HP Wolf Security has issued a stark warning about the overlooked cyber risks of modern printers, as it publishes new global research revealing widespread gaps in platform security.
The report, Securing the Print Estate: A Proactive Lifecycle Approach to Cyber Resilience, draws on the experiences of more than 800 IT and security decision-makers (ITSDMs) worldwide. It highlights systemic failings across the full lifecycle of enterprise printing hardware -from supplier selection to decommissioning.
Despite the growing sophistication and connectivity of office printers, the study reveals that organisations are routinely failing to secure them.
One of the most alarming findings comes from the “Ongoing Management” phase: only 36% of ITSDMs say they apply firmware updates promptly, even though IT teams spend an average of 3.5 hours per printer each month addressing hardware and firmware security issues.
This failure to patch devices quickly leaves systems exposed to risks such as data exfiltration and device hijacking.
Security lapses begin even earlier in the lifecycle.
During the Supplier Selection and Onboarding phase, fewer than four in ten ITSDMs say procurement, IT, and security teams collaborate to define printer security standards.
Most respondents reported gaps in due diligence: 42% do not involve IT or security in vendor presentations, over half fail to request technical documentation to back up vendor security claims, and 55% do not submit vendor responses for security team review.
Once devices arrive, more than half of respondents admit they cannot confirm whether printers have been tampered with during manufacture or transit.
In the Remediation phase, many organisations continue to struggle with basic security hygiene. Just 35% of ITSDMs say they can identify vulnerable printers based on newly disclosed hardware or firmware vulnerabilities. Even fewer – 34% – are able to track unauthorised hardware changes, while only 32% can detect security events tied to hardware-level attacks.
Concerns are not limited to digital threats: 70% of respondents say they are increasingly worried about physical risks such as employees printing and mishandling sensitive data.
The security challenges don’t end when a printer reaches the end of its useful life. During the Decommissioning and Second Life phase, 86% of ITSDMs say data security concerns prevent them from reusing, reselling, or recycling printers – leaving a significant number of devices in limbo.
On average, respondents report having around 80 printers either redundant or awaiting decommissioning. Confidence in sanitisation methods is low, with over a third unsure if devices can be securely wiped. One in four believe storage drives must be physically destroyed, and one in ten go further – demanding the destruction of the entire printer.
“Printers are no longer just harmless office fixtures – they’re smart, connected devices storing sensitive data,” said Steve Inch, global senior print security strategist at HP Inc.
“With multi-year refresh cycles, unsecured printers create long-term vulnerabilities. If compromised, attackers can harvest confidential information for extortion or sale. The wrong choice can leave organisations blind to firmware attacks, tampering or intrusions, effectively laying out the welcome mat for attackers to access the wider network.”
To help organisations respond, HP’s report offers a set of recommendations for securing printers throughout their lifecycle.
Recommended reading
- Darcula Phishing Scam Claims 800K+ Victims
- How Worried Are Brits About AI-Fuelled Phishing?
- Data Breaches, Phishing Attempts, and Scams Surge in Q1 2025
These include ensuring close collaboration between IT, security, and procurement teams; demanding security certifications for both products and supply chains, applying firmware updates promptly, using tools to enforce policy compliance, and deploying printers capable of detecting and containing advanced threats.
HP also urges businesses to select devices that support secure erasure of hardware, firmware, and stored data – allowing safe reuse or disposal.
“By considering security at each stage of a printer’s lifecycle, organisations will not only improve the security and resilience of their endpoint infrastructure, but also benefit from better reliability, performance, and cost-efficiency over the lifetime of their fleets,” said Boris Balacheff, chief technologist for Security Research and Innovation at HP.





