Multifunction printers are networked computers with paper trays. They may run an operating system and expose an embedded web server.

Old firmware, exposed management ports, and unused services create printer security risks and expand the device’s attack surface. That makes printer hardening an IT responsibility, not a facilities afterthought. Physical security still matters because documents, storage, and control panels may be accessible to people near the device.

Start by knowing what is connected, then apply a tested baseline to each model. The aim is simple: staff can print and scan without giving every device broad network access.

Key Takeaways

  • Maintain an accurate inventory with a named owner for every printer, including its firmware, connections, storage, scan routes, and exposed interfaces.
  • Place printers on a restricted VLAN with firewall rules and ACLs that allow only approved traffic, management paths, and scan destinations.
  • Replace default credentials, keep firmware current through staged testing, use HTTPS, IPPS, and SNMPv3 where supported, and disable unused services and interfaces.
  • Protect sensitive documents with secure print release, encryption, automatic data cleanup, controlled scan permissions, and appropriate physical security.
  • Treat unexpected accounts, settings, print jobs, or network connections as possible compromise indicators and follow a documented containment and recovery process.

Network printer security starts with visibility

A proper baseline begins with an inventory and a named owner. Do not assume two printers with similar names have the same controller, firmware branch, or security features.

Record every device and connection

Create a register for every printer and MFP. Include its model, serial number, physical location, IP and MAC addresses, firmware version, network name, print queue, and responsible owner.

Also capture storage type, scan destinations, cloud connectors, local address books, and active protocols. Record relevant physical security controls, including placement, access to the device, and exposed USB or wireless interfaces. Note whether it supports automatic data cleanup, identify any unused services, and record whether jobs travel through a print server, cloud print management, or directly to the device.

Where managed print services are used, record the provider as the named owner or custodian, along with its support responsibilities. Check the manufacturer administration manual for the exact setting names and supported features. A basic desktop printer may not offer encrypted storage, secure release, or remote log export, so test the proposed configuration on one representative device before changing settings.

Lock down management accounts

Replace the default administrator credentials during commissioning, before the printer joins a production network, not during a later review. Give every device a long, unique password and store it in an approved password vault.

The NCSC’s authentication guidance recommends credentials that are user-defined or unique to the device after setup. Shared admin passwords turn one compromised printer into a fleet-wide problem.

Restrict HTTPS remote access from approved IT workstations or a management subnet to the printer’s embedded web server and administrative panel. Use role-based accounts where the device supports them, and add multi factor authentication to the identity provider, VPN, or jump host used for administration.

Put printers in a restricted network zone

Network segmentation places printers on a separate VLAN, which is a logical network segment. However, a VLAN only helps when firewall rules and access control lists, or ACLs, restrict what can cross into it.

Review that network segmentation boundary after every firewall or VLAN change. Confirm that only approved flows still cross it.

Allow only named traffic paths

Place printers on a dedicated printer VLAN. Document approved traffic and management network protocols, then allow connections only between known systems. In most offices, that means the print server, authorised management workstations, monitoring service, DNS, NTP, and approved scan destinations.

For example, an MFP that scans invoices to a finance share needs access to that service. It doesn’t need unrestricted access to staff laptops or every server in the organisation.

Block printer-to-printer traffic unless there is a documented reason for it. Also block outbound internet access by default, then allow only required vendor update or cloud service endpoints.

A separate printer subnet with broad any-to-any access is only a different address range. Firewall rules create the security boundary.

A zero trust architecture grants access through device identity and explicit traffic rules. An office network location doesn’t grant permission.

Replace legacy protocols and unused services with protected options

Use HTTPS for the embedded web server and IPPS, Internet Printing Protocol over TLS, for print submission where supported. For monitoring, configure SNMPv3 with authentication and privacy settings.

Disable unused services such as Telnet, FTP, HTTP, SNMPv1, SNMPv2c, and LPD. Raw port 9100 printing may still be required by older software, but restrict it to the print server and plan a migration where possible.

The NCSC’s device interface controls support the same approach: know which interfaces are exposed and disable those that aren’t required. Feature availability differs by model, so verify every change against the vendor documentation.

Manage printer firmware updates in stages

Printer firmware updates can include security patches for known network vulnerabilities, including published CVEs, alongside reliability fixes. Leaving a device on an old release gives attackers more time to find and exploit known weaknesses.

Build a patch process that preserves service

Subscribe to each manufacturer’s security advisory and firmware notification service. Match every advisory to the exact model, hardware revision, and installed firmware branch in your inventory.

Back up the approved configuration before updating, including certificates, address books, network settings, and print queues where possible. Then test the firmware on a non-production or low-risk device before wider deployment.

Confirm that printing, scanning, authentication, document release, and monitoring still work after the update. Check that unused services remain disabled and automatic data cleanup settings haven’t reset. Schedule the rollout during a maintenance window and keep a rollback plan where the manufacturer supports one.

The NCSC’s secure update principles are a useful benchmark. Only apply firmware obtained through the manufacturer’s approved channel, and check release notes before installation.

Scan carefully and monitor changes

Treat printers as fragile embedded devices during vulnerability scanning. Use conservative scan rates, approved templates, and non-destructive checks. Test the scanner against one device first, especially if the fleet contains older models.

Avoid excessive scans, password spraying, fuzzing, and mass print jobs. These can cause a denial of service by crashing a printer, filling queues, or disrupting a busy office without proving much about its security.

Review printer logs, firewall logs, and print queue alerts for unknown administrator logins, new scan destinations, changed DNS settings, or unusual outbound connections. Central log collection is useful, although many lower-cost models have limited logging options.

