The computers you forgot you own: printers, cameras and the quiet ways attackers get in
Your printers, CCTV cameras and door controllers are computers — usually unpatched, unmonitored and on the same network as everything you care about. How attackers use them, and how to close the gap.
Ask a business owner how many computers they have and they'll count laptops and servers. They're usually off by double. The printers, cameras, door controllers and meeting-room screens are computers too — and they're the ones nobody patches, nobody monitors, and attackers love most.
In one widely reported case, attackers reached a casino's high-roller database through an internet-connected thermometer in the lobby aquarium. It sounds like a joke, and it's actually the modern playbook: don't attack the systems the business protects — attack the ones it forgot were computers at all. The Mirai botnet, which knocked major websites offline, was built almost entirely from compromised security cameras and home routers still running their factory passwords. Your office is full of this category of device, and most of it was set up by whoever installed it, on whatever settings it shipped with, and never touched again.
Take the tour your attacker would take
Walk your office and count the things with a network cable or a Wi-Fi connection that aren't someone's computer:
Printers and multifunction copiers
they run a full operating system, store copies of scanned documents, hold email credentials for scan-to-email, and are famously left on default admin passwords.
CCTV cameras and recorders
internet-reachable by design (that's how the app on your phone works), and a favourite way in when they're old, unpatched or still set to admin/admin.
Door controllers and alarm panels
the physical security system is itself a networked computer; a compromised one is both a cyber problem and an unlocked door.
Meeting-room screens, smart TVs, video-conference gear
network-connected, rarely updated, and often sitting on the same network as your file server.
The long tail
HVAC controllers, time-clock terminals, label printers, that "temporary" 4G router someone installed in 2023.
None of these will ever appear in a laptop count. Every one of them has an IP address, which makes every one of them a possible way in — or a place to hide once in.
Why attackers go for the boring devices
Because the economics are beautiful, from their side. A laptop gets security updates monthly, runs endpoint protection, and its user might notice something odd. A camera or printer gets none of that: firmware nobody has ever updated, a password printed in the manual that's on Google, no security software (none can be installed), and no human watching its behaviour. Best of all, these devices are switched on at 3am and nobody finds their network traffic suspicious — a camera talks to the internet constantly by design. For an attacker, a forgotten device is a free foothold: a place to get in, and a quiet place to stay while they map everything else.
The question that finds the gap: "what has an IP address?"
This is where the fix starts, and it's the same discipline we wrote about in our early-intel post: you can't defend what you haven't counted. Our vulnerability scanning deliberately covers any device with an IP address — not just servers and workstations — precisely because this is where the surprises live. It's common for a first scan to turn up devices the business didn't know were on the network at all, still wearing default credentials, running firmware years out of date, or reachable from the internet when they never needed to be.
Closing the gap: five moves, in order
1. Inventory.
Get the full list of everything with an IP address. A scan does this in hours; guessing does it never.
2. Kill default passwords.
Every device gets a unique, strong admin password — the manual's password is public information.
3. Update or isolate.
Firmware current where the vendor still ships updates; where a device is too old to update, it gets fenced off, not forgiven.
4. Segment the network.
Cameras, printers and building systems belong on their own network zone, so a compromised camera can see other cameras — not your file server. This is the single highest-value change for most offices.
5. Watch the odd ones out.
Our 24/7 SOC watches for the tell-tale behaviour — a printer suddenly talking to an overseas server is not printing.
Why we're unusually opinionated about this
Key IT sits on both sides of this problem, which is rare. We run managed cybersecurity — and we also design and install CCTV, access control and alarm systems ourselves. That means the cameras and door controllers we install are treated as what they are: computers, deployed with proper credentials, current firmware, sensible network placement and ongoing support — not bolted on by a security installer who considers the network someone else's problem. One team accountable for the physical and digital layers means nobody gets to say "not my department" about the device that let the attacker in.
Frequently asked questions
Our cameras were installed years ago by another company. Are they a risk?
Quite possibly — age, default credentials and abandoned firmware are the classic combination. We can assess what's installed, secure what's worth keeping, and tell you honestly what should be replaced.
Can you secure devices you didn't install?
Yes. Inventory, credential changes, firmware updates, segmentation and monitoring apply to any device on your network, whoever supplied it.
Does your vulnerability scanning actually cover printers and cameras?
Yes — anything with an IP address is in scope. Finding forgotten devices is one of the most common outcomes of a first scan.
Is network segmentation disruptive to set up?
Done properly, no — it's planned and rolled out with minimal interruption, and day-to-day nobody notices except the attacker who now can't reach anything from a compromised camera.
The next step
Start with the count. If you can't currently list every device on your network with an IP address, that list is worth having this month — it's the map of your real attack surface. Call 1300 053 948 or start with a free cybersecurity health check, and if your cameras and access control deserve the same scrutiny, our security & access control team handles both sides of the fence.
Related Key IT services
More insights
Security questionnaires, decoded
Client and insurer security questionnaires ask the same ten things in disguise. What each question…
Read article →CybersecurityEarly intel: finding holes before attackers
The gap between a vulnerability being published and being exploited keeps shrinking. How Key IT…
Read article →CybersecurityYour supplier's breach is your problem
An Australian hotel group's guest data was exposed through a third-party provider. Why supply-chain…
Read article →Book your free IT & Cyber Security Review
See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.