Unsecured IoT Devices in the Office
The firm secured its computers. It never thought of these as computers.
The most overlooked computer in your office is the printer. It has a hard drive, a network connection, an admin panel, and — at a lot of firms — the default password it shipped with. It quietly stores images of everything it prints and scans, which at a law firm means client documents. And it is very possibly reachable, right now, from the open internet.
The printer isn't alone. The networked scanner, the security cameras, the smart TV in the conference room, the VoIP phones, the "smart" thermostat, the video doorbell — every one of them is a small networked computer, and every one is a device most firms never think of as something to secure.
Why "smart" office devices are a soft target
The Internet of Things — everyday devices with network connections and small embedded computers — trades security for convenience by default. These devices routinely ship with default credentials, get patched rarely if ever, and are set up by whoever installed them with "does it work?" as the only test. The same device search engines from Chapter 6 (Censys, and tools like Kamerka) find exposed equipment and map it to a location.1 A misconfigured office device is findable the same way a misconfigured database is: by searching.
What makes them genuinely dangerous to a firm is two-fold:
- They hold or see sensitive data. The printer/scanner literally processes client documents. The cameras see the office. The phones carry privileged conversations.
- They're a foothold on your network. A compromised smart device sits inside the firm's network, an ideal beachhead to reach the systems that actually matter — quiet, unmonitored, and trusted by everything around it.
Why firms miss this entirely
Because these devices don't look like IT. Nobody inventories the thermostat. The printer was set up by the vendor who delivered it. The cameras were installed by a security company that used the default login "for now." The smart TV connected itself to the wifi. None of it went through the firm's IT process, so none of it got secured — and years later, nobody even has a list of what's on the network.
In the United States
Rule 1.6(c) again: reasonable efforts to prevent unauthorized access to client information.2 A printer full of scanned client documents, reachable from the internet with a default password, is difficult to square with "reasonable efforts." And the technology-competence dimension of Rule 1.1 (Comment [8]) reaches the fact that these are the technologies the office runs on, whether or not anyone thinks of them that way.3
Worth knowing that the ABA has already gone here specifically. Formal Opinion 498 lists, among its particular virtual-practice considerations, smart speakers, virtual assistants, and other listening-enabled devices — advising that lawyers consider their listening capabilities and disable those functions when not in use, to avoid unauthorized access to client information.3 If the conference-room speaker and the smart TV struck you as too trivial to be an ethics question, the Standing Committee disagrees.
What actually fixes this
1. Inventory everything on the network. You can't secure what you haven't counted. The goal is a list of every device with a network connection — printers, cameras, phones, TVs, sensors, and the router itself.
2. Change every default password. This one step closes most of the risk, because default credentials are the first thing anything scanning for exposed devices tries.
3. Segment the network. Put IoT devices on a separate network segment from the systems that hold client data. Then a compromised thermostat is a compromised thermostat — not a path to the file server.
4. Update firmware, or replace what can't be updated. A device that no longer receives security updates is a permanent liability; budget to replace it.
5. Get devices off the open internet. Almost nothing in the office needs to be directly reachable from outside. Remote access to a camera system or a printer should go through a controlled path, not a port open to the world.
6. Mind the printer specifically. Turn off or secure stored-image retention, require authentication for the admin panel, and wipe drives before any device leaves the office or gets returned to a lease.
Your firm's office IoT checklist

Footnotes
- Rae Baker, Deep Dive: Exploring the Real-World Value of Open Source Intelligence 385, 405–06 (Wiley 2023). ↩
- Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass'n 2023). ↩
- Id. r. 1.1 cmt. 8; ABA Comm. on Ethics & Pro. Resp., Formal Op. 498 (Mar. 10, 2021) (“[u]nless the technology is assisting the lawyer’s law practice, the lawyer should disable the listening capability of devices or services such as smart speakers, virtual assistants, and other listening-enabled devices while communicating about client matters”). ↩ ↩
- Model Code of Pro. Conduct r. 3.1-2 cmts. [4A]–[4B] (Fed'n of L. Soc'ys of Can. 2019). ↩
- Id. r. 3.3-1. ↩