Office copiers handle a surprising amount of sensitive information. Contracts, tax documents, financial records, employee information, customer records, medical documents, identification, and other confidential material all pass through these devices every day.
That makes one of their most convenient features—Scan-to-Email—worth looking at from a security standpoint.
If a copier can send email to any address on the Internet, it can also provide a very simple way for sensitive documents to leave the organization. CM Relay helps businesses reduce that risk by allowing administrators to restrict where their copiers are allowed to send email.
Your Copier Is an Outbound Data Channel
Consider a typical Scan-to-Email workflow. An employee places a document in the feeder, enters an email address, and presses Send.
If there are no destination restrictions, there may be nothing preventing that document from being scanned to:
- A personal Gmail, Outlook, or Yahoo account
- A former employee
- An unauthorized vendor
- A competitor
- An incorrectly typed email address
- The wrong contact selected from an address book
Businesses spend significant time and money securing workstations, USB devices, cloud storage, email accounts, and Internet access. But an unrestricted copier can become another path for company information to leave the network.
Sensitive Information Really Does Leave Businesses Through Email
This isn’t just a hypothetical concern. There are plenty of real-world examples of employees using email to move sensitive company information outside an organization.
In one case, the U.S. Department of Justice reported that an employee of a food and flavor producer used a personal email account to forward 82 files containing proprietary and trade-secret information. According to the DOJ, the files included virtually all of the formulas used by the employee’s department.
In another case, a former Federal Reserve Bank of New York employee pleaded guilty to theft of confidential information. The Justice Department reported that confidential Federal Reserve documents were transferred without authorization, including a document sent from one personal email account to another personal email account.
In a Duracell trade-secret case, the Justice Department reported that an employee copied company research and emailed the information to a home computer before ultimately providing trade-secret information to competitors.
https://www.justice.gov/archive/criminal/cybercrime/press-releases/2007/grandePlea.htm
These incidents did not necessarily involve office copiers. They do, however, illustrate the underlying problem: when employees have an unrestricted way to send sensitive information to external email accounts, that capability can be used to remove information from the business.
An unrestricted Scan-to-Email system creates another potential path.
Sometimes It’s Just a Mistake
Not every disclosure is malicious. In many cases, someone simply sends information to the wrong person.
Verizon’s 2024 Data Breach Investigations Report analyzed 2,671 confirmed data disclosures attributed to miscellaneous errors and found that more than half of those errors resulted from misdelivery—in other words, information being sent to the wrong recipient.
The UK’s Information Commissioner’s Office also specifically tracks data emailed to an incorrect recipient as a type of data-security incident. Its published examples include organizations inadvertently emailing files containing personal information to unauthorized recipients.
A mistyped Scan-to-Email address can create the same problem.
Does Your Copier Really Need to Email Anyone on the Internet?
This is the question businesses should be asking.
Suppose an accounting department uses its copier to scan invoices, purchase orders, tax documents, and other records to employees. If those documents only need to go to addresses at @yourcompany.com, why should that copier also be able to send the same documents to an arbitrary personal email account?
For many organizations, unrestricted Internet delivery simply isn’t necessary.
Removing capabilities that aren’t required is one of the simplest ways to reduce security risk.
How CM Relay Send-To Restrictions Help
CM Relay can enforce Send-To restrictions on messages being relayed from copiers and other devices.
An administrator can define where a device is permitted to send scanned documents. For example, a company might allow destinations such as:
- employee@company.com
- accounting@company.com
- records@company.com
while rejecting destinations that aren’t permitted by company policy.
This means security doesn’t depend entirely on the person standing at the copier entering the correct address. CM Relay can enforce the destination policy before the message is delivered.
Protecting Against Both Mistakes and Intentional Data Theft
Destination restrictions can help with two very different situations.
Accidental disclosure: An employee mistypes an address, chooses the wrong contact, or tries to send a document to a personal account for convenience. If that destination isn’t allowed, the message can be blocked.
Intentional exfiltration: Someone with legitimate access to a copier attempts to scan confidential documents to an external account they control. Being authorized to use the copier doesn’t automatically mean they should be authorized to send company information anywhere on the Internet.
There are really two separate security questions:
Is this copier allowed to send email?
and:
Where is this copier allowed to send information?
A secure Scan-to-Email setup should consider both.
Don’t Forget About the Copier
Businesses increasingly control USB storage, cloud file sharing, automatic email forwarding, endpoint uploads, and other ways sensitive information can leave the organization.
The office copier deserves the same consideration.
An employee might be prevented from copying a confidential file from a workstation to a USB drive, while still being able to print that document, walk over to a copier, scan it, and email the PDF to an external address.
Security controls should follow the information, not just the computer where the information happens to be stored.
A Simple Control That Can Reduce an Unnecessary Risk
Scan-to-Email is useful, and businesses shouldn’t have to give it up just because traditional email authentication and security requirements have changed.
But Scan-to-Email doesn’t need to mean unrestricted email.
By controlling the destinations that copiers are permitted to send to, businesses can reduce the chance of sensitive documents being sent to personal email accounts, unauthorized external recipients, or simply the wrong person.
For organizations handling financial records, customer information, employee data, healthcare information, legal documents, intellectual property, or other confidential material, this can be an important additional layer of security.
CM Relay gives administrators control over not only how their copiers and other devices securely send email, but where those messages are allowed to go.
