Home › Topics › Why FTP Won't Die › The Costs

What FTP's Persistence Costs Organizations

"Passwords in the clear!" The security officer said it with feeling, and everyone in the room nodded. And nothing happened, because it was the same sentence in the same room as the year before. It is true. It has been true for as long as the protocol has existed. And it has never once, in my experience, produced a budget line on its own. The people who approve budgets weigh costs. A risk without a number is the easiest thing in the world to defer. The previous article explained why keeping FTP is a rational cost comparison from the inside. This one fills in the other side of the comparison.

What follows is a ledger, not a scare. It has five categories: cleartext credentials, firewall and network complexity, audit friction, support load, and migration debt. For each, it says what the cost consists of. It also says where the number comes from in your own environment and what makes it large or small. It ends with a worksheet you can fill in for your own estate. Some rows will be small. Contained device FTP on an isolated segment costs very little to keep, and the worksheet will say so. The rows that are large make the retirement case for you. This is part of our Why FTP Won't Die series.

Why Numbers Work Where Fear Fails

An organization that has run FTP for years has, by definition, not yet suffered the catastrophe the warnings describe. Every year without one weakens the warning. A ledger avoids that trap because most of FTP's costs are not catastrophic at all. They are small, recurring, and already being paid. There is the ticket that took an hour, the audit exception that took an afternoon, or the partner onboarding that ran a week long. Those hours are real. They are in your ticket system. Adding them up is a few days of work rather than an act of faith. It is also the form of the argument most likely to survive a budget meeting. The article on why nobody funds file transfer explains why.

The ledger keeps you honest in the other direction too. If the numbers for a flow come out small, that flow does not need a migration project. It needs containment and a review date. That is what living with FTP responsibly covers. Retirement effort should go where the cost is, and the worksheet tells you where that is.

Cost One: Cleartext Credentials

Start with the cost everyone names and few quantify. Every FTP login sends the username and password as readable text across every hop between client and server. That includes the local switch, the wide-area link, the partner's network, and any device in between. Anyone positioned on that path can collect passwords without touching the FTP server at all. That could be a compromised machine on the same segment, a misconfigured tap, or an attacker who already has a foothold elsewhere. The file contents travel the same way.

The cost is not the password itself. It is what the password unlocks. The reuse habits that surround FTP make that far larger than one folder. Three patterns are common enough to check for by name:

  • Domain credentials over FTP. An FTP server that authenticates against the directory is convenient. It also means a user's domain password crosses the wire in the clear every time they upload a file. A captured FTP login is then a captured workstation login, mailbox login, and everything else the account can reach.
  • Service accounts reused across systems. The batch job's FTP password is frequently the same password the same service account uses for a database or a share. That is because someone set them up on the same afternoon.
  • Partner passwords that never rotate. A partner account was created years ago, with a password sent by email at the time. That credential's exposure window is its entire life.

To put a number on it, count accounts and classify what each can reach. Count FTP accounts in use and the number backed by directory credentials. Count the number that can reach personal, financial, or health data. Also count the number of listeners reachable from the internet. The blast radius of one account has a method for the reach question. And what attackers want from file transfer explains why credentials, not files, are usually the prize. Finding the cleartext logins in the first place is the subject of cleartext discovery. That work uses firewall logs, packet captures, and port scans. This article assumes that work.

The last piece is the cost of one incident. It includes forensic hours and, if personal data was reachable, notification obligations. It also includes downtime while credentials are rotated everywhere the reused password lived. Estimate it honestly. Record the likelihood you assumed as "one in so many years" rather than as a percentage. That way the assumption can be argued with instead of hidden. (A percentage looks like data. "One in eight years" looks like what it is: a guess, written down.)

