Home › Topics › Managed File Transfer › Do You Need It

Do You Need MFT? An Honest Assessment

"Do we need MFT?" The question comes up in the budget meeting, and someone has already asked a vendor, who said yes. Ask this question anywhere near the industry that sells the answer and you will hear a remarkable coincidence. Yes, you do, and the person telling you happens to have one available. So let us put our cards on the table before anything else: Sysax sells file transfer software. That makes this the article a vendor is not supposed to write. We are writing it anyway, because the honest answer also earns the trust of the readers who do need it. Some estates genuinely do not need managed file transfer. Many need only part of it, and some need all of it urgently.

The question itself is usually asked wrong. "Do we need MFT?" sounds like a purchasing decision about a product category, which is how the vendor heard it. As this series has argued from its first article, MFT is really four separable capabilities — visibility, control, automation, audit. Each is achievable by assembly as well as by purchase. So the real question is three questions. Which layers does your estate need? How strong must each layer be? By what route should you get them?

This article is a worksheet for answering all three, part of our What Makes File Transfer Managed series. It scores the six pressures that actually create the need and maps them to the layers they load. Then it works three realistic examples to three different verdicts: no, partial, and yes. It ends with the incremental path — how to adopt layers as pressure grows instead of buying everything the day the anxiety peaks.

The Six Pressures That Create the Need

Estates do not need management because they exist; they need it because specific pressures act on them. Six cover nearly every real case. For each, the honest question is not "could this hurt us in theory?" Everything can. The honest question is "is this pressure acting on us now, or visibly approaching?"

  • Scale. How many distinct flows do you run, and how varied are they? Five flows fit in one head and one page. Fifty do not fit in anyone's head, and the pile starts hiding things. If you are not sure of your own count, that uncertainty is itself a score. (Estates that have lost track entirely have a different first project: our sprawl consolidation series.)
  • Consequence. What actually happens when a transfer fails or goes astray? The scale runs from "someone re-sends it after coffee" through "a partner misses a deadline" to "payroll is late, a regulator is notified, money moves twice."
  • Exposure. External parties: partners, customers, banks. Each adds credentials to govern, an endpoint to watch, a counterparty who can dispute facts, and someone else's auditor asking about your controls.
  • Obligation. Regulated data classes and contractual audit rights. If health records, cardholder data, or financial reporting files ride your flows, someone is eventually entitled to ask for proof. The questions appear in what auditors ask about transfers. And "we'd rather not say" is not among the acceptable answers.
  • Fragility of knowledge. The bus factor. If the person who understands the transfer estate resigned today, would the flows keep running — and keep being changeable? An estate that lives in one head is one resignation away from archaeology.
  • Question frequency. How often does someone ask "did it arrive?", "who can access this?", or "can you prove it?" Every such question answered by manual digging is the need, announcing itself politely before it announces itself expensively.

Two things are deliberately not on the list. Data volume is absent, because gigabytes do not create management needs — consequences do. A terabyte of harmless renders needs bandwidth. A two-kilobyte payment instruction needs every layer this series describes. Server count is absent for the same reason: it measures sprawl, not need. It does inflate the cost of whatever you do need, since every capability must stretch across every box. The pressures are about what the transfers mean, which is why no scanner can score this worksheet for you. No scanner has ever known what a file meant.

The Worksheet

Score each pressure 0, 1, or 2 against the anchors below. Be honest in the direction of your evidence, not your anxiety. Score what is true now or visibly arriving, not the worst case a vendor could paint for you. The industry employs very good painters, and we are in it.

