• Home
  • Securing the ‘Third Place’ Office: Policy Guidelines for Employees Working from Coffee Shops and Coworking Spaces
Man remote working in cafe

The modern workplace no longer stops at the office door.

Today, many employees work from home, cafés, libraries, coworking spaces, and even while travelling. These locations often referred to as the “third place” offer flexibility and convenience, but they also introduce risks that simply don’t exist inside a secure office environment.

With remote work now a permanent part of business, organisations must adjust their security approach. A coffee shop cannot be treated like a corporate network, and staff need clear, practical guidance on how to protect company information when working in public.


The Risks of Public Wi-Fi

Free Wi-Fi is one of the main reasons people choose to work from cafés and shared spaces. Unfortunately, these networks are also some of the least secure.

Public networks often lack proper encryption and security controls, making it easier for attackers to intercept data, capture login details, or access sensitive emails.

In many cases, cybercriminals even create fake networks with names that appear legitimate, such as “Free Wi-Fi” or a café’s business name. Once connected, everything sent from the device can be monitored without the user realising.

For this reason, employees should never assume a public network is safe, even if it requires a password.


Making VPN Use Non-Negotiable

A Virtual Private Network (VPN) is one of the most effective protections for remote work.

A VPN encrypts data before it leaves the device, creating a secure connection across an otherwise unsafe network. This prevents anyone on the same Wi-Fi from reading or intercepting information.

Businesses should require VPN use whenever staff are outside the office and ensure the software is simple to use, or even automatically enabled, to reduce reliance on user behaviour.


The Often-Overlooked Risk of Visual Hacking

Not all security threats are digital.

In public spaces, sensitive information can be seen by anyone nearby. A quick glance over a shoulder can expose client details, financial information, or internal documents.

Privacy screens are a simple but effective control. They restrict the viewing angle of a screen so that only the person directly in front can see the content, helping prevent accidental exposure in crowded environments.


Keeping Devices Physically Secure

A laptop left unattended in a café is an easy target.

Unlike an office, public spaces offer no controlled access and no monitoring. Theft can happen in seconds, often without the employee noticing until it’s too late.

Staff should be trained to keep devices with them at all times and use cable locks where appropriate, particularly in coworking environments. Physical awareness is just as important as cyber awareness.


Being Careful with Conversations

Sensitive business discussions don’t belong in public places.

Phone calls and conversations can be overheard, even in noisy cafés. Employees should avoid discussing confidential matters in shared environments and move to private areas if a call is unavoidable.


Creating Clear Remote Work Guidelines

Employees should never have to guess what is acceptable.

A written remote work security policy sets clear expectations and supports consistent behaviour. It should cover:

  • Use of public Wi-Fi
  • Mandatory VPN requirements
  • Physical device security
  • Privacy and confidentiality in public spaces

Regular reviews ensure the policy remains relevant as technology and threats evolve.


Supporting Secure, Flexible Work

Working from a “third place” offers real benefits, but it also requires greater awareness and discipline.

With the right tools, guidance, and policies, your team can work productively and securely from anywhere.

If you’d like help strengthening your remote work security, AST Technologies can assist with practical, business-focused solutions.