New threats are making digital security an essential part of business travel
Business travelers have always had plenty to think about before heading out the door: passports, chargers, itineraries, presentation materials…and the list goes on. Now more than ever, cybersecurity belongs on that checklist.
Travel can create an ideal environment for cybercriminals. People connect to unfamiliar networks, work from hotels and airports, and access company accounts far outside their usual routines. The risks have evolved considerably in recent years.
At the end of July, Microsoft detailed a cyberattack campaign known as CaptiveCrunch that compromised Wi-Fi infrastructure used in hotels, conference centers and other shared environments. The attacks used convincing captive portals and verification prompts to target users, with Microsoft noting that the activity appeared particularly focused on corporate travelers.
For meeting professionals frequently moving between hotels, convention centers, airports and event venues, a few precautions can make traveling with sensitive information significantly safer.
Think Twice About Public Wi-Fi
Free Wi-Fi is convenient, but travelers should treat hotel, airport, conference center and other public networks as untrusted.
Whenever possible, use cellular data or a personal hotspot instead. International travelers can also consider an eSIM, which can provide local cellular data without requiring a physical SIM card.
Read More: Is Your Event Wi-Fi Ready for AI?
If public Wi-Fi is unavoidable, verify the network name with the hotel or venue before connecting. A network with an official-looking name isn’t necessarily legitimate.
A VPN can add another layer of protection by encrypting internet traffic, particularly when using an unsecured network, but it isn’t a cure-all. A VPN won’t protect a traveler who enters credentials into a fraudulent website or follows instructions from a malicious captive portal.
Don’t Trust Unexpected Prompts
One of the newer threats facing travelers doesn’t necessarily look suspicious. Cybercriminals can manipulate the login portals people encounter when joining hotel and other guest Wi-Fi networks. A seemingly routine screen might instruct users to update their browser, install software or complete an unusual verification process.
Don’t download software, certificates, browser updates or security tools because a Wi-Fi login page tells you to do so. Install updates through your device’s operating system, official app store or another trusted source.
When a captive portal suddenly asks for information or actions that seem unrelated to connecting to Wi-Fi, disconnect.
Update Before You Leave
Cybersecurity preparation should start before the trip. Install current operating-system, browser and app updates before departure rather than postponing them until you’re traveling. Security updates frequently address vulnerabilities that attackers can exploit.
Travelers should also back up important information and enable device-location and remote-wipe features where available. If a phone, tablet or laptop disappears, those measures can help protect both personal and company information.
Automatic screen locking and strong device passwords or PINs provide another important layer of protection.
Strengthen Your Logins
Using the same password across multiple accounts remains risky. A password manager can make it easier to maintain strong, unique credentials without having to remember every one.
Multifactor authentication adds another barrier if a password is compromised. When available, travelers can go a step further by using passkeys or other phishing-resistant authentication methods.
Passkeys have become much more widely available in recent years and can provide better protection against phishing because there isn’t a conventional password for a fraudulent website to steal.
Before traveling, make sure authentication methods will remain accessible at your destination—particularly if your normal login process depends on receiving an SMS message at your usual phone number.
Bring Your Own Charger
Public charging stations are another place to exercise caution. The FBI and other government agencies have advised travelers against plugging devices directly into unfamiliar public USB charging ports because compromised connections could potentially be used to access a device or introduce malicious software.
Read More: Smart Tech: The Race to Data Security
A simple solution is to pack a charging cable and wall adapter and plug into a standard electrical outlet. A portable power bank can provide another option when an outlet isn’t available.
Limit What You Carry
The less sensitive information traveling with you, the less there is to compromise. Before departure, consider whether every file stored on a laptop, tablet or phone actually needs to make the trip. Organizations may also have policies governing how employees access or store confidential information while traveling internationally.
Physical security matters, too. Don’t leave devices unattended in public areas, and be conscious of what others can see when working in crowded airport lounges, airplanes, hotel lobbies and conference spaces.
Cybersecurity doesn’t need to make business travel cumbersome. Most precautions are simple: Update devices before leaving, use cellular connectivity when possible, strengthen account authentication and be skeptical when an unfamiliar network asks you to do something unexpected.
As cybercriminals become more sophisticated, that last habit may be the most important one to pack.