Many proposed solutions circulate on this subject, and most of them solve a problem that is already solved. This post lines up what protects what, so a choice can be made on the basis of what is actually needed.
It expands on the recommendation sensitive data on public Wi-Fi.
The four layers of protection
On a public network there are four independent layers, and each covers something different.
| Layer | What it protects | Who provides it |
|---|---|---|
| 1. Network encryption | The radio link between device and router | Whoever runs the network |
| 2. Site encryption | The content exchanged with each individual site | The site |
| 3. A tunnel (VPN) | All the traffic up to an exit point | A provider you choose |
| 4. Device configuration | The device’s exposure on the network | You |
The most common mistake is thinking they are alternatives. They are not: they act on different stretches of the route. Layer 2 does the heavy lifting, and it is already there.
Layer 1 — Wi-Fi network encryption
It concerns only the stretch between your device and the router.
| Kind of network | Encryption of the radio link | Who can read |
|---|---|---|
| Open, no password | Absent on older networks | Whoever is in range, with simple tools |
| Open, recent standards | Present, individual | Only whoever runs the network |
| With a shared password | Present, but a common key | Whoever knows the password |
| With individual credentials | Present, individual | Only whoever runs the network |
There is a little-known positive detail: the more recent standards encrypt the radio link even on open networks, giving each device its own key. They do not verify the network’s identity — so they do not protect against a fake network — but they remove passive listening by the other customers.
In every case, this layer ends at the router. From there on the traffic is in the hands of whoever runs the network, and it is layer 2 that protects it.
Layer 2 — Site encryption
It is the layer that counts most, and it is the one you already have without doing anything.
Every site encrypts its own connection independently, from your device to its own servers. Whoever runs the network, whoever watches it, whoever provides it: none of them can read the content.
What it covers: content, credentials, data entered into forms, apps’ messages.
What it does not cover: which sites you contact, and what you type into the sign-in portal — which is outside this protection because it happens before.
That is why public networks are usable today and were not ten years ago. The network did not change: the web did.
Layer 3 — The tunnel
A VPN creates an encrypted channel between your device and a server you choose. All the traffic passes through it, and comes out from there.
What changes concretely:
| Aspect | Without a VPN | With a VPN |
|---|---|---|
| Traffic content | Already encrypted by the sites | Encrypted twice |
| Which sites you contact | Visible to whoever runs the network | Visible to the VPN provider |
| The sign-in portal | Not encrypted | Not encrypted: the VPN starts afterwards |
| A fake network | The risk is present | The risk is present |
| Apparent location | Yours | The server’s |
The three middle rows are the ones told least often.
A VPN does not remove observation: it moves it. Whoever runs the network no longer sees which sites you contact; the VPN provider does. It is an improvement only if you trust the second more than the first — which, on an airport’s network, is often true, but is worth saying rather than assuming.
A VPN does not protect the portal, because connecting to the portal precedes the tunnel starting.
A VPN does not tell you which network you joined. If the network is fake, it stays fake: it simply will not see your traffic.
When it genuinely makes sense. When you cannot choose the network and the destination itself is information you would rather not make observable; when you have to reach company resources; when you are in contexts where traffic observation is a concrete concern.
Layer 4 — Device configuration
The only layer entirely under your control, and the one covering the residual risks.
| Setting | What it prevents |
|---|---|
| Automatic connection turned off | Joining a network with a known name but a different owner |
| Networks forgotten after use | The device looking for and revealing past networks |
| The “public network” profile | Other devices reaching yours |
| An active firewall | Incoming connections from the local network |
| A private network address | Being recognised across different places |
It is the layer with the best ratio of effort to result, because it covers exactly what the other three do not: the device’s behaviour before and during the connection.
The mobile connection: a case apart
It is worth explaining how it works, because it is the most recommended countermeasure in this unit.
A phone’s data connection has three properties setting it apart:
The radio link is encrypted by the operator, with individual keys tied to the phone’s SIM. It is not a network shared with other customers in the same venue.
There is no sign-in portal. The whole gap described in this unit simply does not exist.
