When UK IT leaders map their attack surface, laptops, mobiles and cloud accounts get the attention. The multifunction device in the corner of the office rarely does. Yet a modern printer is a networked computer with storage, an operating system, an embedded web server and a direct line to some of the most sensitive documents your organisation produces. In a hybrid workplace, where devices sit in offices, branch sites and spare bedrooms alike, that blind spot has widened considerably.
Why print became an endpoint problem
Three things changed at once. Print volumes decentralised as staff split their week between home and office. Consumer-grade devices appeared on corporate networks through VPNs and personal Wi-Fi. And attackers grew more interested in lateral movement β using an overlooked device as a quiet foothold rather than a target in itself.
The result is a category of risk that is easy to describe and easy to fix, but frequently left unowned because print sits between facilities, procurement and IT.
The five risks worth auditing first
- Documents left in the tray. Still the most common breach vector in print. Payroll, patient notes and board papers sitting unattended need no technical skill to exploit.
- Default administrator credentials. A surprising proportion of fleet devices are still reachable on their factory password, exposing address books and configuration.
- Unencrypted traffic. Jobs sent in the clear across a flat network can be intercepted, as can scan-to-email traffic without TLS.
- Retained data at rest. Devices with internal storage may hold job images long after printing β a genuine issue at end of lease or disposal.
- Unpatched firmware. Printers are rarely in the patch cycle, so known vulnerabilities can persist for years.
A layered approach that works
Print security does not require a separate security programme. It requires that print is folded into the one you already run. In practice that means four layers.
- Device layer β change default credentials, disable unused protocols and ports, enable secure boot and signed firmware, and bring devices into your patch schedule.
- Network layer β place print on its own VLAN, enforce IPsec or TLS for job and management traffic, and restrict administration to known subnets.
- Document layer β deploy secure pull printing so jobs release only on card or PIN authentication at the device, and enable encrypted scan destinations.
- Governance layer β log and audit who printed what and when, apply retention rules, and confirm secure data wipe at end of life.
Hybrid working specifics
Home and branch devices need slightly different thinking. Cloud print management removes the need to expose print servers or open inbound firewall rules, letting remote staff print securely without a VPN hairpin. Where home devices are unavoidable, restrict them to non-sensitive output and route confidential documents to a secure office queue for collection. Above all, give people a compliant route that is easier than the workaround β security that obstructs work is security that gets bypassed.
Compliance is the other half of the argument
Under UK GDPR, a printed document containing personal data is processing like any other. Regulators expect appropriate technical and organisational measures across the whole lifecycle, including output and disposal. Pull printing, audit logs and secure wipe are not just good hygiene; they are evidence of accountability if you are ever asked to demonstrate it.
Where to start this quarter
Run a discovery scan to find every networked printing device, including the ones purchased outside IT. Change credentials and disable unused services on all of them. Enable pull printing for HR, finance, legal and clinical teams first. Then add firmware to your regular patch cycle and set a review date. Brother builds enterprise-grade security controls into its business devices and management tools as standard, and our UK team is at your side to help you close the gap.