights.org), there have already been 47 reported leaks or breaches in the health care realm this year. That is about one every other day (102 additional reported breaches if counting business and government).

In the world of data security; breaches are no longer thought of in terms of “if,” but “when.” Fortunately, there are easy steps companies and health care organizations can take to protect the PII that they maintain from direct hacking attempts. The procedures data security companies recommend you acquire begin with the following:

  • Require strong passwords
  • Use encryption to protect files in motion and at rest
  • Reduce the number of computers that process sensitive information
  • Audit every transaction
  • Limit the number of accounts that can access the critical data

The organization you own or work for doesn’t have to be the next headline, start researching different options to protect your customer’s sensitive data and keep your organization from a possible breach. The fines and surcharges are exponentially higher than purchasing a secure managed file transfer solution or a database encryption tool. Not sure where to start? Read the Top 10 Managed File Transfer Considerations.