Eleanor Milner
Marketing Assistant
August 12, 2020
With data being termed by many analysts as “The New Oil”, security and governance are more important than it has ever been, especially when organisations are under increasing pressure to adhere to regulation and legislation.
So why do so many overlook an area that leaves their network and their data vulnerable?
Not us we hear you say. However, when DTP conducted the most basic security assessment for some businesses and presented back our findings, many have been staggered by what we found.
So, what is the technology hiding in plain view on your network? Would it surprise you to hear that it is your network attached printers and MFDS?
If we were to ask an organisation if they have a firewall protecting their security perimeter, they would probably say yes. If we were to ask if they have two factor authentication and anti-virus and malware protection on their client devices, the answer again would most likely be yes. And if we were to ask if these devices were kept up to date in terms of firmware revisions, the answer would again be yes.
Modern MFDs are essentially network PCs that print, copy and scan. They have hard disk drives, keyboards, LCD control panels and they are attached to your network.
They also have firmware and software: printers and MFDs have built-in operating systems, run executables, have DLLs, and run common protocols. What’s more, they are connected to the Internet and can be used to send emails.
With today’s printers and MFDs being a fully functioning client device on the network, they require the same degree of protection, management, updates and monitoring as your PCs.
Why are organisations continuing to overlook this potential hole in their security? We believe it is a combination of things:
We believe that the first step on any journey to best practice is understanding your current position.
In terms of supporting you on this journey, the starting point with DTP is a consultative assessment – whether that be a very simple questionnaire with a DTP Print Security Consultant as a low-cost activity, or a more detailed one to three day piece of consulting – the outputs will give you detailed insights and recommendations to help you meet various compliance requirements (including GDPR).
This service includes a face to face meeting with a DTP Print Security Consultant who will work with you to answer online questions to provide a basic overview of potential risks and recommendations. This service is vendor agnostic however if you are a HP user, then as part of this service we are also able to analyse a subset of your devices to determine their vulnerability. If they are not properly configured, devices can be a point of entry for a breach, allowing hackers access to the network. Settings such as Admin (EWS) Password, FTP, Telnet, Novell and USB Ports are often overlooked and it’s critical to close the opening before hackers ever get in.
DTP performs this Quick Assess review on up to 50 of your devices against 15 essential security settings that we believe should be addressed on all printers and MFDs. At the end of the assessment, we provide you with a status report to view the risks to help you to determine what action needs to be taken to maintain compliance.
This one day on-site security assessment is carried out by an experienced Print Security Consultant and provides a baseline indication of print security risk and compliance (up to 30 security controls).
The output is a report with recommendations on how to reduce risk and improve compliance and includes a hands on demonstration on how to check covered controls. This service is tailored to smaller to medium organisations, typically where an organisation’s IT team is responsible for security.
This three day on-site assessment is carried out by an experienced Print Security Consultant and provides an in-depth assessment of security risk and regulatory compliance. As with option 2, the output is a detailed report with recommendations on how to reduce risk and improve compliance. This service is tailored to enterprise-sized organisations and those within highly regulated industries with CISO or dedicated security teams.
After taking advantage of one of our print security consulting services, clients can then work with DTP Consultants to scope and implement one of a range of solutions and services that we offer. Such as, on-site print security policies, management and remediation software tools or the implementation of DTP’s new DTP’s Print Security as a Service (PrSaaS).
1. Protect your devices and workflow with fleet-wide firmware and certificate management
Our team are experts in managing printers and MFD firmware. DTP ensure the latest safe firmware version is installed and we work alongside the respective vendor to develop patches to fix the issues. Certificates are vital in protecting the flow of information to and from your devices. However, manually installing them can be error-prone and time-consuming process. Our innovative technology solution streamlines this process by deploying unique identity certificates across your fleet.
2. Reduce risk with comprehensive security fleet reporting
As part of the service, we provide detailed monthly reporting of the fleet covered, including details of any alerts during the month; their severity, and escalations, along with our observations and any recommendations.
3. Minimise the investment needed in time and money
Through conducting assessments, our Print Security Consultants will help devise a tailored plan to meet your industry requirements. Delivering as-a-Service and billed on a pay-as-you-use basis reducing any capital outlay.
4. Automate policy enforcement and escalation
Once deployed, the policies are automatically policed. For example, if a setting on a device changes, the solution alerts the DTP Print Security Monitoring Centre and automatically changes the setting back to the agreed policy.
Printer and MFD Security can be daunting and we understand that it is a process, not a quick fix. So talk to DTP about how we can help you on your journey to compliance-get in touch for more information or to book an initial discussion with one of our Print Security Specialists.
CONTACT US