Q&A With Symphion CEO, Jim LaRoe on Protecting IoT Technology

0
Symphion leads in protecting these forgotten endpoint classes. The Symphion Program™ is Symphion’s flagship turnkey program that delivers, maintains, adapts, and proves continuous cyber hygiene for these endpoints—with no operational lift.  One program, All Printers. All IoT. One price. No Lift.

What led Symphion to focus on protecting printers and connected IoT?

We learned about printers as a result of our history. In 2004, we developed our core configuration management database (CMDB), with agentless scanning, and took it to market as a managed service to support IT outsourcing (ITO) providers in their IT asset lifecycle management (ITALM) reporting service level reporting agreements (SLAs). We also developed and included secure content automation protocol (S-CAP) scanning technology for mainstream IT endpoints.

In 2015, a printer original equipment manufacturer (OEM) reached out to us to support their IT services company. As a result of working with them, we first became aware of the printer endpoint and what we call “the print silo”.

Before that, we were like most of IT, we didn’t think about printers. They were outside normal ITALM and security operations—forgotten endpoints operating in a hidden universe parallel to IT.

We saw that the printer OEMs had all competed with each other by building incredible business-enabling capabilities, including protective capabilities, into the devices. But the managed print services (MPS) companies (including the OEMs’ own MPS organizations) were managing devices for cost, supplies, uptime and break-fix, but not cybersecurity. Printers remained exposed mostly with unhardened factory-default configurations.

We learned that printers were effectively servers because of those capabilities but were not under the same cybersecurity disciplines as servers or PCs.

At the same time, the cyber-criminal ecosystem was expanding rapidly.

The result has been a large and growing security gap from these endpoints, with trusted access, that are widely deployed, operationally important and entirely outside cybersecurity governance.

Organizations are heavily investing in cybersecurity, especially in 2026. Why have printers and connected IoT like cameras been getting overlooked?

The biggest reason is the same reason why we didn’t know about printers before getting the call from the printer OEM. Most leaders think printers are still just appliances, like from their analog days or they just don’t ever think about printers at all.

Another major impediment has been technical fragmentation, the absence of a practical program for establishing and sustaining cybersecurity operations for printer endpoints in the reality of enterprise IT operations and MPS. Print environments are made up of different OEMs, models, firmware versions and embedded operating systems. Even within a single OEM, capabilities vary by model and firmware revision.

While each OEM provides security features for its own products, before Symphion there was no practical way to continuously establish, operate and sustain cyber hygiene across the entire print fleet without a heavy and costly manual effort that required specialized skillsets. Customers or MPS providers seeking to protect their printer endpoints were left to cobble together a program using each OEM’s device management software, all while staffing, training on the required skillsets and managing it while disrupting business usage.

There has also been organizational fragmentation. Procurement or Supply Chain commonly owned the devices and the MPS contract, IT supported connectivity and workflows, and Information Security owned the risk—but no one owned a funded cybersecurity program for the endpoint class. As a result, there has been no governance. There has been no requirement, no enforcement and no budget, so no governance.

At most, we’ve seen vulnerability scans on printers and internal IT operations being told to eliminate them. Sometimes, one-time hardening requirements are in a MPS request for proposal but with no governance or assurance that the controls remain in place as devices are reset, moved, repaired, updated or replaced.

Many organizations already have an array of cybersecurity technologies for endpoints such as vulnerability scanners, security incident event management (SIEM) and endpoint detection response (EDR) software products. What makes Symphion’s approach different?

The fundamental difference is that most cybersecurity products discover, alert or assign work. Symphion establishes, operates and continuously sustains the security program for these forgotten endpoint classes. We do not simply discover vulnerabilities, generate alerts or track remediation tickets for the customer to resolve.

The Symphion Program™ establishes, operates, maintains and adapts continuous cybersecurity operations including governance for the endpoint. Customers do not need printer-security expertise, additional staff or a new operational burden.

We recognized early on that IT, Information Security and executive leadership were generally not problem-aware. The existing ‘managed’ state centered on cost, supplies, uptime and hardware—not cybersecurity governance—while the threat environment was becoming substantially more capable.

We concluded that vendor-agnostic software alone would not solve the problem. Customers also needed the operating model, trained professionals, security disciplines, processes, change controls and accountability to keep the endpoint governed over time.

We also had perfected and matured “as a Service” turnkey delivery for household names in ITO and their very largest customers. So, we put everything that a business needs in our endpoint cybersecurity operations program for printers and connected IoT offering, The Symphion Program™.

For one per-device price, we provide not only our technology stack, but also the trained professionals, cybersecurity disciplines and proven processes—all without disrupting business operations or adding operational lift. We call that Operational Trust: customers can modernize security across a complex installed fleet without introducing unnecessary disruption, hidden workload or business risk and with no operational lift.

We take the fleet as it is and as it becomes. During the three-year program, devices may be added, removed, replaced, reset, moved or transferred to a different MPS provider. The program adapts to those changes so that cybersecurity governance does not depend on a static fleet or a particular OEM. Most importantly, like with any cybersecurity operations program, the program is built to seamlessly adapt to changes that affect the endpoint.

Why can’t organizations solve this using OEMs’ device-management software or another cybersecurity platform?

