
Securing the Print Estate: A Proactive Lifecycle Approach to Cyber Resilience
Printers are a long-term investment, with refresh cycles spanning years, yet security is often an afterthought. However, by choosing the right print partner, organizations can not only improve cost-efficiency, reliability and performance – they can also enhance their cyber resilience.
Too often printers are seen as a “harmless box”, rather than a sophisticated networked device with hard drives, and communication capabilities, just like PCs. But unlike PCs, which commonly have layers of endpoint security to defend against cyber threats, many printers have limited, or lack entirely, endpoint protection, making it harder for enterprises to detect and respond to threats.
Today, a new report from HP Wolf Security details common printer security challenges faced by IT leaders and recommendations to address them. Based on a global study of 800+ IT and security decision-makers (ITSDMs), the report found that printer platform security—i.e. the security provided by the printer hardware and firmware—is being overlooked by many organizations, leaving security gaps at each stage of a printer’s life.
But by adopting a lifecycle approach to printer security, organizations can begin to address and even prevent many of these security challenges before they become an issue. In practice, this means considering security at every stage of a printer’s life: from embedding strong security requirements during procurement, to monitoring and managing the security and configuration of their printer fleets during operation, and ensuring safe, secure decommissioning when printers reach end-of-life. A full list of recommendations are detailed in the report.
“Printers and other IoT are powerful computing devices, making them attractive targets for attackers to exploit and use as footholds into enterprise infrastructure. As such, organizations must learn to develop mature security requirements when procuring new devices, and to proactively manage their security configuration over the entire device lifecycle.” – Boris Balacheff, Chief Technologist for Security Research and Innovation at HP Inc.
Key Findings
ITSDMs reported facing printer security challenges at every stage of a printer’s lifecycle:
Supplier Selection & Onboarding
- Lack of procurement collaboration: Only 38% of ITSDMs say procurement, IT, and security collaborate to define printer security standards – with 60% warning that this lack of collaboration puts their organization at risk.
- RFPs going unchecked: 42% of ITSDMs fail to involve IT/security teams in vendor presentations; 54% fail to request technical documentation to validate security claims; and 55% fail to submit vendor responses to security teams for review.
Remediation
- Inability to detect and remediate threats: Many organizations are struggling to keep on top of patching devices. Only 35% of ITSDMs are Only 34% can track unauthorized hardware changes made by users or support teams, and only 32% of ITSDMs can detect security events linked to hardware-level attacks.
- Not just cyber – print risks are physical too: 70% of ITSDMs are increasingly worried about offline threats, such as employees printing and mishandling sensitive company information.
Decommissioning and Second Life
- End of life risk: 86% of ITSDMs say data security is a barrier to printer reuse, resale or recycling – a big problem, given that on average ITSDMs report having approximately 80 printers that are redundant or are in the process of being decommissioned within their organizations.
- Lack of confidence: ITSDMs lack confidence in current sanitization solutions, with 35% saying they are uncertain whether printers can be fully and safely wiped. Meanwhile, 1-in-4 believe it’s necessary to physically destroy printer storage drives, and 1-in-10 insist on destroying both the device and its storage drives to ensure data security.
Read the Report
Download the report: Securing the Print Estate: A Proactive Lifecycle Approach to Cyber Resilience




