What FTP's Persistence Costs Organizations
"Passwords in the clear!" The security officer said it with feeling, and everyone in the room nodded. And nothing happened, because it was the same sentence in the same room as the year before. It is true. It has been true for as long as the protocol has existed. And it has never once, in my experience, produced a budget line on its own. The people who approve budgets weigh costs. A risk without a number is the easiest thing in the world to defer. The previous article explained why keeping FTP is a rational cost comparison from the inside. This one fills in the other side of the comparison.
What follows is a ledger, not a scare. It has five categories: cleartext credentials, firewall and network complexity, audit friction, support load, and migration debt. For each, it says what the cost consists of. It also says where the number comes from in your own environment and what makes it large or small. It ends with a worksheet you can fill in for your own estate. Some rows will be small. Contained device FTP on an isolated segment costs very little to keep, and the worksheet will say so. The rows that are large make the retirement case for you. This is part of our Why FTP Won't Die series.
Why Numbers Work Where Fear Fails
An organization that has run FTP for years has, by definition, not yet suffered the catastrophe the warnings describe. Every year without one weakens the warning. A ledger avoids that trap because most of FTP's costs are not catastrophic at all. They are small, recurring, and already being paid. There is the ticket that took an hour, the audit exception that took an afternoon, or the partner onboarding that ran a week long. Those hours are real. They are in your ticket system. Adding them up is a few days of work rather than an act of faith. It is also the form of the argument most likely to survive a budget meeting. The article on why nobody funds file transfer explains why.
The ledger keeps you honest in the other direction too. If the numbers for a flow come out small, that flow does not need a migration project. It needs containment and a review date. That is what living with FTP responsibly covers. Retirement effort should go where the cost is, and the worksheet tells you where that is.
Cost One: Cleartext Credentials
Start with the cost everyone names and few quantify. Every FTP login sends the username and password as readable text across every hop between client and server. That includes the local switch, the wide-area link, the partner's network, and any device in between. Anyone positioned on that path can collect passwords without touching the FTP server at all. That could be a compromised machine on the same segment, a misconfigured tap, or an attacker who already has a foothold elsewhere. The file contents travel the same way.
The cost is not the password itself. It is what the password unlocks. The reuse habits that surround FTP make that far larger than one folder. Three patterns are common enough to check for by name:
- Domain credentials over FTP. An FTP server that authenticates against the directory is convenient. It also means a user's domain password crosses the wire in the clear every time they upload a file. A captured FTP login is then a captured workstation login, mailbox login, and everything else the account can reach.
- Service accounts reused across systems. The batch job's FTP password is frequently the same password the same service account uses for a database or a share. That is because someone set them up on the same afternoon.
- Partner passwords that never rotate. A partner account was created years ago, with a password sent by email at the time. That credential's exposure window is its entire life.
To put a number on it, count accounts and classify what each can reach. Count FTP accounts in use and the number backed by directory credentials. Count the number that can reach personal, financial, or health data. Also count the number of listeners reachable from the internet. The blast radius of one account has a method for the reach question. And what attackers want from file transfer explains why credentials, not files, are usually the prize. Finding the cleartext logins in the first place is the subject of cleartext discovery. That work uses firewall logs, packet captures, and port scans. This article assumes that work.
The last piece is the cost of one incident. It includes forensic hours and, if personal data was reachable, notification obligations. It also includes downtime while credentials are rotated everywhere the reused password lived. Estimate it honestly. Record the likelihood you assumed as "one in so many years" rather than as a percentage. That way the assumption can be argued with instead of hidden. (A percentage looks like data. "One in eight years" looks like what it is: a guess, written down.)
Cost Two: Firewall and Network Complexity
FTP is the only common protocol whose data travels on a second connection negotiated inside the first. Every firewall, NAT device, and load balancer on the path has to accommodate that. The consequences arrive as tickets. A passive port range that was never opened. A server behind NAT announcing its private address. A firewall helper rewrites the conversation helpfully for plain FTP. It cannot see inside FTPS to do the same, as FTPS, firewalls, and NAT explains. A partner whose client is set to active mode and whose transfer hangs the moment it lists a directory. Each is a known problem with a known fix. Each still costs an hour or an afternoon every time it recurs with a new partner or after a firewall change. The systematic diagnosis is in diagnosing FTP mode failures. The point here is that the diagnosis has to be repeated. FTP does not learn.
The number comes from your ticket system. Search for the keywords (FTP, passive, port range, "hangs on listing," data connection). Count tickets per month and the hours each consumed. Add firewall change requests that mention FTP. This category is modest per incident and surprisingly large per year. It is almost entirely eliminated by a single-connection protocol. A firewall sees SFTP as one ordinary port. That fact is laid out side by side in the firewall's view of the protocols. The same ticket-mining method, applied to every kind of transfer failure, is in costing failed jobs and manual work.
