CNO Financial Group Met a File-Level Encryption Mandate on Files.com Instead of an Emergency SFTP Upgrade
CNO Financial Group (NYSE: CNO) is an insurance holding company with $4.1 billion in annual revenue, serving middle-income pre-retirees and retirees through its life, supplemental health, and annuity carriers. Its worksite arm, Optavise, provides benefits administration and enrollment services.
Both sides of that business run on file exchange with organizations CNO does not control. Employers send enrollment and eligibility data. Carriers and third-party administrators send and receive benefits and insurance files. Much of it is protected health information, which puts every transfer under HIPAA and puts the mechanics of how data moves into the contracts clients sign. For an insurer, the file transfer layer is not plumbing behind the product. It is part of what clients are buying.
When a client's contract required file-level encryption that the on-premises servers did not support, that operating model put new business at risk. An upgrade might have added the capability eventually, but it could not land quickly enough, given the coordination every change to the servers demanded. The choice in front of CNO was to turn away the business or serve it on a platform that already met the requirement.
Upgrades That Had to Be Negotiated With External Clients
CNO's partner file exchange ran on on-premises Windows SFTP servers, and the operating system under those servers was the standing cost. An OS carries vulnerabilities, so the infrastructure team owned a patching workload it could not get ahead of. And the servers were load-bearing for outside parties: employers, carriers, and TPAs connected to them directly, so upgrading the platform meant negotiating change windows with organizations CNO does not control. Upgrades slipped, and the platform fell further behind.
“It's not ideal from a security posture, because it's got an operating system, so you have to deal with vulnerabilities, and then the upgrades are a disaster because we have to coordinate with external clients.”
The deeper cost was not the patching hours. It was that the platform's capabilities set a ceiling on the client requirements the business could accept. A transfer platform that lags its own upgrade cycle also lags the security terms clients write into contracts, and in regulated insurance, those terms are part of the deal.
The Contract That Required What the Servers Could Not Do
What the new platform had to do was specific. It had to speak SFTP to partners who already worked that way. It had to keep each external party walled into its own paths. It had to encrypt files to the client's contractual standard, carry CNO's own branding, and handle PHI under an executed Business Associate Agreement, which CNO treats as a hard requirement of the workload rather than a preference. And it had to do all of that without adding one more operating system to the infrastructure team's patching calendar.
CNO already ran that platform. Since 2018, its Optavise business had operated a branded partner transfer hub on Files.com, exchanging benefits and insurance data with external employers, carriers, and TPAs. The client requiring file-level encryption was onboarded onto the Files.com hub instead.
The broader on-premises SFTP estate remains in place while CNO plans a phased migration, moving workloads one at a time and running the legacy environment in parallel until switchover. Files.com was the established Optavise hub and the immediate answer for this client, not yet a completed replacement for every CNO transfer workload.
A Partner Exchange Layer With No Operating System to Own
For the Optavise-era workloads already running there, Files.com is a governed front door for regulated partner exchange, with no underlying operating system for the infrastructure team to own.
Partners connect over SFTP to a CNO-branded domain, and each external account is provisioned into locked-down paths, so a partner reaches its own folders and nothing else. Per-user IP allow lists, two-factor authentication, and logins restricted to the United States and Canada add layers of access control around that boundary.
The encryption mandate was met on Files.com rather than through an infrastructure project. Transfers are encrypted in transit and files are encrypted at rest as a matter of course, while file-level PGP/GPG encryption runs through the Files.com key manager. PHI moves under an executed Business Associate Agreement covering the workload.
The hub is also not a dead end. Every file a partner uploads is consumed by a downstream internal system, and internal teams use the same site to reach reports and work with uploaded files. The intake point and the processing handoff are one place, with nothing for CNO's team to patch and no upgrade window to negotiate with the external clients connected to it.
The Upgrade Cycle Stopped Being the Gatekeeper
With the client running on Files.com, CNO turned what would have been an emergency infrastructure project into an onboarding exercise.
The immediate result was one client won. The compounding result is that a security requirement a client writes into a contract now meets a platform that keeps itself current, so the answer becomes a matter of configuration rather than a question of whether an upgrade can be scheduled fast enough.
Related Customer Stories
Insurance
BroadTech Retired Its FTP Servers Without Re-Integrating Its Partner Network
Files.com preserved the clients and automations BroadTech’s partners already used while adding encryption, auditability, and managed infrastructure.
Read story →
Insurance
Old Republic Replaced Box with Files.com During Its PHI Backend Migration to Azure
A governed SFTP perimeter secured chain of custody immediately without forcing 15 hospital partners to follow the infrastructure behind it.
Read story →
Insurance
Coalition Automates Workday Report Delivery With an In-House Files.com SFTP Model
A reusable Files.com layer now moves daily claims reports to insurance partners and closes SaaS integration gaps without manual transfers or vendor professional-services projects.
Read story →