How to Stay Safe on Public Wi-Fi and in Public Places

How to Stay Safe on Public Wi-Fi and in Public Places

Whether you're working from a coffee shop, checking an email at an airport, staying at a hotel, or connecting to Wi-Fi at a library, public spaces make it easy to stay connected wherever you are.

But connecting outside your home or workplace can introduce additional cybersecurity and privacy risks. You may be connecting to an unfamiliar network, working around people you don't know, or using a public charging station to power your device.

That doesn't mean you need to avoid public Wi-Fi or stop using your devices in public. By understanding the risks and taking a few practical precautions, you can help protect your information, accounts, and devices while staying connected.

Is Public Wi-Fi Safe?

Public Wi-Fi isn't unsafe, but it shouldn't immediately be trusted either.

Websites and apps today commonly use encryption to protect information as it travels between your device and the service you're using. When browsing the web, look for HTTPS and the lock symbol in your browser's address bar.

However, encryption doesn't protect you from every threat.

A fake Wi-Fi network can be created to look like a legitimate network at a coffee shop, airport, hotel, or other public location. Someone may also use a convincing website or login page to trick you into providing sensitive information.

The safest approach is to treat public networks as untrusted connections and take steps to protect your accounts and devices.

How to Use Public Wi-Fi More Safely

Before connecting to a public Wi-Fi network, take a few simple precautions.

 

Verify the Network

Don't automatically connect to the first network that appears on your device.

Cybercriminals can create networks with names that look similar to legitimate networks. If you're at a hotel, airport, restaurant, or other business, confirm the network name and login process with an employee before connecting.

 

Turn Off Automatic Wi-Fi Connections

Your device may be programed to automatically connect to available wireless networks. Turning off automatic connections can help prevent your device from joining an unfamiliar or potentially malicious network without your knowledge.

When you're finished using a public network, disconnect from it and remove it from your device's saved networks if you don't expect to use it again.

 

Use Your Mobile Hotspot When Appropriate

If you need to access sensitive information or perform an important task while away from a trusted network, consider using your phone's mobile connection instead of public Wi-Fi.

A personal mobile hotspot can provide a more controlled connection than an unfamiliar public network.

 

Keep Your Devices and Apps Updated

Software updates aren't just about new features. They often include security patches that address known vulnerabilities.

Keep your operating system, browser, apps, and security software updated, and enable automatic updates when possible.

This is particularly important when you're regularly connecting to networks outside your home or workplace.

 

Use Strong Passwords and Multifactor Authentication

Public Wi-Fi isn't the only security concern. If someone gains access to one of your accounts, the consequences can extend far beyond the network you're using.

Use strong, unique passwords for your accounts and enable multifactor authentication (MFA) whenever it's available. MFA provides an additional layer of protection if your password is exposed.

Watch out for Fake Wi-Fi Networks and Phishing

One of the biggest risks when using technology in public isn't necessarily someone intercepting your connection. It may be someone trying to trick you.

For example, you might connect to what appears to be a legitimate airport or coffee shop network and then be directed to a convincing login page. A website can use HTTPS and still be fraudulent. Encryption protects the connection to the website; it doesn't prove that the website itself is legitimate.

Before entering a password, payment information, or other sensitive information:

  • Check the website address carefully
  • Be suspicious of unexpected login requests
  • Don't click unfamiliar links or attachments
  • Avoid entering sensitive information into a page you weren't expecting
  • When in doubt, navigate directly to the organization's website or app rather than following a link

 

These habits can help protect you from phishing and other scams whether you're using public Wi-Fi or your own connection.

Protect Your Devices While You're in Public

Cybersecurity doesn't stop at the network.

When you're working or browsing in a public place, someone nearby may be able to see what's on your screen, access an unattended device, or steal a laptop or phone.

Take a few precautions to protect both your device and the information stored on it:

  • Lock your screen whenever you step away
  • Don't leave laptops, phones, or tablets unattended
  • Be aware of people who may be able to see sensitive information on your screen
  • Avoid discussing or displaying confidential information in crowded areas
  • Use device encryption where available
  • Keep important data backed up
  • Report lost or stolen devices as soon as possible

 

Physical security is an important part of cybersecurity. If someone gains physical access to an unsecured device, they may also gain access to the information stored on it.

Are Public Charging Stations Safe?

Public charging stations can be convenient when your phone or laptop is running low on battery, but it's important to understand that USB connections can potentially transfer both power and data.

A compromised charging port or cable could potentially expose a device to unauthorized data access or malware. For that reason, using your own wall charger with a standard electrical outlet is generally the safer option when one is available.

If you need to use a public USB charging station, consider carrying a portable battery or USB data blocker as an additional precaution.

How Public Connectivity Can Affect Organizational Cybersecurity

For individuals, using public Wi-Fi may be a matter of protecting a personal account or device. For organizations, the stakes can be much higher.

Employees and contractors may connect to public networks while traveling, working remotely, attending conferences, or accessing organizational systems outside the office. Those connections can become part of an organization's broader cybersecurity risk.

Organizations should consider how employees access systems and information outside traditional work environments and establish security policies and controls that account for those situations.

This can include:

  • Establishing policies for remote and mobile work
  • Requiring MFA for organizational accounts
  • Protecting sensitive data with encryption
  • Providing secure remote access solutions
  • Training employees to recognize phishing attempts
  • Defining what employees should and shouldn't access from public networks

 

Cybersecurity isn't limited to what happens inside an organization's network. As work environments become increasingly mobile, security practices need to account for how and where people actually work.

Strengthen Your Cybersecurity Strategy

RAMPQuest helps organizations assess their cybersecurity programs, identify areas for improvement, and develop practical strategies for strengthening security and preparing for applicable compliance requirements.

Whether you're building a cybersecurity program, preparing for a security assessment, or working toward a specific framework such as GovRAMP, FedRAMP, or CMMC, RAMPQuest can help you understand where you are today and determine the next steps for your organization.