Skip to main content

Banc of California Replaced MOVEit DMZ Without Interrupting Its Daily HOA Exchange

The bank prebuilt its branded SFTP endpoint, users, permissions, and controls before cutover, then made recurring access reviews a direct export.
Banc of California (formerly Pacific Western Bank)Files.com

Banc of California is a Los Angeles business bank with roughly $33 billion in assets, the third largest bank based in California. The institution that carried out this migration in 2021 was then Pacific Western Bank; after its 2023 merger, the combined bank took the Banc of California name. It banks small, middle-market, and venture-backed companies across the state, but one of its most distinctive franchises is a specialty: HOA banking. In October 2021 the bank acquired Union Bank's Homeowners Association Services division, a national provider of banking to the community association management industry, carrying roughly $4 billion in deposits. The work behind those deposits is operationally demanding: lockbox and electronic receivables processing that reconciles assessment payments across thousands of individual associations and homeowners, nationwide.

That business runs on files. Every day, the HOA program's external counterparties exchange files with the bank. Some of them are automated systems, some are people at a keyboard, and all of them connect to an SFTP endpoint that carries the bank's name. A named party uploads a file for a named recipient, the recipient retrieves it, and the cycle repeats the next day. It is exactly the kind of unglamorous, daily, regulated exchange a bank cannot allow to wobble.

In 2021, the bank replaced MOVEit DMZ by building the Files.com environment in full before cutover. The daily exchange continued unchanged, while recurring access reviews became a direct export of the platform's user and permission records.

A Legacy DMZ Product Under a Regulated Daily Exchange

Until 2021, this exchange ran on MOVEit DMZ. MOVEit DMZ was managed file transfer of an earlier generation: software the customer installs on Windows servers in their own network perimeter, then patches and keeps running themselves. Counterparties were not connecting to a service. They were connecting to a box the bank operated, sitting inside the bank's own DMZ, with the bank's IT team as the infrastructure underneath a live business exchange.

Being a bank compounded that arrangement. Financial institutions carry reporting requirements over exactly this kind of system: on a recurring cycle, the bank's review process required a complete listing of who held access and what permissions each of them held, produced, then reviewed, signed, and dated. The security controls around the exchange had to be evidenced as well. The exchange the bank had to evidence most carefully ran on infrastructure the bank also had to operate itself.

In 2021, the bank moved to retire it.

The Replacement Had to Exist in Full Before the Switch

A daily exchange could not be paused while its replacement was assembled. Counterparty systems and counterparty people connected against the endpoint every day, and a botched cutover would have been visible to all of them at once. So the bank set a condition: nothing would go live until everything already existed. The new environment had to be configured completely in advance, and then convert directly into the bank's primary production site rather than be rebuilt a second time.

The requirements describe what the exchange demanded. The replacement had to present an SFTP endpoint on the bank's own domain, at fixed addresses that counterparty firewalls could allowlist. It had to carry bank-grade access controls: two-factor authentication, per-user IP restrictions, password policy, brute-force lockout. It had to take the entire counterparty user base in one pass rather than account by account. It had to export the complete user-and-permission picture whenever a review came due. And it had to take the server itself off the bank's hands.

The bank selected Files.com to provide that endpoint as a fully managed service.

Built in Advance, Then Converted Into Production

Files.com stood the bank up in an extended pre-production environment, on the understanding that it would convert into the primary site. The bank's network team built the whole destination there before a single counterparty touched it.

A Files.com custom domain put the SFTP endpoint on a subdomain of the bank's own domain, with a dedicated pair of IP addresses. Counterparties connected to an address that read as the bank, and their firewall allowlists pointed at two fixed IPs instead of a shared cloud range. Files.com's bulk user import then provisioned the counterparty accounts in a single operation, with folder permissions assigned as each account was created, so the user base arrived whole rather than being rebuilt by hand.

The bank also configured and documented its required controls in that same environment before cutover. These included two-factor authentication for interactive users, per-user IP restrictions, lockout protection, and tiered administration that kept duties appropriately scoped.

When the environment was complete, it converted into the bank's production site, and the counterparty exchange moved onto it in 2021. The cadence that mattered, a file up once a day and down once a day, carried on unchanged.

Access Reviews Became an Export

With the Files.com endpoint in production, the bank replaced a legacy product it operated inside its own perimeter with a managed service it can evidence on demand.

  • The HOA counterparty exchange has run on Files.com since 2021 at a high, steady daily load, and it accounts for the large majority of the bank's file-transfer activity on the platform. MOVEit DMZ is gone.
  • Periodic access reviews are produced from the platform itself: a complete export of every user and every permission they hold, down to each user's whitelisted IP addresses, which the bank then reviews, signs, and dates as its financial-institution reporting requirements demand.
  • Security-control configuration doubles as audit evidence. Two-factor enforcement, IP restrictions, password policy, and lockout settings are captured directly from Files.com rather than reconstructed for auditors.
  • There is no transfer server left in the bank's perimeter for this exchange. Nothing to patch, nothing to keep alive, and no box for the network team to own underneath a regulated daily workflow.

A live counterparty exchange changed platforms without its users changing their day. The compounding result is the review cycle. Evidence that has to be produced again and again now costs an export each time, so every recurring review since 2021 has drawn from the same source, the platform's own record of who can reach what.

The lesson travels to any bank still running a legacy MFT product under a live exchange: the migration does not require the exchange to stop. Banc of California built the entire replacement first — the domain, the users, the permissions, the controls — and only then made it the system of record, so the moment of modernization was invisible to everyone it served.