Cybersecurity

Keeping a Laptop Secure When You Work From Shared or Public Spaces

Keeping a Laptop Secure When You Work From Shared or Public Spaces

Photo credit: Telecom360.net | Connecting You To The Latest In Telecom

From screen privacy to physical cable locks, here are the layered security practices that matter most when your laptop regularly leaves the home.

Key Takeaways

  • Public Wi-Fi exposes your traffic to interception — a VPN is a practical first line of defense.
  • Physical threats like shoulder surfing and theft are as real as digital ones in shared spaces.
  • Screen privacy filters, cable locks, and automatic screen locks cost little but prevent significant harm.
  • Disabling auto-connect to open networks reduces your passive exposure without extra effort.
  • Full-disk encryption ensures stolen hardware doesn't become stolen data.

Why Public Spaces Raise the Security Stakes

Working from a café, library, coworking hub, or airport lounge is now routine for millions of people. But the convenience of flexible work comes with a threat surface that simply doesn't exist at home: unfamiliar networks, strangers within viewing distance, and no control over the physical environment around your device.

The risks fall into two overlapping categories — digital and physical. Digital threats include network-level interception on unsecured Wi-Fi, rogue access points designed to mimic legitimate hotspots, and malware delivered through compromised public networks. Physical threats include shoulder surfing (someone reading your screen), opportunistic theft, and even evil maid-style tampering if a device is left unattended. For a broader foundation on device protection, see the device security primer covering core habits for every device you own.

Effective protection in public spaces isn't a single tool — it's a stack of habits and settings that work together.

Core Practices for Securing a Laptop on the Go

The following practices address both digital and physical exposure. None require advanced technical skill, but together they substantially reduce your risk profile in shared environments.

1

Enable full-disk encryption before your laptop ever leaves home.

If your laptop is stolen, encryption renders the storage unreadable without your credentials — even if an attacker removes the drive and connects it to another machine. Without it, physical access is effectively complete access to your data.

Example: Most modern operating systems include built-in encryption (such as BitLocker on Windows or FileVault on macOS) that can be enabled in system settings with minimal performance impact on current hardware.
2

Use a VPN on every public or shared network, without exception.

Public Wi-Fi offers no traffic isolation between users. A VPN encrypts your connection before it reaches the local network, neutralizing most passive interception attempts and making man-in-the-middle attacks significantly harder to execute.

Example: Enable your VPN before connecting to café Wi-Fi, and configure it to auto-connect on untrusted networks if your VPN client supports that feature.
3

Attach a physical privacy screen filter to your laptop display.

Shoulder surfing — reading a screen from an angle — is a low-effort, high-reward tactic for stealing credentials or sensitive information. A privacy filter narrows the viewing angle so only the person directly in front of the screen can see the content.

Example: A freelance accountant reviewing client financials in a coworking space uses a privacy filter to ensure no one seated beside them can read account numbers or names from an angle.
4

Set your screen to lock automatically after no more than two minutes of inactivity.

An unattended, unlocked laptop is an open door. Even stepping away for 60 seconds to order a coffee gives an opportunist enough time to insert a USB device, copy files, or install software.

Example: Configure your OS power settings so the screen locks immediately when the lid is closed and after a very short idle period — then confirm the lock screen requires your password or biometric to re-enter.
5

Use a cable lock when working for extended periods at a fixed location.

Physical theft is the simplest attack vector. A cable lock anchors your laptop to a fixed object, deterring opportunistic theft without adding significant weight to your bag.

Example: A remote worker who spends several hours daily in a library loops a Kensington-compatible cable lock through the table frame, removing one of the easiest attack scenarios entirely.
6

Disable automatic connection to open or previously known public networks.

Devices set to auto-connect can be silently lured onto rogue access points mimicking known network names (known as an 'evil twin' attack). Requiring manual confirmation before joining any network gives you a moment to verify legitimacy.

Example: In your Wi-Fi settings, turn off 'Connect automatically' for any network not under your control, and periodically clear the list of remembered public networks your device has joined.

Quick Actions You Can Take Today

Several of the most impactful protections take under five minutes to enable. Start here before your next working session away from home.

high Open your system settings right now and verify that full-disk encryption is turned on — it takes under two minutes to confirm.
high Set your screen lock timeout to two minutes or less in your operating system's display or power settings.
medium Go to your Wi-Fi settings and disable auto-connect on any saved public or open networks.
medium Enable your browser's HTTPS-only mode — available in settings on most major browsers — to block unencrypted page loads.

Position Matters as Much as Hardware

Before sitting down in a public space, scan the room and choose a seat with your back to a wall where possible. This eliminates the angle from which shoulder surfers typically operate. Combine this with a privacy filter for the strongest visual protection without any digital setup required.

Understanding the Network Threat

Public Wi-Fi remains one of the most exploited attack vectors targeting mobile workers. An attacker on the same network can attempt to intercept unencrypted traffic, redirect you to spoofed login pages, or run a man-in-the-middle (MITM) attack — positioning themselves invisibly between your device and a website.

25%

Of public Wi-Fi hotspots use no encryption

According to Kaspersky's analysis of global Wi-Fi hotspot data, roughly one in four public hotspots transmit traffic without any encryption layer.

43%

Of workers report using public Wi-Fi for sensitive tasks

An iPass survey of mobile workers found that a significant share regularly access work email, files, or business applications over public networks.

Even networks that require a password offer no protection against other users on that same network. The password only controls who can join; it doesn't isolate your traffic from theirs. This is distinct from home network security, where you control who can connect — a difference explored further in our piece on home network security and smart device vulnerabilities.

Using a reputable VPN encrypts your traffic between your device and the VPN server, making interception on the local network far less useful to an attacker. Pair this with HTTPS-only browsing — most modern browsers can enforce this automatically — for meaningful network-layer protection. For users storing sensitive files remotely, complementary guidance on securing cloud files is also worth reviewing.

VPNs Have Limitations Worth Understanding

A VPN protects your traffic between your device and the VPN server — it does not make you anonymous online, protect against malware already on your device, or secure connections after the VPN server. Choose a provider with a credible no-logs policy, and remember that a VPN is one layer of protection, not a complete solution.

Cybersecurity Editorial Team

Author

Cybersecurity Editorial Team

Cybersecurity Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.