IoT device security for small offices

Every small office has a shadow IT fleet that appears on no asset list: the multifunction printer that scans to email, the front-desk camera with its own app, the smart TV in the meeting room, the delivery-door buzzer with a web login, the label printer someone port-forwarded "for the vendor." Nobody patched them, nobody inventoried them, and their admin logins are usually the ones printed on a sticker on the box.

This is not a hypothetical. Printers hold PDFs in spool files and SMTP credentials in settings. Cameras are watched from the internet. TVs ship with admin panels reachable from the office LAN. A breach that starts on a $300 device ends up in the same first 24 hours as one that starts on your laptop — except nobody logged into that device, ever, so nobody will notice for weeks. This checklist makes the forgotten fleet survivable in one 90-minute session plus a quarterly 30-minute recheck.

1. Name an owner (5 minutes, changes everything)

The reason the printer has a 2019 firmware and the camera password is "admin123" is not budget — it's that the devices belong to nobody. Whoever fixes the coffee machine is not the same person who manages the laptop fleet, so the fleet simply rots:

2. Walk the office: build the inventory (60 minutes, once)

You cannot secure what you cannot list. One walking pass with your phone notes app:

3. Default credentials: the highest-yield 30 minutes in this whole checklist

Most small-office intrusions into this device class use the password printed on the bottom of the box. One session fixes the whole class:

4. Firmware: a quarterly 30-minute ritual, not a crisis

Device firmware never auto-updates the way laptops do, so the fleet's software is effectively frozen at purchase date. Make the update a calendar event, like tax deadlines:

5. Segregate the device network (the fix that beats patching)

You cannot count on updating everything forever. You can control what a compromised device can reach:

6. The internet-exposure audit: what's actually reachable from outside (30 minutes)

This is where device fleets leak. Someone port-forwarded the camera "to check the office while traveling" in 2022 and nobody removed the rule:

7. Printers: computers pretending to be furniture

The office printer deserves its own section because it's the device most likely to hold data, not just firmware:

8. Cameras and NVRs: the embarrassing breach

Cameras are the device class most likely to be both internet-connected and catastrophically neglected. A camera breach isn't just trespass — it's surveillance of your team, and it becomes a trust event faster than any server breach:

9. Close the loop: ownership, calendar, and the next review

The checklist only holds if the fleet re-enters the routine machinery you already have: