Benoit Charnallet from TSC Auto ID Technology explains why your networked devices might leave you at risk of a cyber attack.

Over half (51%) of organisations such as manufacturers and retailers, predict their operational technology (OT) environments will be targeted by cyber attacks.

As cyber threats become ever more frequent and advanced, it’s vital that cybersecurity strategies include all networked devices, including thermal printers and enterprise mobile computers (EMCs). A global mobile threat report revealed that 50% of mobile devices are running outdated operating systems, creating significant vulnerabilities.

Today’s organisations, from small manufacturers to global operators and public bodies, rely on vast networks of connections to operate. While this is undoubtedly essential, such connections also present potential entry points for hackers to access, breach, or disrupt enterprise systems.

Among such entry points are thermal printers. While they’re becoming more integrated into enterprise networks and support critical functions like shipping, product marking and compliance labelling, they’re often overlooked in cybersecurity planning, even though their connection to critical systems makes them vulnerable if unprotected.

Media outlet, Cybernews, did an experiment to determine how many unsecured printers it could potentially hack. Its results made for sober reading. Through readily available IoT search engines, the publication hijacked nearly 28,000 unprotected printers, amounting to a 56% success rate.

Cyber breaches dominated UK headlines in 2025, crippling manufacturers, retailers and others. The risk of threats is escalating, and attackers are said to be using advanced technologies to target weaknesses faster than organisations can protect themselves. Unsecured printers and EMCs pose a significant risk, so are a vulnerability you cannot afford to ignore.

Recognise your printers as potential attack surfaces

As thermal printers become increasingly embedded within enterprise networks, they face similar threats as any connected device. Understanding these risks is the first step in mitigating them. When evaluating thermal printer security, take a structured approach that addresses both technical vulnerabilities and organisational requirements. Key vulnerabilities to consider include:

Unauthorised access: printers with open network ports or unsecured web interfaces can be exploited

Data interception: print jobs containing sensitive data such as shipping labels may be intercepted

Malware infiltration: printers can be used as a bridge to deploy malware into broader enterprise systems.

Align printer security with industry models and standards

Organise your security measures methodically and effectively around key cybersecurity principles, frameworks, and regulations. These include the CIA Triad, a foundational model in information security emphasising three core principles: confidentiality, integrity and availability.

Another is the NIST Cybersecurity Framework. It provides a comprehensive, structured lifecycle for managing cybersecurity risks across five key functions: Identity, Protect, Detect, Respond, Recover.

In 2024, Gartner reported that 63% of global organisations had implemented a zero-trust strategy, another model that assumes no device or user is inherently trusted, regardless of location inside or outside enterprise networks. Every access request must be verified, making zero-trust especially applicable to networked printers operating on the edge of security perimeters.

As regards other regulations, there’s governmental ones like the EU’s Radio Equipment Directive (RED) for devices with wireless communication functions, including printers equipped with Wi-Fi, Bluetooth, or RFID.

Using printers with embedded security features

By understanding potential vulnerabilities and security frameworks, and by fully leveraging security capabilities built into printers like those from TSC Auto ID, you can mitigate risks and protect your operations without sacrificing efficiency.

TSC devices come equipped with many security capabilities, including firmware authentication, TLS/SSL encryption, and remote management tools. TSC also maintains a dedicated vulnerability disclosure program to report and resolve security issues. It offers a secure channel for customers and partners to report vulnerabilities. Such a proactive approach helps maintain transparency, minimises risk exposure, and supports responsible disclosure best practices, all critical elements for enterprise trust.

A proactive stance on mobile device security

If you’re looking to protect mobile devices like enterprise smartphones, tablets and specialised mobile computers, it can be achieved by implementing robust mobile security best practices from providers such as Bluebird, a TSC Auto ID company.

Protecting devices and sensitive data is vital for ensuring seamless workflows and driving strong business performance. Bluebird actively mitigates security risks and vulnerabilities by integrating multiple layers of protection into its devices and solutions. Every component of its offerings is meticulously crafted to defend against common security threats like malware, phishing, cryptographic failures, and insecure design, all without compromising essential productivity or accessibility.

As businesses become increasingly interconnected, their networks and valuable data are more susceptible to unauthorised access and various security vulnerabilities. Bluebird addresses these risks by adhering to foundational cybersecurity principles and implementing a defence-in-depth approach throughout its architecture and design processes. Through its smart, highly configurable technology, Bluebird empowers organisations to achieve an optimal balance between critical operational objectives and robust security postures.

Learning from vulnerabilities

Bluebird continuously analyses mobile device vulnerabilities, from historical attacks to recent discoveries. This drives its commitment to develop smarter, more resilient security solutions, specifically engineered to tackle today’s complex mobile computing security challenges.

Whenever a new vulnerability is identified, Bluebird swiftly prepares and deploys a patch, informed by a rigorous classification system based on the Common Vulnerabilities and Exposures (CVE) list, which is diligently managed by the National Vulnerability Database. Each vulnerability/threat is assigned a severity level, ranging from 0.1 (low) to 10 (critical) according to the Common Vulnerability Scoring System (CVSS), which details essential actions businesses must take for protection.

Bluebird also monitors the Open Web Application Security Project (OWASP), which provides annual insights and reports on top mobile vulnerabilities. Bluebird’s devices undergo extensive security testing phases, including rigorous internal security assessments (static and dynamic code analysis) as well as independent third-party penetration testing. This external testing ensures its security controls are robust, as pen testers simulate real-world hacker attempts to bypass various layers of protection.

Development of its devices strictly adhere to a corporate-mandated Software Development Lifecycle (SDLC). This ensures all Bluebird’s software is designed and tested following stringent security guidelines embedded within its SDLC. The strict implementation of the principle of least privilege, as well as robust Application Programming Interface (API) controls, prevents unauthorised users from accessing devices. Thorough end-to-end application testing consistently enhances security.

Bluebird diligently tracks Android™ vulnerabilities and threats by monitoring CVE and OWASP. It collaborates with vendors, leveraging its expertise to provide appropriate patches, ensuring all mobile devices are protected against low and critical threats. It ensures every critical mobile vulnerability is thoroughly analysed, including hardware and software.

Elevated trust

A key mechanism used to protect cryptographic operations and sensitive material is a Trusted Execution Environment (TEE). This environment operates in isolation from a device’s Rich Execution Environment (REE), where main operating systems and applications reside. Within the TEE, code executes with a high level of trust, as its environment is completely isolated from the rest of the system. Any threats detected in REE cannot impact TEE and, even if the REE is compromised, data within the TEE remains secure.

Bluebird adds another layer of security to organisations’ TEEs, integrating features like its BOS™ Kiosk / Enterprise Launcher. For example, its enterprise launcher allows administrators to control which users have access to specific environments, ensuring sensitive or confidential data remains secure. By consistently following TEE best practices, which are integrated into all recently produced Bluebird devices, TEEs are robustly protected against new and emerging security threats.

Building pillars of security

As cyber threats become more frequent and more complex, a people, process and technology (PPT) framework can also help you structure your thermal printer and EMC security.

  • Cybersecurity
  • Digital Strategy

We believe in a personal approach

By working closely with our customers at every step of the way we ensure that we capture the dedication, enthusiasm and passion which has driven change within their organisations and inspire others with motivational real-life stories.