Loading...
Loading...

Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage & protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
In this episode of Apple @ Work, Kevin Pickhart, Executive Chairman of Pharos, joins the show to talk about the hidden security risks lurking in office printers, and why zero-trust security needs to include print workflows, not just endpoints and networks.

This episode of Apple at work is sponsored by Mosul.
Deploying managing and protecting Apple devices at work should be difficult or require several solutions.
Mosul is the only Apple Unified platform for business.
By combining enhanced device management, endpoint security, Internet privacy and security,
single sign-on enhanced app management into a single Apple-only platform,
businesses can now easily and automatically deploy, manage, protect their Apple devices automatically
with one solution at an affordable price.
With a solution for every business size and the best support in the market,
so a free 30-day trial and see firsthand while Mosul is more than an Apple MDM.
Mosul is everything you need to work with Apple.
To learn more, visit business.mosul.com
That's business.msos.
YLE.com
Thanks to Mosul for sponsoring Apple at work this week.
Welcome to Apple at work.
The podcast all about Apple and the Enterprise.
My name is Bradley Chambers.
Your host, as always, this week on the show, first time guest, Kevin Picard from Ferris.
Kevin, welcome to Apple at work.
Thank you, Bradley. Happy to be with you.
It's funny when you and I got connected.
I just been thinking about how Apple has pushed the printing industry forward in the Enterprise.
Back 15 years ago, the biggest risk to me when you had upgraded operating systems
with printers, which just break.
With iPads and iPhones, as they became very popular in the Enterprise,
AirPrint really became something that Enterprise printers had to take seriously.
There was a time when it was like, oh, that does never going to work.
But you've really seen that on the Enterprise side, Google Cloud Printing and AirPrint
become really table stakes on every environment.
Of course, that led to other complexities that do technology solve.
But what's your take on just how printing in the Enterprise has involved?
As the devices have gotten more varied, how have you seen this industry evolve?
Yeah, Bradley, and you find out a nice, one of the nice technologies introduced by Apple,
which is the AirPrint.
And really, the technology behind that.
Apple has been ahead of the curve in its introduction of AirPrint.
When you look at sort of the technology that sits behind that,
it was the beginning of trying to isolate these endpoint printer devices
from the operating system and how they interoperate.
So, yeah, Apple did a good job of pushing the industry
to make sure that all printers would accept modern and secure communications.
It does create, as you mentioned, it creates some other gaps that people need to be aware of.
And one of the things that's to recognize in large scale enterprises
is that AirPrint becomes one mechanism for how you reach those printers.
But in large scale enterprises, there is oftentimes servers and queues that go beyond what AirPrint delivers.
So, Apple's a leader in this space, but yes, Print remains a security threat for most enterprises.
I've heard that in my entire 20 years of IT,
is the biggest security threat is things being left on the printer.
I mean, just personal information, things, you know,
print two copies when you leave one and forget about it.
And it really is true.
Why do you think that, I mean, do you still see that as one of the huge security risks
for most organizations is just bad printer security?
Yeah, when we talk about print security,
we're really talking about three distinct things.
And this is part of the challenge for enterprises is print has been around for so long
that it's essentially disappeared into the woodwork.
It's so prevalent.
Organizations had been dealing with this technology for so long that
it's both invisible and organizations think they understand it.
When in reality, very few enterprises understand all the nature of print.
And I mentioned there's three different security problems.
There's the page, which we're talking about now.
What ends up on paper?
Who ends up with that paper?
And what do they do with it?
So there's the data leakage issue that shows up with the printed page.
Then we've also touched on the printer itself.
The printer is an endpoint.
So that becomes an endpoint security problem for organizations
that are looking to manage endpoints.
And then there's the print process.
We touched on air print as one of the plumbing mechanisms.
But the basic print process, the infrastructure identity and privilege required
to enable printing inside of enterprises,
whether we're talking about from a Mac a PC, an iPhone.
All three of those present security risks,
which is really why we talk about it as one of these big unknowns,
is you need to be focused on all three.
Now that's a fair point.
I guess in my mind, I was thinking about just what gets put on the page,
but there's a lot of legacy infrastructure.
And in some ways, it's that going from digital to analog
that creates a little bit of chaos.
Now one of the things that I have found interesting is,
there's multiple ways in enterprise you can deploy printers.
If you've got a small enterprise, you can just deploy things.
Boy, things manually.
Hey, I'm just going to kind of brute force the printer installation.
Or obviously you can hang them off a Windows server and there's various risks like that.
But it has been interesting to me the cloud native solutions that are coming,
are not coming, but are available today for print management
that I think solves a lot of problems for IT,
but also creates a really nice user experience.
How do you, you know, just in terms of like uptime focus,
and then also just a better handle for IT?
Can you talk about the benefits or just how this cloud first printing has evolved?
Sure, sure.
And, and you're right, we ferrous entered into this cloud printing infrastructure
over 10 years ago.
We identified that all IT infrastructure was moving to the cloud.
And when we talk about the organizations enterprises,
we find that all will agree with that, right?
Our print infrastructure is going to move to the cloud.
The question isn't, isn't whether the question is when.
And what's going to be the driver that gets us there?
There's a classic example of the fundamental difference between
when you talk about a cloud infrastructure for printing,
and when you talk about this tradition,
you're talking about the traditional print environment,
we have a large global bank that we work with, hundreds of print servers.
And the task of upgrading all of those print servers,
they were operating on an obsolete version of Microsoft server,
and had to pay Microsoft millions of dollars to maintain that
because of how expensive it was going to be for them to upgrade that print server environment.
So you've got organizations like this that have gone years without upgrading their print environment,
and then you look at what happens in the cloud, how different that is.
Our cloud environment had 287 production upgrades last year.
We're upgrading continuously.
So it's that difference that people understand in cloud infrastructure,
and it's a stark difference when you look at, as you mentioned,
old school legacy print infrastructure, which really is outdated.
Well, and I think one of the things that my mindset is,
when I was trying to uncover in the past couple of years of how this industry is bugged,
printing is a solve problem.
I mean, we've not improved upon the piece of paper.
The same thing that obviously some of the qualities got better,
but printing out reports in 2010 and in 2026,
the end result is functionally so to say,
there's only so much to put on a piece of paper,
but what really has evolved is everything in between.
And because again, like you said,
you had these legacy print servers that I think it's one of those
that people just kind of assume,
like this is how you manage printers.
And then on the, but then clearly companies like you all and other vendors,
look at this and said,
now there's a better way to do this in the cloud that really drives number one,
IT efficiency, helps you really understand your costs.
And I think having those analytics with printing is one of the biggest things
you're seeing with cloud-based solutions.
And then just a much better security posture,
like things are updated more frequently.
It doesn't feel like a legacy infrastructure.
Is that kind of what you are seeing as well?
Yes, yes, absolutely.
The analytics, that's just kind of table stakes in today's world.
It's not table stakes in the print world.
Most organizations are still flying blind when you talk about
who's printing, where are they printing, what are they printing,
when, who picked it up, you know, that kind of telemetry information
that we become accustomed to on the system side.
We're not so accustomed to, as you mentioned,
on the printing side, which has been,
printing is an old technology.
So, yeah, it has not changed significantly.
But one of the things that we need to consider is that as that technology has aged,
that's a double-edged sword.
It's stable, it's understood.
At the same time, it was designed for a different era.
The print vendors, just one quick example of that.
The print vendors had a brilliant idea back before they had access
to all of their printers that they had these endpoints.
And they were trying to figure out how do I upgrade software on the printers?
When I've got all these endpoints distributed around the world.
And so, what they did was they said, well, I've got this print mechanism
for how I get print files to a printer.
Why don't I use the same mechanism?
And I'll basically just make, whether you talk about PCL postscript,
I'll make this page composition and page delivery model my way of delivering software.
So, as a consequence, when most people think about postscript,
they think about PDF, they think about PCL,
these page description language, they're programming languages.
And that is a significant risk for organizations looking at what do I allow?
What is the identity? What do I, in a zero-trust world?
I don't want to just allow any endpoint to submit a print file to a device
without being able to understand what that print file is and what's inside it
and make sure that we're not compromising.