THE SIX-PRESSURE WORKSHEET (score each 0 / 1 / 2)

SCALE        0 = a handful of flows, all listable from memory
             1 = a dozen or two; the list needs writing down
             2 = many dozens, or you honestly do not know the count

CONSEQUENCE  0 = a failed transfer is re-sent after coffee
             1 = a failure costs a business day or a partner's patience
             2 = a failure moves money wrongly, breaks payroll,
                 or triggers reporting duties

EXPOSURE     0 = internal flows only
             1 = a few steady partners
             2 = many partners, or customers, or a bank

OBLIGATION   0 = no regulated data, no contractual audit rights
             1 = some regulated data, or customers who send
                 security questionnaires
             2 = named regulatory regime, scheduled audits

FRAGILITY    0 = two or more people fully understand every flow
             1 = one person understands most of it
             2 = "the scripts know" — and their author is gone or going

QUESTIONS    0 = did-it-arrive questions are rare
             1 = weekly; answering means digging
             2 = daily, or one unanswerable question has already hurt

TOTAL: ____ of 12

The total gives the verdict band, but the per-pressure scores matter more, because each pressure loads specific layers. The grid below is the mapping — find your 2-scores, read down, and you have your priority layers.

A grid mapping the six pressures to the four MFT layers. Scale loads visibility and automation. Consequence loads visibility, automation, and audit. Exposure loads control and audit, with visibility secondary. Obligation loads control and audit. Fragility loads automation and control. Question frequency loads visibility and audit. Filled squares mark primary loads and outlined squares mark secondary loads.

Reading Your Score

0–3: you do not need MFT. Read that again, from a company that sells transfer software: you do not need it. What you need is the hygiene floor every estate deserves. That means encrypted protocols, a written list of your flows, and server logs that go somewhere durable. Then you need to spend your attention on problems you actually have. Skipping capabilities you do not need is not technical debt; it is judgment.

4–7: you need part of it. Your 2-scores name which part. This is the most common verdict in the real world, and the most commonly mishandled. The anxious buy a full suite and operate a third of it. The frugal keep white-knuckling scripts through pressures that have visibly outgrown them. The right move is two or three layers, at assembled or lightly-tooled strength, aimed exactly at the loud pressures. I have watched one organization make both mistakes, a few years apart, with the same scripts.

8–12: you need the discipline entire. All four layers, integrated where integration is honest, assembled where it is not. At this band the question is no longer whether but how. The how is an economics decision about components and effort. That is precisely the ground our build versus buy series covers. Use the one-page business case as the way to ask for whatever that analysis concludes.

One reading rule for lopsided scores: a single 2 amid zeros outranks the band. Consider a three-flow estate whose one flow is a bank payment file. It scores perhaps 3 in total — and still needs the audit and control treatment for that one flow, full stop. The bands describe estates; the 2-scores describe obligations, and obligations do not average away. Scope the layers to the flows that earned them. Managing one critical flow properly while leaving the harmless ones alone is not inconsistency. It is exactly what right-sizing means.

Northgate Retail scored a 4 on its first pass. It had five flows, two administrators who both understood them, nothing regulated, and one weekly payment file to a bank. Both 2s belonged to that one file, so the team gave it the full treatment. It got a dedicated account, a folder of its own, logs copied nightly to an archive with separate credentials, and a monthly drill. The team left the other four flows exactly as they were. The exercise took two weeks of spare afternoons and no purchase. When the bank's auditor asked about the flow the following year, the evidence took ten minutes. The four untouched flows were never mentioned, because nobody had ever needed to ask about them. Right-sizing, it turned out, mostly meant leaving things alone on purpose.

Remember: the worksheet's job is to keep the answer attached to evidence. If you cannot point to the incident, the audit letter, the partner count, or the unanswerable question behind a score, lower the score. Fear of hypotheticals is how shelfware gets bought — and shelfware is worse than nothing, because it lets everyone believe the problem is handled.

Three Worked Examples

Verdict: no — the engineering firm

Fifteen people. Four flows: a nightly backup to a second site, a weekly drawing package to one steady client, and two internal syncs. No regulated data. A failed backup re-runs the next night; a late drawing package earns a mild email. One administrator understands everything, and a colleague could reconstruct it from the wiki page. Scores: scale 0, consequence 0, exposure 1, obligation 0, fragility 1, questions 0 — total 2.

