Your Employees Are Traveling — Is Your Cybersecurity Policy Traveling With Them?

Most organizations spend significant time and money securing their corporate environment.

Firewalls. Endpoint protection. Multifactor authentication. Conditional access. Security awareness training. Network monitoring.

But what happens when an employee closes their laptop, gets on a plane, checks into a hotel, and connects that same corporate device to public Wi-Fi?

Your security perimeter just changed.

Recent reports of attackers compromising hotel and conference Wi-Fi infrastructure to steal Microsoft 365 credentials are a good reminder that cybersecurity policies need to protect employees wherever they work—not just when they're sitting inside the corporate network.

The Modern Workplace Doesn't Have Walls

Think about how many places employees work today:

  • Hotels
  • Airports
  • Conference centers
  • Coffee shops
  • Customer locations
  • Hospitals and remote facilities
  • Home networks
  • Mobile hotspots

Employees may access Outlook, Teams, SharePoint, OneDrive, VPN connections, project management systems, financial applications, and other corporate resources from all of these locations.

That flexibility is great for productivity.

It also creates opportunities for attackers.

The question organizations should be asking isn't:

“Is our corporate network secure?”

It should be:

“Can our employees work securely when we don't control the network they're using?”

Public Wi-Fi Should Be Treated as Untrusted

One of the most important concepts organizations can teach employees is simple:

Just because a Wi-Fi network requires a password doesn't mean it's secure.

A hotel may give every guest the same password.

A conference center may provide Wi-Fi credentials to thousands of attendees.

Worse, attackers may compromise the networking equipment itself.

That means the network can potentially become part of the attack.

This is why employees should treat hotel, airport, conference, and other public Wi-Fi networks as untrusted infrastructure.

Your VPN Configuration Matters

Many organizations provide employees with a VPN, but there is an important distinction between split-tunnel and full-tunnel VPN configurations.

With split tunneling, only certain corporate traffic travels through the VPN while other internet traffic goes directly through the local network.

With full tunneling, internet traffic is routed through the organization's protected VPN connection.

For employees working from potentially hostile networks, that difference can matter.

Organizations should evaluate whether an always-on, full-tunnel VPN makes sense for employees who frequently travel or work remotely.

More importantly, employees need to understand something even simpler:

The VPN needs to be connected before they start working.

Opening Outlook, Teams, SharePoint, or a browser first and connecting the VPN afterward defeats part of the purpose.

Sometimes the Best Wi-Fi Is No Wi-Fi

One of the easiest security improvements for business travelers may already be in their pocket.

Their smartphone.

When reliable cellular service is available, using a personal mobile hotspot can often reduce exposure to potentially compromised public Wi-Fi infrastructure.

That doesn't mean cellular networks eliminate every security risk.

But given the choice between an unknown hotel network and a trusted cellular connection, I know which one I'd prefer for accessing corporate resources.

MFA Is Important — But It Isn't Magic

Multifactor authentication remains one of the most important controls organizations can implement.

But employees should not be taught:

“We have MFA, so we're safe.”

Modern attackers increasingly target authentication sessions, OAuth tokens, device authentication workflows, and users themselves.

An employee who receives an unexpected authentication request should not automatically approve it.

Security awareness training should teach employees to question:

  • Unexpected Microsoft 365 login screens
  • Repeated MFA requests
  • Device-code authentication prompts
  • Certificate warnings
  • URLs that don't look quite right
  • Authentication prompts appearing immediately after joining public Wi-Fi

A few seconds of skepticism can prevent a much larger incident.

Give Employees a Simple Travel Security Checklist

Security policies are important.

But when someone is standing in a hotel lobby after traveling all day, they're probably not going to read a 40-page cybersecurity policy.

Give them something simple.

Before You Connect:

1. Prefer your mobile hotspot when practical.

2. If you must use public Wi-Fi, verify you're connecting to the correct network.

3. Connect your corporate VPN before accessing company resources.

4. Verify Microsoft 365 and other authentication URLs before entering credentials.

5. Never ignore browser certificate warnings.

6. Don't automatically approve unexpected MFA requests.

7. Keep your laptop, browser, VPN client, and security software updated.

8. Report suspicious login prompts or unusual authentication activity to your security team.

That's something employees can actually remember.

Project Managers Should Pay Attention Too

Cybersecurity isn't only the responsibility of the security team.

Project managers frequently have access to information that could be extremely valuable to an attacker:

Project schedules.

Budgets.

Contracts.

Vendor information.

Executive communications.

Risk registers.

Technical documentation.

SharePoint sites.

Teams conversations.

And potentially sensitive operational or healthcare information.

We're also frequently traveling between offices, facilities, vendor locations, conferences, and hotels.

That makes project managers an attractive target.

Security should therefore be part of how we think about project governance and risk management—not something we simply hand over to the cybersecurity department.

Leaders Need to Make Secure Behavior Easy

There's another important lesson here.

If the secure way of working is significantly harder than the insecure way, employees will eventually find shortcuts.

Organizations should make security controls as seamless as possible.

An automatically connecting VPN is better than expecting employees to remember to launch one.

Strong conditional access policies are better than relying entirely on user judgment.

Good endpoint protection is better than hoping employees recognize every threat.

Clear travel security guidance is better than expecting someone to find the answer buried in a policy document.

Security works best when technology, policy, training, and employee behavior reinforce each other.

Cybersecurity Has to Travel With the Employee

The workplace has changed.

Our security assumptions need to change with it.

An employee's corporate laptop doesn't suddenly become less valuable to an attacker because it's sitting on a hotel desk instead of inside an office.

In fact, that may be exactly when the employee is most vulnerable.

Before your organization's next conference, business trip, or remote-work initiative, ask one simple question:

Does our cybersecurity strategy protect employees where they actually work?

Because today, that could be almost anywhere.


For those who travel regularly for work: What is your default approach—corporate VPN, mobile hotspot, hotel Wi-Fi, or a combination of all three?

#Cybersecurity #Microsoft365 #InformationSecurity #CyberSecurityAwareness #ProjectManagement #Leadership #RiskManagement #BusinessTravel #Microsoft365Security #ITLeadership


Comments

Popular posts from this blog

CCNA Routing and Switching Certified

Are you ready for some football?