Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Free Wi-Fi Isn't Really Free: The Risk We Accept Every Time We Connect

Free Wi-Fi Isn't Really Free: The Risk We Accept Every Time We Connect

By
Key Takeaways
  • Public Wi-Fi Creates More Than Network Risk. The security exposure can begin before a user connects, particularly when registration requires personal information.
  • Small Data Points Can Become Valuable Together. Email addresses, phone numbers, postcodes and vehicle registrations can be combined to create convincing phishing or social engineering attempts.
  • Breaches Should Be Assessed by Potential Use. Risk assessments should consider what an attacker could realistically do with exposed information, not simply whether passwords or financial details were compromised.
  • Convenience Can Change Risk Appetite. People routinely provide information for temporary internet access that they might hesitate to share in another setting.
  • Risk Management Is About Informed Trade-Offs. Using public Wi-Fi does not require eliminating every possible risk, but users should understand what they are exchanging for the convenience.
Deep Dive

We have all done it. You are at an airport waiting for a flight. Your train journey is going to take another two hours. You have just checked into a hotel, or perhaps you are sitting in a café trying to get some work done. Your mobile signal isn't great, so you look at the available networks and see exactly what you need: free Wi-Fi.

A few clicks later, you're connected. Maybe you entered your email address first. Perhaps you accepted some terms and conditions without reading them. Within minutes, you are checking emails, scrolling through social media or getting some work done. It feels completely normal. But from a risk perspective, there is a question I think we should ask more often: What are we actually accepting in exchange for that connection?

The Recent UK Airport Breach Made Me Think About This Differently

The recent cyber incident affecting Manchester Airports Group is a useful reminder. Customer information associated with Manchester, London Stansted and East Midlands airports was accessed by an unauthorised third party. The affected data related to services including airport Wi-Fi registrations, parking, lounge and Fast Track bookings.

For many of those affected, the exposed information was limited to email addresses, while some records also included phone numbers, postcodes and vehicle registration details. Importantly, Manchester Airports Group has said payment and banking details were not held in the affected system and airport operations were not disrupted.

That is reassuring, but there is another part of the story that caught my attention: Wi-Fi registrations. Most people probably don't think of registering for airport Wi-Fi as creating a lasting security or privacy exposure. You enter an email address because you want internet access for an hour. You connect, board your flight and probably never think about that registration again.

The organisation, however, may still hold that information long after you have disconnected. That changes the risk conversation.

There Are Really Two Risks With Public Wi-Fi

When we talk about public Wi-Fi security, most of the conversation focuses on the network itself, and rightly so.

Public networks are not environments we control. There is the possibility of connecting to a rogue hotspot designed to look legitimate. There are risks associated with traffic travelling across an untrusted network, and attackers may attempt techniques such as spoofing or man-in-the-middle attacks.

This is why public Wi-Fi in an airport, hotel, train or café should never be treated in the same way as a trusted home or corporate network. But there is another risk that receives less attention: the data we provide before we even connect.

An airport may ask for an email address. A hotel may ask for your surname and room number. Another service might request a telephone number or ask you to create an account. Individually, these details may not seem particularly sensitive.

The risk becomes clearer when information from different sources starts to come together. An email address, a telephone number, a postcode and a vehicle registration may appear relatively harmless in isolation. None of them needs to include a bank account number to be useful to a criminal.

Put enough pieces together, and you can create a convincing story.

Small Pieces of Information Can Create a Bigger Risk

This is something we regularly consider in cybersecurity. Risk isn't always about one catastrophic piece of information being exposed. Sometimes the real exposure comes from combining several pieces of information that appear relatively harmless on their own.

Imagine receiving an email from someone who knows which airport you use. It references airport parking. Perhaps it even contains your vehicle registration. The message says there was a problem processing your parking payment and asks you to follow a link to avoid an additional charge.

Would that feel more convincing than a random phishing email? Probably.

This is why the impact of a breach shouldn't be assessed solely by asking whether passwords or banking information were stolen. We should also ask what someone could realistically do with the information that was exposed.

That is the risk-based question.

Convenience Changes How We Think About Risk

One of the interesting things about public Wi-Fi is how quickly convenience can change our risk appetite. Imagine someone stopping you at an airport and saying, "Give me your email address and some personal information, and I'll give you internet access for an hour." Most of us would probably think twice about the request.

Put the same request on a professional-looking Wi-Fi registration page, however, and most of us will complete it without much thought. I don't say that as criticism. I have used public Wi-Fi myself.

The point is that good risk management isn't about pretending we can eliminate every risk from everyday life. It's about understanding the risk we're taking and deciding whether the convenience is worth it.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong