Working From a Manhattan Co-Working Space? Lock Down Your Company Data
Your landlord runs your network, strangers share your printer, and the desk behind you can read your screen. Here's the fix for each of those, threat by threat.
Co-working makes complete sense for small NYC teams, flexible leases, no build-out, conference rooms on demand. But understand the deal you've made: you've outsourced your office network to your landlord, and you share it with every other tenant on the floor. When we onboard a co-working-based client onto our NYC support plans, we run the same threat-by-threat review. Here it is, with the fixes we actually deploy.
Threat: the shared network itself
The member Wi-Fi at most co-working spaces is one flat network. Unless the operator has done client isolation properly (many haven't, we check, and you should ask), other members' devices can see yours. That means a compromised laptop two desks over can scan for open file shares, outdated services, and unpatched machines. In one Flatiron space we assessed, a quick scan from a member seat showed 60+ visible devices, including other companies' NAS boxes with default admin pages exposed.
The fix
Treat the member Wi-Fi like airport Wi-Fi. Every company device runs an always-on VPN or (better) a zero-trust agent that encrypts all traffic and makes the device invisible to the local network. Turn off all file/printer sharing and network discovery on every laptop. If your space offers a private VLAN or dedicated office network (most premium operators will, for $100-$300/month), buy it. It's the single best security dollar a co-working tenant can spend.
Threat: the shared printer
Underrated and genuinely messy. Shared printers spool documents to local storage, and printouts sit in the output tray for anyone to collect. We've watched a payroll report sit on a co-working printer tray for twenty minutes. There's also the upload path: printing via a space's "email this address" feature sends your document through systems you don't control and can't audit.
The fix
Policy first, hardware second. Rule: nothing with client names, financials, or PII goes to the shared printer, period. If your team prints sensitive material regularly, a $250 desktop laser printer locked in your private office pays for itself instantly. For the rare big job, use the space's secure-release printing if it exists (badge-to-print), and stand at the machine.
Threat: shoulder surfing and visual exposure
Manhattan co-working floors are dense. The person at the hot desk behind your account manager can read client emails, deal terms, and credentials off the screen with zero technical skill. This sounds quaint next to network attacks; it's also the easiest data leak in the building and the one we see ignored most.
The fix
Privacy filters ($30-$60 per laptop) on any machine handling client data, they cut viewing angles to roughly 30 degrees and end the problem. Auto-lock screens at 2-3 minutes, enforced by policy rather than honor system. And seat the people working on sensitive accounts with their backs to a wall. Low-tech, costs almost nothing, closes a real gap.
Threat: the lost or stolen laptop
Open floors, communal kitchens, after-hours events with guests, laptops walk out of co-working spaces at a rate private offices never see. The laptop itself is a $1,500 problem. The unencrypted client data on it is the actual incident, and depending on what's on the disk, potentially a notifiable one.
The fix
Full-disk encryption (BitLocker on Windows, FileVault on Mac) enforced on every device, not "enabled where someone remembered." Device management (Intune or equivalent) so a missing laptop can be located and remote-wiped within minutes of being reported. And cloud-first file storage so the laptop holds synced copies, not the only copies, which is also why backup belongs in this stack even when "everything's in the cloud."
Threat: credentials, the universal skeleton key
Every threat above gets dramatically worse if one phished password unlocks your email, files, and accounting system. Co-working teams are remote-access-heavy by nature, which means identity is your real perimeter, there is no office firewall standing between an attacker with a valid password and your data. The wire-fraud playbook that follows a compromised mailbox is its own subject; we cover it in our post on email compromise attacks against NYC businesses.
The fix
MFA on everything (email, file storage, accounting, password manager) with no exceptions for executives (attackers target them first, not last). A company password manager so credentials are unique per service. And phishing-resistant methods (authenticator app or hardware key, not SMS) for anyone who can move money or change payroll details.
The co-working security baseline we deploy
For a 5-15 person team, this full stack typically runs $15-$30 per user per month in tooling, less than one month of one hot desk:
- Zero-trust network access or always-on VPN Member Wi-Fi treated as hostile; all traffic encrypted, devices invisible to neighbors.
- MFA everywhere + password manager Identity is the perimeter; phishing-resistant methods for anyone who touches money.
- Full-disk encryption + remote wipe Enforced by device management, not by memo. A lost laptop becomes a hardware cost, not a breach.
- EDR on every endpoint Because the machine next to yours on the member network might already be compromised.
- Written co-working policy Printer rules, screen locks, guest rules, hotspot fallback for sensitive work, and who to call when a device goes missing.
One page, signed by everyone
The policy piece matters more than teams expect. Ours fits on a single page: what never goes to the shared printer, when to use the phone hotspot instead of member Wi-Fi (wire transfers, payroll, anything with credentials), screen-lock and privacy-filter rules, and the 15-minute reporting rule for lost devices. New hires sign it during onboarding. Boring, effective, free.
Questions to ask your co-working operator this week
- Is client isolation enabled on the member Wi-Fi? (If they can't answer, assume no.)
- Can we get a private VLAN or dedicated SSID for our team, and what does it cost?
- Does the shared printer support badge-release printing?
- Who has admin access to the network, and what happens to logs?
Their answers tell you how much of the stack above you need to carry yourself. Either way, none of it requires anyone in your office, every control listed deploys and runs remotely, which is exactly the model we make the case for in why remote-first IT support wins for NYC offices.
If you want this handled rather than DIY'd, this baseline is part of our standard cybersecurity services and gets bundled into managed IT for co-working-based teams. Book a free IT assessment and we'll review your space's network from a member seat, what we find in the first ten minutes is usually persuasive. More guides like this live on the Setnom blog.
Shared office. Private data. Let's keep it that way.
Book your free IT assessment. We'll review your systems, flag your biggest risks, and show you exactly what reliable, secure IT support looks like, no pressure, no obligation.
- (646) 719-0490
- info@setnomconsulting.com
- Response within one business day