Skip to main content

CNO Financial Group Met a File-Level Encryption Mandate on Files.com Instead of an Emergency SFTP Upgrade

An existing regulated partner hub let the insurer onboard business its on-premises environment could not support without upgrades coordinated across outside organizations.
CNO Financial Group / OptaviseFiles.com

CNO Financial Group (NYSE: CNO) is an insurance holding company with $4.1 billion in annual revenue, serving middle-income pre-retirees and retirees through its life, supplemental health, and annuity carriers. Its worksite arm, Optavise, provides benefits administration and enrollment services.

Both sides of that business run on file exchange with organizations CNO does not control. Employers send enrollment and eligibility data. Carriers and third-party administrators send and receive benefits and insurance files. Much of it is protected health information, which puts every transfer under HIPAA and puts the mechanics of how data moves into the contracts clients sign. For an insurer, the file transfer layer is not plumbing behind the product. It is part of what clients are buying.

When a client's contract required file-level encryption that the on-premises servers did not support, that operating model put new business at risk. An upgrade might have added the capability eventually, but it could not land quickly enough, given the coordination every change to the servers demanded. The choice in front of CNO was to turn away the business or serve it on a platform that already met the requirement.

Upgrades That Had to Be Negotiated With External Clients

CNO's partner file exchange ran on on-premises Windows SFTP servers, and the operating system under those servers was the standing cost. An OS carries vulnerabilities, so the infrastructure team owned a patching workload it could not get ahead of. And the servers were load-bearing for outside parties: employers, carriers, and TPAs connected to them directly, so upgrading the platform meant negotiating change windows with organizations CNO does not control. Upgrades slipped, and the platform fell further behind.

It's not ideal from a security posture, because it's got an operating system, so you have to deal with vulnerabilities, and then the upgrades are a disaster because we have to coordinate with external clients.
Lilliana Quintero, Senior Director, Infrastructure Architecture, CNO Financial Group

The deeper cost was not the patching hours. It was that the platform's capabilities set a ceiling on the client requirements the business could accept. A transfer platform that lags its own upgrade cycle also lags the security terms clients write into contracts, and in regulated insurance, those terms are part of the deal.

The Contract That Required What the Servers Could Not Do

What the new platform had to do was specific. It had to speak SFTP to partners who already worked that way. It had to keep each external party walled into its own paths. It had to encrypt files to the client's contractual standard, carry CNO's own branding, and handle PHI under an executed Business Associate Agreement, which CNO treats as a hard requirement of the workload rather than a preference. And it had to do all of that without adding one more operating system to the infrastructure team's patching calendar.

CNO already ran that platform. Since 2018, its Optavise business had operated a branded partner transfer hub on Files.com, exchanging benefits and insurance data with external employers, carriers, and TPAs. The client requiring file-level encryption was onboarded onto the Files.com hub instead.

The broader on-premises SFTP estate remains in place while CNO plans a phased migration, moving workloads one at a time and running the legacy environment in parallel until switchover. Files.com was the established Optavise hub and the immediate answer for this client, not yet a completed replacement for every CNO transfer workload.

A Partner Exchange Layer With No Operating System to Own

For the Optavise-era workloads already running there, Files.com is a governed front door for regulated partner exchange, with no underlying operating system for the infrastructure team to own.

Partners connect over SFTP to a CNO-branded domain, and each external account is provisioned into locked-down paths, so a partner reaches its own folders and nothing else. Per-user IP allow lists, two-factor authentication, and logins restricted to the United States and Canada add layers of access control around that boundary.

The encryption mandate was met on Files.com rather than through an infrastructure project. Transfers are encrypted in transit and files are encrypted at rest as a matter of course, while file-level PGP/GPG encryption runs through the Files.com key manager. PHI moves under an executed Business Associate Agreement covering the workload.

The hub is also not a dead end. Every file a partner uploads is consumed by a downstream internal system, and internal teams use the same site to reach reports and work with uploaded files. The intake point and the processing handoff are one place, with nothing for CNO's team to patch and no upgrade window to negotiate with the external clients connected to it.

The Upgrade Cycle Stopped Being the Gatekeeper

With the client running on Files.com, CNO turned what would have been an emergency infrastructure project into an onboarding exercise.

The immediate result was one client won. The compounding result is that a security requirement a client writes into a contract now meets a platform that keeps itself current, so the answer becomes a matter of configuration rather than a question of whether an upgrade can be scheduled fast enough.