Symphion provides operationalized cybersecurity for printers and connected IoT endpoints through vendor-agnostic technology, managed services, and continuous cyber hygiene processes. Its Symphion Managed Endpoint Cybersecurity Operations Program for Printers & Connected IoT, or The Symphion Program, provides services including evergreen inventory, drift detection, remediation, certificate lifecycle management, password and configuration posture management, firmware maintenance, baseline enforcement, recovery, governance, and reporting across mixed device fleets. Pulse 2.0 interviewed Symphion CEO Jim LaRoe — who is also a noted author and speaker focused on printer and IoT endpoint risk and protection — to learn more about the company’s evolution, the security risks surrounding printers and connected IoT devices, and why these endpoints often fall outside traditional enterprise cybersecurity programs.

How Symphion Evolved
When asked how Symphion evolved into the company it is today, LaRoe explained:
We built our first CMDB in 2004 with agentless scanning and delivered it as a remotely managed service to support IT outsourcers, delivering their reporting responsibilities for all in-scope IT assets.
In 2015, a printer OEM contacted us to support its newly acquired IT services company and we discovered the entire printer endpoint class, the most mature and complex of IoT endpoints.
Most importantly, we saw how printers had grown up outside of the protections routinely applied to other more mainstream endpoints like PCs and laptops.
We developed vendor-agnostic software and a programmatic approach to protecting them that addresses the unique complexities involved.
That is where we are focused today.
The Symphion Program, short for The Symphion Managed Endpoint Cybersecurity Operations Program for Printers & Connected IoT, is our answer to the risk faced by businesses across industries.
It is a Done-For-You, or DFY, program that delivers and continuously maintains cyber hygiene for protecting the forgotten and unaddressed printer and connected IoT endpoint classes.
We assume the complexities of each business and continuously deliver protection outcomes.
What Has Surprised Symphion Most
When asked what has surprised him most, LaRoe said:
The absolute nonchalant and indifferent approach companies have shown toward not protecting these complex and numerous endpoint classes.
Leaders have not wanted to deal with printers.
IT doesn’t want another job.
InfoSec has bigger fires.
Supply Chain and MPS are managing cost, device uptime and supplies, not protecting them.
So, an enterprise can have thousands or tens of thousands of printers and other IoT sitting on its network while everyone assumes somebody else has them handled.
We find that they are invisible to the protections routinely applied to other endpoints and organizations still have no plan to do anything differently.
This stance is especially surprising given the realities of the 2026 threat environment.
Why Printer And IoT Endpoints Are Often Unaddressed

When asked why printers and other connected IoT endpoint classes have often been forgotten or left unaddressed, LaRoe explained:
Because they don’t fit neatly into the way enterprises have divided responsibility.
Supply Chain may own procurement and the managed print services, or MPS, relationship.
IT owns the network, infrastructure and operations.
InfoSec owns the risk.
OEMs built security capabilities into the devices.
Yet, they are not used and nobody owns continuously applying, maintaining and proving cyber controls across the endpoint class.
That creates the condition we see repeatedly: no owner, no budget, no action. Thousands of mission-critical, exposed endpoints.
The Symphion Program
When asked what The Symphion Program is, LaRoe explained:
The Symphion Program is our Done-For-You program that delivers and continuously maintains cyber hygiene for these forgotten and unaddressed printer and connected IoT endpoint classes.
We take an endpoint class that typically has no reliable inventory, has been kept at factory defaults, or configured once and never checked again, no firmware updates, no certificates and no visibility to new devices or adds, moves and changes, and establish a known baseline and required control state, implement the controls and continuously keep it there.
The program includes evergreen inventory; implementation and maintenance of the required control state; continuous drift detection and remediation; firmware maintenance; password and credential lifecycle; closed-loop certificate lifecycle and machine identity; backup and recovery; and the governance around all of it, including PMO, testing and turn-up, change control, reporting and evidence.
It is not another platform the customer has to staff and operate.
We deliver the program and the outcome: solved and kept solved.
Why The 2026 Threat Environment Is Different
When asked why 2026 represents a different cybersecurity environment for these endpoints, LaRoe said:
The endpoint problem isn’t new. The environment around it is.
Attackers are using AI as it is exponentially upgrading.
Zero Trust is pushing identity down to the machine level.
802.1X, machine identity and certificate lifecycle matter.
IPP, Mopria and the transition toward driveless printing are changing the environment.
