Cairitech IT Support and Services Logo

Leader in IT Support & Cybersecurity Across Ontario

Cairitech IT Support and Services Logo
CairiTech blog cover image

Your Project Manager Just Logged In From Hotel Wi-Fi — Here's What Could Go Wrong

Powered By CairiTech

Quick answer

Summer scatters your team — to cottages, hotels, airports, and jobsite trailers — and every one of those free Wi-Fi networks is a place where company data can be intercepted or an account quietly hijacked. The risk is real and common: a 2025 Norton report found 63% of public Wi-Fi users admitted doing work tasks on unsecured networks, and nearly half sent confidential information without encryption. The danger isn't the coffee shop itself — it's connecting to sensitive systems without protection.

The fix is a short, enforceable set of habits: a business VPN, multi-factor authentication (MFA) on every account, encrypted access to files, and never using a network you can't verify. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses — including Architecture, Engineering, and Construction (AEC) firms with staff moving between office, site, and the road — keep remote access locked down all summer.

3 min read posted on 07/26/26

Why is public Wi-Fi actually risky?

Public Wi-Fi is risky because you usually can't verify who runs the network or who else is watching the traffic on it. On an open network, an attacker can set up a look-alike hotspot (an "evil twin"), intercept unencrypted data, or push users toward fake login pages. An evil-twin attack is a rogue Wi-Fi access point named to imitate a legitimate one — say "Airport_Free_WiFi" — so your device connects to the attacker instead of the real network. Once you're on it, anything not encrypted is potentially readable.

What can a business actually lose over an unsecured connection?

Over an unsecured connection, a business can lose login credentials, client and project data, and ultimately control of accounts. Stolen credentials are the prize: capture one email or VPN password on an open network and an attacker can return later, at leisure, to reach the whole environment. Remote and hybrid work already raise the stakes — IBM's Cost of a Data Breach research has repeatedly found remote-work-related breaches cost meaningfully more than office-based ones. For an AEC firm, that can mean exposed drawings, bids, or client contracts.

Does a VPN fix the problem?

A VPN fixes most of the public-Wi-Fi problem by encrypting your connection, so even on an untrusted network your traffic can't be read in transit. A VPN (virtual private network) is a secure, encrypted tunnel between a device and your business systems. It's essential — but it isn't the whole answer: VPN accounts themselves are now a favourite target, and unpatched VPN appliances have been tied to a large share of ransomware incidents. That's why a VPN has to be paired with MFA and kept updated, not treated as a set-and-forget fix.

What's the safest way for staff to work while traveling?

The safest approach is layered: assume the network is hostile and let your protections carry the load. Here's how the common options compare:

Method

Open public Wi-Fi, no VPN

Very low protection level — avoid

Best for: Nothing work-related

Public Wi-Fi + business VPN + MFA

High protection level

Best for: Most remote work

Phone hotspot (cellular)

High protection level

Best for: Quick, sensitive tasks

Company-managed device + VPN + MFA

Highest protection level

Best for: Regular travelers and field staff

A simple rule of thumb: if a network is free and unverified, treat it as public and route everything through the VPN — or use your phone's cellular hotspot instead, which is far harder to intercept.

What habits should every traveling employee follow?

Give the team a short, memorable checklist before vacation season peaks:

  • Always connect through the company VPN before touching work files or email.

  • Turn on MFA everywhere — Microsoft estimates it blocks over 99% of automated account-takeover attempts.

  • Prefer a cellular hotspot over open Wi-Fi for anything sensitive.

  • Verify the network name with staff before joining; ignore unexpected "free Wi-Fi" prompts.

  • Keep devices patched and locked with encryption and auto-lock enabled.

  • Never send confidential data over an unverified network without the VPN on.

Your team should be able to work from anywhere this summer without handing a stranger the keys. A VPN, MFA, and a few clear habits make that routine. See our security services and managed IT services for how we secure remote access. Book your free discovery call with CairiTech today and we'll help you lock down remote work before the next long weekend.

FREE REPORT: IT Buyers Guide

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)

Frequently asked questions

Is public Wi-Fi safe if the website shows a padlock (HTTPS)?

HTTPS encrypts traffic to that specific site, which helps, but it doesn't protect everything on your device or stop evil-twin and fake-login tricks. A VPN protects the whole connection, so pair the two.

Is my phone's hotspot safer than café Wi-Fi?

Generally yes. A cellular hotspot is a private connection that's much harder for a nearby attacker to intercept than shared public Wi-Fi, making it a strong choice for sensitive tasks on the road.

Do we really need a VPN if we use Microsoft 365?

Yes. Microsoft 365 secures its own sign-in, but a business VPN and MFA protect access to your broader systems and data on untrusted networks — they solve different parts of the problem.

What should staff do if they connected to a sketchy network?

Disconnect, switch to a trusted connection, change any passwords entered while on it, and report it to IT so accounts can be watched for unusual activity. Fast reporting limits the damage.

Written by the Cairitech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

Popular Reads You Don’t Want to Miss

Blog Cover Image: Cyber Resilience Is Now a Business Requirement for Ontario Manufacturers & Builders

March 29, 2026

Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

Blog Cover Image: Inside Look: How Hackers Use AI To Attack Your Business

January 17, 2025

If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

LOCATIONS

Canada

1-2 Vata Court, Aurora, ON

United States

39288 Calle Tonala, Indio, CA

Copyright 2026. Cairitech. All rights reserved.