DocuCrunch.com » Are these 5 mistakes compromising your printer’s security?

Are these 5 mistakes compromising your printer’s security?

August 11, 2009 by Sam Narisi
Posted in: Security, Special Report

print-secure

MFPs are constantly getting smarter and more “computer-like” — which makes them more vulnerable to the security risks that affect other devices.

With networked MFPs, security breaches are possible at every step of the printing process — on the user’s computer, on the server, between the server and the printer, and on the printer itself.

Last but not least, there’s a low-tech risk that’s been around as long as shared printers: a co-worker or other passer-by taking someone else’s pages out of the printer’s output tray.

That problem’s apparently widespread — 56% of employees have seen sensitive documents left in the printer unattended, according to a recent survey by Samsung Electronics.

Here are five common mistakes businesses make that compromise printer security:

  1. Printing off an unsecured disk If your device prints off its own disk, you can probably set it to erase the disk after every job (sometimes you need to buy add-on software from your vendor). Alternatively, some printers let you bypass the hard disk and print straight from RAM (which is more secure but takes longer). Finally, you can buy a model without a hard disk — that’s an option you may not even need.
  2. Not requiring authentication where it’s needed – A common mistake of setting up shared printers is treating every department the same — even though some deal with more sensitive documents than others. Though it may be too big a hassle in some places, for departments that regularly print confidential documents, consider getting a printer that requires a user to enter a password into the machine before it prints. Some models also use swipe cards, or even biometric fingerprint readers.
  3. Keeping the reprint option – Some printer models let users hit a button that prints another copy of the previous job. Obviously you don’t want that capability when someone’s printing a secure document.
  4. Ignoring virus protection – Printers and MFPs usually get the least attention when it comes to viruses, but there’s still malware out there than can take control of a printer or steal the documents being sent to the device. One way to reduce risk: Get a model with a proprietary operating system.
  5. Failing to train users – Like any security issues, the risks associated with MFPs contain a significant human element. It’s important for employees who regularly print sensitive docs to be aware of the risks and know what they can do to minimize problems.
  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , ,


5 Responses to “Are these 5 mistakes compromising your printer’s security?”

  1. printer cartridge supplies Says:

    This is really one of the informative posts I’ve read. Honestly, I am guilty since I’ve made the above mistakes sometimes that’s why it’s not surprising if I keep on having problems when printing my projects and documents.

  2. Twitted by cactusandivy Says:

    [...] This post was Twitted by cactusandivy [...]

  3. Justin Bailey Says:

    The problems with security are even wider than the story suggests. eCopy commissioned original research earlier this year and found that the vast majority of organisations are still unnecessarily photocopying documents containing sensitive data, increasing the risk of lost information and identity fraud.

    The research found that seven in ten (70%) organisations frequently make paper copies of original documentation containing personal and sensitive information, including letters/correspondence (50%), financial (47%), identification (34%) and legal (30%) documents. One quarter (25%) are failing to securely dispose of documents, with an alarming 22% recycling them without shredding, leaving sensitive and personal data freely accessible to fraudsters – while 3% just throw paper copies into the bin.

    The best solution to capture and protect sensitive data is to introduce it into a secure electronic workflow directly from the input device, either a scanner or an MFP, from where the user can select authentication options that enhance security and accountability, thereby protecting and controlling who gets to view, edit or print the scanned document. In this way organisations can minimise potential failures in following business processes by enabling Intelligent Document Routing and enforce better compliance through comprehensive audit trails.

  4. Paula Says:

    Recently our company had a hard drive replaced on a MFP. While setting up the user mailboxes on the MFP we noticed it had saved scanned data still on it from another organization (it was a used hard drive in which we were aware.) We believe it was an honest mistake, we immediately deleted these documents and notified our vendor how important it is to check these things when dealing with used hardware.

  5. IBM Hunter Says:

    This might be a weird question, but I am a vegan, so am looking for printer toner that do not contain any animal suffering. I understand that a lot of compatible toner cartridges contain either ingredients that have been tried out on rabbits, or are made with animal products. Are there any toners that are completely artificial?


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement