Skip to main content

The Office Printer Security Checklist for NZ Businesses

Adi goldstein E Us Vw E Osbl E unsplash

The Office Printer Security Checklist for NZ Businesses

The short answer: an office printer should be secured like any other device connected to your business network.

Modern printers and multifunction devices can process documents, store settings and data, connect to email or cloud services, and provide remote administration tools. Printer security should therefore cover passwords, user access, network configuration, firmware, document handling, monitoring and secure disposal.

For New Zealand businesses, this is also a privacy issue. Information Privacy Principle 5 requires organisations to take reasonable steps to protect personal information against loss, misuse, unauthorised access and unauthorised disclosure. Read the Office of the Privacy Commissioner’s Principle 5 guidance.

Office printer security checklist

Use this checklist with the person responsible for IT, your privacy officer and your printer service provider.

Device ownership and inventory

  • Record every printer, scanner, copier and multifunction device.
  • Document its make, model, serial number, location and IP address.
  • Record its firmware version, warranty and support status.
  • Identify who owns responsibility for each device.
  • Include printers in the organisation’s asset register.
  • Remove or replace unsupported end-of-life devices.

Accounts and access

  • Change all default administrator passwords.
  • Use a long, strong and unique administrator passphrase.
  • Do not share administrator credentials among general users.
  • Remove or disable unused accounts.
  • Restrict administration access to authorised people and networks.
  • Enable multi-factor authentication where the device or management platform supports it.
  • Review administrator access regularly.

Firmware and configuration

  • Install current manufacturer-approved firmware.
  • Establish a regular patch and firmware-review process.
  • Disable unnecessary ports, services and connection methods.
  • Use encrypted administration and printing protocols where supported.
  • Back up an approved secure configuration.
  • Review security settings after servicing, replacement or factory resets.

Network protection

  • Confirm that the printer is not exposed directly to the public internet.
  • Place printers in an appropriate network segment or VLAN where practical.
  • Use firewall rules to restrict unnecessary communication.
  • Limit printer access to approved devices and users.
  • Secure wireless printing and disable unused wireless functions.
  • Monitor unusual network and administrative activity.

Documents and stored information

  • Enable PIN, card or identity-based secure print release where appropriate.
  • Configure automatic deletion of stored print jobs.
  • Encrypt device storage where supported.
  • Restrict scanning destinations and address-book changes.
  • Remove abandoned documents from output trays.
  • Position printers away from uncontrolled public areas.
  • Use secure document-destruction processes for unwanted pages.

Remote management and support

  • Document who can access printers remotely.
  • Restrict remote access to approved support channels.
  • Use time-limited or explicitly authorised support access where possible.
  • Record significant remote configuration changes.
  • Review the security and privacy terms of cloud-management services.
  • Remove obsolete vendor and technician accounts.

Disposal and lease returns

  • Remove stored print, scan and fax data.
  • Remove address books, email settings and stored credentials.
  • Securely erase internal storage using the manufacturer-approved process.
  • Remove the device from monitoring and management platforms.
  • Remove network certificates and configuration information.
  • Obtain evidence of sanitisation or destruction where risk justifies it.
  • Never assume a factory reset has removed every type of stored data.

Why can an office printer be a security risk?

A modern multifunction printer is more than an output device. Depending on its features and configuration, it may:

  • Receive documents from computers and mobile devices
  • Scan documents to email, folders or cloud platforms
  • Store print jobs temporarily or permanently
  • Retain user details and address books
  • Connect to multiple internal systems
  • Support remote administration
  • Accept USB or wireless connections
  • Maintain activity logs
  • Contain internal memory or storage media

This creates several possible security risks.

An attacker could target an unpatched or poorly configured device as an entry point into the business network. An unauthorised user might access stored documents or change scan destinations. Sensitive pages could be left in an output tray. Data could remain on a device when it is sold, returned or recycled.

The New Zealand National Cyber Security Centre recommends managing devices throughout their complete lifecycle: purchase, maintenance and decommissioning. Its guidance specifically includes printers and scanners in organisational asset management. See NCSC asset lifecycle guidance.

