Skip to content

Is Public Wi-Fi Safe? The Real Risks for Your Business

Published March 13, 2024, updated August 4, 2026

Is Public Wi-Fi Safe? The Real Risks for Your Business

Public Wi-Fi is much safer than the old advice suggests, because nearly every website you use for work now encrypts its traffic with HTTPS, the padlock-in-the-browser standard that scrambles data between your device and the site. The person at the next table cannot casually read your email over the coffee shop network the way warnings from a decade ago described. What still deserves attention is different: look-alike hotspots, the sign-in pages they show you, and above all the condition of the device doing the connecting.

This post is for owners and office administrators whose staff sometimes work from a coffee shop in Gilbert, a hotel lobby, or a gate at Phoenix Sky Harbor, and who want to know which of the old rules still matter. The short version: worry less about the network and more about the laptop.

What changed since the classic advice was written

The standard public Wi-Fi warnings date from a time when most websites sent data in the clear, so anyone on the same network with freely available software could capture logins and read sessions as they went past. That era is over for the everyday web. Google's HTTPS transparency report shows the overwhelming majority of pages loaded in Chrome now travel encrypted, and the Federal Trade Commission's guidance on public Wi-Fi networks says plainly that because of that encryption, the risks are lower than they used to be.

What website-level encryption means in practice: even on a completely open network, what you send to your bank, your email, or Microsoft 365 is scrambled before it leaves your device. Someone watching the network can see that your device talked to a particular service, but not what was said. That is a real improvement, and advice that pretends otherwise tends to get ignored because it no longer matches what people experience.

What can still go wrong

Look-alike hotspots. An attacker can broadcast a network named to match the venue, the hotel name with "Guest" or "Free" added, and wait for people to connect. The payoff today is usually not reading your traffic, which HTTPS mostly blocks anyway. It is the fake sign-in page the hotspot shows you, which asks for an email address and password, or a room number and card details. That page is a phishing form wearing a captive portal costume, and anything typed into it is gone. Confirm the network name with an employee, and never enter a password you use anywhere else into a hotspot's sign-in page.

Auto-join. Phones and laptops remember network names and reconnect to them automatically. A device that once joined a network called "Free Airport WiFi" can join any network broadcasting that name later, anywhere, without the owner noticing. Turning off auto-join for public networks, and forgetting them after use, closes that door.

Traffic HTTPS does not cover. Older line-of-business applications, some legacy email configurations, and the DNS lookups that reveal which sites a device asked for can still travel unencrypted. Most modern software is fine. The exceptions tend to be the aging practice management or accounting tools a business has run for years, which is one reason the answer for regulated work looks different, as covered below.

The oldest risks in the room. A screen visible to the person behind you, a laptop left at the table during a coffee refill, a bag taken from a chair. None of these involve Wi-Fi at all, and in most real incidents involving work in public, they are the plainer explanation. A privacy screen, a short auto-lock timer, and full-disk encryption cover far more ground than any network setting.

The better habit: use your phone's hotspot

For anything sensitive, the simplest upgrade is to skip the public network entirely and tether to your phone. The National Security Agency's guidance on securing wireless devices in public settings recommends a personal hotspot over public Wi-Fi for exactly this reason: it is a network you control, protected by a password only you know, with nobody else on it. The old objections, battery drain and data caps, matter much less than they did, and for a few hours of documents and email the data use is modest.

It is also a good default to hand to staff because it requires no judgment calls. The answer is the same everywhere: hotspot first, public Wi-Fi for the low-stakes rest.

What a VPN actually adds, and when to bother

A VPN, a virtual private network, encrypts everything leaving the device and routes it through a server you trust, covering the gaps HTTPS leaves: legacy application traffic, DNS lookups, and anything else that would otherwise travel in the clear. If your team works with regulated data on the road, or depends on older software, a business VPN is still worth running on untrusted networks.