At the same time, large fleets containing devices of different OEMs, ages, models, firmware and capabilities are still on networks.
Those changes increasingly require enterprises to know exactly what these devices are, whether they can comply with current requirements and what they are going to do with legacy or unsupported devices that cannot.
What was already an unaddressed endpoint class is colliding with a very different threat and technology environment.
Continuing to do nothing or not properly addressing these endpoints is a decision to remain exposed in the face of increasing threats.
Why Enterprises Have Not Already Addressed The Problem
When asked why enterprises have not already addressed these endpoints despite having them on networks for years, LaRoe identified several common assumptions:
Four beliefs keep getting in the way: they’re just printers, from analog beginnings and the supply procurement motion; they’re not really risky; we’re digitizing them away; and they’re already managed.
Then there is the organizational reality.
Who owns the risk? Who owns the execution? Who has the budget?
If those answers cross InfoSec, IT, Supply Chain, the OEM and an MPS provider, it is very easy for the endpoint class to remain everybody’s issue and nobody’s responsibility.
No owner. No budget. No action.
Managed Does Not Mean Protected
When asked whether printers are already managed by IT, OEMs, or MPS providers, LaRoe explained:
Yes, many are managed.
But managed does not mean protected or governed.
OEMs have built security capabilities into their devices.
MPS providers perform the services they were retained to perform that do not include cyber hygiene.
A printer can be inventoried, metered, serviced and automatically replenished with toner while the same endpoint still has factory-default credentials, outdated firmware, an expired or missing certificate, or a configuration that has drifted from the required state.
The device also enjoys administrator-level trusted access to other systems such as email, file server and LDAP.
The gap to fill is continuously operationalizing cyber hygiene across the life of the fleet, regardless of the composition of the fleet.
That means knowing every device, knowing its required state, identifying new and vanished devices, detecting drift, remediating it, maintaining firmware, credentials and certificates, dealing with lifecycle changes and producing evidence that the controls remain in place.
The question isn’t whether somebody manages the printer.
The questions are “who is continuously governing the endpoint” and “are we protected”?
Competitive Differentiation
When asked what differentiates Symphion from other approaches, LaRoe explained:
We deliver outcomes, not dashboards and more work.
There are plenty of products that can discover something, identify a vulnerability, generate an alert or tell the customer what somebody needs to go do.
That can simply move the problem onto an already busy IT team.
Symphion owns the execution.
We implement the controls, continuously identify change and drift, remediate it, manage the lifecycle work, coordinate with stakeholders and provide the evidence.
The customer gets the outcome without having to build, staff and continuously operate another program.
Maintaining Cyber Hygiene Without Disrupting Operations
When asked how Symphion continuously maintains cyber hygiene without disrupting customer operations, LaRoe explained:
Avoiding disruption is built into The Symphion Program.
It is not an afterthought.
We operate through PMO and stakeholder coordination, blueprinting, dependency mapping, testing and turn-up, staged deployment, backup and restore, quiescing when required, firmware prerequisites, change control and CAB coordination, and ongoing reporting.
The objective isn’t to impose cyber controls in a vacuum.
It is to continuously maintain them inside the customer’s real operating environment without creating another operational burden.
In many accounts nothing has been done at all.
They may have thousands of printers, no reliable inventory, unsupported devices, no plan and no idea where to start.
The program gives them a current inventory, known control state, backups, configuration information and the people and process to respond when something changes or an incident is being investigated.
In a healthcare environment, that also means being able to respond while continuing patient care.
One customer, after an implementation of over 7,000 printers, said, “you told us we didn’t need to know printers and you were right.”
Reporting is part of the outcome.
InfoSec and GRC get evidence of what exists, the controls being maintained, exceptions and unsupported devices, remediation activity and current state.
Future Goals
When asked where Symphion goes from here, LaRoe said:
The larger opportunity is the problem we are already solving: connected IoT endpoint classes that don’t fit neatly into mainstream endpoint protection and have been forgotten, excluded or left to somebody else.
Printers, for example, by rough estimates, number over 30 million on corporate networks in the U.S. alone.
They demonstrate the problem at enormous scale.
Cameras are a close second.
Symphion is not moving from printers to IoT.
The same programmatic problem already exists across connected endpoint classes.
Printers are simply an enormous, mature and neglected example of it.
The Symphion Program provides the program to deliver and continuously maintain cyber hygiene for those forgotten and unaddressed endpoint classes.

