When businesses think about cybersecurity, the usual suspects come to mind: laptops, servers, email accounts, cloud services and mobile phones.
The office printer rarely makes the list.
But perhaps it should.
Modern multifunction printers have evolved a long way beyond simply putting toner onto paper. They sit permanently on the company network, communicate with other systems, authenticate users, scan and process documents, connect to cloud services and, in many cases, contain their own internal storage.
In practical terms, today’s multifunction printer is another network endpoint.
Printers have changed. Has the thinking around them?
A modern office copier might allow employees to scan directly to email, save documents into Microsoft 365 or other cloud platforms, access network folders, authenticate using cards or user accounts and submit print jobs from computers and mobile devices.
Those capabilities make modern devices considerably more useful.
They also mean that printer security can no longer be considered separately from general IT security.
This doesn’t mean businesses should suddenly be frightened of their photocopiers. It simply means they should be managed with the same common sense applied to other equipment connected to the network.
The forgotten device on the network
One of the biggest problems with printers is their longevity.
Computers and mobile devices tend to be replaced relatively frequently. Business photocopiers can remain in service for five, seven or even more years.
During that time employees change, networks are upgraded, IT providers change and new cloud services are introduced.
The copier in the corner can easily be forgotten.
A device installed several years ago might still contain old address-book entries, outdated network settings, unnecessary services or administrator credentials that haven’t been reviewed since installation.
None of those things necessarily represents an immediate security problem. Together, however, they demonstrate why printers should be included in routine IT housekeeping.
Start with the basics
Good printer security doesn’t have to be complicated.
Keeping device firmware up to date is an obvious starting point. Manufacturers regularly release updates that fix bugs, improve compatibility and address security issues discovered after a machine was released.
Administrator passwords should also be properly controlled rather than left at defaults or shared unnecessarily.
Businesses should periodically review who can access the device, which network services are enabled and whether old scan destinations or user accounts are still required.
If confidential documents are regularly printed, secure or PIN-release printing can also prevent sensitive information sitting unattended in an output tray.
These are relatively simple measures, but they’re often the ones that get overlooked.
What happens to the data inside the machine?
There’s another aspect of printer security that businesses sometimes don’t consider until a machine is replaced.
Many multifunction printers contain internal storage used for processing print, copy and scan jobs.
That makes disposal and replacement important.
When a copier reaches the end of its life, businesses should understand what happens to any data stored on the device and whether the machine provides appropriate deletion or sanitisation procedures before it leaves their control.
The same principle applies when returning leased equipment.
You wouldn’t normally hand an old company laptop to somebody without considering the information stored on it. A multifunction printer deserves similar consideration.
Cloud-connected printing adds another dimension
Cloud integration has made office printing and scanning much more convenient.
Users can increasingly scan directly into document-management systems, cloud storage and workflow applications without returning to their computers.
That’s a genuine productivity improvement, but every connection between systems needs to be properly configured and maintained.
Permissions should be appropriate, unused integrations should be removed and authentication should be treated seriously.
The objective isn’t to avoid connected printers. It’s to use their capabilities properly.
Printer security should be part of the wider IT conversation
The important change is really one of mindset.
A printer shouldn’t be treated as an isolated piece of office equipment simply because its most visible job involves paper.
It’s a network-connected device that handles business information.
That means whoever looks after an organisation’s IT should know what printers are connected to the network, how they’re configured, whether they’re receiving appropriate updates and what happens to them when they’re replaced.
For businesses with larger fleets, this becomes even more important. Ten, twenty or fifty multifunction devices represent ten, twenty or fifty additional network endpoints that need managing.
Don’t panic about your printer — manage it
None of this means businesses need another cybersecurity scare story.
Modern printers include increasingly sophisticated security features, and properly configured devices can be a secure and extremely useful part of a company’s technology infrastructure.
The problem is rarely that printers are inherently unsafe.
The problem is forgetting that they’re computers too.
The next time your business reviews its cybersecurity, don’t stop at the laptops, servers and cloud accounts.
Take a look at the copier sitting in the corner as well.
