Business travel changes the conditions around a normal workday. Staff may be using unfamiliar networks, moving between countries, working in public spaces, carrying valuable devices and answering messages while tired or rushed. A useful travel security programme prepares people for those moments without turning every trip into a technical exercise.
This guide shows how to train staff on cyber security risks while travelling, from the pre-trip briefing to the return-home check. It is designed for organisations that want a repeatable travel process rather than a once-a-year reminder.
TL;DR
- Classify trips by destination, data, device and access level before deciding what controls and training are needed.
- Give travellers a short checklist for updates, MFA, device encryption, screen locks, backups and emergency contacts.
- Teach people to avoid unknown USB devices, suspicious QR codes, unexpected links and untrusted public networks.
- Keep sensitive work to managed devices and approved services; use mobile data or an organisation-approved connection when possible.
- Make loss, theft, suspicious contact and accidental disclosure easy to report without blame.
- Run a return-home review and rotate or reset access when the trip or risk assessment requires it.
Why travel changes cyber risk
A traveller can be exposed without doing anything obviously careless. A laptop may be left briefly in a hotel room, a phone may be connected to a charging point, a conversation may be overheard in an airport lounge or a rushed message may be opened from a conference contact. The risk comes from the combination of valuable information, unfamiliar surroundings and less access to the normal support team.
The Australian Cyber Security Centre’s enterprise mobility guidance notes that personnel travelling overseas with mobile devices face additional security risks compared with domestic travel, especially when visiting higher-risk destinations. Its social-engineering guidance also identifies senior staff, IT service desks, sales and marketing teams, and people who regularly deal with external parties as common targets. Travel training should therefore be based on the work a person does and the information they carry, not just the fact that a flight is booked.
The aim is not to tell people that hotels, airports or public Wi-Fi are automatically unsafe. The aim is to make the safer choice obvious when a person has only a few seconds to decide.
1. Classify the trip before the briefing
Start with four questions:
- Where is the person going, including transit stops and overnight locations?
- What data, systems and credentials will they access?
- Which devices will they carry, and are they managed by the organisation?
- How much authority does their role have to approve payments, release information or change access?
Use the answers to create simple travel tiers. A domestic trip with a managed laptop and low-sensitivity work may need the standard checklist. An overseas trip involving privileged access, customer data, research material or executive communications may need a loan device, reduced access, additional approval and a security contact who is available throughout the trip.
Do not make the traveller guess the tier. The manager, IT owner or security lead should decide it before departure and record the reason. A cyber security gap assessment can help map which roles, systems and processes need a stronger travel path.
2. Give travellers a pre-departure checklist
Keep the briefing short enough to use. Complete it several days before departure so there is time to replace a device, revoke an old session or fix an account. The checklist should cover:
- operating-system, browser and application updates
- device encryption, screen lock and automatic lock time
- MFA on email, remote access, finance and administrator accounts
- current backups and a tested recovery route
- approved collaboration, storage and messaging services
- the minimum data and applications needed for the trip
- a known contact for lost devices, suspicious messages and urgent access questions
Check that the traveller can find the support number without logging in. If the person loses their phone, they may not be able to reach a directory or receive a one-time code. Give them a second approved route and explain which details must never be shared with a caller or message sender.
The security awareness training programme can provide the common language, but the travel briefing must include the organisation’s actual devices, apps, reporting route and emergency decisions.
3. Minimise what travels
The safest data is the data that does not leave the office or approved cloud service. Ask whether the person really needs local copies of customer lists, source code, financial files, identity documents or administrator tools. Remove unused accounts, browser sessions and downloads before departure.
Use managed devices for business work and keep personal and business accounts separate. Do not copy sensitive files to a personal USB drive or personal cloud account to make a trip easier. If a loan device is used, record who receives it, what access it has, when it must be returned and how it will be checked afterwards.
Travel training should explain the reason for the limit. People are more likely to follow a small-data rule when they understand that a lost device then exposes less information and gives the organisation fewer accounts to reset.
4. Teach the public-space habits
Practise the moments that feel ordinary:
- Lock the screen before leaving a seat, taxi or meeting room.
- Position the display away from passers-by when handling sensitive work.
- Keep devices with the traveller rather than in checked baggage where policy requires it.
- Do not discuss customer, financial or security details where strangers can hear.
- Treat unexpected offers of technical help, charging cables, USB devices or QR codes as a reason to stop and verify.
The traveller should know that a polite refusal is acceptable. A stranger who wants to connect a USB device, install a profile or ‘help’ with a sign-in problem does not get authority from being in a hotel lobby or conference venue.
Use role-play for executives and sales staff who receive frequent approaches. Let the learner practise saying, ‘I cannot open that here; I will use the official application later,’ and ‘Please send the request through the known company contact.’
5. Make network choices simple
Teach people to prefer mobile data or the organisation’s approved connection for sensitive work. Public Wi-Fi can be convenient, but the network name alone does not prove that the connection is genuine. The ACSC provides separate guidance on connecting to public Wi-Fi and hotspots; use it to support the organisation’s own travel policy rather than giving travellers a vague warning.
Tell travellers what to do when a connection requires an unexpected certificate, app, browser extension, configuration profile or login to a sensitive account. Stop and use another route. Do not disable security warnings to make a hotel or airport connection work.
