Use a personal cellular hotspot for sensitive work when coverage and policy allow. Use hotel Wi-Fi for lower-risk activity when the device is updated, accounts are strongly protected and the network has been verified. Use a travel router for convenience and device separation, not because it magically converts an untrusted hotel connection into a trusted one.
The network is only one layer. A secure connection cannot compensate for a compromised laptop, a convincing phishing page or an account protected by a weak recovery process.
Choose by threat, not speed
| Scenario | Preferred path | Why | Residual risk |
|---|---|---|---|
| Reading public news | Verified hotel Wi-Fi | Low data sensitivity | Fake portal, tracking, device exposure |
| Confidential email/document review | Personal hotspot or approved corporate mobile path | Avoids unknown local Wi-Fi operator | Cellular/account/device compromise still possible |
| Video conference | Hotspot if stable; verified hotel Wi-Fi if bandwidth demands it | Balance confidentiality and performance | Room privacy, recording and endpoint risk |
| Several trusted devices | Owned, updated travel router over an approved uplink | Consistent local network and credentials | Router inherits risk from hotel uplink |
| Executive under elevated targeting | Organisation-approved mobile and VPN/zero-trust setup | Managed controls and response | No system is absolute; targeted phishing remains |
| Emergency with no cellular service | Verified hotel Wi-Fi with minimum necessary activity | Availability outweighs ideal architecture | Reduce sensitive tasks and monitor accounts |
Why a hotspot is usually the default
The US Cybersecurity and Infrastructure Security Agency’s travel guidance says a personal hotspot is often a safer alternative to free public Wi-Fi. The Dutch National Cyber Security Centre similarly notes that mobile internet is generally harder to attack than a public hotspot, while correctly avoiding a promise of perfect safety.
A personal hotspot gives the traveller control over the network name and password and avoids joining an access point operated by an unknown party. It also reduces exposure to other guests on a poorly isolated local network.
It does not provide anonymity or end-to-end protection for every activity. The mobile operator, destination service and device still handle data. Encrypted web and app connections remain essential.
Configure the hotspot
use a unique, non-identifying network name;
set a strong password and modern security mode;
disable automatic sharing with nearby strangers;
remove old connected devices;
turn the hotspot off when not needed;
keep the phone charged and physically controlled;
use the organisation’s approved VPN or secure-access client where required.
Do not name the network after yourself, company or hotel room.
When hotel Wi-Fi is acceptable
Public networks are not uniformly malicious. Modern encrypted apps and websites reduce some historic risks. The decision should still reflect the task.
Hotel Wi-Fi may be reasonable when:
cellular coverage is poor;
the activity is low sensitivity;
the network name and sign-in process have been verified with the hotel;
the device firewall, software and secure-access tools are current;
file sharing and local discovery are disabled;
multi-factor authentication protects important accounts.
Ask reception for the exact network name. An access point named after the hotel is not proof that the hotel operates it. Avoid downloading unexpected “security certificates”, device-management profiles or applications from a captive portal unless your organisation and the hotel have verified the requirement.
After the stay, forget the network so the device does not reconnect automatically on a future visit or near an impersonating access point.
What a travel router actually does
A travel router can create a private local network for your devices, allowing one hotel login to serve a laptop, phone and tablet. It can keep familiar device credentials and may support VPN configuration.
Its benefits are:
device convenience;
a consistent local SSID and password;
separation from some direct guest-network exposure;
a single place to apply certain network settings;
wired-to-wireless conversion where a trusted Ethernet port exists.
Its limitation is fundamental: if the router uses hotel Wi-Fi as its internet uplink, traffic still passes through the hotel network. The router can improve the local edge without making the upstream operator trustworthy.
Use an owned, updated router rather than an unknown device. Change default administrative credentials, install firmware before travel and disable remote management and unnecessary services.
The ten-minute hotel-room setup
Minute 1–2: choose the task class
Separate public browsing from confidential work. If the task includes board material, client records, finance, private travel plans or privileged communications, default to the approved mobile path.