Cost Two: Firewall and Network Complexity

FTP is the only common protocol whose data travels on a second connection negotiated inside the first. Every firewall, NAT device, and load balancer on the path has to accommodate that. The consequences arrive as tickets. A passive port range that was never opened. A server behind NAT announcing its private address. A firewall helper rewrites the conversation helpfully for plain FTP. It cannot see inside FTPS to do the same, as FTPS, firewalls, and NAT explains. A partner whose client is set to active mode and whose transfer hangs the moment it lists a directory. Each is a known problem with a known fix. Each still costs an hour or an afternoon every time it recurs with a new partner or after a firewall change. The systematic diagnosis is in diagnosing FTP mode failures. The point here is that the diagnosis has to be repeated. FTP does not learn.

The number comes from your ticket system. Search for the keywords (FTP, passive, port range, "hangs on listing," data connection). Count tickets per month and the hours each consumed. Add firewall change requests that mention FTP. This category is modest per incident and surprisingly large per year. It is almost entirely eliminated by a single-connection protocol. A firewall sees SFTP as one ordinary port. That fact is laid out side by side in the firewall's view of the protocols. The same ticket-mining method, applied to every kind of transfer failure, is in costing failed jobs and manual work.

Cost Three: Audit Findings and Questionnaire Friction

Any compliance framework that cares about data in transit will flag cleartext file transfer. Every framework that covers payment cards, health records, or personal data cares about data in transit. The finding itself is not the cost. The cost is the cycle it starts. There is the written explanation, the compensating-control document, and the exception that must be renewed. Then comes the follow-up in the next audit asking why it is still there. An organization can carry an FTP exception for years. Every year it costs a few days of somebody's time and a little more credibility with the auditor. What auditors ask about transfers describes the conversation. And PCI DSS file transfer requirements covers the payment-card rules specifically.

Bluewater Bank carried an FTP exception for one partner feed through three audit cycles. Each renewal took the compliance officer, an administrator, and the partner's contact about two days between them. There was also a compensating-control memo that grew by a page a year. In the fourth cycle a new auditor asked, mildly, how many hours the exception had consumed so far. The answer was roughly three times the estimate for migrating the feed. It moved to SFTP the following quarter, in eleven hours, and the memo was retired with honors.

A newer form of the same cost arrives from customers and insurers. Security questionnaires now routinely ask whether any file exchange uses unencrypted protocols. And "yes" costs either a follow-up explanation or a deal. Cyber-insurance applications ask the same question, and the answer can affect premiums or coverage. Answering security questionnaires covers the mechanics. For the ledger, count questionnaires per year and the hours each FTP-related answer consumed. Note any deal that was lost or delayed.

Remember: the audit cost of FTP is recurring and the migration cost is one-time. A finding you have explained three years running has already cost more hours than the migration that would have closed it. That arithmetic, in your own numbers, is often the whole business case. The article on audit findings as budget language shows how to write it up.

Cost Four: Support Load and Key-Person Risk

FTP flows cost support hours in ways that do not always carry the label. Partner onboarding on FTP takes longer than it looks, because of the mode and firewall problems above. Plain FTP also tends to come with ad-hoc credential handling. Devices that upload by FTP fail quietly when a password changes or a server moves. The failure surfaces as "the scans stopped arriving" a week later. Old batch jobs fail on the night a certificate or a path changes. The person who understands them is on holiday. (They are always on holiday. I do not know how they arrange it.)

That last case deserves its own line. In most estates there are FTP jobs that exactly one person understands, usually the person who inherited them. See inherited FTP automation for a description. That person's departure converts a running job into an archaeology project. Count those jobs. The number is not a cost in hours; it is a flag. A large flag count belongs in the same conversation as the cleartext one. For customer-facing flows, customer exchange support shows how much of the support burden is protocol-shaped.

Cost Five: Migration Debt, the One That Grows

The costs so far are paid annually. The last one accrues. Every FTP flow that exists today will have to be migrated eventually. That happens when the device is replaced, when the partner moves, or when the audit exception finally is not renewed. Every new flow set up on FTP in the meantime adds to the pile. Meanwhile the cost per flow rises. The people who understood the old jobs leave, the partners' contacts change, and documentation that was thin gets thinner. This is migration debt: a principal that grows with every new flow and an interest rate set by how fast knowledge decays.