Protect documents in the tray and on the disk

A well-configured network still cannot protect a confidential document left on an output tray. Print security needs to cover the job, the person collecting it, and data stored inside the device.

Use secure print release for sensitive jobs

Secure print release holds a job in a queue until the user authenticates at the printer. Users might enter a PIN, tap an access card, or confirm through an approved mobile app.

Apply release controls to HR, finance, healthcare, legal, and customer records containing sensitive data. Set jobs to expire after a sensible period, and align retention and deletion settings with applicable compliance regulations.

This is also a physical security control because it prevents unauthorised collection from the output tray. It reduces accidental collection of the wrong document at shared printers. The HP guidance on holding and authenticating print jobs describes the same hold-and-authenticate approach.

Secure stored jobs and scan routes

Enable disk encryption, automatic data cleanup for completed jobs and scan caches, and secure erase functions where the model supports them.

Check that automatic data cleanup covers temporary files, cached jobs, and address-book exports. The NCSC’s data protection principles call for data encryption to protect scanned files and print jobs both at rest and in transit. This complements local storage controls rather than replacing them.

Review scan connectors closely. Use TLS for email where available, and give service accounts only the permissions they need. Remove retired file shares and former staff from address books.

Before disposing of, returning, or redeploying a printer, use physical security to restrict access to the device and its storage. Wipe the storage using the vendor’s documented process, then document and test the automatic data cleanup interval before it leaves the organisation.

Turn controls into a repeatable routine

Effective printer security best practices rely on consistent checks, not a one-off commissioning exercise. Keep the baseline short enough for review after firmware changes, office moves, and new device purchases.

  • Maintain an accurate printer inventory with an owner for every device.
  • Replace default administrator credentials and remove default SNMP community strings.
  • Keep firmware current through a tested, documented update process.
  • Place devices on a printer VLAN with restrictive ACLs and firewall rules.
  • Prefer HTTPS, IPPS, and SNMPv3 where the printer supports them.
  • Disable unused services, protocols, wireless radios, and physical interfaces.
  • Use secure print release for documents that contain sensitive information.
  • Enable encryption and automatic data cleanup for local job storage.
  • Review scan-to-email, cloud, and file-share permissions regularly.
  • Check physical security around output trays, exposed ports, and device storage.
  • Retain logs and test the incident response process for a compromised device. Confirm automatic data cleanup removes stored jobs during the test.

Set clear boundaries with managed print services

Managed print services can help maintain asset records, configuration standards, firmware schedules, and support escalation. The managed print services agreement should state who approves patches and holds administrator credentials. It should assign responsibility for log retention, reviewing or disabling unused services, configuring automatic data cleanup, and incident response.

Your organisation still needs ownership of access decisions and sensitive data. A provider can manage the fleet, but they should not become an untracked permanent administrator across every device.

Respond quickly to suspected printer compromise

Unexpected admin accounts, changed scan settings, strange print jobs, repeated restarts, or unusual outbound connections are warning signs. Treat the printer as a potential security incident until the team can rule it out.

Contain the device and preserve evidence

Remove the affected printer from the network or place it in a quarantine VLAN. Keep it powered on where safe, as an immediate factory reset can remove useful evidence.

Record the time, serial number, IP address, observed behaviour, active firmware version, and recent configuration changes. Export device logs and collect relevant firewall, printing service, identity, and email logs before making major changes.

Tell the internal security contact and the managed print services team, if applicable. Reset exposed credentials after evidence collection, then check whether the admin account, scan credentials, or certificate store changed.

Recover with a known-good configuration

Rebuild the printer with approved firmware and a documented baseline. Remove unused services during the rebuild. A factory reset may be appropriate, but only after the team has preserved the evidence it needs.

Issue new administrator passwords, certificates, and service-account credentials. Confirm automatic data cleanup is enabled, then test printing, scanning, document release, logging, and VLAN rules before returning the printer to production.

Review which systems and documents the printer could access. If sensitive data may have been exposed, follow the organisation’s incident process and assess its obligations under UK GDPR and other compliance regulations.

Frequently Asked Questions

Why do networked printers need security controls?

Networked printers are embedded computers that may run an operating system, store documents, and expose management interfaces. Weak credentials, outdated firmware, and unnecessary network access can allow attackers to use them as an entry point into the organisation.

How should printers be isolated from the rest of the network?

Place printers on a dedicated VLAN and use firewall rules or ACLs to permit only required connections, such as those from the print server, approved administrators, monitoring systems, and scan destinations. Block printer-to-printer traffic and outbound internet access unless there is a documented business requirement.

Which printer protocols should be enabled or disabled?

Use HTTPS for administration, IPPS for printing, and SNMPv3 for monitoring where the device supports them. Disable unused or insecure services such as Telnet, FTP, HTTP, SNMPv1, SNMPv2c, and LPD, while restricting legacy raw port 9100 printing to the print server when it is still required.

How can confidential documents be protected at shared printers?

Use secure print release so a job is held until the user authenticates at the device with a PIN, access card, or approved application. Also enable storage encryption and automatic cleanup, protect scan destinations with TLS and least-privilege accounts, and secure output trays and exposed ports.

What should we do if a printer may be compromised?

Quarantine the printer or remove it from the network, preserve logs and relevant firewall, identity, print, and email records, and notify the appropriate security and managed print teams. Rebuild it with approved firmware and a known-good baseline, issue new credentials and certificates, and test its controls before returning it to production.

A safer print environment

Printers deserve the same care as any other connected endpoint, with clear ownership, restricted access, current firmware, protected documents, and a plan for responding to suspected incidents.

Network printer security works best when it becomes part of normal IT operations. A printer should have a clear owner, a limited purpose, and no unnecessary route into the rest of the business.