Cost Three: Audit Findings and Questionnaire Friction
Any compliance framework that cares about data in transit will flag cleartext file transfer. Every framework that covers payment cards, health records, or personal data cares about data in transit. The finding itself is not the cost. The cost is the cycle it starts. There is the written explanation, the compensating-control document, and the exception that must be renewed. Then comes the follow-up in the next audit asking why it is still there. An organization can carry an FTP exception for years. Every year it costs a few days of somebody's time and a little more credibility with the auditor. What auditors ask about transfers describes the conversation. And PCI DSS file transfer requirements covers the payment-card rules specifically.
Bluewater Bank carried an FTP exception for one partner feed through three audit cycles. Each renewal took the compliance officer, an administrator, and the partner's contact about two days between them. There was also a compensating-control memo that grew by a page a year. In the fourth cycle a new auditor asked, mildly, how many hours the exception had consumed so far. The answer was roughly three times the estimate for migrating the feed. It moved to SFTP the following quarter, in eleven hours, and the memo was retired with honors.
A newer form of the same cost arrives from customers and insurers. Security questionnaires now routinely ask whether any file exchange uses unencrypted protocols. And "yes" costs either a follow-up explanation or a deal. Cyber-insurance applications ask the same question, and the answer can affect premiums or coverage. Answering security questionnaires covers the mechanics. For the ledger, count questionnaires per year and the hours each FTP-related answer consumed. Note any deal that was lost or delayed.
Remember: the audit cost of FTP is recurring and the migration cost is one-time. A finding you have explained three years running has already cost more hours than the migration that would have closed it. That arithmetic, in your own numbers, is often the whole business case. The article on audit findings as budget language shows how to write it up.
Cost Four: Support Load and Key-Person Risk
FTP flows cost support hours in ways that do not always carry the label. Partner onboarding on FTP takes longer than it looks, because of the mode and firewall problems above. Plain FTP also tends to come with ad-hoc credential handling. Devices that upload by FTP fail quietly when a password changes or a server moves. The failure surfaces as "the scans stopped arriving" a week later. Old batch jobs fail on the night a certificate or a path changes. The person who understands them is on holiday. (They are always on holiday. I do not know how they arrange it.)
That last case deserves its own line. In most estates there are FTP jobs that exactly one person understands, usually the person who inherited them. See inherited FTP automation for a description. That person's departure converts a running job into an archaeology project. Count those jobs. The number is not a cost in hours; it is a flag. A large flag count belongs in the same conversation as the cleartext one. For customer-facing flows, customer exchange support shows how much of the support burden is protocol-shaped.
Cost Five: Migration Debt, the One That Grows
The costs so far are paid annually. The last one accrues. Every FTP flow that exists today will have to be migrated eventually. That happens when the device is replaced, when the partner moves, or when the audit exception finally is not renewed. Every new flow set up on FTP in the meantime adds to the pile. Meanwhile the cost per flow rises. The people who understood the old jobs leave, the partners' contacts change, and documentation that was thin gets thinner. This is migration debt: a principal that grows with every new flow and an interest rate set by how fast knowledge decays.
Measure it in two numbers. The principal is the count of FTP flows multiplied by the hours it takes to migrate one. You establish the hours per flow by migrating two or three and timing them. That is exactly the first step migrating from FTP to SFTP or FTPS recommends. The interest is the number of new FTP flows created in the last year. If that second number is not zero, no retirement program can succeed. New flows are filling the pool faster than it drains. The cheapest single action in this entire article is a policy that no new flow uses plain FTP. That policy is covered in approved and forbidden methods. It costs one sentence. Write it today.
The per-flow hours vary enormously with the tooling. A job that calls the console ftp client from a batch file can often be re-pointed rather than rewritten. Sysax FTP Automation includes a command-line client, sysaxftp.exe. It is meant to stand in for that console client while adding FTPS and SFTP. So migrating such a job is a client swap and a credential change rather than a redesign. A flow embedded in an application, or one owned by a partner, sits at the other end of the range. Record the range, not an average.
The Costs That Do Not Fit on the Worksheet
Some costs are real but resist numbers, and it is more honest to list them than to inflate them. Opportunity cost: the hours above are hours not spent on something that would have moved the organization forward. Timing: incidents do not wait for a convenient week. An FTP credential incident during a month-end close costs more than the same incident on a quiet Tuesday. Reputation: a customer who learns their data traveled in the clear does not do arithmetic. Put these in the memo as a paragraph, not a row, and let the rows carry the argument.
