A nonprofit asks whether an open guest SSID plus captive portal is secure enough for staff workflows that handle PII. What is the sound OSWP-aligned answer?
Select an answer to reveal the explanation.
Short Explanation
A guest portal is a bouncer for coffee-shop Wi-Fi, not a vault for case files. Staff PII needs real auth and crypto, not a splash page. Do not dress Internet gating up as enterprise confidentiality.
Full Explanation
Open networks with captive portals primarily enforce acceptable-use or access gating before Internet use. They do not provide the authentication and encryption strength expected for sensitive staff data workflows. Stronger modes such as WPA2/WPA3-Enterprise with sound EAP methods are appropriate for PII-bearing corporate traffic. Treating guest portal design as sufficient for regulated staff workloads is a fitness-for-purpose failure.