How Diplomat Unified SFTP Security Across Five Autonomous IT Teams With Files.com

Diplomat is a fast-moving consumer goods sales and distribution group headquartered in Israel. It imports, markets, and distributes branded products for international manufacturers through regional operating units. The publicly traded group generates roughly $500 million in revenue, with five business units in Israel, Georgia, South Africa, New Zealand, and Cyprus.
A distribution business of that shape runs on data exchange. Suppliers push product and sales data, orders and inventory flow through SAP, and partner files feed the Power BI dashboards the business is steered by. Because each of the five business units operates in its own market, each runs its own IT team and its own help desk, under a global infrastructure and security function. That structure reached all the way down to file transfer: every country ran its own on-premise SFTP/FTP server.
Five Servers, Five Firewalls, and No Record of Who Touched What
For the global security team, the estate was five separate blind spots. The legacy servers had no login logging enabled, so nobody could say who used them or which files they touched. The only artifact was the list of provisioned accounts, and that list included people who had left the company, still set up with FTP access.
“All I have is this list of users who are set up. Some of them don't even work for the company anymore and are disabled, but they are still set up with FTP.”
Everything else about the estate cost effort in five copies. Every new partner meant an account created by hand on that country's server. Security controls were only as good as each local firewall: Diplomat is required to block access from countries where it is not permitted to have clients, and that geo-blocking had to be operated separately, firewall by firewall. Sending a file too large for email meant local IT creating a temporary user, uploading the file, and sending the recipient a password-protected link, with the password going out over email or WhatsApp. And all five servers were self-managed infrastructure that somebody had to keep patched.
The estate had survived because the obvious fix looked worse. Diplomat's countries are genuinely separate operations, and consolidating onto one centrally run server would have turned global IT into the help desk for five markets' worth of users, partners, and folder changes. But the obligations the servers could not meet were standing ones: GDPR and data residency, audit-log retention, and the basic question of which user touched which file, when. As unattended supplier and customer automation became the dominant file workload, the group could not answer that question in any region.
The Replacement Had to Keep Local IT in Charge
What the new platform had to do was written by the structure of the company. It had to be SaaS, with vendor-managed updates and data hosted in Western Europe. It had to carry one global security posture: geo-blocking of sanctioned countries, plain FTP restricted to named partner IPs, a full audit trail, and retention schedules that differ by business unit—a month in one country, two weeks in another, five days for temporary files. And it had to preserve five autonomous administrative domains, because day-to-day user and folder administration was staying with each country's IT team, without handing every regional team administrative rights over the whole platform.
Diplomat selected Files.com to be that platform: one site holding five separately administered regions under a single security posture.
One Site, Five Delegated Regions
Identity came first. Diplomat connected the site to Microsoft Entra ID for SAML single sign-on, with SCIM provisioning and Active Directory group sync, so accounts follow the directory instead of being built by hand. Using Files.com's group-admin roles and synchronized AD groups, the security team gave each regional IT team control over the users and folders under its own country branch without granting site-wide administrative rights. Each country's IT runs its own region, and nobody outside the global team holds site-admin rights.
Each business unit got its own country-scoped folder tree, with folders per customer, supplier, and sister company underneath it, and Files.com retention policies set per unit, so one country's one-month schedule and another's two-week schedule coexist on the same site. The temporary-account pattern for large files went away too: files far too large for email now move as expiring, password-protected Files.com share links, inside the same audit trail as everything else.
A Global Security Posture, Set Once
The controls that used to live in five firewalls now live in one place. Files.com geo-blocking shuts out the countries Diplomat is not permitted to serve, across every region and every protocol at once.
“We are not allowed to have clients there, so obviously no one is legitimately accessing our stuff here.”
Plain FTP, which one legacy partner connection still requires, is restricted to that partner's named IP addresses; everything else runs over SFTP or HTTPS. The site runs on Diplomat's own branded domain with dedicated IP addresses, so partners whitelist just two addresses. Data is stored in Western Europe, and every login, connection, and file action lands in the audit log, queryable per user and exportable through the Files.com API.
A Process Migration, Region by Region
Diplomat deliberately scoped the move as a process migration: workflows moved to Files.com while legacy data stayed where it was, so no cutover depended on hauling years of files into the cloud. The rollout ran in two phases per country through 2025, automated server-to-server accounts first and human users after, with each regional IT team owning its own deployment and the legacy server running in parallel until the region was verified.
The migration also forced the first real account audit the estate had ever had. Only about a third of the users provisioned on the old servers turned out to be active; the departed and disabled accounts were dropped rather than carried over. As each region was verified, its on-premise server was shut down.
Every Process Moved, Every Server Shut Down
Since the cutover, Diplomat has replaced five locally patched, locally administered servers with one governed platform and completed the rollout, with every remaining user moved.
- Every file-transfer process across Israel, Georgia, South Africa, New Zealand, and Cyprus, plus external counterparties in the Americas, runs through one Files.com site, and all five on-premise servers are decommissioned. There is no server left to patch.
- Global IT can answer who touched which file, and when: per-user connection and file-access history is queryable across all five regions and exportable through the API, and the team runs monthly upload-count reporting where no login logging existed at all.
- The security posture is enforced everywhere from one place. Geo-blocking, protocol restriction, IP whitelisting, and per-business-unit retention apply to every region without five firewalls to keep in step.
- Roughly half of all accounts on the site are system accounts running unattended server-to-server SFTP with suppliers and customers, so the automated data pipelines feeding SAP and Power BI now run inside the same logged, governed platform as everything else.
The compounding change is what growth costs now. Onboarding a new partner in any country is a folder and a user under that country's branch, created by the regional team that owns the relationship: no ticket to global IT, no account built by hand on a server, no new infrastructure anywhere. New users arrive from the directory, and departed ones leave with it.
Consolidated, Not Centralized
Diplomat's structure did not change. Five business units, five IT teams, five help desks, and that was the point. What changed is where the security lives. Before, a security engineer asking who was using a country's file server had a list of provisioned accounts, some belonging to people who no longer worked there, and no way to say more. Now the same question is a lookup on one Files.com site, and the answer covers all five countries. Global IT owns the platform, the posture, and the audit trail; each country's IT still creates its own users and runs its own folders, the way the business is built to operate. Diplomat consolidated five countries' file transfer without centralizing it: the security became global, and the administration stayed local.
Related Customer Stories

Transportation & Logistics
AAA Northeast Replaced Progress WS_FTP Without a Big-Bang Cutover
The migration preserved partner workflows with a hostname-and-credential change while Files.com made encryption, retention, identity, and auditing enforceable.
Read story →
Transportation & Logistics
FlightSafety Moves Oversized, Confidential Aviation Documents Beyond Email With Files.com
Each outside party signs in through a branded browser experience and reaches one permission-scoped folder through an account that expires on schedule.
Read story →
Transportation & Logistics
Need It Now Delivers Retires Its In-House File Server for Unattended SFTP Dispatch
One business-side manager moved client-isolated dispatch feeds to Files.com, where nightly manifests have arrived for three years without daily intervention.
Read story →