Press "Enter" to skip to content

The impact of PSTI

The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) came into effect on April 29, 2024. Part 1 of the Act (which is the focus of this Vox Pop) is intended to improve the UK’s resilience to cyber-attacks by imposing new security requirements for connectable products. Here, we invite some of the print sector’s leading vendors to discuss how the new mandated minimum security requirements will impact the industry and what steps they have taken to comply

PrintIT Reseller: What steps have you taken to ensure you meet the disclosure obligations specified in the PSTI regulations for example, setting up a central point for end-users to report vulnerabilities on devices directly to manufacturers, and
a requirement to provide information about the minimum length of time for a product’s security update lifecycle

Matt Hayman, Head of Governance & Standards, Kyocera Group UK: Applied from April 29, 2024, all Kyocera consumer A4 printers and MFPs will have a unique ‘admin’ password included in the box together with their ‘statement of compliance’ documents. In this way access to internal settings and device security is secured to the owner of the device alone, removing the risk of attack through default and easily guessable passwords.

Kyocera has developed a webpage dedicated to providing key information about PSTI, explaining the implications of the legislation, what can be expected (e.g. what’s in the box) and importantly, how long devices shall be supported for (in terms of firmware and software updates). This webpage is supplemented with information specific to our channel partners on the PSTI section of our partner portal, including video podcasts and FAQs.

Furthermore, the site provides details of Kyocera’s Vulnerability Disclosure Policy (VDP), signposting to publicly communicate security vulnerabilities as well as helping to support academic bodies and security organisations in the important work they perform testing for potential vulnerabilities that can impact the consumer and businesses alike.

For Kyocera, complying with the PSTI Act isn’t just about ticking boxes; it’s about customer service and safeguarding our customers in this increasingly connected world. All security vulnerabilities are announced on our website where we also make security patches and the tools to implement them available. For our warranty customers, our remote resolution team is ready to help and for our fully managed print services customers, it’s all part of the service.

Sarah Mackay, Head of Operations, UTAX: With some of UTAX’s A4 devices being identified as products that could be suitable for consumer use, they have been preparing for PSTI from the
manufacturing process right through to service. Relevant devices will now be shipped with a statement of compliance and a unique password in each box. They have also created a web page to specifically address the new regulations, this page includes a form enabling customers to report a vulnerability or known security issue with a UTAX PSTI-compliant device.

Julian Hodges, Head of Product Marketing, Sharp UK: Sharp ensures that any products in the scope of the new regulation are fully compliant with all the requirements. This includes making available statements of compliance for each product and detailing the defined support period. In addition, we also have a central point available on our website for end-users to report potential product security vulnerabilities.

Phillip John, Category Manager – Office, Konica Minolta: Konica Minolta has published a statement of compliance with the PSTI Act for its devices, and this is available online from the
Konica Minolta download centre, the Konica Minolta website, as well as upon request. This document highlights the products that are covered, details the length of time updates are available, as well as giving contact information to discuss any compliance- related concerns.

A process has been introduced to manage any compliance-related enquiries, which will be reviewed regularly and improved if required.

Konica Minolta Business Solutions (UK) will closely monitor any changes to the PSTI Act and will adjust its compliance strategy in accordance with amendments and timescales.

We have also instigated an education and outreach programme to share information with our internal stakeholders and throughout our extensive partner network.

Arjan Paulussen, Managing Director, Western Europe and English-Speaking Africa, Lexmark: Typically, Lexmark provides firmware support for a minimum of five to seven years after the end of printer production.

PrintIT Reseller: An increased focus on sustainability has seen much wider availability of remanufactured devices, which could potentially be vulnerable to attack if security updates are not maintained. How do you mitigate risk in this area?

Matt Hayman: Sustainability, security and excellent customer service are core components of Kyocera’s corporate philosophy. Our team of product experts are available to answer customer enquiries, provide support and offer solutions. A full spares and repair service is provided through our comprehensive network of certified partners.

Whether you are a customer or partner, one area we always promote is device security and we provide the tools required to stay protected. Available to all in the ‘downloads’ section of our website, Kyocera provides a firmware upgrade tool together with firmware upgrade packs to enable everyone to keep their devices updated with the latest security patches. This is automatically done for customers operating through one of our managed print services such a Kyocera Fleet Services (KFS). Every time a Kyocera engineer visits a device they check and if required update, the device firmware to the latest level, a point strongly emphasised during service engineer training.

