Working From Hotels, Airports and Cafés: Staying Secure on the Road
Travel puts staff on unfamiliar networks, in public places, with devices that are easy to lose. A practical guide to working securely away from the office, for travellers and the teams that support them.

Business travel changes the security picture. The office network, the locked door and the familiar routine are gone. Instead there is hotel Wi-Fi, a busy departure lounge, a laptop on a café table and a phone that is out of your hand more often than you think. None of this needs to be dangerous, but it does need a few habits.
Networks: treat public Wi-Fi as untrusted
- Check the network name with staff before connecting. Attackers can set up a network called "Airport Free WiFi" or the hotel's name.
- Use your organization's VPN if it provides one, especially for work systems.
- Prefer your phone's hotspot over public Wi-Fi for anything sensitive, such as banking or payment approvals.
- Be wary of sign-in pages on public networks that ask for your work email and password. A hotel does not need your company password.
- Turn off automatic connection to open networks, so your devices do not join one without asking.
Devices: assume they can be lost
- Lock your screen every time you step away, even for a moment.
- Make sure disks are encrypted and devices have a strong PIN or password, so a lost laptop is an inconvenience, not a data breach.
- Keep devices with you or in a locked safe, never in checked luggage or left on a table.
- Know how to report a lost device quickly, so IT can lock or wipe it remotely.
- Be careful with public charging points. Use your own charger and a wall socket where you can.
Watch the screen behind you. In airports, trains and cafés, people can read your screen and watch you type a password. A privacy screen filter is cheap, and choosing a seat with your back to a wall is free.
People: travel is when scams land
Attackers know that travelling staff are busy, distracted and harder to reach for a quick check. Messages like "I'm about to board, please pay this supplier today" work better when the real person genuinely is travelling. Keep payment verification rules in place however urgent a request looks, and be cautious with unexpected messages about bookings, flight changes or hotel payments, which are common phishing themes.
Before, during and after a trip
- Before: update devices, check the VPN works, back up important files and take only the data you need.
- During: use trusted networks, lock devices, keep them with you and verify unusual requests.
- After: report anything odd that happened, such as a lost device, a strange sign-in alert or a suspicious message, even if it seemed minor.
For security teams: a one-page travel checklist sent automatically before trips does more than a long policy nobody reads.
Security that travels with your people
Staff who travel need good habits more than anyone. CyberWatch AI's short training lessons can be completed from anywhere, and employees can check and report a suspicious message to their security team in one step, wherever they are.


