← Back to list

The Quietest CUI Risk in Your Facility: 10 Questions to Expose It

20 years later, the same blind spots still exist — and they’re sitting in plain sight.

Mark P. Milton · 2026-05-01 15:20 · 2 claps · 4.6 min read
#printing #icu #cmmc-compliance #cybersecurity-awareness #department-of-defense
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

The Quietest CUI Risk in Your Facility: 10 Questions to Expose It

20 years later, the same blind spots still exist — and they’re sitting in plain sight.

This is all the CUI we have in this area — marked CUI

This is all the CUI we have in this area — marked CUI

Walk any shop floor long enough and you’ll see the same pattern: people pointing out the things they think matter. Machines. Workstations. Cabinets. Maybe a server rack somones wants to show-off.

But printers? Plotters? Digital senders? Those get treated like furniture.

The walkthrough starts. Someone gestures at a CNC. Someone else mentions a workstation. A few notes get scribbled. Everyone nods. The count begins.

And while they’re talking, I’m doing what I’ve done for twenty years — silently counting.

Plotter there. Digital sender tucked in the corner. Two multifunction printers by the tool crib. Another one near the break area. One standalone printer nobody remembers buying.

I don’t say a word. I just keep the tally in my head and jot the locations on my notepad.

By the time we reach the end of the tour, the number is already locked in.

Five plotters. Two digital senders. A handful of multifunction printers. One standalone printer.

Then we head back to the conference room for the debrief.

I flip open the notebook and drop the line I’ve said a hundred times:

On our walkthrough, did anyone else notice the five plotters, two digital senders, and at least five multifunction printers — plus one standalone printer?

That’s when the room shifts. The confused look — yes, its a loaded question. The pause.

“Okay… but why would those be in scope? Are they in scope?”

Yes, they’re in scope. Printers and plotters aren’t passive. They’re computers. They store jobs. They transmit data. They retain images. They sit in the middle of workflows that handle CUI every single day.

But because printers don’t look like computers, they get ignored like furniture.

And that’s how exposure hides in plain sight.

Vendor tethered to a Plotter working on a CUI Diagram.

Vendor tethered to a Plotter working on a CUI Diagram.

As we continued to debrief I mentioned that I also noticed in one shop the plotter that was tucked against a wall — nothing special at first glance. No network cable. No markings. Just a big machine that printed big drawings.

Who uses this?” “Anyone who needs to print a drawing.” “Do vendors use it?” “Yeah, sometimes.”

Then I saw the USB cable.

A vendor workstation — unmanaged, unmonitored, unpatched — tethered directly to a plotter that printed CUI drawings all day long. No secure print. No access control. No sanitization. No markings on the output.

Just a quiet, steady stream of sensitive data flowing through a device no one considered part of the system.

And when the prints were done?

“They usually pin them to the board so the team can work off them.

Pinned. Unmarked. Visible to anyone walking by.

That’s not a hypothetical risk. That’s exposure in motion.

This is the part people forget: CUI doesn’t care whether a device is IT, OT, vendor‑owned, or “just a printer.” If it processes, stores, or outputs CUI, it inherits the full control requirements.

No exceptions. No interpretations. No “but it’s just a plotter.”

This is the key part that makes this unique.

This is the key part that makes this unique.

Another key issue found during the tour the group ahead of us crossed the purple “DO NOT CROSS” line. Machines hum. Operators move. Everything looks controlled, orderly, intentional.

Then the tour lead points at the wall.

A large technical print — detailed, precise, and completely unmarked — hangs in full view. The group leans in. They study it. They talk about it. They admire it.

No one realizes what they’re looking at.

No commentary. No warning. Just the quiet tension of a moment where the truth is visible but unspoken.

This is the part that makes the whole thing unique — not the machines, not the controls, not the floor markings.

It’s the drawing. The unmarked, unprotected, untracked drawing.

The one thing no one thought to question.

THESE 10 QUESTIONS THAT CHANGED EVERYTHING

These ten questions expose more CUI risk than any tool, scan, or checklist:

  1. Who prints here?
  2. Do they print CUI?
  3. Is the device networked, USB‑connected, or standalone?
  4. Does it have internal storage?
  5. Is secure print or follow‑me print enabled?
  6. Who can walk up and use it?
  7. Who can scan to email?
  8. Where do printed drawings go after use?
  9. Are prints marked and shielded from unauthorized view?
  10. Is the device in your inventory, baseline, and sanitization policy?

If these can’t be answered, control doesn’t exist. Only assumptions do.

THE REAL PROBLEM: Printers and Plotters fall into no-man’s-land;

Printers and plotters fall into a no‑man’s‑land:

  • Facilities buys them
  • Vendors install them
  • Operators use them
  • IT assumes they’re “just printers”
  • Compliance teams never walk the floor

So they slip through the cracks — not because anyone is negligent, but because no one owns them.

And when no one internally really owns the device, no one protects it.

Hey, don’t forget me-without me you wouldn’t be able to Print CUI…

Hey, don’t forget me-without me you wouldn’t be able to Print CUI…

THE FIX IS SIMPLE — BUT NOT OPTIONAL

You don’t need complex controls. You need simple discipline.

  • Inventory every device that can touch CUI
  • Identify whether it stores jobs
  • Disable storage where possible
  • Enable secure print
  • Move devices to controlled VLANs
  • Lock down/encrypt scan‑to‑email
  • Add drives to the sanitization chain
  • Setup periodic sanitization wipes of hard drives
  • Shield prints on the shop floor
  • Treat OT‑adjacent devices like systems

This is not advanced cybersecurity. This is basic stewardship of sensitive data.

The forgotten devices aren’t a future compliance failure. They’re a current one.

If printers, plotters, and digital senders aren’t in the SSP, they’re still in the environment — collecting, storing, and exposing CUI every day.

Security requires acknowledgment. Compliance requires visibility. Both require knowing where the data lives.

And most of the time?

It’s sitting right there on the wall. Unmarked. Unprotected. Unnoticed. Unclaimed and collecting a library of CUI in Plain Sight.

If you enjoyed this article, follow me on Medium.

I’ve spent decades building this experience — and now I’m spending the next decade giving it away. The same problems keep showing up, and it’s clear we’re still fighting the same battles we were twenty years ago.

You can also visit CompliancePages.com to explore everything compliance — built from real assessments, real environments, and real lessons learned.

Thanks for reading. — Mark


메타데이터
post_id
fca05af3da37
slug
the-quietest-cui-risk-in-your-facility-10-questions-to-expose-it-fca05af3da37
url
https://medium.com/@mark_3934/the-quietest-cui-risk-in-your-facility-10-questions-to-expose-it-fca05af3da37
canonical_url
https://medium.com/@mark_3934/the-quietest-cui-risk-in-your-facility-10-questions-to-expose-it-fca05af3da37
author_url
https://medium.com/@mark_3934
status
ok
fetched_at
2026-06-09 15:37:30