Measure it in two numbers. The principal is the count of FTP flows multiplied by the hours it takes to migrate one. You establish the hours per flow by migrating two or three and timing them. That is exactly the first step migrating from FTP to SFTP or FTPS recommends. The interest is the number of new FTP flows created in the last year. If that second number is not zero, no retirement program can succeed. New flows are filling the pool faster than it drains. The cheapest single action in this entire article is a policy that no new flow uses plain FTP. That policy is covered in approved and forbidden methods. It costs one sentence. Write it today.

The per-flow hours vary enormously with the tooling. A job that calls the console ftp client from a batch file can often be re-pointed rather than rewritten. Sysax FTP Automation includes a command-line client, sysaxftp.exe. It is meant to stand in for that console client while adding FTPS and SFTP. So migrating such a job is a client swap and a credential change rather than a redesign. A flow embedded in an application, or one owned by a partner, sits at the other end of the range. Record the range, not an average.

The Costs That Do Not Fit on the Worksheet

Some costs are real but resist numbers, and it is more honest to list them than to inflate them. Opportunity cost: the hours above are hours not spent on something that would have moved the organization forward. Timing: incidents do not wait for a convenient week. An FTP credential incident during a month-end close costs more than the same incident on a quiet Tuesday. Reputation: a customer who learns their data traveled in the clear does not do arithmetic. Put these in the memo as a paragraph, not a row, and let the rows carry the argument.

The Cost Worksheet

Fill this in for your own estate. Every line names where its number comes from. Where you have to estimate, write the assumption beside the figure so it can be challenged rather than trusted:

FTP PERSISTENCE COST WORKSHEET            estate: ________   date: ________

A. SECURITY EXPOSURE                              source: server accounts, logs
 A1 FTP accounts in use (logged in within a year) ......... ____
 A2  ...backed by directory (domain) credentials .......... ____
 A3  ...reaching personal, payment, or health data ........ ____
 A4 FTP listeners reachable from the internet ............. ____
 A5 Cost of one credential incident (forensics, rotation,
    notification, downtime) ............................... ____
 A6 Assumed likelihood: one incident in ____ years
 A7 Annual exposure = A5 / A6 ............................. ____

B. NETWORK AND FIREWALL                           source: ticket system
 B1 FTP tickets per month ____ x hours each ____ x 12 ..... ____ h/yr
 B2 Firewall changes touching FTP per year ____ x hours ____ ____ h/yr

C. AUDIT AND QUESTIONNAIRES                       source: audit files
 C1 Audit cycles per year ____ x hours on FTP findings ____ ____ h/yr
 C2 Questionnaires per year ____ x hours on FTP answers ____ ____ h/yr
 C3 Deals or renewals delayed by an FTP answer ............ ____

D. SUPPORT AND KEY PEOPLE                         source: tickets, interviews
 D1 Partner onboardings on FTP per year ____ x extra hours
    versus SFTP ____ ...................................... ____ h/yr
 D2 Device or job failures traced to FTP per year ____ x
    hours ____ ............................................ ____ h/yr
 D3 FTP jobs only one person understands (risk flag) ...... ____

E. MIGRATION DEBT                                 source: census, timed pilots
 E1 FTP flows today ____ x hours to migrate one ____ ....... ____ h (principal)
 E2 New FTP flows created in the last year ................ ____ (interest)
 E3 Loaded hourly rate ................................... ____

ANNUAL RECURRING = (B1+B2+C1+C2+D1+D2) x E3 + A7 ........... ____ per year
ONE-TIME MIGRATION = E1 x E3 .............................. ____
PAYBACK = one-time / annual ............................... ____ years

The payback line is the sentence your manager needs: "retiring FTP pays for itself in about so many years, and the risk row is on top of that." When the payback comes out at a year or two, the case makes itself. When it comes out at ten, the honest reading is that this estate's FTP is cheap to keep. The right response is containment, a no-new-FTP rule, and a review date rather than a project.

