Unsecured IoT Devices in the Office

The firm secured its computers. It never thought of these as computers.

Law Firm Cybersecurity · Chapter 11~5 min read

The most overlooked computer in your office is the printer. It has a hard drive, a network connection, an admin panel, and — at a lot of firms — the default password it shipped with. It quietly stores images of everything it prints and scans, which at a law firm means client documents. And it is very possibly reachable, right now, from the open internet.

The printer isn't alone. The networked scanner, the security cameras, the smart TV in the conference room, the VoIP phones, the "smart" thermostat, the video doorbell — every one of them is a small networked computer, and every one is a device most firms never think of as something to secure.

Why "smart" office devices are a soft target

The Internet of Things — everyday devices with network connections and small embedded computers — trades security for convenience by default. These devices routinely ship with default credentials, get patched rarely if ever, and are set up by whoever installed them with "does it work?" as the only test. The same device search engines from Chapter 6 (Censys, and tools like Kamerka) find exposed equipment and map it to a location.1 A misconfigured office device is findable the same way a misconfigured database is: by searching.

What makes them genuinely dangerous to a firm is two-fold:

  • They hold or see sensitive data. The printer/scanner literally processes client documents. The cameras see the office. The phones carry privileged conversations.
  • They're a foothold on your network. A compromised smart device sits inside the firm's network, an ideal beachhead to reach the systems that actually matter — quiet, unmonitored, and trusted by everything around it.
FIGURE 1 — THE OFFICE, AS A DEVICE INVENTORY
Printer / scannerStores scanned client docs · default password · admin panel · reachable from the internet?
Security camerasInstalled with the default login "for now" — three years ago
Conference-room smart TVConnected itself to the wifi · listening-enabled
VoIP phonesCarry privileged conversations · last firmware update: unknown
Thermostat / doorbellNobody inventories the thermostat
The routerThe front door to all of it — see Chapter 14
One compromised device → the network → the file server that matters.

Why firms miss this entirely

Because these devices don't look like IT. Nobody inventories the thermostat. The printer was set up by the vendor who delivered it. The cameras were installed by a security company that used the default login "for now." The smart TV connected itself to the wifi. None of it went through the firm's IT process, so none of it got secured — and years later, nobody even has a list of what's on the network.

What this means for your professional obligations

In the United States

Rule 1.6(c) again: reasonable efforts to prevent unauthorized access to client information.2 A printer full of scanned client documents, reachable from the internet with a default password, is difficult to square with "reasonable efforts." And the technology-competence dimension of Rule 1.1 (Comment [8]) reaches the fact that these are the technologies the office runs on, whether or not anyone thinks of them that way.3

Worth knowing that the ABA has already gone here specifically. Formal Opinion 498 lists, among its particular virtual-practice considerations, smart speakers, virtual assistants, and other listening-enabled devices — advising that lawyers consider their listening capabilities and disable those functions when not in use, to avoid unauthorized access to client information.3 If the conference-room speaker and the smart TV struck you as too trivial to be an ethics question, the Standing Committee disagrees.

In Canada

The competence commentary's scope is the technology your practice uses — and the office runs on these devices as surely as it runs on laptops.4 The confidentiality duty is the exposure when the device that sees client documents is the one left open.5

What actually fixes this

1. Inventory everything on the network. You can't secure what you haven't counted. The goal is a list of every device with a network connection — printers, cameras, phones, TVs, sensors, and the router itself.

2. Change every default password. This one step closes most of the risk, because default credentials are the first thing anything scanning for exposed devices tries.

3. Segment the network. Put IoT devices on a separate network segment from the systems that hold client data. Then a compromised thermostat is a compromised thermostat — not a path to the file server.

4. Update firmware, or replace what can't be updated. A device that no longer receives security updates is a permanent liability; budget to replace it.

5. Get devices off the open internet. Almost nothing in the office needs to be directly reachable from outside. Remote access to a camera system or a printer should go through a controlled path, not a port open to the world.

6. Mind the printer specifically. Turn off or secure stored-image retention, require authentication for the admin panel, and wipe drives before any device leaves the office or gets returned to a lease.

Your firm's office IoT checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. Rae Baker, Deep Dive: Exploring the Real-World Value of Open Source Intelligence 385, 405–06 (Wiley 2023).
  2. Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass'n 2023).
  3. Id. r. 1.1 cmt. 8; ABA Comm. on Ethics & Pro. Resp., Formal Op. 498 (Mar. 10, 2021) (“[u]nless the technology is assisting the lawyer’s law practice, the lawyer should disable the listening capability of devices or services such as smart speakers, virtual assistants, and other listening-enabled devices while communicating about client matters”).
  4. Model Code of Pro. Conduct r. 3.1-2 cmts. [4A]–[4B] (Fed'n of L. Soc'ys of Can. 2019).
  5. Id. r. 3.3-1.

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer