Two opposite positions circulate about this recommendation, both imprecise: “public networks are extremely dangerous” and “there is no problem any more”.
The reality sits in between, and it is more useful than either. The main risk of public networks today is not that somebody reads your traffic — that is encrypted. It is that you do not know who you connected to, and that the network itself is the instrument of the deception.
What this recommendation says
Recommendation R10 establishes that you should avoid operations involving sensitive data when connected to a Wi-Fi network you do not control, and take some precautions when using one is necessary.
By “sensitive data” we mean: banking and payment operations, access to confidential documents, handling credentials, and in general anything you would not want to repeat in front of a stranger.
By “a network you do not control” we mean: cafes, hotels, airports, trains, shopping centres, libraries, other people’s offices, and an acquaintance’s network too.
What it is not. It is not an invitation to avoid public networks. They are a useful tool and, with encryption everywhere, reasonably safe for ordinary use. The recommendation concerns a category of operation, not the connection itself.
Scope. Any device connecting to networks that are not yours.
Why it matters
The risk has shifted in recent years, and it is worth seeing where to.
| Risk | How relevant it used to be | How relevant it is today |
|---|---|---|
| Reading the traffic | Very high | Low: the traffic is encrypted |
| Altering pages | High | Low: encryption detects it |
| A fake network with a plausible name | Medium | High: it is the main technique |
| A deceptive sign-in portal | Low | High: it asks for data and nobody notices |
| Automatic reconnection to known networks | Low | Medium-high: it happens without you knowing |
| The device’s exposure on the local network | Medium | Medium: it depends on the settings |
The three highlighted rows describe the contemporary risk, and they have one thing in common: they do not concern the traffic, they concern the network’s identity. Whoever sets up a fake network does not need to decrypt anything — it is enough that you type something into their sign-in page.
A concrete example
Helen is at the airport and looks for the Wi-Fi. She sees two networks with similar names: Airport_WiFi and Airport_WiFi_Free. She picks one.
A page opens asking her to register with an email address and a password to “create an access account”. Helen enters her personal email and the password she usually uses.
The traffic afterwards will be encrypted and unreadable. But she has already handed over the credentials voluntarily, on a page in the clear, to a party she did not check.
The point: the encryption worked perfectly and was of no use at all, because the problem was not interception.
When to apply it
- Before a banking operation or a payment, even a small one.
- When the network asks you to register with the credentials of existing services.
- In airports, stations and hotels, where the number of people makes setting up fake networks worthwhile.
- When your device connects by itself to a network you do not remember choosing.
- Before opening confidential work documents from a network that is not yours.
- When travelling abroad, where network names are less familiar and harder to verify.
- On devices your children also use, since they tend to connect to any open network.
How to apply it
- Prefer your phone’s data for sensitive operations. It is the most effective countermeasure and the least demanding: the mobile connection is encrypted over the radio link and is not shared with strangers.
- Check the network’s exact name by asking whoever runs the place, instead of inferring it. It is the only way to tell the real one from a copy.
- Do not enter other services’ credentials into the sign-in portal. If the network asks for an email and a password, use a secondary address and a password made for the occasion — or give it a miss.
- Turn off automatic connection to known networks. Otherwise the device reconnects to any network with a name it has seen before, even if it is not the same one.
- Forget public networks after use. It avoids future reconnections and reduces the information the device broadcasts looking for them.
- Turn off file and printer sharing when you connect to a public network. Many systems ask at the first connection: the correct answer is “public network”.
- Use official apps instead of the browser for banking and financial services, when you really have to.
Common mistakes to avoid
- Registering on the portal with your main email and usual password. It is the most costly mistake and the most frequent.
- Trusting the network’s name. Anybody can call their network whatever they like: the name cannot be verified.
- Leaving automatic connection on. It is how people connect to networks they never chose.
- Thinking a password-protected network is secure. A cafe’s password is known to every customer: it does not separate you from the others.
- Believing a VPN covers every case. It protects the traffic, it does not tell you which network you connected to nor what you type into the portal.
- Overlooking the sharing settings. On a public network your device can be visible to the others connected.
- Considering only open networks “public”. A client’s office network is also a network you do not control.
A password-protected network is not a private network
It deserves clarity, because it is this recommendation’s most widespread misunderstanding.