So, yeah, it's old technology, and that's double edged.
Well, I mean, so there is a risk.
Again, you think about endpoints seem to be upgraded.
If you've got just old, old legacy firmware on some of these printers,
and of course, I've seen printers that have lasted for 15 years,
they just keep the new users in there.
And it's like, when's the last time the firmware was updated?
It's like, nobody knows.
Well, again, so there's potential there that if you have an exploit in the printer,
you're sending essentially programming language inside of a document.
You could export that exploit that printer,
and then there's all sorts of security risks that can be happening
because you're capturing things before they're ever printed on the page.
But again, if you, I'm just thinking of, if your company manages the IT infrastructure
for a thousand gas stations around the country,
and they all have a printer on site, when are you upgrading that printer?
You're probably not.
And that's not, and sticking your head in the sand is not a good security strategy.
No, no.
And it really is right for this world of zero trust.
I know that's a common discussion on your podcast.
But what does zero trust mean in the world of printing?
In most cases, when people think about printing and print drivers,
printing is designed to be peer-to-peer.
It is designed to be bidirectional in its communication.
I reach out to the printer and it tells me
how many paper trays it has, and what kind of media is in which paper tray?
And it presents me those capabilities so that I can have an interaction with the printer.
This is bidirectional, which is not a part of zero trust.
So once you enter into a zero trust world,
the printing technology is not designed for that.
So yes, when we're talking to enterprises,
it's another big advantage of shifting things to the cloud
is bringing in a zero trust mentality to make sure that we have trusted endpoints
communicating to each other, that it is identity driven,
and that the types of communication and types of files and interchange
are acceptable and managed.
So if somebody's listening and they've got 15 printers on the organization,
and they're like, okay, we need to, this is legacy technology.
What is the transition to moving to a solution that Ferris offers this cloud-based,
very, very secure, easy to manage?
Do you have to rip and replace all your printers?
Is there a great path for the firmware?
What's that process like?
No, there's two different ways of when you think about printing today.
There's what most people think about printing.
I say file print and paper comes out, right?
And that creates its own risk because you need to figure out who ends up with that paper
when I say file print and run down the hallway to catch that document before somebody else does.
That's our traditional world of printing.
And then you've got, as you were talking about before,
secure printing or pull printing.
I print, the file does not come out.
The file is held securely.
And then when I go to the printer, I authenticate in one manner,
another, I either put it in a pin or very often I'll use my employee ID badge
or I'll use my mobile phone as an authentication token
and my print will come and find me there.
In both of those worlds,
the cloud is really a pretty straightforward.
You're looking at putting in essentially a driverless interaction
at the end point, like a PC.
It's almost like looking at downloading a print driver,
although it's no longer print drivers
because we're not using that older technology.
And then the printers, you just have to realign.
You close down all the ports and you realign them to the cloud
so that they will only accept information that is coming and certified.
So for most employees, you're not going to notice much of a difference.
We want to keep printing simple.
It's your IT organizations that is,
we're talking about ripping out the plumbing,
not changing fundamentally changing printing employees.
Once our software is deployed and employees is file print,
they don't know that they're using our software
or that it's going through the cloud or that the encryption is happening
and how it's being delivered.
They just know the file print.
Well, it's one of those rare times.
Again, if the goal is to just kind of redo the plumbing and the infrastructure,
it's one of those rare times.
You can tell me to follow me printing where you can just pick it up from anyone.
It's one of those rare times when actually increasing security,
increases user satisfaction at the exact same amount.
There's no downside to being able to print securely to any printer.
And then IT has kind of a centralized way to manage who's printing wide,
easy audit trails, but it's a massively better user experience for your employees.
It is.
And what we find is employees, all of us as humans, we resist change.
So generally when somebody changes the print process and somebody has to go up
and authenticate at the printer before they get their print job,
the first time that they do that, they're going to complain.
I never had to do this before.
I just want my print file sitting at the printer.
It takes a very short time before you're exactly right.
Bradley, I sit at my PC, my Mac, I submit my print files,
and I only choose which ones I want to release when I go to a printer,
and I go to the one that's convenient for me.
