Printers: the computer nobody patches, the disk nobody wipes
Every office has one device that is treated as furniture: the printer. It is actually a computer — a Linux box with a web server, stored credentials, a hard drive that has copied every page anyone printed or scanned for years, and a firmware update cadence that runs in years, not weeks. Auditors ask about printers because attackers do: a printer on the flat office network is the classic lateral-movement hop, and a lease return without a disk wipe is a quiet data-breach event. This checklist walks the whole fleet in about an hour, then keeps it honest in ten minutes a quarter.
1. Count the fleet and give every device an owner
- Every printer and MFP is a computer; inventory it like one. Walk the office and the network: DHCP leases, the router's client list, and the physical room. Label each device with a sticky note inside the tray lid: model, serial, owner, date checked. The IoT device checklist runs the same sweep for cameras, thermostats, and door controllers — do both walks in the same hour, because printers and cameras fail the same way.
- One named owner per device, even for the $99 inkjet. Unowned devices are the ones nobody patches and everybody assumes somebody else admins. The owner does not need to be technical; they need to be the person who notices when the printer starts offering a new cloud service after a firmware update.
- Retire the zombie. Every office has a printer that only one person uses, in a corner, on the flat network, running 2019 firmware. Decide at inventory time: keep it (then own and patch it) or unplug it. The honest answer for most five-person offices is unplug.
2. Fix the admin plane first — it outranks every other printer control
- Log in to the printer's web admin and change the default password. If admin/admin or admin/serial-number still works on a network-connected device, that is finding number one and the day is not done until it is changed. The server hardening checklist starts with the same step for the same reason: the management plane is the machine.
- Unique admin credential, stored in the password manager, never on a sticker. Printer admin passwords live taped to printers in half the offices in the world. The password manager entry is named after the device; the sticker is retired the day the entry is created.
- Disable remote administration from the internet. "Allow admin from WAN" and vendor cloud remote-print portals are how printers end up in botnets. If a vendor portal is genuinely used, it gets an owner, a named account with MFA, and a line in the shadow IT audit — because a printer that phones home is a third-party service whether anyone called it that or not.
3. Put the printer where the damage stops
- Best: a dedicated VLAN or guest-lan segment for printers, cameras, and smart TVs. The printer that talks only to the print server cannot hand an attacker a route to the file server. If the router supports guest networks or VLANs, use one for the device zoo — the wifi checklist covers the SSID split; extend it to wired ports where the switch allows.
- Flat network reality: document it, then compensate. Most small offices run one flat network, and the fix is not a weekend re-cabling project. The compensations that matter: unique admin credentials, firmware current, printers on wired LAN only (no duplicate WiFi radio), and no stored credentials beyond what scanning genuinely needs. Write the flat-network gap into the annual security review so it is a known, owned risk instead of a surprise.
- No printer on the office WiFi "for convenience". The duplicate SSID radio inside an MFP is a second front door that nobody audits. Wired only, unless the device lives in a room with no cable — and then it gets the same segment treatment as guest devices.
4. Firmware on a calendar, not on a crisis
- Twice a year, per device: check and install firmware. Printer vendors ship fixes slowly but they do ship — including for the print-spooler and web-UI vulnerabilities that get printers added to botnets. The ten-minute per-device check goes on the same calendar as the quarterly router check in the wifi checklist, and the patch management checklist owns the general cadence: printers are simply the slowest, most-forgotten line in it.
- End-of-life means replace or quarantine. A seven-year-old MFP that the vendor will never patch again either leaves the network (pull the cable) or leaves the office. The lease cycle is the natural decision point — make "is the replacement more secure?" part of the copier RFP.
- Watch what a firmware update turns ON. The classic small-office surprise: an update enables the vendor's cloud-print service by default, and suddenly the printer has a new internet account nobody chose. The owner from section 1 checks the admin screen after every update for new services and turns them off unless they were deliberately wanted.
