Digital and Cyber Security for Travellers
How to recognise cyber risks while travelling, protect accounts and devices, and respond quickly if a phone, laptop, password or financial account may have been compromised.
1. Why Cyber Security Matters When Travelling
Travel changes the way people use technology. Travellers often rely on public networks, carry devices through unfamiliar locations, use QR codes and charging points, and make urgent bookings or payments. These conditions create opportunities for theft, fraud, surveillance, malware and account takeover.
Cyber security while travelling is not only about installing an antivirus product or using a VPN. It is a combination of reducing the data you carry, protecting accounts, using safer connections, staying alert to deception, and knowing how to react when a device or account may no longer be trustworthy.
Public Wi-Fi risks
A fake or poorly protected hotspot can expose traffic, redirect users to malicious pages or trick them into entering credentials. Even a legitimate hotel, airport or café network should be treated as untrusted.
Device theft and loss
A stolen phone or laptop may provide access to emails, saved passwords, authentication codes, photos, financial apps and corporate systems if it is not locked and encrypted.
Phishing and travel scams
Attackers exploit urgency: a supposed airline change, hotel payment failure, passport issue, delivery notice or security alert. A convincing message can lead to a fake login page or malware download.
Physical access and surveillance
Unattended devices, unknown USB accessories, public computers and potentially inspected devices can expose data or introduce malicious software. Treat a device that has been out of your control with caution.
2. Before You Travel: Reduce the Attack Surface
The most effective security measures are completed before departure, when there is time to update, back up, configure and test devices. For business travel, follow the organisation’s IT and information-security requirements; do not attempt to work around controls for convenience.
Take only what you need
Every device and every file creates exposure. Consider whether you need to take a laptop, tablet, external drive, confidential client data, address book or offline document archive. For higher-risk trips, organisations may provide a clean travel device with only the applications and information needed for the assignment.
Prepare every device
- Install operating-system, browser, application and security updates before departure.
- Enable full-disk encryption, a strong screen lock and an automatic lock after a short idle period.
- Back up essential data securely and verify that it can be restored.
- Turn on device-location and remote-lock or remote-wipe functions where available and permitted.
- Remove unnecessary apps, old accounts, saved payment cards and files containing sensitive data.
- Record the device model, serial number and support contacts separately from the device.
- Carry devices and data storage in hand luggage rather than checked baggage.
Prepare accounts and recovery methods
Review the recovery email address, recovery phone number and multi-factor authentication method for important accounts before travel. Ensure that authentication will still work abroad: for example, consider whether SMS codes will arrive without your usual SIM, whether a trusted authenticator app has been backed up, and whether your organisation has an emergency identity-support process.
- Update, encrypt and back up all devices.
- Use a password manager and replace reused passwords with unique ones.
- Enable multi-factor authentication, preferably using an authenticator app, passkey or security key where supported.
- Install and test the approved VPN before departure; some destinations may restrict or block particular services.
- Save IT support, security incident and bank/card emergency numbers in a secure place.
- Tell your bank or card provider about the trip if required by its procedures.
3. Public Wi-Fi, Mobile Data and VPNs
A VPN can add important protection, but it is not a guarantee of safety. It encrypts the connection between your device and the VPN service; it does not make a fake website legitimate, prevent phishing, remove malware or replace good account security.
Choose the safest practical connection
| Connection | Typical risk | Recommended use |
|---|---|---|
| Mobile data / personal hotspot | Lower exposure to local public Wi-Fi attacks, but still vulnerable to phishing, malware and account compromise. | Prefer for banking, work systems and sensitive tasks when roaming or a trusted local SIM/eSIM is available. |
| Trusted home or corporate network | Risk depends on device and account security; it is not risk-free. | Suitable for normal sensitive activity when devices are current and accounts are protected. |
| Hotel, airport, café or conference Wi-Fi | Network impersonation, interception, captive-portal scams and other local threats. | Avoid sensitive transactions if possible. Verify the network name with staff and use the organisation-approved VPN where required. |
| Public computer or shared kiosk | Keylogging, malware, saved sessions and shoulder surfing. | Do not use for banking, corporate systems, password resets, email or other sensitive accounts. |
Safe Wi-Fi behaviour
- Ask staff for the exact network name and login process; do not connect merely because a name looks plausible.
- Disable automatic Wi-Fi connection and forget public networks after use.
- Turn off file sharing, network discovery and AirDrop-style sharing functions when not needed.
- Use HTTPS websites, but remember that a padlock does not prove a website is genuine or safe.
- Do not conduct sensitive transactions on public Wi-Fi unless there is no reasonable alternative and you are following your organisation’s approved security controls.
Using a VPN responsibly
Use the VPN approved by your employer for business activity. Configure it before travel, keep the client updated and confirm that it reconnects after sleep or a network change. Organisations may require always-on or full-device VPN configurations to reduce accidental traffic outside the protected connection. Do not use a VPN to bypass local law, organisational policy or service restrictions.
Further reading: Dutch NCSC guidance for travelling with mobile equipment, UK NCSC VPN guidance, and CISA cybersecurity when travelling tip sheet (PDF).
4. Passwords, Passkeys and Multi-Factor Authentication
Most serious online incidents start with stolen, guessed, reused or phished credentials. The goal is to ensure that a password theft alone does not give an attacker broad access to your accounts.
Use a password manager
A reputable password manager makes it practical to use a long, unique password for every account. It also reduces the temptation to reuse passwords and can help identify fake login pages because it normally will not autofill credentials on the wrong domain. Protect the password-manager account itself with a long unique master password and strong multi-factor authentication.
