top of page

Your Employees Are Traveling — Is Your Cybersecurity Policy Traveling With Them?

Writer: Brian Bond
Brian Bond
Aug 11
2 min read

Organizations spend significant time and money protecting their corporate environments: firewalls, endpoint protection, MFA, conditional access, VPNs, and security awareness training.

But what happens when an employee gets on a plane, checks into a hotel, and connects that same corporate laptop to public Wi-Fi?

Your security perimeter just changed.


Recent attacks targeting hotel and conference Wi-Fi are an important reminder that cybersecurity needs to protect employees wherever they work.

Public Wi-Fi Should Be Considered Untrusted

A Wi-Fi network requiring a password doesn't necessarily make it secure.

Hotels and conference centers may have hundreds or thousands of users sharing the same infrastructure. Attackers can also compromise network equipment and potentially redirect users to malicious sites designed to steal credentials.

Employees should treat hotel, airport, conference center, and other public Wi-Fi as untrusted infrastructure.


VPN Configuration Matters

If your organization provides a VPN, employees should connect to it before accessing corporate resources.


Organizations should also evaluate whether an always-on, full-tunnel VPN is appropriate for traveling employees. Full tunneling routes internet traffic through the protected VPN connection rather than allowing some traffic to travel directly across the local network.


Sometimes the Best Wi-Fi Is No Wi-Fi

When cellular service is available, I often prefer a mobile hotspot over an unknown public network.

It doesn't eliminate every security risk, but it reduces your reliance on infrastructure you don't control.


MFA Is Important — But It Isn't Magic

MFA remains an essential security control, but attackers increasingly target authentication sessions, tokens, device authentication workflows, and users themselves.

Employees should be suspicious of:

• Unexpected Microsoft 365 login screens• Repeated MFA requests• Device-code authentication prompts• Certificate warnings• Suspicious or slightly altered URLs

Never automatically approve an MFA request you didn't initiate.


A Simple Travel Security Checklist

Before accessing company resources:

✓ Prefer a mobile hotspot when practical✓ Verify you're connecting to the correct Wi-Fi✓ Connect your corporate VPN first✓ Verify login URLs before entering credentials✓ Never ignore certificate warnings✓ Don't approve unexpected MFA requests✓ Keep devices and software updated✓ Report suspicious authentication activity


Cybersecurity Has to Travel With the Employee

This isn't just an IT or cybersecurity issue.

Project managers, executives, and other employees may have access to budgets, contracts, project plans, SharePoint sites, Teams conversations, technical documentation, and sensitive business information.

Organizations shouldn't only ask:

“Is our corporate network secure?”

They should also ask:

“Can our employees work securely when we don't control the network they're using?”

Security policies need to protect employees where they actually work.

Today, that could be almost anywhere.

Business travelers: What's your default—corporate VPN, mobile hotspot, hotel Wi-Fi, or a combination?

 
 
 

Comments


bottom of page