Most offices protect laptops, email and Wi-Fi, then forget the printer. But a modern printer is a networked computer. The print-management vendor Pharos says that multifunction printers run operating systems, so they should be treated as endpoints and get the same security controls, monitoring and updates as any other device. This checklist turns that idea into steps you can take this week.
In a joint advisory published in October 2023 (AA23–278A), the NSA and CISA listed printers, scanners, security cameras and other IoT devices among the equipment that commonly keeps its default login, which gives attackers an easy way in. The same advisory warns that printers and scanners may have privileged domain accounts saved on them so staff can scan to a shared drive or email. An attacker who gets in with the default login can use those accounts to move out of the printer and compromise the wider domain.
UC Berkeley’s information security team notes that many printers ship with insecure, unnecessary protocols switched on, such as Telnet, HTTP and FTP. Its guidance also says printers should not be reachable from the public internet. A SANS Institute paper on multifunction devices makes a similar point: treat them like servers, and disable the network services you do not use.
The network vendor AIS points out that many multifunction printers keep images of the documents they scan or print. The U.S. EPA’s media sanitization fact sheet lists imaging equipment, including printers, copiers, scanners, fax machines and multifunction devices, among the equipment to consider when data must be removed, and it points readers to NIST SP 800–88 for detailed guidance.
Printer security is not only about the printer itself. In July 2021, CISA issued an emergency directive about “PrintNightmare” (CVE-2021–34527), a flaw in the Windows Print Spooler service that CISA said was being exploited by multiple threat actors. Federal agencies were told to install the patches and to disable the service on Active Directory domain controllers. The University of Chicago’s security team advised disabling the spooler wherever printing is not needed. The lesson for any office is to keep the PCs and servers that handle printing patched too.
Among the mitigations in the NSA and CISA advisory is to remove default credentials and harden configurations. On a printer, that means opening its settings page and replacing the factory administrator login with a strong, unique password before anything else.
Open the scan-to-folder and scan-to-email settings and check which accounts are stored there. Because the advisory warns about privileged domain accounts on printers and scanners, avoid saving any account that has more access than scanning needs.
Switch off old protocols and services your office does not need. Berkeley’s guidance singles out Telnet, HTTP and FTP as common defaults, and the SANS paper recommends disabling unused print, fax, scan and management services.
Berkeley advises that printers should not be exposed to the public internet. AIS describes network segmentation as one of the most effective protections: if a multifunction printer is compromised, a dedicated VLAN stops attackers from moving sideways across the network. A report from the IT firm DDL Business Systems adds that CISA has specifically recommended VLANs to separate printers. The SANS paper also suggests limiting access to particular ports.
Berkeley’s guidance says printers and multifunction devices need updates and patches like computers, and that firmware checks belong in your regular patch schedule. AIS adds that routine firmware review reduces the risk of network attacks on printers and cites NIST on the importance of patch management for network-connected devices. Download updates only from the manufacturer’s own support page.
AIS recommends requiring a PIN, badge, mobile authentication or network login before documents print or the device is used. It also recommends placing multifunction printers in monitored areas, restricting access to devices kept in server rooms, and requiring authorization before anyone removes a hard drive.
AIS says end-of-life devices should follow a documented wipe procedure, and that for leased machines you should confirm the data destruction policy at the end of the contract. Guidance on ISO 27001 from Presencis explains that NIST SP 800–88 defines three levels of sanitization (Clear, Purge and Destroy) and warns that simply stating a drive was formatted is not enough. A compliance guide from Accountable HQ describes a wipe attestation as a signed statement that specific media were sanitized to a defined NIST 800–88 category, with a certificate of destruction when a drive is physically destroyed. Ask for both when a printer is returned, resold or recycled.
DDL Business Systems notes that NIST includes printers, copiers, scanners and multifunction devices in its guidance on information handled by “replication devices,” and that the Center for Internet Security publishes security configuration benchmarks for multifunction print devices. Larger offices can use these as a formal checklist.
A security guide from ABM Colorado says the first step is containment: unplug the device if you can, or isolate it from the network if the business cannot do without it. Berkeley also asks its staff to report unexpected printouts, such as spam or offensive material, to IT as soon as possible so the printer can be secured.
If you outsource printer management, these questions follow from the sources above:
How and how often do you apply firmware updates?
Do you support PIN, badge or mobile release printing?
What happens to the storage in a printer when it leaves my office?
Will you provide a wipe attestation or a certificate of destruction?
Who do I call, and how quickly, if I suspect a problem?
Change the printer’s default administrator password.
Check the manufacturer’s support page for a firmware update.
Turn off protocols and services you do not use.
Review the accounts saved in scan-to-folder and scan-to-email settings.
Check the output tray at the end of the day, and note a date to repeat this checklist.
You do not need to be a security expert to protect an office printer. You need to treat it like the networked computer it is: change its login, remove what it does not need, keep it updated and separate from your main systems, control who can use it, and wipe it before it leaves. If you would rather not do this alone, a printer support specialist can audit your devices and apply these settings for you.