Catch Advisors
IT Strategy

Managed File Transfer Renewal: Trace Every Scheduled Exchange to a Business Owner

Managed file transfer renewals often start with a product question: Should we keep the platform, move it to the cloud, or replace it?

That question comes later.

First, prove what the platform is moving. MFT environments collect scheduled jobs, partner accounts, service identities, folders, keys, certificates, scripts, retention rules, and support dependencies. Some exchanges run every five minutes. Others run once a quarter. A few may have stopped doing useful work years ago, but nobody wants to touch them because the original owner left.

Do not renew that mess as one package.

Trace every important exchange to a business purpose, a sender, a recipient, accountable owners, defined data, working credentials, usable evidence, and a tested recovery path. Then decide what to renew, correct, retire, restrict, consolidate, or compare.

Build the exchange register before reviewing the quote

Start with the agreement, order forms, invoices, job export, user and service-account export, partner list, endpoint configuration, key and certificate inventory, transfer logs, error queues, support cases, data-classification records, retention settings, network rules, and business application inventory.

Create one row per scheduled or event-driven exchange. Separate inbound and outbound flows when the owners, credentials, controls, or failure impact differ.

AreaWhat to record
IdentityJob name, environment, protocol, source, destination, folder, filename pattern, and schedule
PurposeBusiness process, business owner, technical owner, support owner, and criticality
PartiesSending organization, receiving organization, partner contact, and escalation path
DataFile contents, classification, system of record, expected size, volume, and retention requirement
AccessUser or service identity, authentication method, key or certificate, permissions, and network restrictions
OperationsLast success, recent failures, retries, alerts, processing confirmation, recovery objective, and manual fallback
CommercialsLicensed endpoints, jobs, users, volume, storage, environments, add-ons, support, and administration effort
DecisionRenew, correct, retire, restrict, consolidate, compare, or investigate

The register should let a reviewer follow a file from the sending system to the receiving process. If it stops at “SFTP server,” the record is not finished.

Inventory the transfers outside the MFT platform

Your MFT console shows what was configured inside that product. It does not prove that every business file exchange uses it.

Compare the platform export with:

  • Operating system schedulers, scripts, cron jobs, and automation accounts
  • Application integrations, ERP jobs, payroll feeds, bank files, EDI processes, and reporting exports
  • Cloud storage events, integration platforms, email workflows, shared folders, and manual upload portals
  • Firewall rules, DNS records, load balancers, proxies, storage accounts, and network flow data
  • Identity records, SSH keys, API credentials, TLS certificates, and service principals
  • Support tickets, failed-job emails, partner onboarding records, and incident history

The ERP renewal integration inventory can help when file exchanges are buried inside an application upgrade. Use the integration platform renewal audit when the same business transaction also crosses low-code workflows or application connectors.

Make ownership specific enough to act

“Finance” is not an owner. “The vendor” is not an owner either.

Each exchange needs a business owner who can confirm why the data still moves and a technical owner who can explain how it moves. It also needs a receiving owner who can confirm that the file is consumed correctly. A successful upload does not prove the downstream process worked.

Ask the owners:

  1. Which business process depends on this exchange?
  2. Who sends the file, who receives it, and who acts on it?
  3. What data is inside, and is every field still needed?
  4. How often should it run, and how late can it be?
  5. What proves successful processing beyond delivery?
  6. Who responds to a failure, and who can authorize a replay?
  7. What is the manual fallback if the platform or partner is unavailable?
  8. What would need to happen before this exchange could be retired?

An unknown owner is not a reason to preserve a job forever. It is a reason to investigate before signing.

Review credentials and permissions by exchange

Shared credentials make an old environment easier to operate until somebody needs to revoke access, investigate a transfer, or move one partner without breaking three others.

For each flow, confirm:

  • The service identity maps to one defined purpose or an approved group of related exchanges
  • Permissions are limited to the required folders and actions
  • Interactive access is disabled when the job does not need it
  • Keys, passwords, tokens, and certificates have owners and rotation procedures
  • Old partner users and former administrators have been removed
  • Network access is limited where the business and architecture allow it
  • Emergency access is documented, monitored, and tested

The NIST Cybersecurity Framework 2.0 gives buyers a clean basis for this review. ID.AM-03 calls for maintained representations of authorized internal and external data flows. PR.AA-01 covers identities and credentials for users, services, and hardware. PR.AA-05 addresses permissions, least privilege, and separation of duties. PR.DS-02 covers the confidentiality, integrity, and availability of data in transit.

Those outcomes are practical renewal criteria. Can the current product and operating team show the flow, the identity, the access, and the evidence for each important exchange?

Coordinate expiring keys and certificates with the certificate management renewal audit. Rotating one shared credential without a dependency map is a reliable way to create an avoidable outage.

