CYBER WELFARE

Protect your Digital Privacy

Choose the strongest hotspot encryption: WPA3, or WPA2 when you need it

You are in a waiting room, your laptop cannot find a network you trust and you have a video call in ten minutes. You turn on your phone’s hotspot, connect the laptop and carry on. From that moment, everything you do — emails, documents, messages — travels through the air for a few metres, from the laptop to the phone.

That stretch of air is invisible, but it is not private: any device nearby can pick up the signals from your network. What stops a stranger from reading them is encryption, the system that turns data into a form nobody can read without the key. And not every type of encryption your phone offers protects you in the same way.

This recommendation — R15 of the Cyber Welfare Framework — helps you choose the strongest hotspot encryption available, understand what the abbreviations in your settings actually mean, and know when a compromise makes sense. It is the natural companion to your mobile hotspot password: the password decides who gets in, and encryption protects what passes through.

What this recommendation says

Recommendation R15 states that, whenever you turn on your phone’s hotspot, you should choose the strongest type of protection available: WPA3 when it is there, the mixed WPA2/WPA3 mode only if an older device cannot connect, and WPA2 if your phone offers nothing better — never an open network, never WEP or WPA.

Only a handful of abbreviations appear in the settings, and one line each is enough to find your way:

  • Open network (no security) — no password and no encryption: whatever passes through the network travels in plain text, readable by anyone nearby.
  • WEP (Wired Equivalent Privacy) — the first security system for Wi-Fi, dating from the late 1990s: today it is easy to get around and is considered obsolete.
  • WPA (Wi-Fi Protected Access) — the stopgap introduced to replace WEP in a hurry: better than its predecessor, but now outdated and not recommended either.
  • WPA2 — the standard that has protected most Wi-Fi networks for many years: strong, provided the password is long and hard to guess.
  • WPA3 — the most recent generation: it makes guessing the password by trial and error far harder and gives better protection to traffic that has already been sent.

Alongside these, many phones offer a mixed WPA2/WPA3 mode (sometimes called “transition” mode): recent devices connect with WPA3, older ones with WPA2.

What it is not. It is not a matter for network experts: it is a single option in your hotspot settings, to check once and look at again from time to time. And it is not a protection that replaces the others: encryption does not stop someone who already knows the password, and it does not protect your data beyond the phone, along the rest of its journey across the internet.

Where it applies. To every phone or tablet you use as a hotspot, personal or for work, and to the small portable routers that share a mobile data connection. The same principle applies to your home router, although that is a subject of its own.

Why it matters

Wi-Fi is a radio connection. Unlike a cable, the signal does not stay between the two devices talking to each other: it spreads out, passes through walls and seats, and reaches anyone with an antenna in range. In busy places — a train, a coworking space, an airport — there are plenty of antennas in range.

Encryption is what makes that signal useless to anyone who picks it up without permission. When it is weak, or missing altogether, three things can happen:

  • the traffic can be read — with an open network or one protected by WEP, someone nearby can observe what passes between your devices and the phone;
  • the password can be worked out — with the older systems, and with WPA2 if the password is short, someone who records the moment a device connects can later try a huge number of combinations at their leisure, far away from you;
  • someone can join the network — once the key has been found, a stranger connects as if they were authorised, uses up your data allowance and ends up on the same network as your laptop.

In recent years many websites and apps have started encrypting their own communications — this is the idea behind browsing only over HTTPS — and that reduces what a stranger can read. But not everything is encrypted in the same way: the names of the sites you visit, some apps, and the devices connected to the network itself remain more exposed. Hotspot encryption is the first layer, the one that protects everything travelling through the air, without you having to think about it.

There is also a less obvious point. With WPA2, someone who knows the password and watches the moment another device connects can, in theory, decrypt that device’s traffic. WPA3 gives every connection its own keys, which cannot be derived from the password alone: even someone legitimately on the network cannot read what the others are doing.

Benefit of strong encryptionWhy it counts
Makes what travels through the air unreadableAnyone picking up the signal sees only meaningless data
Protects the password from remote guessingWith WPA3, recording a single connection is not enough to try combinations endlessly
Keeps connected devices apartKnowing the password does not mean reading other people’s traffic
Protects past traffic tooIf the password were discovered in future, sessions that have already ended stay encrypted
Works automaticallyOnce chosen, it needs no further action from you

A concrete example

Sarah often works on the move. Twice a week she takes a ninety-minute regional train and turns on her phone’s hotspot to use her laptop. She has already followed the advice to choose a long password, and she changes it whenever she lends the hotspot to someone.

One day, while looking for a different setting, she notices a “Security” option on the hotspot screen. It is set to WPA2: perhaps that was the default, or perhaps she changed it years ago to connect an old tablet that would not join the network. WPA3 is also on the list.

Sarah selects it. Her laptop, which is only a few years old, reconnects without any trouble. The children’s tablet, much older, can no longer find the network. Rather than going back, Sarah chooses the mixed WPA2/WPA3 mode: the laptop carries on using WPA3, while the tablet connects with WPA2. She makes a note to check, at the tablet’s next update, whether WPA3 support has arrived.

Nothing serious had happened, and there was no immediate danger. But now every hour of work on the train travels with the best protection her devices can offer, and Sarah knows exactly why.

When to apply it

The rule always applies, but there are moments when it makes a real difference.

  • The first time you turn on the hotspot on a new phone. The default setting is not always the strongest: some phones start from the most compatible mode, not the most secure one.
  • When you work on the move. Trains, stations, airports, coworking spaces, hotels: more people and more devices within range of the signal.
  • When you send confidential data. Work documents, health information, dealings with public offices: this is when every layer of protection counts.
  • After an operating system update. Updates can add support for WPA3, or reset some settings to their defaults.
  • When a device cannot connect. This is when it is tempting to lower the protection — and it is also the moment to do so with care.
  • When you replace your laptop or tablet. A new device almost always supports WPA3: it can be the moment to leave the mixed mode behind.

How to apply it

It only takes a few minutes, and the sequence is always the same.

  1. Open your hotspot settings. They are usually in the section devoted to networks or connections, under an option such as “Personal hotspot”, “Hotspot and tethering” or similar. The path varies from phone to phone, but it is the screen where you set the network name and password.
  2. Look for the security option. It may be called “Security”, “Security type” or “Protection”. Some phones do not show the abbreviations at all, but an option for compatibility with older devices instead: turning it on usually means dropping down to WPA2.
  3. Choose WPA3 if it is available. It may appear as “WPA3”, “WPA3-Personal” or “WPA3-SAE”. SAE (Simultaneous Authentication of Equals) is the name of the mechanism WPA3 uses to check the password without sending it in a form that can be attacked by trial and error.
  4. Check that all your devices connect. Try the laptop, the tablet and any other device you usually use with the hotspot.
  5. If a device will not connect, use the mixed mode. Choose “WPA2/WPA3” rather than dropping to WPA2 alone: recent devices will keep using the stronger protection. It is a transitional solution, not a permanent one.
  6. If WPA3 is not there, choose WPA2. It often appears as “WPA2-Personal” or “WPA2-PSK”. In that case the strength of your password matters even more: a long, unique password, as explained in the recommendation on your hotspot password, is what makes WPA2 genuinely effective.
  7. Always rule out the outdated options. No open network, no WEP, no plain WPA — not even “just for five minutes”.
  8. Keep your phone and devices up to date. Over the years, flaws have been found in Wi-Fi protocols and fixed through software updates: keeping your software up to date is also how WPA3 reaches devices that do not support it today.

Common mistakes to avoid

  • Leaving the default setting without looking at it. It is not necessarily wrong, but it may not be the strongest option: it is worth checking once.
  • Dropping to WPA2 (or worse) for a single device. If an old device will not connect, the mixed mode solves the problem without lowering the protection for everything else.
  • Opening the network “for a moment”. A network with no password is visible and reachable by anyone in range, even for those few minutes.
  • Assuming encryption is enough on its own. With a short password, or one shared with too many people, even the best encryption protects less: the two work together.
  • Confusing your hotspot with other networks. Hotspot encryption protects the stretch between your devices and your phone. When you connect to someone else’s network, different rules apply: those on sensitive data on public Wi-Fi and, for confidential traffic, those on using a VPN for sensitive traffic.
  • Leaving the mixed mode on for good. It is meant as a transitional solution, yet it often stays in place for years after the old device has stopped being used.

How this connects to the Cyber Welfare Framework

R15 turns a technical setting into an informed choice: understanding what encryption protects is what lets you avoid lowering it at the first sign of difficulty.

PillarHow this contributes
SkillsKnowing how to find the hotspot’s security option and tell WPA3, WPA2 and the outdated options apart
AwarenessUnderstanding that Wi-Fi travels through the air and that the password and encryption protect two different things
Secure BehaviourAlways choosing the strongest protection available and using the mixed mode only when it is genuinely needed

Digital maturity levels.

  • FL1 — Basic. You use the hotspot with its default setting, without knowing which protection is active. It is the most common starting point, not a fault.
  • FL2 — Beginner. You have checked the setting and chosen WPA3, or WPA2 if WPA3 is not available; you never use an open network.
  • FL3 — Autonomous. You manage the mixed mode sensibly, you know which of your devices support WPA3 and you check the setting again after updates.
  • FL4 — Skilled. You apply the same principle to every network you manage — hotspot, home router, portable routers — and you can explain the limits of each type of protection.
  • FL5 — Expert-Guide. You help other people — in your family, your team, your organisation — to check and improve the protection of their own networks.

R15 is a key step towards FL2, and it remains an active requirement at every level after that.

How to check you are applying it properly

Three questions, to be answered honestly.

  1. Do I know which type of protection is active on my phone’s hotspot right now?
  2. If a device could not connect, would I know to choose the mixed mode instead of opening the network or dropping to an outdated protection?
  3. Have I checked the setting again since my phone’s last update?

Quick checklist

  • ☐ My hotspot uses WPA3, or WPA2/WPA3 if a device needs it, or WPA2 if my phone offers nothing else
  • ☐ I never use an open network, WEP or plain WPA
  • ☐ The mixed mode stays on only as long as a specific device needs it
  • ☐ My hotspot password is long, unique and changed after occasional sharing
  • ☐ My phone and connected devices receive security updates
  • ☐ I know that encryption protects the stretch up to my phone, not the whole journey across the internet

If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.

In short

Your phone’s hotspot creates a small Wi-Fi network, and everything that passes through it travels through the air, where anyone nearby can pick it up. Encryption is what makes that data unreadable to anyone without the key.

The choice is simple once you know the abbreviations: WPA3 when it is available, the mixed WPA2/WPA3 mode only if an older device cannot connect, WPA2 if your phone offers nothing else. Never an open network, never WEP or WPA. And, alongside encryption, a long, unique password and up-to-date devices.

Security here does not ask you to become a network expert. It asks you to open one screen, read one option and choose with awareness: a few minutes that go with you through every hour of work on the move.

Something to think about. If you opened your hotspot settings today, could you say which protection you are using, and why?

Explore this recommendation

This recommendation is the pivot of a content unit. Each post looks at a different aspect.

Related resources

Short reads from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.