How to Ensure the Cybersecurity of Your Coworking Space on a Daily Basis

A freelancer connected to the Wi-Fi on the fifth floor is downloading a client file while an unknown coworker, two tables away, is using the same network without any access restrictions. This scenario repeats itself every day in most French coworking spaces. The cybersecurity of a coworking space does not rely on a single tool, but on a set of technical reflexes applied daily by managers and members.

Wi-Fi Network Segmentation: The Often Absent First Line of Defense

In many shared spaces, a single Wi-Fi network serves all workstations. It is believed that the password displayed at the reception is sufficient. In reality, on a flat network, any connected device can potentially scan the traffic of others.

The first concrete measure is to separate the network into distinct VLANs: one segment for permanent members, one for occasional visitors, and one for connected devices (printers, cameras). Each VLAN has its own subnet and firewall rules that prohibit lateral communication between segments.

This segmentation is complemented by enabling the WPA3 protocol on each access point and by a captive portal that assigns named credentials rather than a shared password. A manager detailing their measures on Open Syd’s security page shows members that data protection is not just marketing talk, but a verifiable infrastructure.

Feedback on this point varies depending on the size of the space: a coworking space with ten workstations can suffice with a professional router with integrated VLANs, while a site with several hundred members requires a centralized Wi-Fi controller.

Network technician installing and securing the network infrastructure in the server room of a coworking space

Multi-Factor Authentication and Named Access in a Coworking Space

The single password remains the weak link. When a member leaves the space, their access to shared services (NAS, booking platform, billing tool) often persists for weeks. This is an identity management issue, not a technology one.

Each account must be named and associated with multi-factor authentication (MFA). In practice, this means that when logging into the network or an internal service, the member enters their password and then validates it via an authentication app on their phone.

Access removal must follow a simple process: when a member cancels their subscription, their credentials are deactivated the same day. A shared spreadsheet is not sufficient for this tracking. A centralized directory (such as LDAP or a cloud identity management service) is recommended, allowing access to be cut off with one click.

What the NIS2 Directive Changes for Coworkings

The NIS2 directive, transposed in France by the law on the resilience of critical infrastructures and cybersecurity adopted in 2025, does not directly target small coworking spaces. It applies to digital service providers (cloud, hosting) that these spaces use.

The cascading effect is concrete: clients subject to NIS2 now require named access and tested backups from their workplace. A space that cannot provide an inventory of its systems or an incident notification procedure will lose these clients to a better-prepared competitor. The entities concerned must register with ANSSI via the MonEspaceNIS2 platform.

Protection Against Visual Hacking and Physical Leaks

Cybersecurity is not limited to cables and servers. In an open space, a screen visible from the hallway exposes confidential data without any malware intervening.

  • Install privacy filters on shared screens and encourage each member to place one on their laptop. The cost is low, and the effect is immediate.
  • Position workstations so that screens face a wall or partition, never towards a passageway or a glass wall.
  • Always lock your session when leaving your workstation, even to get a coffee. On Windows, the shortcut Win+L takes less than a second.
  • Reserve confidential calls for an acoustic booth or a closed room. A phone conversation with a client heard by ten people constitutes a data leak under GDPR.

Two colleagues discussing a cybersecurity checklist in a semi-private coworking space to protect their data

Choosing Cloud Providers and ANSSI 2026 Reference Framework

A coworking space generally uses several cloud services: reservation management, billing, shared document storage, network monitoring. The choice of these providers has a direct impact on the data protection of members.

The reference framework for cloud service providers, approved by an order dated August 12, 2026, in application of Article 31 of the law of May 21, 2024, creates an official framework for qualifying these services. For a space manager, favoring a cloud provider qualified by ANSSI reduces legal and technical risk.

In practice, three points are checked before signing a contract with a provider:

  • The location of the data (servers in the European Union, outside the reach of the U.S. Cloud Act).
  • The encryption policy at rest and in transit, with keys managed by the client or a trusted third party.
  • The contractual commitments regarding incident notification: the provider must alert within a defined timeframe, compatible with the NIS2 obligations of your members.

Replacing a public cloud tool with a qualified service requires migration time, but a coworking space that stores data from dozens of companies has a responsibility comparable to that of a host.

Daily Cybersecurity Routine for a Shared Space

Tools do not compensate for the lack of discipline. A daily checklist applied by the manager anchors security in the actual operation of the space.

Every morning, it is checked that firmware updates for routers and access points are applied. Uninstalled security patches represent the most exploited entry point by attackers. Every evening, the list of devices connected to the network is reviewed to spot any unknown machines.

Once a month, the restoration of a backup is tested. A backup that has never been tested does not exist. This is also an opportunity to revoke access for former members and update internal documentation.

The cybersecurity of a coworking space relies less on the purchase of equipment than on the rigor of habits. A segmented network, named access, qualified providers, and a daily verification routine form a foundation that each space can implement without a huge budget. The ANSSI 2026 reference framework and NIS2 requirements only accelerate a movement that benefits both managers and members.

How to Ensure the Cybersecurity of Your Coworking Space on a Daily Basis