An OEM’s device management software only supports that OEM’s devices and still has to be operated by a person. Enterprise cybersecurity operations and governance are fundamentally different missions. Traditional cybersecurity platforms may discover an endpoint, identify vulnerabilities or generate a ticket, but they do not perform and sustain the device-level operating work.

The problem therefore cannot be solved by another software tool. It requires vendor-agnostic technology, printer and IoT expertise, cybersecurity disciplines, operating processes, change control and continuous accountability. That combination is why The Symphion Program™ is a continuously operated cybersecurity program—not just a software platform.

Organizations may understand the risk but still fear disrupting critical print and connected-device workflows. How does Symphion address that concern?

That concern is legitimate. Printers and connected IoT are embedded in healthcare, manufacturing, finance, logistics and other critical workflows, and security changes cannot be made recklessly. The Symphion Program™ is built around Operational Trust.

We use inventory, device blueprinting, dependency mapping, testing, staged implementation, backups, rollback planning, quiescence, change control and ongoing program management to strengthen security without introducing unnecessary disruption. The objective is not merely to establish secure configurations, but to maintain them as the fleet, network, firmware, certificates and business requirements change, without disrupting the business.

What innovations are you most excited about as organizations expand Zero Trust and identity-based security initiatives?

The most important innovation is extending trusted identity all the way to the device and then sustaining that trust operationally.

We have been enabling Zero Trust (ZT) on these endpoints, since well before ZT became a mainstream enterprise priority. For instance, as organizations adopt ZT, network access control (NAC), segmentation and certificate-based authentication, maintaining trusted identities across printers and connected IoT has become an operational challenge.

Certificate lifecycle-management platforms can manage policies, issuance and expiration, but they generally do not perform the device-level work required across printers and connected IoT. That work includes preparing the device, generating the CSR, configuring services and protocols, installing and validating the certificate, managing prerequisites, coordinating quiescence where required, and restoring trusted operation after device or firmware changes.

That’s why in January 2026 we introduced our Security Certificate Deployment and Management Service™ as part of The Symphion Program™. It is a closed loop service to remove operational labor costs for customers.

It deploys, validates, restores and continuously sustains certificates and trusted identity across printers and connected IoT endpoints. This closed-loop capability becomes even more important as maximum public TLS certificate lifespans move toward 47 days, potentially requiring as many as 8 certificate cycles per year.

The conversation around printer security has changed dramatically over the past few years. What’s different today?

AI is reducing the time, expertise and cost required to identify and exploit overlooked attack paths. Organized criminal groups and nation-state actors can search more broadly and move faster, making the enterprise’s weakest and least-governed endpoints increasingly consequential. What was once isolated criminal activity has become a sophisticated ecosystem of organized cybercrime looking for the easiest path into an organization.

At the same time, businesses have become far more dependent on connected systems and digital workflows. Printers and connected IoT devices sit directly in many of those critical workflows—from healthcare and manufacturing to finance, logistics and customer operations. As organizations implement Zero Trust, network segmentation and identity-based security, every connected endpoint is expected to meet the same security standards.

The challenge isn’t the printers themselves. The challenge is that organizations haven’t operationalized cybersecurity for printers and connected IoT. These devices are everywhere. They are trusted endpoints with trusted network access, yet they still operate outside established cyber-hygiene controls and continuous cybersecurity governance. Attackers do not need printers to be uniquely vulnerable; they only need 1 of them to be ignored.

The printers haven’t changed. The consequences of continuing to ignore them have.

What’s the biggest challenge organizations face when trying to protect printers and connected IoT?

Risk ownership. The largest barrier is not technical; it is the organization deciding who owns the risk, who is accountable for the outcome and which budget will fund the solution. The ownership of the endpoint has been fragmented.

Supply Chain or Procurement generally owns the devices and the MPS relationship. IT Operations supports connectivity and business workflows but is already overextended and often lacks printer-specific expertise. Information Security does not operate the devices, but it ultimately owns the obligation to identify and address the risk. As a result, the endpoint falls between teams, responsibilities and budgets.

In practical terms, ownership is not established unless a named executive or function is accountable and a recurring budget exists to operate the required controls.

That is why we built The Symphion Program™ to establish, maintain and continuously adapt cybersecurity operations and governance for these endpoints. Our vendor-agnostic technology, trained professionals, proven processes and turnkey delivery create Operational Trust: stronger security without adding operational lift or introducing unnecessary disruption.

As CEO, what principle has guided both your leadership and Symphion’s growth?

Our guiding principle is that complexity should be absorbed by us, not transferred to our customers. We continually innovate, but innovation only creates value when it can be delivered seamlessly, sustained over time and operated without adding burden or business risk for our customers.

For more information, visit: https://symphion.com/

Related News: 

DXC Workplace Services: Powering the Next Era of Work

PDQ Expands Endpoint Management and Vulnerability Capabilities

Share.

About Author

Bio: Jim LaRoe is CEO at Symphion, Inc. a Dallas, Texas based software and services company specializing in operationalized cybersecurity for printers and connected IoT through vendor agnostic technology, concierge delivery and proven process. Symphion is the leader in protecting these forgotten endpoint classes. The Symphion Program™, is Symphion’s flagship turnkey program to deliver, maintain, adapt and prove continuous cyber hygiene for these endpoints—all with no operational lift. One program, All Printers. All IoT. One price. No Lift.