A VPN can be part of an organisation’s control, but training should not reduce the decision to ‘turn on the VPN and everything is safe’. The device, account, application and destination still matter.
6. Train against travel-themed social engineering
Travel creates believable stories for attackers. A message may claim that a flight changed, a hotel booking failed, a colleague is waiting at the venue or an executive needs a document immediately. A caller may mention the conference name, the traveller’s employer or a public itinerary to sound credible.
The response is the same as at home: pause, avoid unexpected links and attachments, verify through a known channel and report the communication. The ACSC says never to enter credentials or personal information into a website reached through a suspicious message, and advises preserving and reporting suspected social-engineering attempts rather than engaging with them.
Use the phishing programme to run scenarios based on the traveller’s actual channels. Include email, text, collaboration chat, voice calls and QR codes. The correct answer should be a behaviour: open the official app, call the known number, ask the service owner or report the message.
7. Define the lost-device and incident response
A traveller should not have to decide alone whether a missing phone is serious. Give them a three-step response:
- Move to a safe place and contact the organisation through the approved emergency route.
- Report what happened, including the device, location, time, account and data involved.
- Follow instructions to lock, wipe, revoke sessions, change credentials or seek local assistance.
Tell staff not to delay reporting because they hope to find the device. Do not promise that remote wiping will always work; the organisation needs the report while it can still protect accounts and sessions.
Include accidental disclosure and suspicious contact in the same route. A traveller who opened a document, scanned a QR code or spoke to someone claiming to be support should be able to report it without being punished for asking early.
8. Run the return-home check
Travel security does not end at the airport. On return, require the traveller to report lost or borrowed equipment, unusual prompts, new applications, suspicious messages and any device that was inspected or repaired. Review whether temporary access, local downloads, browser sessions or shared files should be removed.
For higher-risk trips, the security team may require credential rotation, session revocation, malware checks or replacement of the device before it reconnects to sensitive systems. Make that decision in the travel tier, not after an incident.
Record the questions people asked. If several travellers were unsure whether a hotel network was approved or where to report a lost phone, improve the process rather than repeating the same warning.
9. Measure behaviour, not attendance
Track whether the controls worked:
- percentage of travellers completing the briefing before departure
- MFA, updates and encryption checks completed
- high-risk trips using the required device or access tier
- time from loss or suspicious contact to report
- travel-related phishing reports and repeat errors
- return-home checks completed and temporary access removed
Do not treat a completed slide deck as proof that someone can make the right choice under pressure. Use short scenario questions and a post-trip check. Human risk reporting can help bring training, quiz and phishing evidence together when the organisation’s data-handling rules permit it.
Troubleshooting
Travellers say the checklist is too long
Split it into a standard checklist and a higher-risk addendum. Remove questions that do not change a decision, but keep the emergency route, device controls, MFA and data-minimisation checks.
Staff need to work on an unapproved network
Give them a fallback before departure: mobile data, an approved hotspot or a delayed task. If the work is urgent, ask the service owner to decide whether the data and access level can be reduced. Do not make the traveller bypass a warning alone.
A device is lost overseas
Use the emergency route immediately, even if the device may be recovered. The security team can decide whether to lock accounts, revoke sessions, wipe the device or notify other stakeholders.
People ignore the travel briefing
Make the manager accountable for the tier and completion, and keep the training tied to real travel decisions. A short scenario about the traveller’s role will usually be more useful than a generic policy reminder.
FAQ
What cyber security risks do employees face when travelling?
They may face loss or theft of devices, overheard information, untrusted networks, unexpected charging or USB devices, targeted social engineering and pressure to work around normal controls. Risk increases when the device carries sensitive data or privileged access.
Should employees use public Wi-Fi while travelling?
They should follow the organisation’s travel policy and prefer an approved connection for sensitive work. If a public network requests an unexpected certificate, app, profile or security change, stop and use the documented fallback.
What should staff do if a work phone is lost overseas?
Report it immediately through the approved emergency route, provide the device and account details, and follow instructions to lock, wipe, revoke sessions or change credentials. Do not wait to see whether it turns up.
How do you train staff for travel cyber security?
Classify the trip, minimise the data and access that travel, practise public-space and social-engineering scenarios, provide a short checklist and emergency route, then complete a return-home review.
Should a separate device be used for high-risk travel?
The organisation should decide this from the destination, data, access and role. Where the travel tier requires it, use a managed loan device with only the access needed and a defined return and inspection process.
One last thing
Travel security succeeds when the safest option is also the easiest option. Give people fewer files to carry, fewer decisions to make and a real person to call when something feels wrong.
What to do next
Create two travel tiers, publish the standard checklist, test the lost-device phone number and run one scenario workshop with executives, sales staff and anyone who carries privileged access. Use the Cyber Aware comparison page to evaluate training, phishing and human-risk reporting requirements in the same workflow.
Sources
- Guidelines for enterprise mobility, Australian Cyber Security Centre guidance on mobile devices and overseas travel, accessed August 2026.
- Connecting to public Wi-Fi and hotspots, Australian Cyber Security Centre guidance, accessed August 2026.
- Social engineering, Australian Cyber Security Centre guidance, last updated 9 April 2026.