<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Everyday Security Risks: Wi-Fi

Reviewed and updated in October 2026.

Wi-Fi has been part of our daily lives for more than 25 years. First used to connect laptops in enterprise environments, it quickly spread to homes, offices and public places, connecting mobile devices to local networks and the Internet for management and data exchange. The growth of the Internet of Things (IoT) has made it even more prominent.

Understanding your users' Wi-Fi risks

Caution is warranted, because Wi-Fi is one of attackers' favorite ways to steal valuable information from devices, whether personal (credentials, credit card details) or work-related (emails, classified documents).

There are many well-documented Wi-Fi attacks. The most common are man-in-the-middle (MitM) attacks, in which an attacker intercepts the communication between two parties and can alter it, while both believe they are talking directly to each other. One technique is DNS spoofing or DNS hijacking: the attacker intercepts DNS queries and returns a different address to redirect traffic to a rogue server under their control. Another is eavesdropping, or "sniffing": the attacker secretly listens to the communication to collect valuable information, typically credentials, payment data or anything else that can be extracted from unencrypted transmissions.

Today, most web and app traffic is encrypted with TLS, which makes passive eavesdropping on content much harder than it used to be. The risks have not disappeared, though. Rogue access points that imitate a known network name, fake captive portals that ask for credentials, DNS manipulation and attacks on VPN routing still target public Wi-Fi. A current example is the TunnelVision technique, in which a rogue DHCP server can route traffic around a VPN tunnel; read more in Public Service Announcement (PSA): TunnelVision Vulnerability.

Protect your users' devices

You cannot trust or control any Wi-Fi network except your own, so one of the best ways to keep corporate data safe is to secure the devices themselves. From an enterprise perspective, you want to prevent any data on managed devices from travelling over an unsecured, untrusted network. What you can do depends on the type of device, its ownership and its management mode.

Managing BYOD

With Bring Your Own Device (BYOD), you cannot control the device itself, only the work part. So you want to make sure that corporate information stays safe even if the device or the connection is compromised. The best option here is a containerized solution for work apps and data, which protects data both at rest and in transit. Communication stays encrypted, nothing usable can be extracted by an attacker and company data remains safe.

Managing corporate-owned devices

For corporate-owned devices, your UEM software should already include Wi-Fi policies and profiles that control which networks devices can connect to and how. There are two main management modes: Corporate-Owned, Personally Enabled (COPE) and Corporate-Owned, Business Only (COBO), depending on how much room you want to leave users for personal apps and documents.

Configure and provision corporate Wi-Fi networks automatically on all managed devices with Wi-Fi configuration profiles, so that work data only travels over secure and trusted networks.

Securing communications

The next step is to make sure all work-related data (COPE) or even all device data (COBO) travels over a secure connection to your own back-end servers, whether they sit behind a firewall on premises or are reachable on the Internet. Your UEM vendor should offer a containerized solution, a VPN-like solution or its own infrastructure that secures communication end to end. For the basics, see Demystifying Security: Virtual Private Network (VPN).

Going further on corporate-owned devices

For specific use cases, you can lock down corporate-owned devices even further. You can control which Wi-Fi networks they connect to by preventing users from adding new networks manually (for example at home), from connecting to public networks with captive portals (for example in malls or hotels), or by blocking known untrusted networks (for example carrier-provisioned hotspots).

To prevent data leakage, also disable Wi-Fi Direct where supported, so that devices cannot exchange data point to point without any control or monitoring of that connection.

In highly regulated environments where security comes first, you can disable Wi-Fi on the device entirely so that the cellular network is used instead, ideally with a dedicated Access Point Name (APN), so work data still travels over a secure connection to your internal network.

Note: Policy options differ by device type (iOS, Android) and UEM solution, but these controls are available in most cases. For current guidance on Wi-Fi security standards such as WPA3, see the Wi-Fi Alliance.

This post is part of our Everyday Security Risks series, together with QR codes at restaurants and USB.

Want to review your Wi-Fi and VPN policies? Our team supports endpoint management and endpoint security projects, and our trainings cover the management modes in depth. If you have questions about improving your security posture, contact us.