Securing shared workspaces: How to protect business-critical data in open environments

Get in touch

daniel dsouza
Head of Information Security Solutions, Canon Business Services ANZ

Daniel D'Souza is a highly accomplished Information Security professional with a wealth of experience spanning over a decade. His professional journey has covered multiple market sectors including finance, insurance, technology, education, and consulting. The latest of which led him to join the dynamic team at Satalyst, a Canon Business Services Australia company, as an Information Security Manager. In this role, Daniel was instrumental in helping customers safeguard their digital assets, protect their data, and mature their Information Security control environment. 

In recognition of his expertise Daniel was then transitioned into a pivotal secondment as the Manager of IT Governance, Risk & Compliance within Canon Business Services. Daniel's scrupulous oversight in ensuring key security audits and assessments were delivered has not only strengthened the implementation of CBS’ governance framework, but also substantiated a robust security infrastructure, both for CBS and its customers. 

Currently serving as the Head of Information Security Solutions at CBS, Daniel’s insightful approach to cybersecurity leadership plays a key role in ensuring CBS customers leverage the latest in Information Security technology and services. In this role he brings together strategic vision and a team of highly skilled cyber security professionals with vast real-world experience in reducing business risk through cyber resilience. 

Last updated Tuesday 18 August 2026
Open, flexible work has changed what the modern workplace looks like. Teams now move between corporate offices, coworking spaces, home setups, airport lounges, cafés, and client sites, often in the same week.

That agility brings real benefits. It supports collaboration, talent flexibility, and faster decision-making. But it also changes the security equation.

In shared spaces, business-critical data is more exposed than many leaders realise. The risk isn't limited to hackers exploiting public Wi-Fi. It also includes overheard conversations, unlocked screens, shared devices, misdirected files, weak access controls, and everyday human shortcuts.

The potential threat surface is both digital and physical. For organisations handling personal information, sensitive data, financial information, intellectual property, or regulated records, that matters. Effective shared workspace security protects people, devices, networks, and data wherever work happens.

"Flexible work should increase productivity, not increase risk. Security needs to evolve alongside the way people work," explains Daniel D'Souza, CBS Head of Information Security.

This shift accelerated during the COVID-19 pandemic. In 2020, the FBI reportedly recorded a 400% increase in cyberattack complaints as work rapidly moved outside traditional offices. While that figure reflects a particular point in the pandemic rather than today’s baseline, it shows how quickly potential threats followed employees into less controlled environments.

Why shared workspaces create a different security problem

Traditional offices offered clearer boundaries. Devices stayed on site. Access was easier to control. Conversations happened behind closed doors.

A shared environment is different by design. We've built our coworking spaces for openness, mobility, and convenience. That openness is precisely what makes the space more productive and potentially riskier.

In a coworking space, employees sit near contractors, competitors, visitors, or members of the public.

In a hybrid office, teams often assume a familiar space is secure when desks and meeting rooms are used by multiple people throughout the day.

In public settings, staff may connect through untrusted Wi-Fi networks, discuss confidential matters within earshot of strangers, or work on devices visible to anyone passing by.

The result isn't a single glaring vulnerability. It's a chain of small exposures that, together, create significant security risks. Coworking spaces increase the likelihood of data breaches, data theft, and unauthorised access because people, devices, and information move through shared networks and communal facilities.

Privacy matters here, too. A 2020 survey of coworking employees found 48% cited a lack of privacy as one of the biggest challenges of using a coworking space. That concern is practical, not abstract. It affects what can be seen on screens, what can be heard in conversations, and how confidently people can handle sensitive information.

The security gap is often behavioural, not just technical

Cybersecurity discussions often start with tools. Firewalls. VPNs. Endpoint protection. Identity management. These are still essential. But in a shared environment, behaviour becomes just as important as technology.

Think about shoulder surfing. A single glance at a visible screen can expose personal information, customer records, pricing models, financial forecasts, or login credentials. Visual hacking doesn't require sophisticated software. Someone only needs a clear view of the screen.

Consider device sharing. An employee lending a laptop “just for a minute” can bypass security policies entirely. Australian Cyber Security Centre guidance warns that shared devices can expose or delete important information and may become infected with malware. In a coworking space, malware can then spread through file sharing, removable storage, or insecure network connections.

What about verbal disclosure? Teams discussing restructuring, client matters, medical, legal or financial details, or commercially sensitive negotiations in open areas can reveal more than they intend. Confidential meetings should take place in a private office, soundproof booth, or another controlled space... not beside the coffee machine.

