Home › Topics › Governed Alternatives › The Risks

The Real Risks of Ungoverned File Movement

You have sat through the lecture version of this article. It had a slide with a padlock on it, a statistic nobody could source, and a closing line about how one lost stick could end the company. This is the risk article of our Governed Alternatives series, and it comes with a promise: no scare stories. Fear is a bad foundation for engineering decisions, and it is an even worse tool for changing user behavior. People who feel accused stop telling you things, and the previous article's whole method depends on them telling you things. What you need instead is a sober account of how ungoverned file movement actually fails. "Actually" is doing a lot of work in that sentence. The failures are quieter, slower, and stranger than the slide with the padlock suggested.

So this article tells four small stories instead. Each one is synthetic (the companies are invented), but each is assembled from the ordinary mechanics of real incidents. None requires anyone to be malicious or stupid. In every story, a reasonable person does their job with the tools at hand, and the failure comes from the tool, not the person. I have been the reasonable person in one of them, and I would rather not say which. Along the way we will name the four risk families: loss, leakage, malware carriage, and the missing audit trail. By the end you will have a worksheet for ranking which habits in your own estate deserve attention first. You cannot fix everything at once, and you should not try.

Four Failure Families, One Pattern

The habits cataloged in why chaos happens work fine almost every day. That is precisely what makes them durable: the risk does not live in the average day. It lives in the tails — the one stick in hundreds that goes missing, the one sync that includes the wrong folder. A user who has moved files on a stick a thousand times without incident has a thousand data points telling them it is safe. They are not wrong about the thousand. They are unequipped to reason about the one, because the one lands on the organization, not on them.

The four families differ in mechanism but share a structure. Loss is a file failing to be where it should be. Leakage is a file succeeding at being somewhere it should not. Malware carriage is a file bringing company along. And the missing audit trail is the multiplier that makes each of the others worse. An incident you can reconstruct is a bad week. An incident you cannot reconstruct is an open question that never fully closes. Keep that multiplier in mind through the stories — it appears in all of them.

Loss: The Stick That Never Arrived

Harlan Freight runs its dispatch office and its accounting office in buildings a few miles apart, on networks that were never properly joined. Every month, a payroll coordinator exports the hours file, copies it to a USB stick, and drives it over. She inherited this routine from her predecessor, who inherited it from hers. It takes twenty minutes and it has never failed.

One month it fails. Somewhere between the parking garage and the accounting office the stick is no longer in her coat pocket. She retraces her steps twice. Nothing.

The lecture version skips the next part: the immediate operational problem is trivial. She exports the file again and drives it over before lunch. The real problem arrives that afternoon, when someone asks the question the stick cannot answer: is it lost, or is it taken? The file held names, pay rates, and bank details for four hundred employees, unencrypted, because sticks bought from the supply cabinet are just storage. There is no way to distinguish "in a storm drain" from "in someone's laptop," so policy and prudence require treating it as potentially disclosed. Now it is notification assessments, a call with counsel, and an all-staff email. This is not because anything provably happened, but because nothing could be proven at all.

The counterfactual is almost boringly small. The same file, moved by a scheduled transfer between the two offices — encrypted in transit, logged at both ends — is a non-event forever. This exact site-to-site pattern is one of the easiest habits to retire. A tool like Sysax FTP Automation can watch the export folder, encrypt the file with OpenPGP, and move it on schedule. It can send an email notification when the file lands. That is the whole courier run without the coat pocket.

Loss has a second, quieter face: the junk share that gets "cleaned up." When a well-meaning admin finally purges the TRANSFER share, somewhere in those folders is the only copy of something a team depended on. Ungoverned locations attract single copies, because nobody classified anything as worth protecting. The share called TEMP is, in practice, the archive.

Leakage: The Folder That Synced Too Much

At Calloway Precision, a design engineer set up a personal cloud storage account during a crunch, so he could review tooling drawings from home. It worked beautifully, which is why it was still running three years later. That was long after the crunch, long after he had forgotten the sync client was there at all. The synced folder grew to include whatever passed through his working directory: drawings, quotes, one customer's complete fixture package. He had forgotten the sync client. The sync client had not forgotten him.

The exposure was never dramatic. The account's sharing link — created once, for one file, for his own convenience between devices — pointed at the folder, not the file. The link never expired. The package was findable by anyone holding the link, and eventually a link travels. The customer's own security review found it, which is the worst possible discoverer short of a competitor: the awkward call came inbound.

The story contains almost no wrongdoing. The engineer solved a real problem — remote access — with the only tool available to him, and every individual decision was reasonable. The failure is structural. Consumer sharing defaults favor convenience. Nobody but the account owner could see the exposure, and the organization had no view into the account at all. That last property matters at offboarding, too. When he eventually leaves, the folder leaves with him, entirely legally as far as the storage provider is concerned. The overlap between personal accounts and departures is a core scenario in our guide to insider risk in file transfer. Most of that article is about exactly this kind of non-malicious insider.