In line with Kyocera’s VDP, if a security vulnerability is discovered Kyocera will actively contact and resolve the issue with all partners, managed print customers and customers we have direct contact with. For the general public, security vulnerabilities are communicated online, enabling customers to take necessary steps to remediate the vulnerability.

Sarah Mackay: Customers need to understand the security implications when purchasing non-new equipment. Whilst every effort is made to advise companies of the risks involved with purchasing devices that have not been manufactured to current standards, the responsibility must lie with the purchaser. Robust security policies for organisations to minimise risk, are the only way to ensure vulnerabilities are not exploited.

Julian Hodges: Our refurbished devices are fully evaluated and refurbished by Sharp qualified technicians. This means that we follow a comprehensive and stringent refurbishment process that includes hard disk and personal data wipe, security and firmware updates.

Phillip John: Security is and always will be a fundamental priority for the company. Konica Minolta has committed to providing firmware updates after the end of life of a machine, to help protect our customers from evolving threats and vulnerabilities.

Arjan Paulussen: We implement a robust testing and quality control process to ensure that all remanufactured devices are free from any vulnerabilities or security issues. In 2020, Lexmark was the first imaging manufacturer to receive ISO 20243 certification for the entire printing device, including supplies, cartridges, and integrated solutions.

Our security staff also monitor all channels for potential security vulnerabilities. If something pops, a process is in place to score, test and patch a bug fix. We have a dedicated site and channels for communicating security advisories of any vulnerabilities and appropriate remedies to the wider user base.

To better protect the integrity of our device, Lexmark is leaning more into sourcing original components in-house, starting with the recently launched 9-Series line of A3 enterprise printers. This is all part of the company’s grander secure by design approach to ensure the utmost security for every device we produce.

PrintIT Reseller: What security standards e.g. ISO/ IEC 27001 have you achieved? Do you see independent validation of your company’s commitment to security as a key differentiator?

Matt Hayman: Kyocera supports all our customers in tackling cyber and data security risks by supplying products and services that incorporate the highest standards of data security. Assessed and certified to the ISO/IEC 27001 security standard, Kyocera’s products’ (printers, MFPs, document solutions and ICT services) support and aftersales services all operate above and beyond to keep customers’ data safe.

Kyocera Document Solutions UK has been assessed under the Cyber Essentials framework, evaluating the fundamental skills and security controls we have in place within our IT department and IT systems. Certified to Cyber Essential Plus, the highest level of certification, to give our partners the confidence that we are addressing cyber security effectively and the peace of mind that we have the fundamental skills and ability to respond to any threat.

More than this, Kyocera instructed Keypoint Intelligence to test the security features on our products. Equipped with a Kyocera TASKalfa 3554ci, this company employed certified security experts to use a combination of automated tools and manual exploitation attempts to probe for potential vulnerabilities in the device firmware/OS, ports, print protocols, embedded web page, connectivity avenues, and more. They were unable to penetrate the device and access the customer network.

So impressed were these ethical hackers that the device earned the BLI Security Validation, Device Penetration award, confirming Kyocera’s security credentials. We call this level of security K-Level security, and it is not only being implemented across Kyocera’s range of business focussed TASKalfa MFPs but also implemented on its range of ECOSYS consumer products.

Kyocera’s products are certified under IEEE 2600.1, an international security standard for hard copy devices enacted in 2009. Additionally, some Kyocera device models offer a FIPS 140-2 certified hard drive for sensitive data protection.

Kyocera adheres to various other security standards, including ISO/IEC 27001 information security management system, ISO/IEC 27017 cloud security, Common Criteria (ISO/IEC15408) evaluation of security properties, GDPR, HIPAA, and more.

At Kyocera we take data security very seriously and not only carry out internal testing but encourage independent external testing to give confidence to all our customers, large and small. We see this as a key differentiator for the company and proof of our commitment. Customers can see we have the products, staff and testing regimes in place to keep their data safe whichever Kyocera product or service they take.

