The old advice is mostly out of date
The classic warning went like this: never check your bank account on café Wi-Fi, because the hacker at the next table can read everything. A decade ago that was fair. Today it is mostly wrong, and the outdated advice distracts people from the risks that actually remain.
The reason is HTTPS, the padlock you see in the browser address bar. It means the connection between your browser and the website is encrypted, so someone sharing the network sees scrambled data, not your passwords or messages. Nearly every site that matters, and every major app, uses it by default now. Your bank login on café Wi-Fi is encrypted between you and the bank.
What someone on the network can still see
Encryption hides the contents of your traffic, not all traces of it. A person on the same network can typically still see which websites your device talks to, meaning the domain names, even though they cannot read what you do there. For most business owners that is a privacy footnote, not an emergency.
The more practical risks are impersonation tricks.
- Fake login portals: those sign-in pages that ask for an email and password before granting Wi-Fi access. A malicious one harvests whatever you type. Never reuse a real password on a Wi-Fi portal.
- Look-alike networks: anyone can name a hotspot CoffeeShop_Free_WiFi and wait for devices to connect automatically. Confirm the network name with staff, and turn off the setting that auto-joins open networks.
- Phishing works exactly as well on café Wi-Fi as anywhere else. Encryption does not protect you from typing your password into a fake site you clicked from an email.
The biggest risks are physical, not digital
In my experience the realistic café threats are things you can see.
Shoulder surfing is simply someone reading your screen, and a crowded café is ideal for it. If you handle client data or payroll in public, a privacy filter, a thin screen cover that blacks out the display from side angles, costs about 30 to 50 dollars and solves most of it.
Device theft is the other one. A laptop grabbed while you order a refill can be worth far more for the files and logged-in sessions on it than for the hardware. Three settings turn a stolen laptop into a brick instead of a breach: a login password that is actually required, auto-lock after a minute or two of inactivity, and full-disk encryption, which scrambles everything on the drive so it cannot be read without your password. On Windows this is BitLocker; on a Mac it is FileVault. Both are free and usually just need to be switched on.
Do you actually need a VPN?
A VPN, a service that wraps all your traffic in an encrypted tunnel to a server elsewhere, is one of the most oversold products in consumer security. Since HTTPS already encrypts the sensitive parts, a VPN on café Wi-Fi mainly hides which sites you visit from the local network and adds a layer for any old app that skipped encryption.
That is genuinely useful in a few cases: if you access internal company systems, if your industry has compliance obligations, or if you simply want the extra margin. It is not a magic shield. A VPN does nothing about phishing, weak passwords, malware, or a stolen unlocked laptop, and those are the ways small businesses actually get hurt. If you run a team, a business-grade VPN or the secure-access features built into Microsoft 365 and Google Workspace matter more than any consumer VPN subscription.
What to do next
Here is my honest café checklist, in priority order.
- Turn on full-disk encryption and a one-to-two-minute auto-lock on every laptop today.
- Turn on multi-factor authentication for email and banking, so a stolen password is not enough by itself.
- Stop auto-joining open Wi-Fi networks, and never type a real password into a Wi-Fi sign-in portal.
- Buy a privacy filter if you regularly work with sensitive data in public.
- Use your phone's hotspot for anything that makes you hesitate; it is your own private network and takes ten seconds to switch on.
As a Security+ certified founder I will tell you plainly: the person who steals your data at a café almost certainly is not sniffing packets. They are reading your screen, taking your laptop, or emailing you a fake invoice. Defend against those first.