The junk share leaks in its own way: an everyone-readable share means "everyone" precisely, including the contractor, the intern, and the compromised account. A salary review parked there "for a minute" is published, internally, for as long as the minute lasts. If you are unsure what sensitive material is flowing through paths like these, the survey method in what data leaves your network is the place to start.

Malware Carriage: The Stick That Visited

Fenwick Assembly did its network segmentation properly. The packaging line controllers sit on an isolated segment. The office network cannot reach them. The vendor's remote access was decommissioned years ago after a security review. When the packaging line needs a parameter update, the vendor's field technician arrives in person with the update on a USB stick. That is, after all, the approved procedure for an isolated system.

The stick has a route of its own. Before Fenwick, it visited the vendor's office laptop, two other customers' sites, and — because field technicians are people — a home computer. On that home computer, a stowaway attached itself to the autorun files. On update day, the stick bridges every network it has ever touched to the isolated segment. The segmentation was never defeated. It was carried across.

That is the honest way to think about removable media and malware: a stick is a network link that shows up in nobody's diagram. It connects machines that were deliberately not connected, in whatever order its owner's errands dictate. It has none of the scanning or filtering that sits on your real network paths. The plausible version of the story is not a cinematic plant shutdown. Usually it is a scanning alert, a quarantined controller workstation, and two days of verifying that nothing spread. It is expensive, survivable, and entirely preventable at a scanning station by the door. That is exactly the containment pattern we build in the genuine USB cases.

The deeper point generalizes past USB: any path files travel without inspection is a carriage risk. That is why governed flows put scanning at the choke points — the argument laid out in why transfer flows need scanning. Ungoverned paths have no choke points. That is most of what "ungoverned" means.

Remember: in all three stories so far, the person at the center was doing their job, competently, with the tools available. If your incident retrospective ends at "user error," it stopped one level too early. The fix that works is structural — a better path — not a sterner reminder.

The Missing Audit Trail: The Question Nobody Could Answer

The fourth story is the quietest, and it is the one that turns the other three from bad days into permanent mysteries. An account manager resigns from Bray & Holt, a professional services firm, and joins a competitor. Six weeks later, two clients mention that the competitor's pitch seemed unusually well informed. Leadership asks IT a simple question: in his last month, did he take the client files?

The client files lived on a shared drive his role legitimately required. There is no file access auditing on the share — there rarely is, because nobody turned it on and the volume would have been enormous. His USB history exists only as a registry trace on a laptop that was reimaged for the next hire, per standard process. The honest answer to leadership is: we cannot know. Not "no." Not "yes." A shrug, delivered to people who badly need a fact.

Sit with how corrosive that is. If he took the files, the firm cannot act — no evidence. If he took nothing, he stands quietly accused forever — no exoneration either. The missing audit trail hurts the innocent as much as the guilty, and it converts every future anomaly into a re-litigation of the mystery. The same absence hollows out compliance. An auditor asks who can access client data and who did access it. "Here is the permission list, and we log nothing" is half an answer.

This is the risk family a governed path fixes most completely. Logging is not an add-on to managed transfer — it is a defining feature. A transfer server such as Sysax Multi Server records activity to a log file or a database as accounts connect, upload, and download. That means the question "who touched this file, and when?" has a lookup instead of a shrug. What belongs in such a record, and how to keep it trustworthy, is covered in what to log. The point here is that the record exists on one path and cannot exist on the other.

Ranking Your Own Estate

Four families, and — if you ran the inventory from the previous article — a few dozen ungoverned flows of your own. You cannot replace them all at once, and the migration article later in the series will insist that you should not try. What you need now is a defensible ordering, which takes an hour with a simple worksheet, not a risk-management framework. The framework can come later, if anyone still wants one.

Score each flow from your inventory on four factors, one to three each:

RISK RANKING WORKSHEET - score each inventoried flow, 1 to 3 per factor

SENSITIVITY  what the data is
  1 public or trivial      2 internal business      3 personal, financial,
                                                      regulated, or customer-owned
EXPOSURE     how far outside control it travels
  1 stays on managed       2 crosses internal        3 leaves the organization
    equipment                boundaries                (physical media, personal
                                                      accounts, consumer services)
FREQUENCY    how often the flow runs
  1 rare                   2 monthly-ish             3 daily or weekly
SILENCE      would you know if it went wrong?
  1 failure would be       2 might surface           3 nothing would ever
    noticed quickly          eventually                tell you

PRIORITY = SENSITIVITY x EXPOSURE, ties broken by SILENCE, then FREQUENCY

Sensitivity times exposure is the heart of it. A public price list on a stick (one times three) does not compete with payroll on a stick (three times three). The multiplication keeps it that way. Silence breaks ties because a risk you would never detect deserves attention before an equal risk that announces itself. Frequency comes last deliberately. A rare flow of regulated data outranks a daily flow of nothing much. Intuition tends to get that backwards because frequency is what we see. The daily flow is loud. The rare one is merely important.