The network’s identity is verified by the SIM, which recognises the operator. It is not possible to “connect by mistake” to somebody else’s mobile network with the same name.
An intermediary remains — the operator — with visibility over the metadata, exactly like any internet access provider. But from the point of view of this unit’s specific risks, a mobile connection closes nearly all of them with no configuration at all.
What does not work as promised
For completeness, and without naming names.
Programs that “protect your Wi-Fi”. Many do no more than check the network’s settings and show a verdict. The traffic was already protected before and stays protected afterwards.
Antivirus “insecure network” warnings. They report that the network is open or uses a dated standard. It is correct information, but it concerns layer 1 — the one layer 2 makes largely irrelevant.
Free VPNs. A VPN service has real infrastructure costs. If you are not paying them, something else is — and in this case what the provider has to monetise is exactly the traffic you are entrusting to it. It is the opposite of what you were looking for.
The case of the corporate VPN
It deserves a distinction, because its logic differs from a personal one.
A corporate VPN does not exist to protect the user’s traffic: it exists to bring the device inside the organisation’s network, so it can reach internal resources not exposed to the internet.
Two practical consequences follow:
The traffic leaves from the company’s premises, so the organisation sees the browsing — declared in the policies and legitimate on a work device, but worth knowing if the same device is also used for personal things.
Security stops depending on whichever network happens to be chosen, which is the real reason it is required on mobile devices. With the VPN on, whether the connection comes from a hotel’s Wi-Fi or an airport’s makes little difference.
If you use one, two points of care: check it is on before working — many disconnect when the network changes — and do not turn it off for convenience when it slows things down, because that is the moment it stops doing its job.
How to choose, in practice
| Your situation | What you need |
|---|---|
| I browse, read and work on non-confidential things | Layers 2 and 4: you have the first, configure the second |
| I have to do a banking operation | A mobile connection |
| I reach company resources | The organisation’s VPN |
| I do not want the network to know which sites I visit | A paid VPN you trust |
| I am in a high-confidentiality context | VPN + mobile connection + care with the portal |
The first row covers most everyday situations. For most people, device configuration is worth more than any additional tool.
How to judge a VPN provider, if you decide to use one
Since a VPN moves observation rather than removing it, the decisive question is who you are trusting. A few concrete criteria, in order of importance.
The business model. A VPN service has significant infrastructure costs. If it is free, those costs are covered another way, and what the provider has to sell is the traffic you entrust to it. It is the most decisive criterion of all.
The logging policy. What it states it keeps, for how long, and in which jurisdiction. A generic declaration of “we keep nothing” is worth little without detail.
Independent verification. Some providers submit to external audits of their practices. It is the only element turning a declaration into something verifiable.
The legal seat and jurisdiction. It determines which retention obligations and which requests the provider is subject to.
Transparency about ownership. Knowing who owns the service is basic information that not every provider makes easy to find.
Behaviour if the connection drops. An option blocking the traffic if the tunnel breaks stops data leaving in the clear without you noticing. Check it exists and is on.
An honest clarification: none of these criteria can be fully verified by a user. Choosing a VPN is, ultimately, a choice of trust. That is one more reason to use one when it is genuinely needed, rather than as a generic precaution.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Telling the four layers apart and what each one covers |
| Awareness | Understanding that a VPN moves observation, it does not remove it |
| Secure Behaviour | Choosing the tool according to the real risk |
Reference level: FL3 — Autonomous.
Summary
- The four layers are not alternatives: they act on different stretches.
- Layer 2 — site encryption — does the heavy lifting and is already there.
- A VPN moves observation from the network’s operator to the VPN provider.
- A mobile connection closes nearly every risk in this unit with no configuration.
One thing to do today. Before looking for a tool, check layer 4: automatic connection off, old networks deleted, the “public network” profile. It costs five minutes and covers more than many paid solutions.
Related content
- Sensitive data on public Wi-Fi — the recommendation this expands on
- How to use public Wi-Fi safely — configuring layer 4, step by step
- How HTTPS works — layer 2 in detail
- Attacks on public Wi-Fi — what these layers stop and what they do not
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