The honest verdict is that MFT — bought or assembled — would be ceremony. Four flows do not need a visibility dashboard. They need the wiki page kept current (the hit-by-a-bus test is the standard to keep it to). They need SFTP instead of anything plain, and logs that survive ninety days in case a question ever comes. Total ongoing cost: an hour a quarter. The only real advice is to write down the tripwires that would change the answer. Those are a second client, a compliance clause in a contract, the administrator resigning. Re-run the worksheet when one fires. The worksheet keeps; the answer does not.

Verdict: partial — the regional distributor

Two IT staff. Around twenty-five flows: nightly price and inventory feeds to a dozen retail partners, order files coming back, a bank upload weekly. No regulator, but two large partners send annual security questionnaires. Failures cost real time — a missed price feed means a morning of angry calls. The senior admin wrote most of the scripts; the junior can run them but not confidently change them. Scores: scale 1, consequence 1, exposure 2, obligation 1, fragility 2, questions 1 — total 8, but look at the 2s: exposure and fragility. The grid says control and automation, with audit strengthening.

The right-sized program has three moves, none of which is "buy a suite." First, formalize automation so it survives the senior admin. Either apply the script contract from the automation article ruthlessly, or rebuild the flows in a modest tool. This is the natural home for something like Sysax FTP Automation. There, a wizard defines each scheduled task with retries and email notifications. The junior admin can read every job as settings instead of decoding a colleague's scripting style. Second, control tightened where the exposure is: one account per partner, least privilege, and the quarterly reconciliation from the control article. Third, the cheap audit floor: every log copied to one archive, because the questionnaires will eventually grow teeth. Total: some weeks of effort and a small license — and the estate stops depending on one person's memory. Visibility, notably, stays assembled: a digest and an expected-files list are plenty at twenty-five flows.

Verdict: yes — the claims processor

Consider a firm processing insurance claims. It handles health-adjacent data under a named regulatory regime, with sixty-plus flows and forty external parties including two banks. Its annual audit produced findings last cycle ("insufficient transfer logging" among them). It has steady turnover in the operations team. Scores: 2, 2, 2, 2, 2, 2 — total 12. Honestly, the worksheet was a formality; the audit findings already answered the question. An audit finding is the worksheet, filled in for you, in a less friendly font.

Here all four layers are needed at strength, and integration earns its cost. It brings capture without enrollment gaps, control enforced at connection time, and flows legible to a rotating team. The shape of the build starts with a hardened transfer server as the single sanctioned front door. That is the role a product like Sysax Multi Server plays. It provides directory-backed accounts, per-area permissions, IP restrictions, and activity logging to a database feeding the evidence archive. Add automation in tooling rather than personal scripts, and the audit pipeline from the audit article run as designed. Consolidate the accumulated extra doors behind one gateway. The estate had four exposed servers; the pattern for retiring three is our gateways and proxies series. And the standing honesty note applies even here, at maximum need: no product delivers the four layers by itself. The claims processor still writes its policy, its retention schedule, and its expected-files list. Those are decisions, and decisions do not ship in installers.

The Incremental Path

Verdicts of "partial" and even "yes" rarely justify a big bang. The layers adopt well one at a time, and experience suggests an order:

  1. Visibility first. It is the cheapest to start — a digest and an expected-files list. It produces the evidence that calibrates everything else. Estates routinely discover, in their first month of actually looking (see why jobs fail silently), that they had daily failures nobody knew about. You cannot right-size the other layers over transfers you cannot see.
  2. One exception: start the audit archive on day one anyway. Not the whole audit layer — just the scheduled copy of logs to one protected place. It costs an afternoon, and it is the only layer that cannot be added retroactively. Records not kept tonight are unprovable forever.
  3. Automation where the toil or fragility is loudest. Formalize the flows that page people or depend on one person, and leave the harmless ones for later.
  4. Control as exposure grows. Each new partner and each new hire raises the price of folklore accounts. The reconciliation loop starts paying for itself around the time you stop recognizing every username.
  5. The rest of audit when obligation arrives. Retention schedules, tamper resistance, rehearsed reports — build them ahead of the first scheduled audit, not during it.

