TL;DR:
- 6 in 10 small businesses have experienced a print-related data breach — usually from outdated firmware, default passwords, or documents left in output trays
- Modern office printers are networked computers with internal storage, web interfaces, and processing power; they need the same security attention as your other computers
- The fixes are straightforward: change default passwords, enable encryption, set up regular firmware updates, and control who can print what
If you asked most small business owners to list their biggest cybersecurity risks, they’d say phishing emails, weak passwords, or ransomware. Printers wouldn’t make the list. That’s the problem.
Research published in 2026 found that 67% of organisations have experienced print-related data loss. A separate study from HP found that only 26% of business owners feel confident their printing infrastructure is secure. And among SMBs, 60% reported at least one printer-related breach in the past twelve months.
The attacks aren’t sophisticated. They exploit the fact that office printers are treated as furniture — set up once, forgotten, never patched.
What Makes Printers a Real Security Risk
Modern office printers are not what they were in 2005. A typical multifunction device today is a networked computer. It runs a web server (for remote management), stores documents in internal memory or hard drive storage, can receive print jobs from the internet, and has an operating system that receives security vulnerabilities like any other software.
Several specific risks:
Stored documents: Most office printers queue print jobs internally. Many have hard drives that retain document data even after the job has printed. When that printer is sold, disposed of, or stolen, those stored documents go with it — complete patient records, client contracts, financial statements, whatever passed through it.
Default credentials: Printers ship with default usernames and passwords for their web management interfaces. The HP default is often admin/admin or blank. Brother devices commonly have admin with no password. Canon uses canon or ACCESS. These defaults are documented publicly. A criminal on your network — or anyone who can reach the printer’s web interface — can access configuration, download stored documents, and redirect print jobs.
Unpatched firmware: Printer firmware receives security updates just like PC operating systems, but nobody has told most small business owners this. A printer purchased in 2021 and never updated may be running firmware with vulnerabilities that have been publicly known for years. HP disclosed new printer vulnerabilities affecting millions of devices in May 2026, but most of those devices will never receive the patch because their owners don’t know it exists.
Network access: A printer on your network can be used as a pivot point by an attacker who’s gained access to it. Printers typically have no detection or prevention capabilities — they don’t notice unusual outbound connections or port scans the way a modern endpoint security tool would. This makes them attractive as persistent access points after an initial breach.
Public print queues: In offices with shared printers, sensitive documents sit in the output tray waiting to be collected. If staff are slow to retrieve documents, anyone who passes by can read — or photograph — them.
The Quick Wins: What to Do First
These take less than an hour and eliminate the most common attack vectors:
Change the default password. Find your printer’s web interface by typing its IP address into a browser (check your router’s device list if you don’t know it). Log in and change the admin password to something strong and unique. Record it in your business password manager. This single step closes the most commonly exploited vulnerability.
Check for and apply firmware updates. Go to your printer manufacturer’s support site, find your model, and download the latest firmware. Most modern printers can also be configured to check for updates automatically. Do this now, then set a quarterly reminder to check again.
Enable PIN-release printing. Almost all modern office printers support “pull printing” or “secure print” — jobs are held until the person who sent them authenticates at the printer using a PIN or badge. This prevents sensitive documents sitting uncollected in the output tray. It takes about 15 minutes to configure on most devices.
Disable remote printing from the internet. Printers that accept print jobs directly from the internet (via TCP port 9100 or the IPP protocol) can receive malicious print payloads from anywhere. Unless you have a specific business need for internet-facing printing, disable it on your router and in the printer’s network settings.
The Medium-Term Work: Slightly More Involved
Enable storage encryption. Many business printers offer hard drive encryption for stored documents. On HP printers, look for “High Performance Secure Hard Disk” settings. On Canon, look for “HDD Data Encryption.” This protects stored documents if the printer is physically stolen or disposed of.
Wipe before disposal. When you’re getting rid of a printer, perform a factory reset and storage wipe before it leaves your premises. Many manufacturer support sites have instructions for this. If the printer predates proper wipe functionality, remove the hard drive before disposal.
Network segmentation. Ideally, printers should sit on a separate network VLAN from your main business systems. This limits what an attacker can reach if they compromise the printer. If you have a managed switch and a technically capable person, this is an afternoon’s work. If not, it’s worth asking your IT support provider about.
Audit who can do what. Business printers support user accounts with different permission levels. Do all staff need to be able to scan to external email, or just their own? Do all staff need to be able to access the document management storage? Restricting capabilities to what people actually need reduces the blast radius if credentials are compromised.
The GDPR Angle
If your business handles personal data about clients, employees, or customers — which it almost certainly does — your printer is within scope of GDPR. A printer that stores client documents without adequate security controls is a potential data protection liability. If stored data is accessed by an unauthorised person, that’s a reportable breach with obligations to notify the ICO and potentially the individuals affected.
The ICO has issued enforcement notices related to inadequate physical controls over printed documents, and guidance makes clear that GDPR applies to printed personal data as well as digital.
The practical implication: if your business is audited for GDPR compliance, “we never patched the printer” or “it used the default password” are the kinds of control failures that create regulatory risk.
What to Watch Out For in 2026
Printer-focused malware is increasingly real. Security researchers demonstrated a technique in 2025 that uses a printer as a pivot point to extract credentials from a Windows domain — the printer’s managed status on the domain gives it access that a guest device wouldn’t have. This isn’t yet a common attack against small businesses, but as awareness of the printer security gap spreads among defenders, it will spread among attackers too.
Remote work has also extended the attack surface. Employees printing from home office printers — particularly consumer-grade devices with minimal security features — creates exposure that corporate IT controls don’t reach. If your staff regularly print sensitive documents at home, it’s worth including home printer security in your security guidance alongside the standard advice about home WiFi and VPNs.
The Five Things to Do This Week
- Find every printer and multifunction device on your network
- Change the admin password on each one
- Check for firmware updates and apply them
- Enable secure/PIN-release printing for sensitive print jobs
- Configure automatic firmware updates where available
None of these require specialist technical knowledge. They take an afternoon. They close the most common attack vectors that have contributed to the majority of print-related breaches reported in 2026. Your printer isn’t just an office appliance — it’s a networked device that needs the same basic security hygiene as everything else.