
Businesses that have already been struggling to keep out the growing number of cyber threats would have been happy to see AIs now adding to their list of concerns.
Hardly a week passes without yet another headline of an attack engineered by AI or worse, by an AI that had escaped the safe confines of its test environment.
With so much to manage, businesses need to focus on getting their foundation right, like getting visibility of their digital assets and using AI too to secure the infrastructure, according to Japanese firm Canon.
For a company that provides technology management services to businesses but is known more for its printers and cameras, it also advises its clients not to forget the printer or multi-functional device (MFD) that sits in a corner of the office and remains a possible loophole for hackers.
While AI is worrying organisations, they should also secure the many connected devices in their network, says Hiroshi Yokota, senior vice-president for regional digital printing and business solution operations at Canon Singapore.
“Organisations must treat printers and other Internet of Things (IoT) devices as integral parts of their core cybersecurity strategy rather than peripheral assets,” he tells Techgoondu in this month’s Q&A.
NOTE: Responses are edited for style.
Q: An AI recently “escaped” its sandbox and went on to hack other companies to accomplish its given task. Given how fast these AI-powered threats are appearing – including those engineered by hackers – what areas should businesses focus on with their limited budgets and capabilities?
A: Autonomous, AI-driven threats bypassing traditional sandboxes prove that the threat landscape is evolving faster than corporate infrastructure can keep pace.
For businesses navigating these shifting dynamics with limited budgets and capabilities, trying to defend every single digital asset equally is operationally challenging. They must instead focus resources on areas that yield the highest impact, such as visibility and the security of their digital footprint.
With almost 40 per cent of cyber attacks in Singapore targeting small- and medium-sized enterprises (SMEs), a secure foundation is essential for these organisations to scale and innovate with confidence in today’s digital world.
Building a clear cybersecurity plan allows businesses to establish foundational visibility over their digital footprint and prioritise risk mitigation effectively.
With a solid cybersecurity plan in place, investing in the right automated security tools enables rapid incident response, while regular cybersecurity awareness training fosters cyber-safe behaviours and strong cyber hygiene across the workforce.
Rather than attempting to build an expensive, in-house security operations centre, resource-constrained firms can also maximise their resilience by leveraging trusted partners to manage their broader security ecosystem. This ensures that even small businesses can close critical visibility gaps without needing to hire specialised cybersecurity professionals.
Q: If well guarded servers are susceptible to the advanced capabilities of AI, then would it mean connected devices such as printers that are often set up and forgotten are even easier targets? What happens if they are compromised?
A: Connected edge devices like MFDs are critical vulnerability points because print environments remain an often-overlooked security exposure within the enterprise network. When a device is set up and forgotten, it effectively turns into a silent backdoor.
Bad actors can then exploit the MFDs’ connectivity to access document data in the system, extract sensitive corporate credentials, or use the device as a strategic entry point to move laterally across the organisation’s network. In some cases, compromised devices can even be recruited into botnets to launch wider attacks on other organisations.
To counter this, a security-by-design philosophy must govern device-level protection from the earliest stages of product development. This enables organisations to bridge the gap between physical and digital security by leveraging a unified defence that secures the entire business ecosystem – from the multi-function devices (MFDs) in the office to the networks these devices are connected to.
Ultimately, organisations must treat printers and other IoT devices as integral parts of their core cybersecurity strategy rather than peripheral assets. Integrating these endpoints into broader Security Information and Event Management (SIEM) solutions will also ensure the print environment is never overlooked.
By maintaining regular firmware updates, enforcing strong authentication, and including connected devices in continuous monitoring and incident response programmes, businesses can effectively neutralise these risks before cyber threats can impact organisations.
Q: Using AI to fight AI seems to be the only way forward. How would you deploy AI to safeguard your business?
A: Deploying AI as a core pillar of risk management requires shifting from a reactive posture to predictive, continuous defence. In an environment where automated attacks are executed in real time, human intervention alone can no longer intercept anomalies before the attacks occur.
With the use of AI, organisations can analyse vast volumes of device and network usage data in real time across the enterprise ecosystem, and flag or isolate any suspicious activities before they escalate.
By embedding AI capabilities into managed detection and response frameworks, businesses can reduce potential security gaps. AI can also be leveraged for proactive threat hunting and real-time response automation, which enables organisations to reduce their response time to threats.
However, organisations cannot view AI as a standalone solution for cybersecurity. To truly safeguard a business, AI must be seamlessly integrated into a holistic security model that protects every layer of the enterprise, from physical devices and critical information assets to the broader network environment.
Deploying AI as the “connecting engine” across these physical and digital layers is what enables an organisation to build a resilient, scalable defence capable of countering modern AI-driven threats.
Q: With so much data sitting in different locations, from the edge to the cloud, is it possible for a company to patch all its vulnerabilities?
A: Modern enterprise IT ecosystems are expanding faster than ever across cloud, edge, and local servers. This increasingly complex attack surface leaves security teams with a critical challenge: patching every single vulnerability instantly is no longer practical due to the sheer scale of the environment and the limited time and resources available.
Businesses should focus on achieving continuous operational resilience instead. Achieving an optimal security posture requires creating a structured environment governed by security-by-design principles.
This means knowing exactly where sensitive data sits, paying strict attention to often-overlooked endpoints like MFDs, and deploying robust information management solutions to eliminate fragmented silos. When organisations establish clear data visibility and secure physical access points, they create a highly structured environment that can help contain threats more effectively.
Rather than chasing every minor software patch, IT teams should focus on building a robust ecosystem that supports automated vulnerability management with 24/7 continuous monitoring across endpoints, email, and cloud applications. While vulnerabilities are an inevitable reality of digital growth, rapid detection and mitigation are what define a truly resilient enterprise.