5. The credentials stored inside the printer outlive the people who set them
- Scan-to-email is an email account with a password saved in the printer. When the staff member who set it up leaves, that password stays behind. Rotate the printer's SMTP or mailbox credential in the same pass as offboarding — the offboarding checklist pattern applies to devices too: list what the device holds, rotate it, log it.
- Scan-to-folder runs on a service account — scope it to one folder. The scan destination should be a single drop folder with write-only access, not a domain-wide account. If the only way to make scanning work was a full admin service account, that is a finding for the next access review.
- Treat a compromised print server like a compromised mailbox. The printer's scan-to-email identity can send. If a printer account gets phished or abused, the blast radius includes your email domain's reputation — check the SPF/DKIM guidance in the email security checklist and keep printer identities out of any domain-spoofable path.
6. What the drive keeps — and what leaves with the lease
- Modern MFPs copy every page to an internal disk. Contracts, salaries, medical letters, that passport someone scanned at reception. The controls: enable disk encryption or the data-overwrite feature if the device has one, and enable secure print release so jobs print to the person standing at the tray, not the tray.
- Lease return without a wipe is a data-breach event. The copier that leaves the building carries years of documents on its disk. Before the lease truck arrives: run the vendor's disk-wipe / data-overwrite utility (three passes is the standard), photograph the confirmation screen, and file it with the lease paperwork. The same discipline the vendor offboarding checklist applies to SaaS accounts applies to the box in the corner — it is just heavier.
- When a printer dies or is stolen, treat the event like a lost laptop. A stolen networked MFP is a device with stored credentials and possibly a document history. The first hour of the data breach runbook is the right play: rotate the credentials it held, note what it could reach, log the timeline.
7. The human layer: paper is a data-loss channel too
- Abandoned printouts are the classic office leak. The salary schedule someone printed and left, the client contract at the tray, the HR letter in the recycle bin. The rules are small: collect jobs within minutes, a locked shred bin within one step of every printer, and a walking route that does not cross the reception line. The visitor log exists because strangers see paper; the shred bin exists because colleagues forget it.
- Sensitive data gets a release code, not a hope. Secure print release (badge or PIN at the device) costs minutes to enable on most MFPs and removes the abandoned-document problem for anything sensitive. For the small office that cannot justify it, the written rule "no customer PII on paper unless it is being collected immediately" costs nothing.
- The fax line still exists — and still routes to the same disk. Law firms and clinics still fax. If the MFP faxes, the received-fax store is part of the same data picture: clear it with the same wipe routine at lease end, and include the fax number in the inventory row.
8. The quarterly ten minutes that keep it all true
- One walk, four checks, ten minutes: firmware current? admin password still unique (not the one taped inside the tray lid in 2022)? device count on the network still explainable? no new cloud services switched on by an update? Four yes answers and the printer leaves the risk register for another quarter.
- Log it next to the router and badge reconciliations. The wifi checklist's quarterly router pass, the physical security walk, and this printer pass are the same fifteen-minute block on the same calendar day — three small walks that together are the audit evidence for the "we manage our physical and network devices" question.
- The printer gets a row in the inventory the way every device does: model, serial, owner, firmware date, admin credential location (vault entry name, never the password), lease end date. The row takes two minutes to maintain and turns the next unexpected question — from an auditor, an insurer, or a new hire — into a lookup instead of an archaeology project.
A printer is a computer that copies everything and gets patched never. Give each device an owner, fix the admin plane before the WiFi, segment the device zoo, put firmware on a calendar, rotate the scan-to-email credentials at every offboarding, wipe the disk before the lease truck arrives, and spend ten minutes a quarter keeping all of it true. The Ops Starter Kit ($14) includes the device-inventory row and the quarterly walk sheet, and the Automation Starter Pack ($19) schedules the firmware checks and the offboarding rotation so the printer stops being the machine everyone forgot.