Test evidence, not only delivery

A green “completed” status may mean the platform opened a connection and moved bytes. The business needs stronger evidence.

Select a representative sample that includes a high-volume job, a regulated file, an external partner, a quiet quarterly flow, a job with recent failures, and a critical exchange with a tight deadline. For each one, test:

  1. The expected file arrives from the approved source.
  2. Authentication and permissions work as designed.
  3. The transfer protects the file in transit.
  4. The receiving system accepts and processes the file.
  5. Duplicate, late, partial, malformed, and oversized files follow defined handling rules.
  6. Alerts reach someone who can act.
  7. A failed exchange can be retried without creating duplicate business transactions.
  8. Logs answer who moved what, when, where, and with which result.
  9. Evidence remains available for the required investigation and audit window.

NIST CSF 2.0 also calls for inventories of data and metadata, lifecycle management, log generation, and monitoring of runtime environments and their data. Do not accept “the logs exist” as the answer. Retrieve a real transfer record, connect it to the job and identity, and follow the alert to its owner.

Treat the platform as an exposed data system

MFT often sits on the boundary between your company and customers, banks, suppliers, benefits providers, regulators, or service providers. It may hold sensitive files while also accepting connections from outside the organization.

CISA and the FBI documented the risk in their 2023 advisory on CL0P exploitation of MOVEit Transfer. The advisory also describes earlier campaigns involving Accellion file-transfer appliances and GoAnywhere MFT. The point is not that one vendor is uniquely unsafe. The pattern shows why internet-facing transfer systems, stored data, software maintenance, monitoring, and incident response belong in the renewal review.

Check current versions, patch ownership, vulnerability handling, administrative access, security testing, storage encryption, malware inspection where appropriate, backup and restoration, incident notification, provider responsibilities, and the ability to isolate a compromised endpoint.

If the platform handles sensitive data, connect its rules to the DLP renewal controlled-policy test. Do not assume the transfer platform and DLP tool see the same files or enforce the same actions.

Price the corrected estate

MFT cost can be tied to servers, endpoints, partner connections, users, workflows, protocol modules, transaction volume, storage, high availability, environments, support, and professional services. Internal labor counts too. Someone onboards partners, rotates credentials, fixes jobs, reviews failures, manages upgrades, answers audits, and coordinates migrations.

Build three cost views:

ScenarioWhat to include
Current estateEvery licensed component, active and inactive job, storage, support, and administration cost
Corrected estateRetired flows, separated identities, fixed monitoring, right-sized capacity, and required controls
Change optionMigration, partner coordination, dual running, testing, retraining, data movement, and exit support

Make the vendor map each quoted unit to the corrected register. A discount on unused jobs or abandoned partner accounts is still waste. A higher price may be justified when the service replaces brittle scripts, produces usable evidence, and reduces support work. Prove that outcome instead of assuming it.

Test the exit before signing

File-transfer migrations involve both technology and people. A new platform does not help if forty partners must change hostnames, firewall rules, keys, folders, or file conventions without a coordinated plan.

Before renewal, require usable exports for jobs, users, permissions, schedules, endpoints, partner records, keys and certificate metadata, logs, alerts, and configuration. Document what cannot be exported in a portable format. Test how a small exchange would move, run in parallel, reconcile results, and roll back.

Set contract expectations for support ownership, incident notification, vulnerability response, log retention, data return, secure deletion, transition help, scope reductions, and renewal notice dates. If stored files matter after termination, run the relevant checks in the SaaS data export test.

Bring a disposition list to the renewal meeting

The decision should fit on one page:

  • Renew exchanges with confirmed owners, valid business use, controlled access, working evidence, tested recovery, and defensible cost.
  • Correct jobs with weak credentials, missing alerts, unclear retention, or broken processing confirmation.
  • Retire exchanges only after the sender, recipient, downstream process, retention need, and rollback path have been checked.
  • Restrict accounts, folders, protocols, and network access that are broader than the job requires.
  • Consolidate scripts and transfer methods when the operating benefit outweighs migration risk.
  • Compare another platform when the current service cannot meet required controls, reporting, support, resilience, or commercial terms.
  • Investigate every exchange that still lacks an owner, purpose, destination, or trustworthy evidence.

That is a managed file transfer renewal decision. Approving the same capacity because nobody wants to disturb the scheduled jobs is not.

If your MFT agreement is approaching renewal, request a Contract and Spend Risk Review. Bring the agreement, invoices, job and account exports, partner inventory, keys and certificates, transfer and error logs, support history, and notice dates. Catch Advisors will help you reconcile the commercial scope with the exchanges, owners, controls, and dependencies your team can defend.