Prefer phishing-resistant authentication where available
Passkeys and hardware security keys can provide stronger resistance to phishing than passwords or one-time SMS codes. Where these are not available, an authenticator app is generally preferable to SMS for important accounts. Keep backup codes offline in a secure location, not in an unprotected note on the same device.
Recognise phishing attempts
- Do not act on a message only because it creates urgency, fear or a promise of refund or upgrade.
- Do not use a link in an unexpected email, text message or QR code to sign in, reset a password or make payment.
- Open the airline, hotel, bank or company application directly, or type the known website address yourself.
- Check the full sender address and website domain; visual branding and a padlock icon are not proof of authenticity.
- Never approve an unexpected multi-factor authentication request. Repeated prompts may mean that someone already knows your password.
5. Device Protection and Physical Security
A technically secure device can still be compromised when someone obtains physical access. Good travel security combines encryption and access control with simple habits: keep devices with you, do not leave them exposed, and reduce opportunities for observation or tampering.
Protect your devices in public
- Keep your phone, laptop and bags in sight; do not leave them unattended in vehicles, hotel conference rooms, lounges or restaurants.
- Use privacy screens and position yourself to reduce shoulder surfing when working in public.
- Lock the screen whenever you put the device down, even briefly.
- Do not share PINs, unlock codes, recovery codes or security tokens with other people.
- Keep Bluetooth, NFC and personal hotspot functions disabled when they are not required.
Charging safely
Use your own wall charger and cable, or a trusted power bank. Avoid unfamiliar USB charging stations and unknown USB accessories, which may expose a data connection as well as power. If a public USB connection is unavoidable, use a suitable data-blocking adapter and do not unlock or trust prompts from the connected device.
High-risk destinations or sensitive work
Some trips require enhanced controls because of the traveller’s role, the sensitivity of the information carried or the local threat environment. In these situations, take a clean device if available, limit data to what is strictly needed, use approved encrypted services and follow your employer’s instructions on borders, inspections and device handling. If a device is searched, seized, left out of your control or shows signs of tampering, treat it as potentially compromised and report it before reconnecting it to a corporate network.
The Swiss NCSC travel guidance recommends taking only necessary devices and information, encrypting necessary sensitive data and treating public networks and charging points cautiously. The Safe Travels guidance (PDF) also advises treating a device as compromised if it has been inspected or potentially accessed without your control.
6. What to Do If Something Happens
Fast, calm reporting limits damage. Do not delay because you are unsure whether an incident is serious. A lost phone, suspicious login, phishing click or possible malware infection can often be contained quickly when reported early.
If a device is lost or stolen
- Move to a safe location and, if relevant, contact local emergency services.
- Use another trusted device to locate, lock or erase the device remotely, if this is part of your approved setup.
- Notify your employer’s IT/security contact immediately if a work device, work account or corporate data may be involved.
- Contact your mobile provider to block the SIM/eSIM where appropriate.
- Change passwords for the most important accounts from a known-safe device, starting with email, password manager, banking and corporate identity accounts.
- Contact banks or card providers if payment cards, banking applications or financial data may be exposed.
- Make a police report when appropriate and retain the reference number for insurance or corporate reporting.
If you clicked a suspicious link or opened an attachment
- Stop interacting with the page, file or message. Do not enter further information.
- Disconnect the affected device from Wi-Fi, mobile data and wired networks if malware is suspected; do not destroy evidence or attempt complex cleanup yourself.
- Report the incident immediately to your organisation’s IT/security team or, for personal accounts, to the relevant service provider.
- From a known-safe device, change any password entered on the suspicious page and revoke active sessions where the service provides that option.
- Review email forwarding rules, recovery addresses, payment details and recent account activity for unauthorised changes.
- Follow professional guidance on device isolation, investigation and recovery before reconnecting a work device.
If you suspect account takeover
Signs include login notifications from an unfamiliar location, password-reset emails you did not request, unexpected MFA prompts, messages sent from your account, changed recovery details or unexplained payments. Use the provider’s official account-recovery page reached through a known bookmark or app. Change credentials, revoke unknown sessions, remove unfamiliar app permissions, verify recovery methods and notify affected contacts if an attacker may have used your account to impersonate you.
If a bank card or payment account is affected
Contact the card issuer or bank using the number in its official application, the back of the physical card, or a previously saved official number. Freeze or block the card, dispute unauthorised transactions and watch for follow-up phishing messages that pretend to be from the bank. Do not disclose one-time codes or approve unexpected payments to a caller, email or chat message.
See CISA phishing guidance and CISA’s phishing response postcard (PDF) for further incident-response guidance.
7. After Travel: Recover, Review and Monitor
Post-travel checks are especially important after visiting a high-risk destination, using public networks, losing sight of a device or working with confidential information. The objective is to identify suspicious activity early and prevent a temporary travel exposure from becoming a longer-term compromise.
- Install outstanding updates and run the approved security checks on each device.
- Review account sign-in history, active sessions, recovery methods, email-forwarding rules and connected applications.
- Change passwords if a device was lost, inspected, tampered with or otherwise out of your control; change any reused password immediately.
- Review bank, card and mobile-provider activity for suspicious charges, transfers or SIM changes.
- Remove public Wi-Fi networks from saved connections and disable unnecessary permissions granted to travel apps or websites.
- For work devices, follow the organisation’s return-and-inspection process before reconnecting to sensitive systems.
- Record and report any incident or near miss so that the organisation can improve its travel guidance and security controls.