Insider threats also deserve attention. A rogue employee, contractor, or visitor may deliberately steal information, while a well-meaning user can create the same outcome through carelessness. The security risk is similar: sensitive data falls into the hands of someone unauthorised to access it.

These aren't edge cases. They're normal workplace behaviours in the wrong setting. And because they feel ordinary, they're easy to overlook.

"Most workspace risks are not caused by technology gaps. They come from behaviours, visibility, and access that organisations have not fully considered."

Daniel D'Souza, Head of Information Security at Canon Business Services ANZ (CBS)


That's one reason data security leaders are shifting from perimeter-based thinking to context-based control. The question isn't simply whether a user is inside the corporate network. It's whether the user, device, connection, and physical environment are trustworthy enough for the data being accessed.

Physical security and digital security now overlap

In shared workspaces, physical and digital security are no longer separate disciplines. They intersect constantly.

A secure laptop isn't secure if it's left unattended in a communal kitchen. A well-configured collaboration platform isn't enough if it displays sensitive documents in meeting rooms with glass walls. A strong password policy loses value if a user takes a call about payroll in a public lounge.

Security breaks down when digital controls assume physical privacy that doesn't exist.

This overlap is why organisations need to think beyond traditional IT controls. Screen privacy filters, automatic screen locks, secure print release, clean-desk practices, visitor management, and private call zones all play a role alongside device encryption, two-factor authentication, conditional access, and endpoint security.

Coworking space operators and tenant organisations can also implement controlled access systems to restrict entry to authorised members. Keycards, mobile credentials, biometric access control using fingerprints or facial recognition, and turnstiles can help manage entry and high foot traffic.

These protective measures work best when you cancel access cards promptly, maintain visitor records, and employees report suspicious behaviour or lost credentials. Organisations can also monitor physical access to private office areas, meeting rooms, storage facilities, and network equipment.

A clean-desk policy is equally practical. Don't leave sensitive documents on desks, printers, or in shared meeting rooms. Lockable storage can safeguard confidential papers, portable drives, and other information assets. When you no longer need information, you can shred confidential papers and securely erase or sanitise digital devices before disposal.

The aim is simple: reduce the likelihood that information can be seen, heard, shared, modified, or accessed by the wrong person, whether intentionally or accidentally.

"Good security should be built into everyday work, not added as an obstacle after the fact," Daniel says.

Why access control matters more in open environments

When people work across multiple locations, access control becomes one of the most effective ways to contain risk. Not everyone needs access to everything, everywhere, all at once.

Role-based access, least-privilege models, and conditional access policies help reduce unnecessary exposure. The principle of least privilege limits each user to the systems, data, and services required for their role. Segmenting sensitive information by business function, project, or data classification adds another layer of control.

If someone loses a device, hijacks a session, or works from an insecure location, tightly governing access from the start significantly reduces the impact. Strong authentication, access logs, and regular reviews also help organisations monitor unusual activity and respond before it becomes a breach.

This is especially important as collaboration tools become the default workspace. File-sharing platforms, messaging apps, virtual meeting tools, and AI-enabled productivity platforms have made business communication faster. They've also multiplied the number of places where sensitive data and personal information can live, move, and be copied.

Used well, these platforms provide genuine benefit without compromising data security. Used poorly, they create a sprawling, inadequately monitored data footprint across software, cloud storage, devices, and third-party services.

"The goal is not to restrict collaboration. It is to put sensible controls around it," Daniel explains.


Public Wi-Fi and shared networks need extra care

Public Wi-Fi is convenient, but convenience isn't a control. Open, unsecured, or fraudulent Wi-Fi networks can allow attackers to intercept traffic, capture credentials, or place malicious files on a device.

These incidents are sometimes described as man-in-the-middle attacks because an attacker positions themselves between the user and the network or service they're trying to reach. A fake Wi-Fi network may even imitate the name of a legitimate coworking space, café, hotel, or airport network.

The Australian Cyber Security Centre recommends checking the correct Wi-Fi network name, disabling automatic connection and file sharing, avoiding open networks, and reconsidering whether sensitive information should be accessed at all. Where you can't avoid public Wi-Fi, a reputable VPN can encrypt internet traffic and provide an additional layer of protection. A private mobile connection or a trusted office network is the safer choice.

