Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Printer and Copier Security for Small Business

The office MFD is a networked computer with a hard drive, a web admin page and a stored email password — and almost nobody secures it. Here's what to check.

When a business writes down its computers — for an insurance form, an asset list, a Cyber Essentials assessment — the printer never makes the list. It’s furniture. It sits in the corner, it hums, someone puts paper in it.

It is, in fact, a computer. It runs an operating system. It has a network address, a web administration interface, storage inside it, and usually a saved copy of at least one mailbox password. It talks to your file server. It has probably never been updated. And unlike your laptops, nobody has ever logged into it to check.

Here’s what’s actually wrong with the average small-office multifunction device, in the order worth fixing.

The admin password is still “admin”

Nearly every multifunction device ships with a default administrator login, printed in the manual and available to anyone who types the model number into a search engine. On most machines in most offices, it’s still set.

Anyone on your network can reach that page. So can anyone on the guest Wi-Fi, if visitors and staff share one network — a good reason to separate the two properly. And if the device has ever been given a public IP address or a forwarded port so somebody could print from home, it’s reachable from the whole internet. Automated scanners sweep the entire address space continuously. Anything exposed is found, and found fast.

Change the admin password. Store it in the business password manager, not on a sticky note under the tray.

It keeps what you scan

Devices with an internal drive write jobs to it as they work. Scans, print spools, stored jobs, fax images. Depending on the model and its settings, those files can sit there long after the job is done — invoices, signed contracts, HR letters, passport copies for right-to-work checks, client paperwork.

Two things follow. Look in the device’s security settings for overwrite, encryption or “delete after job” options and switch them on. Then remember the drive exists when the machine leaves.

The end of the lease is the dangerous moment

Copiers are usually leased. At the end of the term, a van arrives and the machine goes back — to be refurbished, resold, or broken for parts, often abroad. The drive goes with it, along with whatever’s on it.

Before collection, get it in writing that the drive will be securely wiped or removed, and ask for confirmation once it’s done. Better still, negotiate at the point of signing the lease that you keep the drive and pay for a replacement. It’s a small cost, and it turns a data protection problem into a non-event. This is squarely within what GDPR expects of a small business: personal data shouldn’t leave your control on hardware you no longer own.

Scan-to-email is a password on display

Scan-to-email needs credentials to send through your mail system. In a lot of offices someone configured it years ago using a real staff mailbox, real password, typed into the printer’s web page.

That password is now sitting in a device with a default admin login. Anyone who opens the admin page has a working mail account for your business — enough to send invoices from a genuine internal address, which is precisely how invoice fraud gets convincing.

The fix is to stop using a person’s account. Use a dedicated send-only account or an authenticated relay set up for the device, restricted to sending only, with no access to anything else. Getting this configured correctly is a normal part of a proper printer and MFD setup, and it’s the sort of thing that gets skipped when a machine is installed in a hurry by whoever delivered it.

Scan-to-folder with far too much access

The same story again, with worse consequences. Scan-to-folder needs an account that can write to a network share. Someone in a rush uses a domain administrator account, or a general staff account with access to everything, because that definitely works.

Now the printer holds credentials to your whole file server. Create a dedicated account instead, with write access to exactly one scans folder and nothing else. If someone extracts those credentials, all they’ve won is the ability to drop files into a folder.

The tray is the simplest breach there is

No hacking required. Someone prints a salary review, gets distracted, and it sits face-up in the tray until whoever prints next picks it up with their own document. Where the printer sits in a corridor or a reception area, visitors walk past it all day.

Secure printing — also called pull printing — holds each job until the sender enters a PIN or taps a card at the device. Most business MFDs support it already, and it cuts waste as well, because nobody collects the four accidental copies of a 60-page document. If you run several devices, a managed approach to print and copier management turns this on across all of them at once.

Firmware nobody applies

Printer manufacturers publish security updates that fix genuine remote flaws. Almost nobody installs them, because it means taking the office printer offline for ten minutes and there’s never a good moment.

Enable automatic firmware updates if the device supports it, or diarise a check twice a year. If the manufacturer has stopped issuing updates for your model, that’s a real argument for replacing it, not just a nag.

The fax line and the disposal pile

Plenty of MFDs still have a phone line attached, used once in 2019. If nothing uses fax, disconnect it — an unused line is an unmonitored route into the device. If you do still fax, incoming faxes may be stored as images on that same internal drive.

When a device is finally scrapped, treat it like a retired server. Drive removed or wiped, confirmation in writing, a record of where it went.

The checklist

Work through these in order. None needs deep technical skill.

  1. Log into every printer’s admin page. If the default password still works, change it now and record the new one properly.
  2. Confirm the printer isn’t reachable from outside. No port forwarding, no public IP. Printing from home should go through your normal remote access, not a hole in the firewall.
  3. Put printers on the staff network only — never on the network you hand to visitors.
  4. Check the scan-to-email account. If it’s a real person’s mailbox, replace it with a dedicated send-only account.
  5. Check the scan-to-folder account. Cut its access down to one folder.
  6. Turn on the security settings — drive overwrite or encryption, if your model offers them.
  7. Enable PIN release for anything printed near a shared space.
  8. Check for firmware updates, and set a reminder to look again in six months.
  9. Disconnect the fax line if nothing uses it.
  10. Write the end-of-lease question into your calendar for three months before the term ends, so the drive conversation happens before the van arrives.

Most of that is an afternoon’s work, once. If you’d rather it were handled alongside the rest of your defences, it fits naturally into ongoing cyber security support — because the machine in the corner is on your network whether you count it or not.

Frequently asked questions

Does an office copier really keep copies of what I scan?

Most multifunction devices with an internal drive do, at least temporarily. Scans, prints and stored jobs get written to the drive so the machine can queue, reprint and finish jobs, and on many models those files linger until the space is needed. Some devices offer overwrite or encryption settings that reduce what's left behind. Check your model's manual for "data security" or "hard disk overwrite" options and turn them on — they're rarely enabled by default.

What should I ask the leasing company before a copier goes back?

Ask three things in writing. Will the drive be securely wiped or physically removed before the machine leaves your premises or is refurbished? Will they provide written confirmation once it's done? And can you keep the drive instead, paying for a replacement if needed? A reputable supplier will answer all three without fuss. If the answer is vague, treat the machine as unwiped and insist before it's collected.

Is secure or pull printing worth it for a small team?

If your printer sits anywhere shared — a corridor, a reception area, a room clients walk through — then yes. Pull printing holds the job until the person who sent it authenticates at the device, so payslips and client letters never sit face-up in the tray waiting to be read or picked up by mistake. Most business MFDs already support it with a PIN, which costs nothing beyond ten minutes of setup.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.