1. Identify every printer and assign responsibility

You cannot secure equipment you do not know exists.

Create an inventory covering:

  • Networked printers
  • Multifunction devices
  • Desktop and USB printers
  • Wide-format printers
  • Scanners
  • Label printers
  • Devices at satellite offices
  • Spare and temporarily stored equipment

Record who is responsible for firmware, configuration, access reviews, servicing and eventual disposal. Depending on the organisation, responsibility may sit with internal IT, an external IT provider, the office manager or a managed print provider.

Avoid having security tasks divided between suppliers without clear ownership. For example, a printer provider may maintain firmware while an IT provider manages the network and user identities. The responsibilities should be documented so nothing falls between them.

2. Change default passwords and restrict administrator access

Default and weak administrator credentials are among the most avoidable device-security risks.

Every printer should have a unique administrator password or passphrase. Do not use the same administrator password across the fleet, particularly if it is also used for routers, switches or other business systems.

Apply these controls:

  • Replace manufacturer-default credentials before normal use.
  • Use long, strong and unique passwords.
  • Store credentials in an approved password manager.
  • Restrict access to authorised administrators.
  • Disable unused default accounts.
  • Avoid sharing administrator credentials by email or in unprotected documents.
  • Review access after staff or suppliers change.

The NCSC’s asset-hardening guidance recommends removing or updating default accounts and passwords before new assets are used. It also recommends disabling unused services and updating software to the latest supported release. See NCSC asset-hardening guidance.

Where supported, use multi-factor authentication for cloud-based printer-management systems and sensitive administrative accounts.

3. Keep printer firmware up to date

Printer firmware is software. Like software on a laptop or server, it can contain vulnerabilities that manufacturers address through updates.

Establish a repeatable process to:

  1. Record the current firmware version.
  2. Check for manufacturer security notices.
  3. Assess available updates.
  4. Test material changes where appropriate.
  5. Install approved firmware.
  6. Confirm the printer still operates securely after the update.
  7. Record the result.

Do not assume firmware is being maintained merely because the printer is under a service contract. Confirm whether firmware reviews and security updates are included and who is responsible for approving them.

The NCSC describes patching as one of the simplest and most effective security steps, noting that attackers commonly exploit known vulnerabilities in software that has not been updated. Read the NCSC’s patching guidance.

A device that no longer receives security updates should be assessed for replacement, isolation or additional controls.

4. Disable services and features you do not use

Printers are often installed with more connection options than a business needs.

Depending on the model, these might include:

  • Wireless Direct or ad hoc wireless printing
  • Bluetooth
  • Fax
  • FTP
  • USB storage
  • Cloud connectors
  • Remote administration
  • Mobile printing
  • Legacy network protocols
  • Embedded web services

Each enabled service expands the number of ways the device can communicate.

Work with your IT and printer providers to disable unnecessary functions. Where a service is required, configure it securely and restrict who can use it.

Avoid disabling services without understanding operational dependencies. Scan-to-folder, print management and remote monitoring may rely on specific settings. The objective is to reduce unnecessary exposure without interrupting legitimate workflows.

5. Protect printers at the network level

A printer should not normally be exposed directly to the public internet.

Network controls can limit which users, systems and services can communicate with it. Depending on the size and complexity of the organisation, controls may include:

  • A dedicated printer network or VLAN
  • Firewall rules
  • Approved print servers
  • Restricted administrator access
  • Encrypted protocols
  • Controlled wireless access
  • Logging and alerting

Network segmentation can make it more difficult for an attacker to move between a compromised device and higher-value systems. The NCSC recommends understanding every device on the network, hardening network devices and configuring appropriate separation, access control and logging. See NCSC network segmentation guidance.

Segmentation should be designed by someone who understands the organisation’s network. A poorly planned change can disrupt printing, scanning, monitoring and user authentication.

