{"id":71312,"date":"2025-09-08T07:36:13","date_gmt":"2025-09-07T23:36:13","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=71312"},"modified":"2025-08-24T16:40:38","modified_gmt":"2025-08-24T08:40:38","slug":"only-36-of-it-teams-apply-printer-firmware-updates-promptly-leaving-devices-vulnerable","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/09\/08\/only-36-of-it-teams-apply-printer-firmware-updates-promptly-leaving-devices-vulnerable\/","title":{"rendered":"Only 36% of IT teams apply printer firmware updates promptly, leaving devices vulnerable"},"content":{"rendered":"<p><strong>HP Wolf Security released a new report \u2013 Securing the Print Estate: A Proactive Lifecycle Approach to Cyber Resilience &#8211; highlighting the challenges of securing printer hardware and firmware (platform security), and the implications of these failures across every stage of the printer\u2019s lifecycle. Based on a global study of 800+ IT and security decision-makers (ITSDMs)1 , the findings show that platform security is being overlooked, leaving concerning security gaps.<\/strong><\/p>\n<p>Exploring four lifecycle stages, the report reveals that during the Ongoing Management stage, just 36% of ITSDMs apply firmware updates promptly. This is despite IT teams spending 3.5 hours per printer per month managing hardware and firmware security issues. Failure to promptly apply firmware updates to printers unnecessarily exposes organizations to threats that could lead to damaging impacts, such as cybercriminals exfiltrating critical data or hijacking devices.<\/p>\n<p>Further security gaps revealed across the other stages of the printer\u2019s lifecycle include:<\/p>\n<p><strong>Supplier Selection &#038; Onboarding stage:<\/strong><\/p>\n<p>Lack of procurement collaboration: Only 38% of ITSDMs say procurement, IT, and security collaborate to define printer security standards \u2013 with 60% warning that this lack of collaboration puts their organization at risk.<\/p>\n<p>RFPs going unchecked: 42% of ITSDMs fail to involve IT\/security teams in vendor presentations; 54% fail to request technical documentation to validate security claims; and 55% fail to submit vendor responses to security teams for review.<\/p>\n<p>Inability to verify the printer\u2019s integrity: Once the printer arrives more than half (51%) of ITSDMs cannot confirm if the printer has been tampered with in the factory or in transit.<\/p>\n<p><strong>Remediation stage:<\/strong><\/p>\n<p>Inability to detect and remediate threats:  Many organizations are struggling to keep on top of patching devices. Only 35% of ITSDMs are able to identify vulnerable printers based on newly published hardware or firmware vulnerabilities, not to mention zero-day threats that are unknown to the vendor or the public.  Only 34% can track unauthorized hardware changes made by users or support teams, and only 32% of ITSDMs can detect security events linked to hardware-level attacks.<\/p>\n<p>Not just cyber \u2013 print risks are physical too: 70% of ITSDMs are increasingly worried about offline threats, such as employees printing and mishandling sensitive company information.<\/p>\n<p><strong>Decommissioning and Second Life stage:<\/strong><\/p>\n<p>End of life risk: 86% of ITSDMs say data security is a barrier to printer reuse, resale or recycling \u2013 a big problem, given that on average ITSDMs report having approximately 80 printers that are redundant or are in the process of being decommissioned within their organizations.<br \/>\nLack of confidence: ITSDMs lack confidence in current sanitization solutions, with 35% saying they are uncertain whether printers can be fully and safely wiped. Meanwhile, 1-in-4 believe it\u2019s necessary to physically destroy printer storage drives, and 1-in-10 insist on destroying both the device and its storage drives to ensure data security.<\/p>\n<p>\u201cPrinters are no longer just harmless office fixtures \u2013 they\u2019re smart, connected devices storing sensitive data,\u201d warns Steve Inch, Global Senior Print Security Strategist at HP Inc. \u201cWith multi-year refresh cycles, unsecured printers create long-term vulnerabilities. If compromised, attackers can harvest confidential information for extortion or sale. The wrong choice can leave organizations blind to firmware attacks, tampering or intrusions, effectively laying out the welcome mat for attackers to access the wider network.\u201d<\/p>\n<p>The report offers recommendations on how to address these security challenges across the printer\u2019s lifecycle, including:<\/p>\n<li>Ensure IT, security and procurement teams collaborate effectively to define security and resilience requirements for new printers.<\/li>\n<li>Require and leverage manufacturer provider security certificates for products and \/ or for supply chain processes.<\/li>\n<li>Apply firmware updates promptly to minimize exposure to security threats.<\/li>\n<li>Leverage security tools to streamline printer policy-based configuration compliance.<\/li>\n<li>Deploy printers that can continuously monitor for zero-day threats and malware with the ability to prevent, detect, isolate and recover from low-level attacks.<\/li>\n<li>Select printers with built-in secure erasure of hardware, firmware and stored device data to enable safe second life and recycling. <\/li>\n<p>\u201cBy considering security at each stage of a printer\u2019s lifecycle, organizations will not only improve the security and resilience of their endpoint infrastructure, but also benefit from better reliability, performance, and cost-efficiency over the lifetime of their fleets,\u201d comments Boris Balacheff, Chief Technologist for Security Research and Innovation at HP Inc.<\/p>\n<p>For further insights and recommendations, download the full report \u201cSecuring the Print Estate: A Proactive Lifecycle Approach to Cyber Resilience\u201d <a href=\"https:\/\/www.hp.com\/content\/dam\/sites\/garage-press\/press\/press-kits\/2025\/hp-wolf-security-study-reveals-gaps-in-print-security-leaving-devices-vulnerable-to-risk\/Print%20Lifecycle%20Short%20Report.pdf\" target=\"_blank\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Exploring four lifecycle stages, the report reveals that during the Ongoing Management stage, just 36% of ITSDMs apply firmware updates promptly. This is despite IT teams spending 3.5 hours per printer per month managing hardware and firmware security issues.<\/p>\n","protected":false},"author":6,"featured_media":71313,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,18],"tags":[51,307,96],"class_list":["post-71312","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-white-papers","tag-hp","tag-printer","tag-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/71312","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=71312"}],"version-history":[{"count":2,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/71312\/revisions"}],"predecessor-version":[{"id":71316,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/71312\/revisions\/71316"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/71313"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=71312"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=71312"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=71312"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}