Join our Newsletter — 33% off our NHI Course

What should organisations tell staff to do when shopping on public WiFi?

Staff should avoid entering passwords, account numbers, or payment details on open networks. If shopping cannot wait, use a VPN and only access sites that use HTTPS. A trusted location does not make the WiFi trusted. The right control is to delay sensitive transactions until a secure network is available, especially on mobile devices.

Why public WiFi creates a shopping trust problem

Public WiFi is convenient, but it is a shared and often untrusted network path. For online shopping, the main issue is not the WiFi name itself, it is whether the connection can be observed, redirected, or tampered with before the browser completes a secure session. That is why organisations should tell staff to treat open networks as unsafe for any transaction that exposes payment or account data.

The practical decision is simple: browsing product pages may be acceptable, but entering credentials, card numbers, shipping details tied to sensitive accounts, or purchase approvals should wait until a trusted network is available. If the business need is urgent, the safer fallback is to reduce exposure with a VPN and only proceed on sites that enforce HTTPS end to end.

What employees should do instead of transacting on open networks

Staff guidance should be specific enough to change behaviour. The right instruction is not just “be careful”, but “do not complete sensitive shopping on public WiFi unless you have a secure connection and a trusted device.” That means delaying checkout, using cellular data where appropriate, or moving the transaction to a secure office or home network.

Organisations should also make clear that a familiar place does not make the network trustworthy. Airport lounges, hotels, cafés, and conference venues all use networks that can be shared, impersonated, or captured by rogue access points. The safer habit is to separate low-risk browsing from high-risk actions, and to assume that anything typed into a checkout form on open WiFi could be exposed if the session is not properly protected.

For teams that need a concrete policy, NIST Cybersecurity Framework 2.0 supports this kind of user protection and risk reduction through its protect and govern functions, while NIST AI Risk Management Framework is not the relevant lens here and is better left out of this control decision.

Which protections actually reduce the risk during shopping

When shopping cannot wait, the control stack matters. A VPN helps by reducing exposure on the local network path, but it does not make an unsafe site safe by itself. HTTPS is still essential because it protects the browser session to the site, confirms transport security, and reduces the risk of interception or content manipulation in transit.

Staff should also be told to verify the visible signs of a secure session before entering payment details, especially on mobile devices where users are more likely to move quickly and trust whatever network is available. If the site fails to load securely, presents certificate warnings, or repeatedly redirects in a way that breaks the secure path, the correct decision is to stop and continue later on a safer connection.

For organisations that want to anchor this in recognised control language, NIST SP 800-53 Rev 5 Security and Privacy Controls provides the broader access control and system protection context, and NIST Cybersecurity Framework 2.0 helps frame the user-facing safeguard as part of a wider protect posture.

What good staff guidance looks like in practice

Good guidance is short, memorable, and tied to a clear decision rule. Tell staff to browse freely if needed, but delay any sensitive checkout, login, or payment step until they are on a secure network. If the purchase must happen immediately, require VPN use, HTTPS verification, and a pause before any payment or account field is completed.

Decision rule: if the transaction involves credentials, payment details, or account numbers, do not rely on open WiFi alone. If the network cannot be trusted, the safest control is to wait rather than to improvise.

What to verify: the device is using a secure connection, the site is genuinely HTTPS, and the user is not being pushed through certificate prompts or suspicious redirects. On shared networks, those checks should be part of the user’s normal behaviour, not an optional extra.

Practitioner takeaway: The control objective is not to make public WiFi “safe”, it is to keep sensitive shopping actions off it unless a secure transport path and a trusted session are clearly in place.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-05 — Protective Technology Applies to securing user transactions and sessions on untrusted networks.
Recommendation — Require secure connectivity and trusted transport before allowing sensitive online purchases.
NIST SP 800-53 Rev 5 AC-17 — Remote Access Relevant because shopping on public WiFi depends on controlling remote session exposure.
IA-2 — Identification and Authentication (Organizational Users) Supports protecting account logins used during online shopping.
Recommendation — Limit sensitive access over untrusted networks and require stronger session protection. Enforce strong authentication before any purchase or account access on untrusted networks.
ISO/IEC 27001:2022 A.8.20 — Network security Supports protecting data in transit when staff use public or shared networks.
A.5.14 — Information transfer Relevant to protecting shopping data as it moves across public networks.
Recommendation — Apply network security controls that reduce exposure on untrusted WiFi. Protect information transfers with approved secure channels before sensitive data is entered.