Two-thirds of organisations in the UK, France, Germany and the US suffered a print-related data loss in the past year, and Quocirca now puts the average cost of a print-related data breach above £1 million. Only 31% of organisations rank office print infrastructure among their top security priorities, placing it seventh behind concerns such as cloud, AI and email.

Those numbers come from Quocirca’s Print Security Landscape 2026, published in July 2026. MPS Monitor is included in the report for the fifth consecutive year, assessed alongside manufacturers and platform providers from across the print industry.

What Quocirca says about MPS Monitor

The 2026 vendor assessment looks at how print security offerings are built, governed and evidenced. In its profile of MPS Monitor, Quocirca writes that the company “is strengthening its security credentials by embedding security controls into its cloud platform and the agent layer that connects customer environments to its service”, and that “MPS Monitor’s strongest differentiator is the consistency of its security-by-default and by-design posture across governance, monitoring, and remediation”.

The analyst records four areas of strength:

  • Security governance with independent validation. An Information Security Management System (ISMS) certified to ISO/IEC 27001:2024, a SOC 2 Type 2 audit, CSA STAR Level 2 accreditation and GDPR compliance, with the certifications and the accreditation maintained under recurring independent assessment.
  • Security focus on the agent layer. Secure communications, release validation and external testing of the Data Collection Agent (DCA), the component that sits closest to the customer’s network.
  • Identity-centric access controls. Single sign-on (SSO), multi-factor authentication (MFA) and role-based access control, aligning permissions with organisational roles.
  • Operational security maturity. Penetration testing, red-team exercises and continuous vulnerability scanning, which Quocirca reads as “a shift toward continuous assurance rather than point-in-time compliance”.

The security question that gets less attention

Print security is usually discussed as something done to a customer’s fleet, through print management and device controls: secure release, mandatory authentication, firmware governance, driver control. All of that matters, and Quocirca’s findings show how much ground is still to be covered on it.

There is a second exposure that receives far less attention. The software used to manage the fleet forms part of the customer’s attack surface in its own right. A data collection agent runs inside the customer’s network, holds a permanent channel to a cloud service, receives commands and software updates, and in some deployments enables remote access to device interfaces. It is a link in a software supply chain that reaches from the platform vendor, through the dealer, into the end customer’s network.

Quocirca’s 2026 data shows security expectations rising across that chain. Integration between print infrastructure and identity platforms such as Active Directory and Entra ID is now rated extremely important by 41% of organisations, up from 34% in 2024, reaching 52% among the most security-mature. Organisations Quocirca classifies as print security leaders, those with at least six security measures in place, report fewer print-related data losses than laggards (56% against 73%) and much higher satisfaction with their supplier’s security capabilities (48% against 23%). Supplier choice is now visible inside the customer’s own security assessment.

For anyone building and operating a SaaS platform for Managed Print Services (MPS), that puts the burden of proof on the vendor: certifications kept current under recurring independent audit, security testing run continuously, and a data collection agent engineered, tested and released as a security component of the customer’s environment. This is also what makes an analyst assessment useful to a dealer. It is a document written by a firm the customer’s IT team already knows, applying the same published criteria to each vendor it assessed, which carries a weight that supplier material does not.

Before you build an MPS practice on a SaaS platform, put these questions to the vendor:

  • Which certifications do you hold, to which version of the standard, and when were they last independently audited?
  • How is the data collection agent secured, tested and released, and who reviews that code?
  • How often is the platform penetration tested, and will you share the results under NDA?
  • Does access control integrate with the identity provider our customers already use?
  • What happens, and how quickly are we told, when a vulnerability is disclosed?

Answers in writing give a dealer something to pass straight to a customer’s compliance team. Without them, the dealer ends up vouching for a platform they have no visibility into.

Read the full Quocirca analysis

The MPS Monitor excerpt of Quocirca’s Print Security Landscape 2026 includes the complete vendor profile, the executive summary, the full set of key findings and Quocirca’s recommendations for suppliers and buyers. Download it to read the analyst’s assessment in full, and to bring the findings into your own customer conversations.

 

Frequently asked questions

What is Quocirca’s Print Security Landscape?

It is an annual study by Quocirca, an independent market research firm specialising in print and digital technologies, examining print security practices among organisations in the US and Europe. The 2026 edition combines market research with a vendor assessment of print security offerings across the industry.

Why does the monitoring platform matter to print security?

A printer fleet management platform collects data from inside the customer’s network through an agent that maintains a permanent connection to a cloud service. Its certifications, its development practices and the way that agent is secured all form part of the customer’s exposure, alongside the security of the devices themselves.

What security certifications does MPS Monitor hold?

MPS Monitor operates an ISMS certified to ISO/IEC 27001:2024, is audited against SOC 2 Type 2 and holds CSA STAR Level 2 accreditation. The certifications and the accreditation are maintained through recurring independent assessment on a defined audit cycle. GDPR compliance is governed within the same ISMS.

How can a dealer use this report in a sales conversation?

The report gives an independent description of the print security landscape and of the platforms serving it. Dealers commonly use analyst material to answer customer security questionnaires, support responses to enterprise tenders, and open a structured conversation about a customer’s own print security maturity.

How long has MPS Monitor been included in Quocirca’s print security research?

The 2026 edition is the fifth consecutive year MPS Monitor has been included in Quocirca’s Print Security Landscape. The company was also named an Innovator in Quocirca’s 2026 ACT Print Industry Ecosystem report, and has been included in research by Keypoint Intelligence.

 

Download Quocirca’s Print Security Landscape report excerpt here

Quocirca Print Security landscape report 2026

START YOUR JOURNEY
WITH MPS MONITOR