Employees should also keep devices and software up to date, use two-factor or stronger multi-factor authentication, and install approved antivirus and endpoint protection software. Updates address known weaknesses attackers may otherwise use to gain access to systems.

For a coworking space or shared office, network design matters as well. Separate guest Wi-Fi from business systems, segment shared networks, and monitor access to servers, cloud services, and data repositories. A single flat network can turn one compromised device into a much broader business risk.

Practical protections for individuals and teams

The strongest coworking space and shared-workspace security strategies aren't usually the flashiest. They're clear, repeatable, and easy to adopt.

Employees should:
  • Lock screens whenever they step away, even briefly, and enable an automatic lock after a short period.
  • Avoid public Wi-Fi where possible and use a trusted office network, secure hotspot, or reputable VPN.
  • Confirm the Wi-Fi network name before connecting and disable automatic connection and file sharing.
  • Move sensitive conversations and confidential meetings to a private office, a soundproof room, or encrypted channel.
  • Never share devices casually or leave shared devices signed in.
  • Clear personal information and business data from shared equipment immediately after use.
  • Store and transfer sensitive documents through approved collaboration platforms, not personal email, consumer apps, or unencrypted USB drives.
  • Keep software, devices, and security tools up to date.
  • Implement multi-factor authentication on work accounts.
  • Report suspicious behaviour, lost access cards, missing devices, and suspected data breaches immediately.
  • Recognise when a coworking space, café, train or public lounge is unsuitable for handling sensitive information.

Teams also need guidance on context. Not every task belongs in every setting. Reviewing quarterly results on a train, discussing a grievance in a coworking booth, or editing contracts over café Wi-Fi might be convenient, but convenience isn't a security measure.

What the Privacy Act and Australian Privacy Principles require

Security in shared environments can't rest on individual vigilance alone. It needs organisational backing and, in many cases, legal compliance.

The Privacy Act 1988 is the primary Australian Government legislation regulating how personal information is handled. It generally covers Australian Government agencies and organisations with annual turnover above $3 million, along with certain organisations below that annual turnover threshold. Some smaller health service providers and businesses that trade in personal information, for example, may still have Privacy Act obligations. State and territory government agencies may be subject to separate privacy regulations.

For workplace security, Australian Privacy Principle 11 is important. It requires covered organisations and agencies take reasonable steps to protect personal information held from misuse, interference and loss, as well as unauthorised access, modification, or disclosure.

These can include:
  • Governance and employee training
  • Internal security practices and procedures
  • ICT, network and software security
  • Physical security and access control
  • Third-party provider oversight
  • Data breach preparation and response
  • Secure destruction or de-identification

The Australian Privacy Principles connect digital data protection with the physical security of records, devices, and workspaces. The more sensitive the personal information held, and the greater the potential consequences of a breach, the stronger the reasonable steps an organisation may be expected to implement.

The wider Australian Privacy Principles also affect how organisations manage information outside the traditional office. They govern when to collect personal information, how organisations use or disclose personal information, and when sensitive information requires additional consent.

This doesn't mean every coworking space incident is automatically a Privacy Act breach. But organisations should understand:

  • What personal information it collects and holds
  • Which users, employees, agencies, and service providers have access
  • Where to store personal information
  • How to disclose personal information
  • Whether you can send information overseas
  • How privacy policies, security measures, and workplace practices operate in the real world

The Privacy and Other Legislation Amendment Act 2024 strengthened parts of Australia’s privacy framework and the Australian Privacy Commissioner’s regulatory powers. Serious interferences with privacy can attract substantial penalties. For a body corporate, the maximum can be the greater of $50 million, three times the benefit obtained, or—where that benefit cannot be determined—30% of adjusted turnover during the relevant breach period.

Ensuring compliance, therefore, can't be treated as a paperwork exercise. Organisations should regularly review whether their policies, access controls, and security practices genuinely protect personal information across offices, coworking spaces, cloud services, and employee devices.

Disclaimer: This information is provided for general informational purposes only and does not constitute legal advice. For more information about the Privacy Act 1988 and the Australian Privacy Principles, visit the OAIC website: Privacy Act and Australian Privacy Principles Guidelines.

Preparing for and responding to data breaches

A data breach occurs when personal information is lost or subjected to unauthorised access or disclosure.
data breach in shared spaces
Under the Notifiable Data Breaches scheme, an organisation or Australian Government agency covered by the Privacy Act must notify affected individuals and the OAIC when an eligible breach is likely to cause serious harm. The notification should explain the breach and provide individuals with practical steps they can take.

