Adam Kangiser, Iviry’s Compliance Analyst

When manufacturers picture ITAR risk, they usually picture something dramatic: a breach, a rogue email, a bad supplier. What actually trips most companies up is smaller and a lot more mundane. In the ITAR Data in Manufacturing webinar, GRC Manager Sarah Lane walked through the gaps Iviry sees most often in manufacturing environments, starting with a risk sitting right next to the shop floor: the office printer.

Why printing can be the death of compliance

A printer doesn’t feel like IT, and it doesn’t feel like export control, but it’s both. Here’s what typically goes wrong:

  • Printed drawings and work instructions posted on the shop floor, visible to anyone walking by.
  • ITAR or CUI pages left in output trays or recycling bins after a job is picked up, or never picked up at all.
  • Printer and copier jobs cached on the device’s internal drive, often never wiped or accounted for.
  • Scan-to-email or scan-to-cloud features that bypass controlled channels entirely.
  • No clear tracking of who printed what, or where the copies ended up.

ITAR is ITAR in any form. That includes printed documents. A file doesn’t stop being controlled technical data just because it left a screen and became paper.

Other common compliance gaps in manufacturing

  • Uncontrolled PLM/ERP access: missing role-based access and need-to-know limits.
  • Unencrypted sharing: drawings and specs sent to suppliers over plain email or unsecured cloud links.
  • Foreign national access granted without proper screening.
  • Unmanaged USB drives and removable media, an easy path for data to walk out the door.
  • Shadow IT: personal cloud storage and email accounts quietly holding controlled data.

The human element is the real threat surface

According to the Verizon 2026 Data Breach Investigations Report’s manufacturing snapshot, the industry saw 3,627 incidents and 2,713 confirmed data-disclosure breaches, and the human element was cited in 56% of those breaches. Separately, the FBI’s Internet Crime Complaint Center (IC3) recorded 333,981 cyber-enabled fraud complaints in 2024, totaling $13.7 billion in losses. Business email compromise accounted for 38% of complaints, and investment fraud drove 83% of total losses.

Most of the risk on this list isn’t about sophisticated attackers. It’s about ordinary daily workflows, printing, emailing, sharing, that were never brought inside the compliance boundary.

How to close the printing gap specifically

Sarah’s team outlined four physical controls that directly close the printing risk:

  • Secure print release (badge-based pickup): jobs are held at the device until the user authenticates with a badge, so nothing sits in an open tray.
  • Restricted MFP scan destinations: scanning is limited to approved, secure destinations only.
  • Regular drive wiping and disposal procedures: internal drives are wiped on a schedule, and devices are disposed of securely at end of life.
  • Document tracking: every print, scan, and copy job is logged with user, time, device, and action, so there’s full accountability.

Physical security is stronger compliance, and stronger compliance protects the data.

Next in this series

Closing gaps like these isn’t about more paperwork. It’s about making sure your controls actually match how data moves through your business today. In our final post, we cover the specific controls to put in place, plus where ITAR compliance overlaps with CMMC. [ITAR Controls, CMMC Overlap, and Your Next Steps, link once published]

For the full session, including a complete walkthrough of these gaps, watch the recording below.

Watch the ITAR Data in Manufacturing Webinar Recording

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.