Securing the “Third Place”
Office Policy Guidelines for Employees Working From Coffee Shops and Coworking Spaces
The workplace no longer begins and ends at the office door. Since the rapid shift to remote and hybrid working during and after COVID, employees are increasingly logging on from home offices, libraries, coffee shops, coworking spaces, and even while travelling. These locations are often referred to as “third places” — environments that sit outside both the home and the traditional workplace.
While third places offer flexibility and convenience, they also introduce security risks that many organisations underestimate. Unlike a controlled office environment, public spaces expose company devices and data to a wider range of digital and physical threats. As remote working becomes a permanent fixture for many businesses, security policies must evolve to reflect this reality.
A coffee shop should never be treated as a secure office. Open networks, shared spaces, and a lack of physical controls mean employees need clear, practical guidance to protect company systems and sensitive data. Without it, organisations remain exposed to unnecessary cyber and compliance risks.
Failing to address security in public environments can have serious consequences. Cybercriminals actively target public Wi-Fi networks, knowing they are frequently used by remote workers. By equipping your team with the right tools, training, and policies, you can reduce risk and maintain a strong security posture wherever work takes place.
The Dangers of Open Networks
Free Wi-Fi is one of the biggest attractions of working from cafés, shopping centres, libraries, and coworking spaces. Unfortunately, these networks are rarely designed with business-grade security in mind. Even when passwords are required, they are often shared widely and lack the monitoring, segmentation, and encryption found on corporate networks.
This creates an ideal opportunity for attackers to intercept traffic and capture login credentials, emails, and sensitive business information. In many cases, this can happen silently and within seconds.
One common tactic is the use of rogue Wi-Fi networks. Attackers set up fake access points with convincing names such as “Free Wi-Fi” or mimicking a nearby business. When an employee connects, the attacker gains visibility into the data being transmitted — a classic man-in-the-middle attack.
(You can read more about this type of threat on the National Cyber Security Centre (NCSC) website: https://www.ncsc.gov.uk)
Employees should be instructed never to assume public networks are safe. Even password-protected connections can pose a significant risk. Exercising caution on all public networks is essential to protecting company data.
Mandating Virtual Private Networks
A Virtual Private Network (VPN) is one of the most effective tools for securing remote work. A VPN encrypts data before it leaves the device, creating a secure tunnel across the public internet. This ensures that even if traffic is intercepted, the information remains unreadable.
Providing a VPN should be considered a baseline requirement for any organisation supporting remote work. Employees must be required to use it whenever they are working outside the office or connecting to unsecured networks. To ensure adoption, VPN software should be easy to use and configured wherever possible to connect automatically.
To reduce reliance on user behaviour, technical controls should also be implemented to prevent employees from accessing company systems without an active VPN connection. This removes guesswork and significantly lowers the risk of accidental exposure.
Sedcom supports businesses with secure remote access solutions designed for real-world working environments. Learn more about our approach to secure remote working.
The Risk of Visual Hacking
Not all threats are digital. In public spaces, visual hacking is an often-overlooked risk. This involves sensitive information being viewed, memorised, or photographed simply by someone glancing at a screen.
Employees can easily forget how visible their screens are in crowded environments. Client data, financial information, internal systems, and intellectual property can all be exposed to anyone sitting nearby.
To reduce this risk, organisations should provide privacy screens for laptops and monitors used in public settings. These filters restrict the viewing angle so that only the person directly in front of the screen can see the content. Some modern devices also include built-in privacy features that can be enabled when working remotely.
Addressing visual security closes a critical gap that technology alone cannot solve.
Physical Security of Devices
Leaving a device unattended in a public space significantly increases the risk of theft. Actions that feel routine in an office environment — such as stepping away to get a drink — can result in lost devices and compromised data when working from a café or shared workspace.
Remote work policies should clearly state that devices must remain with the employee at all times. Laptops should never be left unattended or entrusted to strangers, even briefly. A stolen device can be accessed or removed in seconds.
Employees should also be encouraged to use cable locks, particularly in coworking spaces or when remaining in one location for extended periods. While no deterrent is foolproof, these measures make theft more difficult and help reduce opportunistic attacks.
Handling Phone Calls and Conversations
Confidential conversations can be just as vulnerable as unsecured networks. In public spaces, voices carry, and sensitive discussions can easily be overheard by unintended listeners.
Employees should avoid discussing confidential or sensitive business matters in third-place environments. If a call is unavoidable, it should be taken in a private area, such as outside or in a vehicle. While headphones prevent others from hearing the remote party, the employee’s own voice can still disclose sensitive information.
Clear guidance on this point helps reduce the risk of accidental information leakage.
Creating a Clear Remote Work Policy
Security policies should never rely on assumptions. A documented remote work policy removes ambiguity, sets expectations, and provides a framework for training and enforcement.
Policies should include dedicated guidance on public Wi-Fi usage, VPN requirements, physical device security, and acceptable behaviour in public environments. Explaining the reason behind each rule helps employees understand their importance and improves compliance.
Ensure the policy is easy to access, for example via your company intranet, and review it at least annually. As threats evolve, your policies must evolve with them. Regular updates and reminders keep security at the forefront of everyday working habits.
Sedcom works with organisations to develop practical, enforceable IT security policies that align with real working practices. Find out more about our cyber security services.
Empower Your Remote Teams
Third-place working offers flexibility and can improve productivity and morale, but it demands greater awareness and stronger safeguards. Public Wi-Fi security, physical awareness, and clear policies are no longer optional — they are essential.
By combining the right tools, training, and controls, businesses can manage risk while supporting modern working patterns. Well-informed employees are one of the strongest defences against cyber threats.
Is your team working remotely without a safety net? Sedcom helps businesses implement secure remote access solutions and practical policies that protect data, even on public networks.
Get in touch today to strengthen your remote working security.