Sarah Mackay: UTAX achieved Cyber Essentials Plus which is valid until April 2025. This accreditation is issued by IASME Cyber Assurance standard, which is a comprehensive, flexible and affordable cyber security standard. It provides assurance that UTAX has put into place a range of important cyber security, privacy and data protection measures. As their website states: the IASME Cyber Assurance standard was developed over several years during a government funded project to create a cyber security standard which would be an affordable and achievable alternative to other international standards.

Julian Hodges: Sharp UK has achieved both Cyber Essentials and ISO 27001. The ISO 27001 standard is certified by an independent UKAS accredited partner each year. We believe that achieving and maintaining security standards and certifications are essential to our position as a technology leader and partner. We demonstrate to our clients, who we also provide cyber security services to, that we are dedicated to the highest levels of security and protecting their data to an internationally recognised standard.

Phillip John: We have implemented and maintain a robust information security programme. Konica Minolta Business Solutions (UK) is Cyber Essentials and Cyber Essentials Plus certified, as well as maintaining ISO 27001 certification, along with Konica Minolta International.

Arjan Paulussen: Lexmark has ISO 27001 certification for its worldwide managed print services and cloud services. We also design devices to meet ISO/IEC 15408 Common Criteria Certification, an international standard on security capabilities. Lexmark is committed to validating this design through both the IEEE 2600 family of standards and the US-based National Information Assurance Partnership’s (NIAP’s) Hard Copy Device Protection Profile (HCDPP).

Lexmark follows the Federal Information Processing Standards (FIPS) 140 Publication Series issued by the National Institute of Standards and Technology (NIST), which outlines requirements and standards for cryptographic modules, including both hardware and software components. Adherence to this standard for hard disk encryption and IPsec networking helps us better secure any transmitted data.

Lexmark is also certified to the Open Trusted Technology Provider Standard (O-TTPS) for laser printer controller cards and firmware stored on the card. This standard has been adopted as ISO 20243-1 and addresses threats related to maliciously tainted and counterfeit products.

SOC2 Type II (cloud), and ISO 27001 (information) are additional standards Lexmark adheres too. We believe that independent, third-party validation is the best ways to assure customers that their manufacturer is being honest about the security features of the devices they are using.

PrintIT Reseller: How have you adapted your security risk and assessment services offering to help customers keep on top of the print security challenge in a world where BYOD and home printer usage is the norm rather than the exception, and zero trust is fast becoming the de facto standard?

Matt Hayman: In this new world where home working is the norm, printers and MFPs are connected into the home network but rarely, and perhaps never, get updated by the IT department. Therefore, it is very important to set up the device correctly during the initial installation. As part of Kyocera’s dealer certification program, engineers are trained on how to do this, including the firmware upgrade process. Also, in line with our philosophy, Kyocera makes things simple, providing the tools and support for users to update their device security.

In line with the PSTI legislation, all Kyocera A4 printers/MFPs have a unique admin password (included in the box) and armed with this password users can access the Kyocera command centre – the internal webpage of their device. Here they can lock out dormant USB ports, close any unused protocols and apply IP filtering so that only their PC/ tablet/phone can have access to their print device. In this way BYOD can be enabled or disabled applying zero trust policies.

Kyocera Cloud Print and Scan (KCPS) tackles print security challenges in the modern workplace by providing secure, cloud-based printing and scanning solutions. Amid the widespread use of BYOD and home printers, KCPS ensures secure print job release through user authentication methods. It prioritises document security and adheres to zero trust principles while seamlessly integrating with popular cloud storage services and operating without on- premise infrastructure.

Additionally, Kyocera offers specialist business solutions and consultancy services, to help organisations understand how their infrastructure stands up against the vigorous security threats that modern businesses must be resilient to. This forms an important foundation for businesses looking to establish a more robust security strategy.

Sarah Mackay: UTAX has tackled this challenge using solutions. There are so many solutions on the marketplace to improve workflows, it’s just a case of ensuring that you have the right solutions for your end-users, and that the solutions you use have strong security credibility. Solutions are a great way to standardise processes, allowing less room for error (which can frequently result in security breaches).