The worksheet applied to the four story flows, plus one harmless control to show the scale working:

Flow Sens. Exp. Freq. Silence Priority
Payroll file by courier stick 3 3 2 3 9 — first
Design folder in personal cloud sync 3 3 3 3 9 — first
Vendor media to isolated line 2 3 1 2 6 — contain
Client files on unaudited share 3 2 3 3 6 — next
Marketing photos passed on sticks 1 3 3 1 3 — later

The output is not science and does not need to be. Its job is to produce an ordering you can defend in one sentence per row. That way, the migration starts where a failure would hurt most. You can say "later" to the rest without saying "never."

Score it with company, not alone; I have scored alone and been wrong in both directions in the same hour. An hour with one person from the affected teams — the payroll coordinator, the design lead — fixes the two mistakes IT makes solo. One is overestimating sensitivity you do not handle daily ("those drawings are public at trade shows anyway"). The other is underestimating sensitivity you never see ("that folder also holds the customer's pricing"). That hour together also plants a seed for later. The person who helped rank a flow as risky has already half-agreed that it deserves a better path. That will matter enormously when you come asking them to switch. Nobody argues with a ranking they helped write.

Kestrel Payroll ran the worksheet twice, once with IT alone and once with the payroll lead in the room. The solo version put the monthly bank file first and a folder of scanned timesheets last, on the grounds that timesheets are hours and names. The payroll lead pointed out that the scanned timesheets carried signatures and, on the back page, new-starter bank details, because that was the form. The folder moved from a three to a nine before the coffee arrived. Nothing had gone wrong yet. The point of the second hour was that nothing would.

Gotcha: resist the urge to add factors and decimal points. A four-factor, one-to-three worksheet done this week beats a weighted model done next quarter. False precision invites arguments about scoring instead of decisions about flows. If two rows tie and it matters, you already know enough about both to break the tie by judgment.

What the Ranking Buys You

With stories for vocabulary and a ranked list for sequence, the series turns constructive from here. The ranking tells you where to begin. The next article, designing sanctioned paths, supplies the method. It pairs each high-priority habit with a governed alternative that passes the as-easy-or-easier test. A replacement that loses on convenience will not be used. Flows that scored high on the malware-carriage pattern feed into the containment kit in the genuine-USB article. And if your top rows surprised you — they often do — that surprise is the whole value of writing scores down. Writing scores down beats trusting the squeaky wheel. The squeaky wheel is rarely the payroll file.

One last calibration before you go. The purpose of naming risks is not to build a case against your users. The stories should have made it clear that the users are rarely the failing component. The purpose is to know what you are buying when you spend effort on governed paths: fewer unanswerable questions. Loss becomes a re-send. Leakage becomes a revoked account. A carried infection becomes a quarantine log entry. And "did he take the files?" becomes a query with a result — which, for everyone involved including the person asked about, is mercy.

Frequently Asked Questions

Is a lost USB stick automatically a reportable data breach?
It depends on what was on it, whether it was encrypted, and which regulations cover the data. Those are questions for your compliance owner or counsel, not for an article. The practical takeaway is that an unencrypted, unlogged stick forces you to assume the worst, while an encrypted governed transfer usually makes the whole question moot.
Are personal cloud accounts riskier than USB drives?
They fail differently. Sticks concentrate loss and malware-carriage risk. Personal cloud accounts concentrate leakage and offboarding risk, because copies persist outside your control and sharing links outlive their purpose. Rank both with the worksheet rather than debating which is "worse" in the abstract.
What does an audit trail actually mean for file movement?
A record, kept automatically by the system, of who connected, what they uploaded or downloaded, and when. Its value shows up only when something goes wrong. It is the difference between answering "who accessed this file?" with a query and answering with a shrug.
How real is the malware-by-USB risk for an ordinary office?
For machines on your scanned, filtered network, it is one modest risk among many. It becomes serious wherever a stick bridges environments — isolated production systems, vendor equipment, home computers. That is because it crosses boundaries that have no other crossing and therefore no inspection. That is why containment focuses on the bridging cases rather than on every stick everywhere.
We are a small shop. Do we really need a formal risk ranking?
You need the one-hour version, not a framework. Even ten flows benefit from an explicit ordering, because the loudest habit is rarely the riskiest one. Writing scores down is the cheapest known cure for fixing things in the order people complain about them.

From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.