Two honest caveats. A VPN does nothing about phishing, so the fake portal page problem is untouched. And a free consumer VPN from an unknown vendor can be worse than nothing, because it routes all of your traffic through a company you know nothing about. If a VPN is worth using, it is worth using one your business chose deliberately. Many businesses we work with end up going a step further and making the network irrelevant: managed devices that are patched, encrypted, and monitored wherever they sit, with sign-in rules that check the device before granting access. That is the approach our security practice builds toward, because it protects the person who forgot the rules along with the person who followed them.

The device matters more than the network

Almost everything on the traditional public Wi-Fi checklist is really a device question, and a business can settle it once, centrally, instead of hoping each person remembers.

  • Patching. An up-to-date operating system and browser close the holes that network-based attacks need. A patched laptop on an open network is in better shape than an unpatched one on the office Wi-Fi.
  • Disk encryption. BitLocker on Windows, FileVault on Mac. If the laptop is stolen from the table, the data on it stays unreadable.
  • Endpoint protection. Modern detection software watches behavior on the device itself, which travels with it to every network.
  • Multi-factor authentication. If a password does get phished at a fake portal, a second factor is what keeps the account from falling with it.
  • Sensible network settings. The "public network" profile in Windows, file sharing off, auto-join off. Set once through management tools rather than per machine.

Keeping that baseline true across every laptop and phone, month after month, is routine work for a managed IT service and nearly impossible to sustain by memo.

If your team handles patient or client data

For medical and dental practices, law firms, and accounting firms, the question usually arrives as "is it a violation to work on public Wi-Fi." The HIPAA Security Rule does not name Wi-Fi at all. It requires safeguards, encryption in transit and at rest, access controls, and the ability to show your risk was assessed and addressed. A managed, encrypted laptop connecting through a hotspot or VPN can satisfy that. A personal laptop on hotel Wi-Fi with a shared password cannot, no matter how careful the person using it is. If you are unsure where your setup lands, that is a compliance conversation worth having before an auditor or an insurer asks it for you.

Frequently asked questions

Is public Wi-Fi safe to use?

For ordinary browsing on an up-to-date device, generally yes. Nearly all websites now encrypt traffic with HTTPS, so the classic fear of someone reading your session over the network is largely handled. The remaining risks are look-alike hotspots, phishing pages, and working with sensitive data on a device nobody manages.

Do I still need a VPN on public Wi-Fi?

Sometimes. A VPN encrypts everything leaving the device, including traffic from older applications and DNS lookups that HTTPS does not cover, so it still earns its keep for regulated work or legacy software. For quick email and browsing on a patched, managed device, a phone hotspot is often the simpler answer.

What is a rogue hotspot or evil twin?

A Wi-Fi network an attacker sets up with a convincing name, such as the hotel's name with a word added, hoping people connect to it. The modern danger is mostly the fake sign-in page it shows you, which harvests whatever password you type. Confirm the network name with staff and never reuse a real password on a portal page.

Is my phone's hotspot safer than public Wi-Fi?

Usually, yes. A personal hotspot is a network you control, encrypted with a password only you know, with no strangers on it, and NSA guidance recommends it over public Wi-Fi for exactly that reason. The trade-offs are battery drain and cellular data use, which matter less than they used to.

What should a business require before staff work on public Wi-Fi?

A managed, patched device with disk encryption and endpoint protection, multi-factor authentication on every account, auto-join turned off, and a rule against typing real passwords into hotspot sign-in pages. Get those in place and the specific network matters far less, because the protections travel with the device.

So, is public Wi-Fi safe for your business?

Safe enough for the everyday, on a device that is patched, encrypted, and managed, with a phone hotspot or a trusted VPN for anything sensitive. The network in the coffee shop was never really the thing you controlled. The laptop is, and that is where the effort pays.

If you would like a plain read on how your team's laptops and phones would hold up on networks you do not control, Desert Lakes Solutions offers a no-pressure discovery call to walk through your current setup and where the easy wins are. Book a discovery call.

Find out where you stand

Tell us a little about your business and what is prompting this. We will come back with a clear scope and a fair, written quote, usually within one business day.

Call (855) 737-9500 / (480) 573-3349

Email [email protected]

15-minute response on critical issues, 24/7. Onboarding in two to three weeks.

We reply within one business day. No spam, no pressure.