Minute 3–4: verify the network
Confirm the official hotel network name and portal. Check that the browser reaches the expected domain over an encrypted connection. Stop if the portal requests unusual software or credentials unrelated to network access.
Minute 5–6: reduce local exposure
Disable file sharing, AirDrop/nearby sharing as appropriate, printer discovery and automatic network joining. Mark the network public or untrusted when the operating system offers that classification.
Minute 7–8: establish secure access
Connect the organisation’s approved VPN, zero-trust or remote-access tool. Confirm it is actually connected before opening sensitive material.
Minute 9: protect the room
Use headphones for confidential calls, position the screen away from doors and mirrors, and review lock-screen notifications. Network security does not stop visual and acoustic disclosure.
Minute 10: prepare the exit
Plan to log out of captive portals, forget the network and check that no unexpected profile or certificate remains.
The executive travel kit
primary phone with a verified destination data plan;
independent charger and power bank compliant with airline rules;
approved laptop with current updates;
hardware security key if supported by the organisation;
owned travel router only when its use is justified;
privacy screen where shoulder-surfing risk is material;
offline contact and recovery instructions;
minimum necessary files, not a complete corporate archive.
The best kit is small enough that the traveller will actually follow the process.
If the hotspot fails
Cellular networks can be congested, blocked by building materials or unavailable after disruption. A resilient plan has an order:
primary cellular connection;
secondary operator or roaming fallback;
verified hotel network with approved secure access;
offline work until a trusted path is restored.
The last option is underrated. Downloading the necessary documents before travel can be safer than forcing a sensitive connection in poor conditions.
Meetings, screens and voice are part of the threat model
An encrypted connection cannot stop someone in the room from reading a screen or hearing a call. Executive travel security should therefore include the physical environment.
Before a confidential meeting, close unrelated documents, disable message previews and check what a screen-sharing tool will expose. Use headphones, but remember that your own voice remains audible. Avoid taking a sensitive call in a lift lobby, lounge or car with an unknown driver merely because the phone shows a secure-network icon.
If an AI transcription or meeting assistant is enabled, confirm participant consent, organisational policy and where the recording or transcript will be stored. Network choice does not authorise data collection. When the room is unsuitable, postpone the sensitive portion or move to an approved space.
The device remains part of the system
A privacy-positioned phone remains part of a system. The traveller must still choose the network, approve access and respond to loss.
What each option cannot solve
| Option | Cannot solve |
|---|---|
| Hotel Wi-Fi | Phishing, compromised endpoints, careless sharing, account takeover |
| Personal hotspot | Malicious apps, stolen credentials, insecure destination services, physical observation |
| Travel router | An untrusted upstream network, outdated firmware, weak endpoint controls |
| VPN | Everything outside its tunnel or policy; unsafe actions by the authenticated user |
Treat anyone promising “complete protection” from one device or subscription with caution.
For a broader device-selection framework around sensitive executive work, see the secure-device guide for corporate executives.
The final decision
For sensitive executive work, choose a personal hotspot or an organisation-approved mobile connection first. Use verified hotel Wi-Fi when availability or bandwidth requires it and the task’s consequence is acceptable. Add a travel router when several devices and a consistent local network justify the operational burden.
The secure choice is not the most elaborate network. It is the one whose operator, device, account and recovery path you can explain before opening the confidential file.
Frequently asked questions
Is a phone hotspot always safer than hotel Wi-Fi?
No. A hotspot can reduce exposure to an unknown local network, but safety still depends on the mobile network, device configuration, account security and the sensitivity of the work.
Does a travel router make hotel Wi-Fi trusted?
No. It can create a controlled local network for your devices, but the router still uses an upstream connection. Treat that upstream network as untrusted and keep sensitive services protected.
Can a VPN make any public network safe?
A reputable VPN can protect traffic in transit, but it cannot fix a compromised device, a malicious login page, weak account security or unsafe user decisions.