6. Use secure print release for sensitive documents

Secure print release holds a job until the authorised user authenticates at the device, typically with a PIN, card or account.

This reduces the risk of documents being:

  • Collected by the wrong person
  • Left unattended
  • Sent to the wrong shared printer
  • Viewed in an uncontrolled area
  • Reprinted unnecessarily

Secure release can be particularly valuable for:

  • Payroll and human resources
  • Legal documents
  • Customer records
  • Financial information
  • Health information
  • Contracts and commercially sensitive material

Authentication should be simple enough that employees consistently use it. If the process is slow or unreliable, people may develop workarounds that weaken the control.

Also configure stored jobs to expire after an appropriate period. A secure queue should not become an indefinite document archive.

7. Secure scanning and address books

Scanning can create greater information risk than printing because it sends documents from the physical environment into email, folders, cloud systems and business applications.

Review:

  • Who can add or change scan destinations
  • Whether employees can scan to personal email addresses
  • Whether address-book changes are logged
  • How scan-to-email accounts are authenticated
  • Whether stored credentials are protected
  • Which cloud services receive scanned information
  • Whether old destinations remain active
  • Whether scans are encrypted in transit

Remove obsolete email addresses, folders and user accounts promptly.

If scanned personal information is sent to a third-party cloud or document service, confirm who is responsible for that information and what privacy and contractual protections apply.

8. Protect the physical device and printed pages

Technical security does not prevent someone from picking up a sensitive document from the output tray.

Position devices according to the information they process. A printer used for payroll, customer records or legal documents may not belong in a reception area or publicly accessible corridor.

Practical controls include:

  • Secure print release
  • Controlled physical access
  • Regular clearing of output trays
  • Locked paper-storage areas where necessary
  • Shredding or secure destruction bins
  • Staff procedures for misdirected documents
  • Avoiding sensitive print jobs when no one is present to collect them

Staff should know how to report a document printed to the wrong device or collected by the wrong person.

9. Control remote monitoring and technician access

Remote monitoring can improve printer reliability and security by supporting automated meter readings, consumable ordering, maintenance alerts and updates.

It must still be governed appropriately.

Confirm:

  • Which organisation provides the service
  • What information the monitoring platform collects
  • Where that information is processed
  • Which people and accounts can access the platform
  • Whether multi-factor authentication is available
  • How remote support sessions are authorised
  • Whether access and changes are logged
  • How supplier access is removed

KMBE’s real-time fleet monitoring can support maintenance, consumable supply and remote device management. Security responsibilities should be agreed between KMBE, the customer and the customer’s IT provider.

10. Monitor printer activity

Logging can help detect and investigate misuse, but logs are only useful if someone reviews them.

Depending on the device and management platform, useful information may include:

  • Administrator logins
  • Configuration changes
  • Failed authentication attempts
  • Firmware updates
  • Scan destinations
  • Unusual print volumes
  • New user accounts
  • Device errors
  • Remote support access

Decide which events matter, how long logs should be retained and who reviews them.

Logs may themselves contain personal or commercially sensitive information. Protect them with appropriate access controls and do not retain them longer than required.

11. Include printer security in purchasing decisions

Security is easier to manage when it is considered before equipment is purchased or leased.

Ask prospective suppliers whether a device supports:

  • Unique administrator credentials
  • User authentication
  • Secure print release
  • Storage encryption
  • Secure erase
  • Signed or verified firmware
  • Encrypted printing and scanning
  • Certificate management
  • Network access restrictions
  • Activity logging
  • Automatic job deletion
  • Supported firmware updates
  • Secure remote management

Also ask how long the manufacturer expects to provide firmware and security support.

The cheapest device may not be the lowest-risk or lowest-cost option if it requires manual workarounds, cannot integrate with existing identity systems or becomes unsupported during the planned lease term.

12. Securely erase devices before disposal or return

Many businesses carefully erase laptops and phones but return leased printers without checking their storage.

