This Cyber Action Year, Let's Not Overlook the Print Fleet - Konica Minolta

This Cyber Action Year, Let’s Not Overlook the Print Fleet

As organisations put real work into cyber resilience this year, the print fleet is one part of the estate that’s easy to leave off the list, and simple to bring back onto it.

There’s a lot of good cyber work happening across Australian organisations right now; endpoints hardened, identity tightened, cloud environments secured. It’s exactly the kind of momentum Cyber Action Year is meant to build. While that work is underway, there’s one part of the estate worth making sure we include: the print fleet.

Konica Minolta Australia and New Zealand’s research with global analyst firm Omdia, a survey of 400 senior IT decision-makers across Australia and New Zealand, found that 56 per cent of Australian organisations experienced a print-related security incident in the past 12 months. Not because those organisations aren’t investing in security; most are, heavily. It’s that print has tended to sit outside the governance frameworks applied to everything else.

That’s worth a closer look this year in particular. The Australian Signals Directorate has reframed Cyber Security Awareness Month as the inaugural Cyber Action Year, built around a single shift in mindset: assume breach. Plan for if, not when, and build to withstand a compromise. It’s a useful lens to hold up to the print fleet, because it’s precisely the kind of device an assume-breach plan tends to overlook.

A printer is a computer that happens to print

It’s easy to forget, but modern print devices are networked computers. They have a processor, an operating system, local storage and a web-based admin console. They hold credentials: the service accounts it uses to scan to email, drop files into SharePoint, or authenticate against your directory. They talk to the internet and to the rest of your network. In other words, it has everything an attacker needs, and, as the research bears out, almost none of the scrutiny the rest of your fleet gets.

Walk the attacker’s path

Assume the breach has already happened. A phishing email landed, a credential was reused, and someone is now inside your network looking for a way to move, escalate and take something valuable. Where do they go?

The unmanaged print fleet is close to an ideal waypoint. It’s rarely segmented, so a device sharing a flat network with your finance systems offers a path sideways. It’s rarely monitored, so activity on it doesn’t trip an alert the way it would on a server. It’s quietly useful, stored service-account credentials can be lifted and reused elsewhere, the device’s own memory may hold cached copies of everything recently scanned or printed and a printer that can reach both the internal network and the outside world makes a discreet channel for moving data out.

The research points to where the soft spots already are. Home and remote printing is now the leading print security vulnerability across both markets, a direct consequence of hybrid work. Inconsistent authentication is the biggest governance gap in Australia; patchy secure-release printing is the biggest in New Zealand. Each is a door an attacker who’s already inside would be glad to find open.

From awareness to action

The Australian Signals Directorate’s framing this year is deliberate – awareness alone isn’t enough. The market seems to agree, 72 per cent of Australian organisations told us they expect to increase print security investment over the coming year. The value is in spending that intent well.

Here’s a practical set of actions that brings the print fleet up to the standard you already hold the rest of your environment to. They map cleanly onto the Essential Eight thinking most Australian organisations already work from.

  1. Segment the fleet – Put print devices on their own VLAN, away from sensitive systems, and restrict what they’re allowed to talk to. A compromised printer should be a dead end, not a corridor.
  2. Take back admin access – Change every default credential, still the single most common finding on any print fleet and restrict administrative access to the device consoles. Treat printer admin rights the way you treat any other privileged access.
  3. Fix authentication and release – Apply consistent authentication across every site and enable secure-release printing so jobs only print when the right person is at the device. It’s the gap the research flags most often, and one of the easiest to close.
  4. Watch them – Feed device logs into the same monitoring you use everywhere else and make sure your incident response playbook names print devices as something to check.
  5. Close the lifecycle – A device’s storage can hold data long after the job is done. When a printer is retired, redeployed or returned at end of lease, its drive needs to be securely wiped, not left to walk out the door with years of scanned documents on it.

The question worth asking

Assume-breach just means asking the same fair question of every device on the network, including the ones that quietly do their job in the corner – what happens if an attacker reaches this one? The print fleet is a good candidate to add to that list this year, and one of the more straightforward wins once it’s on there.

The full findings are in our research report with Omdia, The Security Mandate: Protecting Modern Print. And when you’re ready to bring the fleet up to the standard you hold the rest of your environment to, bizhub SECURE hardens the devices to recommended settings. It’s the same attention to configuration behind our bizhub i-Series firmware earning Keypoint Intelligence’s independent Security Validation Seal for Device Penetration, and a straightforward way to make sure the print fleet isn’t the blind spot in the plan.

You may also be interested in