Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do USB drives, optical media, and FTP…
Cyber Security

Why do USB drives, optical media, and FTP clients create so much data loss risk in organisations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Cyber Security

These older tools move data outside normal cloud and application controls, so they can bypass many standard monitoring paths. USB drives and discs make copying easy, while FTP can expose file transfers that are hard to spot without dedicated oversight. That combination makes both accidental loss and deliberate exfiltration more likely.

Why removable media and FTP bypass so many everyday controls

USB drives and optical media create a direct path for data to leave the normal managed environment, so they often sidestep cloud logging, CASB-style oversight, and application-level controls. FTP has a similar problem on the transfer side: it moves files through a protocol that is easy to automate, hard to inspect well, and often tolerated for compatibility even when better options exist.

The core issue is not that these tools are exotic, it is that they sit outside the more visible workflows organisations build around email, collaboration suites, and sanctioned file sharing. When transfer channels are fragmented, teams lose a reliable view of who copied what, where it went, and whether the destination was approved.

That makes the risk especially high when controls depend on central logging, endpoint governance, or approved content platforms. A file copied to removable media can disappear from the normal chain of custody, while an FTP transfer may leave only partial audit evidence unless the organisation has explicit monitoring and policy enforcement for that protocol.

Why accidental loss and deliberate exfiltration become hard to distinguish

These channels create the same operational ambiguity for both mistakes and abuse. A user can copy sensitive files to a thumb drive for convenience, but the same action can also be used to stage exfiltration with very little friction. Optical media adds a further challenge because it can be treated as “offline” even when it carries highly sensitive data.

FTP is especially problematic when it is used as a legacy integration path. It can become the default fallback for vendors, admins, or operations teams who need simple file movement, yet that convenience often comes with weak visibility, broad destination exposure, and unclear ownership of the transfer process.

In practice, the more a transfer method relies on local action and external destinations, the more difficult it becomes to apply consistent classification, review, and retention rules. Once data is copied onto media or sent through a loosely governed client, downstream controls have to recover context that was never captured at the point of transfer.

Why the risk scales quickly across a large organisation

The risk is not just the individual transfer, it is the repetition of the pattern across many users, sites, and business units. One unmanaged channel can become the preferred workaround for whole teams, especially when approved tools are slower, blocked, or poorly integrated with the task at hand.

That scale problem is why media sanitisation, endpoint policy, and transfer governance matter together. NIST SP 800-88 Media Sanitization is useful here because the same organisations that struggle with offboarding media often also struggle with knowing when copied data should be cleared, purged, or destroyed after use.

Legacy transfer paths also become resilience problems. If the organisation cannot see or control them, it cannot reliably prove whether sensitive data has left the environment, whether it has been duplicated, or whether a transfer path is still being used after policy changes.

Risk and Threat Considerations

These channels are attractive because they reduce friction for both careless disclosure and targeted theft. A removable drive, disc, or FTP session can move data out of the normal approval chain, which weakens detection, complicates attribution, and makes it easier for an insider or compromised endpoint to exfiltrate material without immediate challenge.

Failure mechanism: The organisation lacks consistent control over the transfer point, so copying occurs outside the systems where classification, logging, destination restriction, and alerting are normally enforced.

Impact: Sensitive files can be removed, duplicated, or transferred to unapproved destinations with limited visibility, creating loss, breach, and investigation risk that is harder to reconstruct after the fact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Audit EventsLegacy transfers need auditable events for file movement and destination tracking.
AC-19 — Access Control for Mobile DevicesRemovable media risk depends on controlling portable storage use on endpoints.
MP-7 — Media UseUSB and optical media are media-use pathways that can bypass normal controls.
Recommendation — Log removable-media and FTP transfer events with user, device, file, and destination context. Restrict portable storage use on managed devices and enforce exceptions. Define and enforce approved media use, handling, and transfer restrictions.
ISO/IEC 27001:2022A.8.12 — Data leakage preventionThe subject is fundamentally about data leaving controlled environments through weak channels.
Recommendation — Apply data-loss-prevention controls to detect and block unauthorised file transfer.

Practitioner Guidance

What to verify: Confirm whether removable media, optical drives, and FTP are still enabled on managed endpoints, and whether their use is logged at a level that lets you identify the user, device, file, and destination. If you cannot reconstruct those four elements, the control is weaker than it appears.

What to prioritise: Treat these channels as policy exceptions, not as normal file-transfer options. The highest-value work is usually to remove unnecessary use cases first, then tightly constrain the remaining ones with approval, monitoring, and destination restrictions.

Common mistake: Teams often focus on blocking USB storage while leaving FTP and other legacy transfer paths untouched. That creates a false sense of control because the organisation still has an easy, under-monitored route for bulk file movement.

Practitioner takeaway: The real objective is not to eliminate every transfer method, but to ensure that any channel capable of moving sensitive data outside normal controls is either removed, tightly governed, or made fully observable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org