Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Public Wi-Fi Risks for Business Travellers (and How to Stay Safe)

In short

Public Wi-Fi in cafes, hotels and airports is convenient but rarely private. The main risks are fake hotspots and snooping on unsecured networks. The fix is simple: use your phone's mobile hotspot where you can, a reputable VPN when you can't, and always check for HTTPS. A few habits keep your business data safe on the road.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why public Wi-Fi is a business problem, not just a personal one

Working from a cafe, a hotel lobby or an airport lounge is normal now. So is connecting to whatever free Wi-Fi is on offer. For a personal catch-up on the news, that’s fine. For your business email, your accounting system or a client’s confidential documents, it deserves a second thought.

The good news: you don’t need to be technical to stay safe. You need to understand two or three real risks and adopt a couple of simple habits. This guide keeps it plain.

The real risks (and the ones that are overblown)

There’s a lot of scaremongering about public Wi-Fi. Let’s separate the genuine concerns from the myths.

Fake hotspots

This is the big one. Anyone can set up a Wi-Fi network and give it a convincing name — “Airport_Free_WiFi” or “Hotel Guest”. If you connect to it thinking it’s the real thing, everything you do passes through equipment a stranger controls. They can’t magically read everything, thanks to modern website encryption, but they can try to trick you onto fake login pages or push dodgy downloads.

Snooping on unsecured networks

On an open network with no password, other people connected to the same Wi-Fi can potentially see some of what’s happening. Again, encryption limits this a lot, but older devices, outdated apps and misconfigured software can leak information.

Out-of-date devices

A laptop or phone that hasn’t been updated is far more vulnerable on any network, public ones included. Missing security updates are one of the most common ways attackers get in — which is exactly why they matter more when you’re outside your usual office network.

The overblown bit

You’ll read that hackers can “steal everything” the moment you connect. In practice, the HTTPS padlock you see in your browser encrypts your connection to most legitimate websites, so a casual snooper sees scrambled data, not your passwords. The risk is real, but it’s specific — not the movie-style free-for-all it’s sometimes made out to be.

How to protect yourself: the simple version

1. Use your phone’s mobile hotspot first

Before you hunt for Wi-Fi, ask whether you need it at all. Your phone’s 4G or 5G connection is encrypted and private, and tethering your laptop to it (“personal hotspot”) sidesteps public Wi-Fi entirely. The safest network is often the one already in your pocket. Keep an eye on your data allowance, but for email and document work it goes a long way.

2. Use a reputable VPN when you can’t

If you do need public Wi-Fi — perhaps for a long download or a poor-signal area — a VPN (Virtual Private Network) wraps your entire connection in encryption, so even a fake hotspot sees nothing useful. The key word is reputable. Free VPNs often fund themselves by logging and selling your data, which is the opposite of what you want. We recommend a paid provider with a genuine no-logs policy, such as Proton VPN, which is straightforward to install on a laptop or phone and costs a few pounds a month.

3. Look for HTTPS

Check that the padlock and “https://” appear in your browser’s address bar before entering any login or payment details. Nearly every legitimate site uses it. If a page asks you to log in and there’s no padlock, stop.

4. Turn on multi-factor authentication before you travel

This is the safety net. With multi-factor authentication switched on, a stolen password isn’t enough for anyone to get into your account — they’d also need the code from your phone. It’s the single most effective thing you can do, and it protects you everywhere, not just on public Wi-Fi.

What not to do

  • Don’t do sensitive tasks on a fake-looking network. If a hotel’s Wi-Fi asks for unusual permissions or the name doesn’t match the one on the reception card, ask a member of staff for the correct network.
  • Don’t ignore “this connection is not secure” warnings. They exist for a reason.
  • Don’t leave Wi-Fi set to connect automatically. Your device may silently join a network with a familiar name that isn’t the one you think it is. Turn off auto-connect for public networks.
  • Don’t skip updates because you’re busy. An out-of-date device is the weak link. Install updates before you leave.
  • Don’t reuse the same password across accounts. If one leaks, the rest fall too. A password manager fixes this for good.

A quick pre-travel checklist

Before your next trip, take five minutes to:

  • Update your laptop and phone
  • Confirm MFA is on for email and key business apps
  • Install and test a VPN, or set up your phone’s hotspot
  • Turn off auto-connect for Wi-Fi and Bluetooth
  • Make sure your data is backed up, so a lost device isn’t a lost business

Done once, most of this stays done. The habits are the point.

Where DACROS fits in

Staying safe on the road is part of a bigger picture: keeping your devices updated, your accounts protected and your data backed up wherever your team works. That’s the everyday job of managed IT support — quietly handling the settings and safeguards so you don’t have to think about them.

If your team works from cafes, client sites or home as often as the office, and you’d like a sensible, jargon-free plan to keep company data safe, get in touch. We’re based in Leeds and work with small businesses across Yorkshire.

Frequently asked questions

Is public Wi-Fi actually dangerous, or is that overblown?

The risk is real but manageable. Modern websites use HTTPS encryption, which protects most of what you do. The genuine dangers are fake hotspots set up to impersonate a legitimate network, and out-of-date devices or apps that leak data. Using a mobile hotspot or a reputable VPN removes almost all of the risk, so you can work from a cafe or airport without worrying.

Should I use a free VPN to protect myself?

We'd avoid free VPNs. Many make their money by logging and selling your browsing data, which defeats the purpose. A paid VPN from a provider with a clear no-logs policy, such as Proton, costs a few pounds a month and is worth it for a business. If cost is a concern, using your phone's mobile hotspot instead of public Wi-Fi is free and very safe.

Is my phone's mobile data safer than hotel Wi-Fi?

Yes, in most cases. Your mobile network (4G or 5G) is encrypted between your phone and the operator, and there's no shared local network for anyone nearby to snoop on. Tethering your laptop to your phone's hotspot is one of the simplest and safest ways to work while travelling, as long as you have signal and enough data allowance.

What's the single most important thing to do?

Turn on multi-factor authentication (MFA) for your email and key business accounts before you travel. Even if something did go wrong on a network, MFA stops an attacker logging in with just a stolen password. Combine that with a VPN or mobile hotspot and you've covered the vast majority of the risk.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.