UTAX offers various software solutions that allow print devices to be managed centrally, ensuring secure logins for all members which are recorded in an audit log. Our software solutions enable the ability to block users or groups from accessing specific devices or features if needed.

UTAX also issues regular firmware updates to stay on top of evolving security threats.

Julian Hodges: Our professional services team are experienced, working with our clients and partners on how best to maintain the highest levels of print security in a dynamic and changing digital landscape, leveraging our technologies and those of our strategic solution partners to do so.

Phillip John: The continuous improvements to the security of our entire product range is a key pillar of our development programme. The new bizhub i-Series features an advanced firmware upgrade, which delivers greater protection against malicious activity.
A new authentication attack detection function blocks brute force attacks, a technique increasingly used by cyber criminals to attempt to crack passwords and other access data.

Konica Minolta customers can also select Bitdefender anti-virus protection to add further layers of protection that prevent the spread of malware to other networked devices. Furthermore, they can see the status of the device’s anti- virus via the home screen, and should a threat be detected, the IT administrator is immediately notified with information about the type and origin of the threat.

Arjan Paulussen: Lexmark realises organisations are considering zero trust principles to provide tighter access controls, both inside and outside the network perimeter. Securing an enterprise environment is growing more complex and requires a comprehensive understanding of software, hardware, network architecture, and each organisation’s security posture and goals. Lexmark supports zero trust architectures today with our advanced device management and conformance tools, on-device runtime and firmware protections, and security analysis and analytics services.

With the increasing sophistication of cyberthreats, print security is now more important than ever. As organisations consider the various aspects of security, we recommend that BYOD and mobile printing policies are considered in their security risk profiles.

Lexmark’s unique MPS approach offers solutions, management, and visibility across a customer’s entire hybrid environment – not just those in a corporate office. Lexmark’s vision is to deliver its leading print services anywhere, at any time, to any print environment – whether they be a 100,000 device global fleet, a single device in a remote home office or everything in between. From our leading, fully customisable direct MPS offering to our cloud-based remote fleet management tools, Lexmark Cloud Bridge connectivity suite enables that today and is the network flexibility foundation for the future.

Lexmark Cloud Bridge technology brings Lexmark’s most advanced managed print services functionality to all hybrid network environments. It delivers measurable savings by leveraging cloud and the IoT to simplify and optimise print environments.

PrintIT Reseller: What training/support do you provide for channel partners to help them develop a strong security services and solutions offering?

Matt Hayman: Kyocera authorised service partners are trained to support all aspects of our products from installation and repair to firmware upgrades. This training includes a detailed explanation of the Kyocera command centre where they are shown how to limit device access by locking ports, close any unused protocols
and apply IP filtering. Training also includes a run through of how to update the device firmware with each engineer carrying out the firmware upgrade process. In this way Kyocera can be certain that each of our certified service partners is aware of the security features of our devices and how they are implemented.

Sarah Mackay: UTAX offers solutions training to all UTAX Partners, aiming to educate partners in the risks, solutions products available to mitigate risks, and the reasons we have chosen specific solutions to work with our devices. As soon as PSTI became apparent, UTAX was working on providing relevant information via email, website, and through offering constant sales support.

Julian Hodges: We offer a comprehensive range of in-house and online training resources for
our technology partner programme across the full range of hardware and solutions in our portfolio. Security specific training is also provided, which is regularly reviewed and updated to ensure we are offering the very best training and support to our partners.

Phillip John: We have provided our partners with information on the provisions contained in the PSTI Act, along with a copy of our statement of compliance. The company has also created a channel for them to ask specific questions in this area as part of our commitment to providing them with all the help and support they need from us.

Arjan Paulussen: Lexmark provides in- depth sales and technical training across our entire offering. Designed with our partners in mind, we give our partners the knowledge to meet every customer challenge by leveraging industry leading hardware, supplies, security solutions, services and software. Lexmark partners have access to the PartnerNet portal that includes access to exclusive marketing and sales tools, content, training and resources. In addition, our training catalogue is constantly enhanced and expanded to accommodate new collateral, offers and services.

www.kyoceradocumentsolutions.co.uk

www.utax.co.uk

www.sharp.co.uk

www.konicaminolta.co.uk

www.lexmark.co.uk

Author

Get in touch with us today!