Where Each Number Comes From

Category Where the number comes from Usually large when What shrinks it
Security exposure Server account list, login logs, data classification Domain credentials over FTP; internet-facing listeners; sensitive data Unique local accounts, internal-only exposure, encryption
Network and firewall Ticket search, firewall change log Many partners; FTPS through helpers; load balancers Single-connection protocols; documented passive ranges
Audit and questionnaires Audit reports, exception register, sales records Regulated data; customer-facing security reviews Closing the finding, not re-explaining it
Support and key people Tickets, onboarding records, a short interview per team Undocumented jobs; frequent partner onboarding Documentation, a standard client, rehearsed jobs
Migration debt Flow census; two or three timed pilot migrations New FTP flows still being created; knowledge leaving A no-new-FTP rule; drop-in clients; a server that speaks both

There is one shortcut for the A rows. The FTP listener may already live on a server that also speaks the secure protocols. Sysax Multi Server runs FTP, FTPS, SFTP, and HTTPS on one Windows machine. It has per-account authentication and activity logging to file and database. If your listener lives on such a server, the account list and the login log are in one place. Then "which accounts still use plain FTP" is a report rather than a research task. And because one server answers all four protocols, a flow can move from FTP to FTPS or SFTP without moving machines. That is what makes flow-by-flow retirement practical instead of a big-bang cutover.

From Ledger to Decision

A completed worksheet produces one of three conclusions, and all three are respectable. If the annual cost is high and the payback short, you have a funded retirement program. The articles why retire FTP and the FTP retirement plan take it from here. If the cost is concentrated in a few flows, you have a short list to migrate first and a long tail to contain. Typically, the cost is concentrated in the internet-facing flows and the ones carrying sensitive data. And if the numbers are small across the board, you have evidence that containment is the right posture for now. You also have a document to show the next auditor that the decision was made with numbers rather than by neglect.

Whatever the conclusion, keep the worksheet and refill it once a year. Migration debt only shows its growth over time. A ledger that gets worse annually is the most persuasive argument this article can offer. It is also the one the security officer's sentence, however heartfelt, could never make. The series continues with the FTP family tree, which sorts out what you would be migrating to. And living with FTP responsibly covers the containment the small-number case calls for.

Frequently Asked Questions

Is plain FTP on an internal network really a security cost?
Yes, though a smaller one than on the internet. Internal networks carry compromised laptops, contractors, and misconfigured equipment. Any of these can capture cleartext logins on the same segment. The cost is largest when the FTP password is also a domain password. Then one captured login opens far more than a folder.
How do I get real numbers instead of guesses?
Most rows come from records you already keep. These include the server's account list and logs, the ticket system, the audit exception register, and the flow census. For migration hours, migrate two or three flows and time them rather than estimating. Where you must assume, write the assumption next to the figure.
What if the worksheet shows FTP is cheap to keep?
Then believe it, and respond with containment rather than a project. Use internal-only exposure, unique accounts, logging, a rule that no new flows use FTP, and a review date. Keep the worksheet as evidence that the decision was deliberate. Refill it next year to see whether the debt is growing.
Which cost is usually the biggest?
For most organizations it is the recurring audit and questionnaire friction plus the growing migration debt, not a dramatic incident. Those are quiet, annual, and easy to overlook, which is exactly why writing them down changes the conversation.
Does migrating to SFTP or FTPS remove all of these costs?
It removes the cleartext exposure and most of the audit and firewall costs. It also stops the migration debt from growing. Support and key-person costs shrink only if the migration also brings documentation, a standard client, and rehearsed jobs. Moving an undocumented job to a better protocol leaves it undocumented.

From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.