top of page
it support sheffield

Cybersecurity

Is public Wi-Fi safe for business use?

By Steve Harper  |  8 min read  | Last updated:

6 August 2026 at 15:05:31

Public Wi-Fi for Business Use

TL;DR

Public Wi-Fi can be used for business, but employees should treat it as an untrusted network.


Use a managed and fully updated business device, confirm that the network is genuine, use multi-factor authentication and follow the organisation’s remote-working policy. A company-managed VPN may be required when accessing internal systems or sending data across an untrusted connection.


When the network cannot be verified, using a trusted mobile hotspot is usually the safer option.


Key Takeaways

  • Public Wi-Fi should be treated as untrusted.

  • Employees should verify the network name before connecting.

  • A managed business device is safer than an unknown or shared computer.

  • Multi-factor authentication helps protect accounts if a password is compromised.

  • A company VPN may be required for access to internal services.

  • A mobile hotspot can be safer when the public network cannot be trusted.

  • Devices should not connect to public networks automatically.

Can your employees work securely from any location?


IT Desk can help protect remote and hybrid teams with managed devices, secure access controls, multi-factor authentication and practical remote-working policies. We can review how employees connect to company systems and reduce the risks created by unmanaged networks and devices.



What are the risks of using public Wi-Fi for work?

Public Wi-Fi is shared with people and devices the business does not control.


Potential risks include:

  • Connecting to a fake network created to resemble the legitimate Wi-Fi

  • Traffic being intercepted if an application or website does not encrypt it correctly

  • Devices being exposed through unnecessary network-sharing settings

  • Login details being entered into a fraudulent sign-in page

  • An employee’s screen being viewed by people nearby

  • A lost or unattended device being accessed

  • Business information being downloaded to an unmanaged device

  • Automatic reconnection to a network using a familiar name


Modern websites and cloud services normally encrypt information while it travels between the device and the service. This reduces some traditional public Wi-Fi risks, but it does not make every network, device or login page trustworthy.


Can employees use public Wi-Fi safely?

They can use it more safely when the business has appropriate controls in place.


A secure remote-working setup should include:

  • Business-managed laptops and mobile devices

  • Current operating-system and application updates

  • Endpoint protection

  • Multi-factor authentication

  • Strong account-access policies

  • Device encryption

  • Screen locking

  • Controlled administrative privileges

  • Secure access to internal systems

  • The ability to remotely disable or erase a lost device

  • Clear instructions for reporting suspicious activity


Security should not depend entirely on the employee recognising every technical risk. The business should configure devices and accounts so that important controls remain active wherever the employee works.



How can I check whether public Wi-Fi is genuine?

Ask a member of staff or check an official notice for the exact network name.


Attackers can create networks with names resembling those of cafés, hotels, stations or conference venues. A convincing name alone does not prove that the network is legitimate.


Employees should avoid connecting to networks that:

  • Have an unexpected or slightly misspelt name

  • Appear several times with similar names

  • Request unusual personal or payment information

  • Ask them to install unknown software

  • Require a work password that is unrelated to the Wi-Fi service

  • Produce unexpected security-certificate warnings


If there is any doubt, use a trusted mobile connection or hotspot instead.


Is a mobile hotspot safer than public Wi-Fi?

A personal or company-managed mobile hotspot is generally a better choice when the public network cannot be verified.


The mobile connection is under greater control than an open network shared by unknown users. However, it still needs to be configured securely.


The hotspot should use:

  • A strong and unique password

  • Current device software

  • Modern Wi-Fi security settings

  • A name that does not disclose unnecessary personal or company information

  • Automatic disconnection or deactivation when it is no longer needed


Employees should also consider mobile-data limits, coverage and the sensitivity of the work being performed.


Do employees need a VPN on public Wi-Fi?

It depends on what they are accessing and how the organisation’s systems are designed.


A corporate Virtual Private Network creates an encrypted connection between the employee’s device and an approved company service or network. The NCSC describes VPNs as one way to protect data travelling across an untrusted network.


A VPN may be required when employees need to access:

  • Internal file servers

  • Applications hosted on the company network

  • Remote desktops

  • Administration systems

  • Other services not safely exposed directly to the internet


A VPN may not be necessary for every cloud application if the service already uses properly configured encrypted connections and the organisation uses modern identity and access controls.


Employees should follow the company’s policy rather than installing an unapproved consumer VPN. An unknown VPN provider can introduce its own privacy, security and management risks.


A VPN also does not protect against every threat. It cannot make a fraudulent website genuine, correct an infected device or prevent an employee from sharing information with the wrong person.


Is it safe to access Microsoft 365 on public Wi-Fi?

Microsoft 365 can be accessed securely over the internet when accounts, devices and policies are properly configured.


Businesses should use controls such as:

  • Multi-factor authentication

  • Microsoft Entra Conditional Access where available

  • Managed and compliant devices

  • Microsoft Intune device policies

  • Supported web browsers and applications

  • Endpoint security

  • Restricted administrator accounts

  • Appropriate session and sign-in controls


The organisation may configure access differently according to the user, device, location and sensitivity of the information.


For example, an employee might be allowed to read ordinary company information on a managed laptop but blocked from downloading sensitive data to an unmanaged personal device.


What should employees avoid doing on public Wi-Fi?

Employees should avoid:

  • Ignoring browser or certificate warnings

  • Installing software requested by the network

  • Using shared or public computers for company accounts

  • Leaving the business device unattended

  • Discussing or displaying confidential information where others can see or hear it

  • Disabling security software to make the connection work

  • Sharing files directly with unknown devices on the network

  • Using the same password for work and public Wi-Fi services

  • Connecting automatically to any available network

  • Accessing highly sensitive systems when the connection cannot be verified


If the employee sees an unexpected login prompt, multi-factor authentication request or security warning, they should stop and contact their IT support provider.


Should file sharing be turned off on public networks?

Yes, unnecessary local sharing and device-discovery features should be disabled on public networks.


Windows allows a network to be classified as public or private. The public setting applies more restrictive discovery and sharing behaviour and should be used for networks the employee does not control.


Business devices should ideally have these settings managed centrally so employees do not need to configure them manually for every location.



What happens if an employee connects to a suspicious network?

The employee should disconnect and report the incident promptly.


They should tell IT support:

  • The network name

  • Where and when they connected

  • How long they remained connected

  • Which accounts or systems they accessed

  • Whether they entered a password

  • Whether they approved an authentication request

  • Whether any files were opened or downloaded

  • Whether the device displayed any warnings


IT support can then assess whether passwords need changing, sessions should be revoked or the device requires inspection.


Employees should not be discouraged from reporting mistakes. Early reporting gives the business a better chance of limiting any damage.


What should a public Wi-Fi policy include?

A practical business policy should explain:

  • Whether public Wi-Fi is permitted

  • When employees must use a mobile hotspot

  • When a corporate VPN is required

  • Which devices may access company systems

  • Whether confidential work is allowed in public places

  • How to confirm a network is genuine

  • Which warnings employees must not ignore

  • How lost devices and suspicious connections should be reported

  • Whether local file sharing and automatic network connection are disabled

  • How the business monitors and manages remote devices


The policy should be supported by technical controls, device management and employee training.


Businesses with remote or hybrid teams can also review IT Desk’s cloud strategy guidance for remote teams.

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

bottom of page