CtrlShiftIT
Security guide

Man-in-the-Middle Attacks for Small Business

A man-in-the-middle attack means traffic passes through an untrusted point where it can be observed, redirected, or tampered with. For small businesses, the practical concern is usually unsafe Wi-Fi, rogue access points, unmanaged devices, or staff working from locations the business does not control.

Modern HTTPS and cloud apps reduce a lot of old interception risk, but they do not remove every issue. Staff can still be led to fake portals, prompted by captive networks, exposed through unmanaged devices, or tricked into trusting the wrong network.

What it means

The “middle” is any network position between the user and the service they meant to reach. That could be a fake Wi-Fi network, an unsafe guest network, a compromised router, or a malicious hotspot portal.

The goal for defenders is to make trusted paths easy and risky paths obvious. Managed devices, secure Wi-Fi, browser updates, certificate warnings, and clear staff guidance all help.

How it affects small businesses

A consultant working from a cafe, a clinic employee using guest Wi-Fi, or a law clerk travelling between client sites may all connect through networks the business does not manage. If the device is unmanaged or users ignore browser warnings, credentials and sessions become harder to protect.

The impact is often identity-related: fake login pages, session exposure, or staff trusting the wrong portal. That is why this topic connects closely to MFA, Conditional Access, compliant devices, and phishing protection.

Warning Signs & First Controls

Warning signs and first controls

  • Unexpected certificate warnings: Users should report browser security warnings instead of clicking through them.
  • Duplicate or lookalike Wi-Fi names: Networks with similar names near the office can confuse staff and guests.
  • Captive portals asking for work credentials: Public Wi-Fi portals should not request Microsoft 365 passwords.
  • Sign-ins from unmanaged devices: Microsoft 365 logs may show access from devices outside the business management baseline.
  • Use trusted office Wi-Fi designs: Separate staff, guest, and device networks with strong encryption and documented access.
  • Require managed devices for sensitive access: Conditional Access can limit high-risk apps to compliant or trusted devices.
  • Keep browsers and operating systems updated: Modern browser security helps users identify unsafe certificates and suspicious redirects.
  • Use VPN where it fits the workflow: A VPN can protect traffic on untrusted networks, especially for internal resources.
  • Train users on practical signals: Teach staff to stop on certificate warnings, fake portals, and unexpected login prompts.
ops@ctrlshiftit: ~/guides

Want this mapped to your own tenant?

We can review accounts, endpoints, remote access, and backup readiness against this guide.

no obligation~30 minutesGTA-based engineers