The Cost Worksheet
Fill this in for your own estate. Every line names where its number comes from. Where you have to estimate, write the assumption beside the figure so it can be challenged rather than trusted:
FTP PERSISTENCE COST WORKSHEET estate: ________ date: ________
A. SECURITY EXPOSURE source: server accounts, logs
A1 FTP accounts in use (logged in within a year) ......... ____
A2 ...backed by directory (domain) credentials .......... ____
A3 ...reaching personal, payment, or health data ........ ____
A4 FTP listeners reachable from the internet ............. ____
A5 Cost of one credential incident (forensics, rotation,
notification, downtime) ............................... ____
A6 Assumed likelihood: one incident in ____ years
A7 Annual exposure = A5 / A6 ............................. ____
B. NETWORK AND FIREWALL source: ticket system
B1 FTP tickets per month ____ x hours each ____ x 12 ..... ____ h/yr
B2 Firewall changes touching FTP per year ____ x hours ____ ____ h/yr
C. AUDIT AND QUESTIONNAIRES source: audit files
C1 Audit cycles per year ____ x hours on FTP findings ____ ____ h/yr
C2 Questionnaires per year ____ x hours on FTP answers ____ ____ h/yr
C3 Deals or renewals delayed by an FTP answer ............ ____
D. SUPPORT AND KEY PEOPLE source: tickets, interviews
D1 Partner onboardings on FTP per year ____ x extra hours
versus SFTP ____ ...................................... ____ h/yr
D2 Device or job failures traced to FTP per year ____ x
hours ____ ............................................ ____ h/yr
D3 FTP jobs only one person understands (risk flag) ...... ____
E. MIGRATION DEBT source: census, timed pilots
E1 FTP flows today ____ x hours to migrate one ____ ....... ____ h (principal)
E2 New FTP flows created in the last year ................ ____ (interest)
E3 Loaded hourly rate ................................... ____
ANNUAL RECURRING = (B1+B2+C1+C2+D1+D2) x E3 + A7 ........... ____ per year
ONE-TIME MIGRATION = E1 x E3 .............................. ____
PAYBACK = one-time / annual ............................... ____ years
The payback line is the sentence your manager needs: "retiring FTP pays for itself in about so many years, and the risk row is on top of that." When the payback comes out at a year or two, the case makes itself. When it comes out at ten, the honest reading is that this estate's FTP is cheap to keep. The right response is containment, a no-new-FTP rule, and a review date rather than a project.
Where Each Number Comes From
| Category | Where the number comes from | Usually large when | What shrinks it |
|---|---|---|---|
| Security exposure | Server account list, login logs, data classification | Domain credentials over FTP; internet-facing listeners; sensitive data | Unique local accounts, internal-only exposure, encryption |
| Network and firewall | Ticket search, firewall change log | Many partners; FTPS through helpers; load balancers | Single-connection protocols; documented passive ranges |
| Audit and questionnaires | Audit reports, exception register, sales records | Regulated data; customer-facing security reviews | Closing the finding, not re-explaining it |
| Support and key people | Tickets, onboarding records, a short interview per team | Undocumented jobs; frequent partner onboarding | Documentation, a standard client, rehearsed jobs |
| Migration debt | Flow census; two or three timed pilot migrations | New FTP flows still being created; knowledge leaving | A no-new-FTP rule; drop-in clients; a server that speaks both |
There is one shortcut for the A rows. The FTP listener may already live on a server that also speaks the secure protocols. Sysax Multi Server runs FTP, FTPS, SFTP, and HTTPS on one Windows machine. It has per-account authentication and activity logging to file and database. If your listener lives on such a server, the account list and the login log are in one place. Then "which accounts still use plain FTP" is a report rather than a research task. And because one server answers all four protocols, a flow can move from FTP to FTPS or SFTP without moving machines. That is what makes flow-by-flow retirement practical instead of a big-bang cutover.
From Ledger to Decision
A completed worksheet produces one of three conclusions, and all three are respectable. If the annual cost is high and the payback short, you have a funded retirement program. The articles why retire FTP and the FTP retirement plan take it from here. If the cost is concentrated in a few flows, you have a short list to migrate first and a long tail to contain. Typically, the cost is concentrated in the internet-facing flows and the ones carrying sensitive data. And if the numbers are small across the board, you have evidence that containment is the right posture for now. You also have a document to show the next auditor that the decision was made with numbers rather than by neglect.
Whatever the conclusion, keep the worksheet and refill it once a year. Migration debt only shows its growth over time. A ledger that gets worse annually is the most persuasive argument this article can offer. It is also the one the security officer's sentence, however heartfelt, could never make. The series continues with the FTP family tree, which sorts out what you would be migrating to. And living with FTP responsibly covers the containment the small-number case calls for.
Frequently Asked Questions
Is plain FTP on an internal network really a security cost?
How do I get real numbers instead of guesses?
What if the worksheet shows FTP is cheap to keep?
Which cost is usually the biggest?
Does migrating to SFTP or FTPS remove all of these costs?
From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.