I don't have to think about where I'm printing.
So yes, it is employees pretty quickly decide,
this is a better model for printing.
And in place that goes.
And print volume goes to IT.
Well, exactly.
And IT is a huge one for IT because upgrading is much easier.
Adding new printers is much easier.
On voting new employees is much easier.
It's really, to me, it's not that you're making like the printer,
the actual printer of commodity, but you're adding some real intelligence
in between these two endpoints.
Is you're adding this intelligence that gives IT the control it needs.
And really, yeah, there's cost in putting the infrastructure in,
but everybody's winning with that.
The analytical interface about who's printing why is such a win.
And you can then have start to have honest conversations about what we're printing.
And who's going to pay for it?
Rather than because right now in a lot of organizations,
the printing budget is just, this is what we printed $20,000.
We had $20,000 with the prints last year.
What was it? Nobody knows.
Nobody knows.
Did we make any money off that?
Nobody knows.
What was printed? Nobody knows.
And what you want to say, well, and to, you know,
a lot of printers, especially if you were just a PC environment,
they supported that.
We're going to put it, make you put in a little key code before you print anything.
That seemed to work.
Okay.
But as, as the devices evolved, there's no way to, you know,
put in that code on an iPad.
There's no way to put in that code on an iPhone.
When the CEO just wants to print something from his or her iPad in a,
in a, you know, board meeting, they just want to print.
Well, so IT had to come up with solutions to make that work.
So what we're finally at this place is where the,
the CEO gets the simplicity of printing from their iPad.
IT gets the control that finance, the finance can also charge back
and start having conversations with like different departments like,
hey, you printed 30% of our prints last year.
What are you doing?
And everybody wins.
That's, that's exactly right.
And the other, the other benefit you mentioned that, that CEO,
the CEO is printing in his office in New York and then goes to London.
He doesn't need to figure out what printers exist in London and,
and how do I download and connect to the printer that's now down the hall.
He prints in London the same way he prints in New York,
to the exact same printer, the exact same queue.
Authenticase to that same printer in London.
He can even print to his, before he leaves New York and,
and authenticate and release it in London.
So, yeah, it just becomes a more seamless, more modern approach
to how we think about printing that, that is, it just makes sense.
Kevin, I was going to, I'm going to, I'm going to pitch you something
after we close the show, because I kind of want our,
our listeners and readers to have a more, have a more in depth
and look at what this looks like.
So, again, I, this to me is some of the most interesting technology
of the decade, because it's solving a huge need.
And an, and an interesting, almost felt stagnant in terms of like,
you know, you had your major players on the, on the printer side,
and just, you just kind of dealt with it.
But I think there's a lot of fun here that can be had for IT fun,
meaning get better security, you get better usability,
you get better reporting.
There's, there's really no downside here for anybody.
So, I, this is, this is an incredible industry.
And again, the fact that it's cloud-based means that, you know,
worldwide organizations can do this in a way that's easy to spin up.
Yeah. And the other thing I would say,
Bradley, is, Ferris has introduced our space.
When we look at this from a cloud standpoint,
we believe there's a new space, which we've turned print ops,
which is really all of that plumbing.
It is the operations behind print, which has been,
which has been scattered throughout enterprises.
Who's managing servers?
Who's managing security?
Who's got the endpoints?
How are they getting delivered?
Just as you said, devices are up, devices are down.
Who's, who's managing?
All of that sits inside of a, of an operational world.
And once we put in a cloud infrastructure,
to deliver modern communication, monitoring tools,
then print begins to be brought into the modern world.
And, and that's really our view of the,
the emerging world of print, what we call print ops or print operations.
I like the print ops name.
I'm all still that. That's really good.
Kevin, thanks for chatting with us today.
Thanks for having the listening.
We'll have a link to learn more about Ferris and the show notes.
But again, if you're still, if you're still just managing printers manually,
if you're using legacy print servers,
there are better solutions out there.
I promise you, your employees will love it.
The first time you have a system where you can print 20 printers at once
and just pick it up the one you're near, you know, the one you're near at the time.
It's a, it's a new world.
So thanks for everybody for listening this week.
And we'll talk to you next time.