Before a printer leaves your control:

  • Cancel queued and stored jobs.
  • Remove address books and user records.
  • Delete stored email and folder credentials.
  • Remove certificates and network settings.
  • Disconnect the device from cloud and monitoring platforms.
  • Use the manufacturer’s approved storage-erasure process.
  • Confirm whether internal drives or storage modules require separate handling.
  • Record who completed the process and when.
  • Request written evidence where the sensitivity of the information justifies it.

A factory reset may remove settings without securely sanitising every type of internal storage. Confirm the process for the particular make and model.

This requirement should be included in lease-return, resale, recycling and equipment-disposal procedures.

13. Prepare for a printer-related security incident

Printer incidents should be included in the organisation’s cyber security and privacy response plans.

Possible incidents include:

  • A sensitive document collected by the wrong person
  • A scan sent to an incorrect recipient
  • Unauthorised access to the printer’s administrator interface
  • A compromised scan-to-email account
  • Missing or stolen equipment
  • Discovery of an unpatched vulnerability
  • Loss of data during disposal or lease return
  • Unexpected configuration or address-book changes

The immediate response may include isolating the device, preserving logs, disabling accounts, changing credentials, contacting IT support and assessing which information was affected.

If a privacy breach has caused or may cause serious harm, a New Zealand business must notify the Office of the Privacy Commissioner and affected people unless an exception applies. Notification should happen as soon as practicable; the Commissioner’s guidance says businesses should ideally notify within 72 hours of becoming aware of a notifiable breach. See the Privacy Commissioner’s NotifyUs guidance.

This article provides general security and privacy information, not legal advice. Obtain specialist advice for your organisation’s systems, risks and regulatory obligations.

Warning signs that a printer needs immediate attention

Prioritise a review if:

  • The administrator password is still the manufacturer default.
  • No one knows when firmware was last updated.
  • The device is accessible from the public internet.
  • Remote administration is enabled without restrictions.
  • The manufacturer no longer supports the model.
  • Sensitive documents are regularly left in output trays.
  • All users share the same account or PIN.
  • Scan destinations have not been reviewed.
  • The device is missing from the IT asset register.
  • There is no process for securely erasing returned equipment.
  • Former employees or suppliers may still have access.
  • The business cannot identify who owns printer security.

Frequently asked questions

Can an office printer be hacked?

Yes. A network-connected printer can contain software, accounts, communication services and administrative tools. Weak passwords, outdated firmware or unnecessary internet exposure can increase its risk of compromise.

Do office printers store copies of documents?

Many multifunction devices temporarily or permanently store print, scan or fax data, depending on their hardware and configuration. Check the specifications and storage settings of the particular model.

What is secure print release?

Secure print release holds a document until the authorised user authenticates at the printer. It helps prevent confidential pages from being collected by someone else or left unattended.

Should printers be placed on a separate network?

Network segmentation may improve security by limiting communication between printers and other systems. Whether a separate network or VLAN is appropriate depends on the organisation’s technical environment and should be assessed by its IT or security provider.

How often should printer passwords be changed?

Default credentials should be changed before the device enters normal use. Passwords should also be changed after suspected compromise, inappropriate disclosure or supplier and staff access changes. Follow the organisation’s credential policy rather than changing strong passwords on an arbitrary schedule.

What should happen before a leased printer is returned?

Stored jobs, address books, credentials, certificates and network settings should be removed. Internal storage should be sanitised using the manufacturer-approved process, and completion should be documented.

Who is responsible for printer security?

Responsibility is usually shared between the business, its IT provider and its printer service provider. The organisation should document exactly who handles accounts, networks, firmware, monitoring, incident response and disposal.

Review your printer fleet

Printer security starts with knowing which devices are connected, how they are configured and what information they process.

KMBE can help review device capabilities, firmware, fleet monitoring and printer-management requirements. Your IT or cybersecurity provider should remain involved in network architecture, identity controls and wider security monitoring.

Talk to KMBE about your business printer fleet.

Back to Insights & Guides
image title

Request consultation

Simply enter your details along with a message and we will be in touch.