EXPERIENCES

Protecting yourself from cyberattacks at events: essential precautions

To contact us: editorial@fw.media

International trade shows, technology conferences and economic summits have never concentrated so much data, so many identities and so many digital connections within such a short period. For attendees, whether executives, investors, journalists or company employees, these venues have become cybersecurity pressure points where individual vigilance directly determines the level of risk.

The challenge is no longer confined to securing the infrastructure provided by the organiser. It now extends to the digital behaviour of the participants themselves.

Events: a cybersecurity blind spot

In an event environment, the usual reference points disappear. Visitors leave their secure workplace to enter a temporary, hybrid and often hyperconnected space. Open Wi-Fi networks, shared charging stations, continuous demonstrations and informal exchanges of links and files all contribute to expanding the attack surface.

This creates a familiar bias: an event is perceived as a social, even convivial, setting when, from a cybersecurity perspective, it should be treated as an untrusted environment by default.

Public Wi-Fi: misplaced trust

Most incidents observed at professional events begin with a simple entry point: the network. Connecting to an event’s Wi-Fi, even the official network, means entrusting your security to infrastructure you do not control.

The recommended precautions are well known, but rarely applied consistently:

  • Use your mobile hotspot whenever possible.
  • Avoid accessing sensitive services over a public network.
  • Use a VPN when connecting is unavoidable.
  • Verify the network’s exact name and access method.

The threat is not necessarily a sophisticated attack. Opportunistic interception or the theft of active sessions may be enough.

Laptops and smartphones: people remain the weakest link

At a trade show, a laptop left on an open table or a phone connected to a public USB charging point becomes a passive target. Malware is not always necessary. Physical access may be sufficient.

A few precautions can make a substantial difference:

  • Configure devices to lock automatically after a few seconds.
  • Disable wireless-sharing features.
  • Avoid unknown USB charging stations.
  • Use only your own cables and chargers.

In a crowded environment, the exposure window may be brief, but it can still be long enough.

QR codes, links and physical media: social engineering at events

Events have widely adopted QR codes, branded USB drives and shortened links. This modernisation has created new opportunities for social engineering. Scanning a code or connecting a storage device has become routine and is rarely questioned.

Yet:

  • A QR code can redirect users to a malicious page.
  • A promotional USB drive can contain malicious executable files.
  • A link shared verbally offers little context for verification.

The precautionary principle is simple: no content should be considered legitimate by default, even when it is branded or presented as official.

Accounts, identities and post-event exposure

Events also create periods of intense identity exposure. Badges, conversations, public speaking appearances and social-media posts all provide information that can be exploited in delayed attacks.

Before and after an event, several measures can substantially reduce the potential impact:

  • Enable multifactor authentication systematically.
  • Limit which accounts can be accessed from mobile devices.
  • Change sensitive passwords after returning.
  • Delete automatically saved Wi-Fi networks.
  • Many attacks begin several days later, once vigilance has declined.

The overlooked risks: conversations and exposed screens

Cybersecurity is not limited to tools. Events encourage informal conversations, often in open spaces. Strategic discussions, financial information and internal decisions may be exposed, deliberately or otherwise.

A visible screen, including a smartphone without a privacy filter, an overly detailed conversation or a job title displayed on a badge can be enough to reconstruct an exploitable context. In this environment, discretion remains an underestimated security measure.

A discipline in its own right

A professional event should no longer be treated merely as a networking opportunity. It is a temporary concentration point for data, identities and connections, making it particularly attractive to opportunistic threat actors.

For attendees, the right approach is neither fear nor excessive restriction, but one straightforward rule: behave as though the environment cannot be trusted by default.

As the boundary between the physical and digital worlds continues to blur, cybersecurity at events is becoming a natural extension of basic professional hygiene.

EDITORIAL TEAM

To contact us, we have created a short form to help us process your request efficiently and handle it in complete confidentiality. Click here to access it.

Related Articles

Back to top button