A password on a network stops passers-by connecting. It stops nothing for whoever has the password — and in a cafe every customer has it, often written on the menu.
| Kind of network | Who can connect | Who can observe |
|---|---|---|
| Open, no password | Anybody | Whoever is connected, with simple tools |
| With a shared password | Every customer | Whoever knows the password |
| With individual credentials | Whoever has an account | Only whoever runs the network |
| Your home network | The people you live with | Only whoever controls the router |
The first two rows are the typical situation in a public place. The difference between them, from the point of view of somebody wanting to observe, is minimal.
What still makes them acceptable to use is the site-by-site encryption of the traffic — not the network’s password.
What “sensitive data” means concretely
The recommendation’s wording contains a term worth making operational, because otherwise it stays a piece of guidance everybody interprets their own way.
| Activity | On a public network | Why |
|---|---|---|
| Reading news, watching video | No problem | Encrypted traffic, nothing to hand over |
| Checking personal mail | No problem | The session is already active, the content encrypted |
| Video calls | Mind the surroundings, not the network | Whoever is beside you can hear |
| Working on company documents | Check the policy | Often governed by rules |
| Signing in to a new service with credentials | Acceptable if the site is encrypted | The credential does not pass in the clear |
| Banking operations and payments | Better on your phone’s data | Not for interception: for the context |
| Registering on the network’s portal | Never with real credentials | It is the only part that is not encrypted |
The last two rows are the only ones where the recommendation really imposes a change. Everything else is usable.
It is worth explaining why banking operations stay on the list despite the encryption: not because the traffic is readable, but because they are operations where an interruption, a doubt or a mistake carries a high cost, and where the physical context — a visible screen, an observable keyboard — weighs more than the network.
The perimeter almost nobody considers
“Public network” evokes the cafe or the airport. In fact the useful definition is wider: any network whose router you do not control is public.
That includes situations nobody usually classifies that way:
- the network at friends’ or relatives’ homes, whose configuration you do not know;
- the network at a client’s or supplier’s office;
- the network of an accommodation provider, however upmarket;
- the network of a coworking space;
- the network of a school or university;
- a hotspot shared from somebody else’s phone.
It does not mean they are hostile — in almost every case they are not. It means the configuration, the updates and the management of that router do not depend on you, and that the same care therefore applies.
How this connects to the Cyber Welfare Framework
| Pillar | How it contributes |
|---|---|
| Awareness | Understanding that the risk is the network’s identity, not the reading of traffic |
| Skills | Configuring automatic connection and sharing correctly |
| Secure Behaviour | Moving sensitive operations onto your phone’s data |
Digital maturity levels.
- FL1 — Basic. Connecting to any open network, automatic connection on, registering with the usual credentials.
- FL2 — Beginner. Banking operations on public networks are avoided.
- FL3 — Autonomous. Automatic connection off, networks forgotten after use, the portal never filled in with real credentials.
- FL4 — Skilled. The network’s name is checked at the source; sharing turned off; phone data as the default choice for sensitive operations.
- FL5 — Expert-Guide. You help others, particularly frequent travellers, tell the real risk from the perceived one.
R10 rests entirely on R9: it is site-by-site encryption that makes a public network usable. Without it, this recommendation would be far more restrictive.
How to check you are applying it correctly
- Does my phone connect by itself to networks I did not deliberately choose?
- When I last registered on a public Wi-Fi, which credentials did I use?
- If I had to make a bank transfer right now, away from home, which connection would I use?
Quick checklist
- ☐ Automatic connection to known networks turned off
- ☐ Public networks forgotten after use
- ☐ Never real credentials in the sign-in portal
- ☐ File and printer sharing turned off on public networks
- ☐ Banking operations done on the phone’s data
- ☐ The network’s name checked by asking, not inferring
- ☐ Official apps instead of the browser for financial services
For an overall measure of where you stand, you can take the digital resilience self-assessment.
In short
Public networks are not to be avoided: they are to be used knowing what they protect and what they do not.
The traffic is encrypted and unreadable. What stays uncovered is everything happening before the encryption: choosing the network, the sign-in portal, and the settings your device presents itself with.
One rule, if only one were to remain: for the operations that count, use your phone’s data. It costs nothing and closes the whole category of problems.
Something to think about. How many Wi-Fi networks are saved on your phone right now — and how many would it reconnect to on its own, without asking you?
Explore this recommendation
- Impact of untrusted networks — what is really exposed and what is not
- Consequences of using a public network — the concrete effects
- How to use public Wi-Fi safely — the configuration and the habits
- Signs of an untrustworthy Wi-Fi network — how to recognise a network that does not convince
- Protecting traffic on public networks — the technologies available and what they actually do
- Attacks on public Wi-Fi — the techniques in use today
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