Two properties make this path safe to walk slowly. Each step pays for itself independently. A digest is worth having even if you never buy anything. A reconciled account list is worth having even if automation stays scripted. So there is no half-built bridge, no sunk investment that only pays off at the end. And a partial verdict is a legitimate destination, not a waystation. An estate that stabilizes at two well-run layers has finished, not stalled, and owes nobody an upgrade. Least of all us.

And put re-assessment on a calendar: the worksheet annually, or immediately when a tripwire fires. Tripwires include the first regulated contract, partner count doubling, the script author resigning, and the first question you could not answer. The answer is allowed to change in both directions. Estates that simplify sometimes score lower next year, and should downsize their tooling accordingly.

Keeping the Answer Honest

Three closing disciplines keep this decision clean over the years. Buy only what you will operate. A suite with unconfigured dashboards and an empty policy engine is a script estate wearing an expensive costume. Capability you do not operate is cost without control. Match strength to pressure, not to peers. The claims processor's architecture would smother the engineering firm. The firm's wiki page would sink the processor — both are correct designs for their scores. Distrust urgency, including ours. Real transfer-management needs announce themselves through evidence — failures, questions, findings, growth. Evidence gives you time to adopt incrementally. Anyone insisting you must buy everything at once is describing their quarter, not your estate.

The Short Version

"Do we need MFT?" is really "which of the four layers do we need, how strong, and by what route?" Score the six pressures — scale, consequence, exposure, obligation, fragility, question frequency — and let the 2-scores name your layers. Low totals mean the honest answer is no, and the hygiene floor is enough. Mid totals, the commonest case, mean two or three layers at right-sized strength. High totals mean the full discipline, integrated where integration is honest. Adopt incrementally, visibility first and the log archive immediately, and re-run the worksheet when the world changes. That is the whole method. If a vendor disagrees with your low score, including us, ask them which pressure they think you mis-scored. Make them point at evidence. Take that into the budget meeting; it beats a brochure.

Frequently Asked Questions

What should a small IT team choose: an MFT solution or an SFTP server with scheduling?
Run the worksheet first. Most small teams land on the partial verdict: a Windows SFTP/FTPS server for the endpoints, a scheduler or watch-folder tool for the automation, and the server's logs shipped somewhere central for the audit trail. That covers the four MFT capabilities at a fraction of a suite's cost. Move to a full MFT solution when partner count, workflow complexity or a regulator pushes the score into the yes column.
Can a small company really skip MFT entirely?
Yes — if the pressures genuinely score low: few flows, no regulated data, mild consequences, more than one person who understands the setup. Keep the hygiene floor (encrypted protocols, a flow list, durable logs), write down what would change the answer, and re-check yearly.
Which MFT layer should I adopt first?
Usually visibility, because it is cheap to start and its findings calibrate everything else. Add the audit archive (a scheduled copy of logs to one protected place) immediately, because audit records cannot be created retroactively. Then automation, control, and the rest of audit as their pressures demand.
Do I need to buy software to act on a "partial" verdict?
Not necessarily. Two or three layers at assembled strength — centralized logs, a script contract, an account reconciliation — cover many partial verdicts. A modest tool earns its place when uniformity or survivability is the loud problem. That is a smaller and cheaper decision than adopting a full suite.
Our auditor said we need "an MFT solution." What do they actually want?
Almost always the capabilities, not a brand: provable records of who moved what, enforced access control, and reliable flows. Translate the finding into layer language, fix the named gaps, and document the result. Auditors accept well-evidenced assembled builds far more often than vendor marketing suggests.
How often should we revisit the decision?
Annually, plus immediately when a tripwire fires. Tripwires include first regulated data, a doubling of partners or flows, the departure of whoever understands the scripts, or the first question you could not answer. The score moves in both directions — simplifying estates should downsize tooling too.
Isn't a vendor telling me I might not need their product just reverse psychology?
A fair suspicion — so do not take the conclusion, take the method. The worksheet forces every score to point at evidence you can check yourself: your flow count, your incidents, your obligations. If the evidence is thin, no vendor's framing should talk you into a purchase, including this one.

From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.