Don't wait for a breach to decide who is responsible. A practical response plan should establish:

  • How employees report lost devices, suspicious access, or accidental disclosure
  • Who assesses whether an incident presents a significant security risk or is likely to cause serious harm
  • How to revoke access and isolate compromised devices
  • How to inform affected individuals, leaders, insurers, and regulators
  • How to preserve access logs and network records
  • How to translate lessons into improved controls and training
Security and privacy obligations evolve as threats, technology, and working practices change. Review and test your response processes regularly, rather than assuming a policy written for a traditional office will protect a mobile workforce.

What should leaders build into policy and governance?

Define where sensitive work can occur with clear expectations, guidelines on which services and tools to use, how to protect devices, when printing is permitted, and what kinds of conversations require private spaces.

Bring-your-own-device policies, privacy policies, collaboration rules, data classification frameworks, and incident reporting practices should reflect the reality of hybrid and open work. Leaders can pressure-test controls through privacy impact assessments, shared workspace security risk reviews, access audits, and regular training. They should also monitor emerging threats and reassess protective measures whenever their workforce, network, software, services, or coworking space arrangements change.

Policies are only useful if they match how people actually work.

The strategic opportunity

There's a broader lesson here. Shared work isn't going away. Nor should it. Flexibility is now part of how modern organisations operate, collaborate, and compete. The goal isn't to retreat from open environments, but to secure them intelligently. "As workplaces become more open and connected, organisations need to be just as deliberate about protecting information as they are about enabling collaboration," Daniel says.

That means designing for real rather than ideal behaviour. It means accepting security risk follows people, devices, and data across locations. And it means implementing guardrails that make secure work the easy default, not the burdensome exception.

For executive leaders, the question isn't whether shared workspaces are productive. They are. The question is whether security, privacy, governance, and compliance have evolved at the same pace.

In many organisations, that's where the real gap still sits.

How CBS helps

Canon Business Services ANZ helps organisations secure modern workplaces without sacrificing flexibility.

We bring together stronger information governance, secure collaboration, access controls, and practical risk management to protect business-critical data across shared, hybrid and open environments.

Because workplace security takes more than technology alone, we help put the right people, processes, and protections in place to reduce risk, safeguard trust, and support productive teams.

Get in touch to see how Canon Business Services ANZ can help strengthen workplace security for the way your teams work today.

Similar Articles

View all

A guide on AI fraud detection

Explore how AI fraud detection enhances security of businesses in Australia. Learn about machine learning algorithms, benefits, challenges, and best practices.

APRA CPS 230 & the future of IT compliance

Ensure IT compliance with APRA CPS 230. Learn how AI and automation help enterprises build resilience in a changing regulatory landscape.

What is Security Automation?

Learn how automated security transforms cybersecurity, making it simpler and more efficient. Protect your business data with CBS Australia's expert insights now!

What are the benefits of penetration testing?

Gain confidence in your digital security with the benefits of penetration testing. Enhance cybersecurity, identify vulnerabilities, and fortify your defences with CBS Australia's expert insights now!

Cybersecurity Threat Detection: Proactive strategies

Stay ahead in cybersecurity with our 2024 guide on threat detection. Learn advanced technologies & response plans to protect your business against threats with CBS Australia.

Cybersecurity risk assessment

Learn how to protect your business with a detailed cybersecurity risk assessment. Start now to identify threats and secure your digital assets!

CIO vs CISO: Key differences

Uncover the distinct roles of CIO and CISO in Australian business: Key responsibilities, overlaps, and IT leadership evolution.

Digital transformation in different industries

Discover how digital transformation is driving innovation across industries like healthcare, finance, and retail in Australia. Learn more.

Essential 8 maturity levels

Learn about Essential 8 Maturity Levels to protect your business from cyber threats. Discover strategies to enhance security for Australian organisations. Start meeting compliance standards today.

How do you prevent phishing attacks?

Prevent phishing attacks with MFA, anti-phishing tools, and employee training to safeguard sensitive information and stay secure with Cannon Business Services Australia!

Ultimate guide to internal penetration testing

This Internal Penetration Testing guide covers techniques, analysis, and best practices for identifying vulnerabilities & strengthening your cyber defense in Australia.

Understanding the key differences of MSP vs MSSP

Explore the nuances of MSP vs. MSSP for Australian businesses in our latest blog. Uncover key differences, cybersecurity insights, and make informed choices for your business. Find out more!